Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
AdobeReaderPDFonline.exe

Overview

General Information

Sample name:AdobeReaderPDFonline.exe
Analysis ID:1587434
MD5:af1d0f01b01da4da3a9a54b2bee820e9
SHA1:859814a52ba8c1a67468cce646974be9bdece0cb
SHA256:d883efc9e3f21d039ba1bec082b390432ea3f3608657e9ced8682be27c318ec2
Tags:exeuser-zhuzhu0009
Infos:

Detection

Score:88
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected AntiVM3
AI detected suspicious sample
Allocates memory in foreign processes
Drops PE files to the document folder of the user
Drops large PE files
Injects a PE file into a foreign processes
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Writes to foreign memory regions
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Compiles C# or VB.Net code
Contains functionality to query CPU information (cpuid)
Contains long sleeps (>= 3 min)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Launches processes in debugging mode, may be used to hinder debugging
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • AdobeReaderPDFonline.exe (PID: 5056 cmdline: "C:\Users\user\Desktop\AdobeReaderPDFonline.exe" MD5: AF1D0F01B01DA4DA3A9A54B2BEE820E9)
    • csc.exe (PID: 2760 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" MD5: EB80BB1CA9B9C7F516FF69AFCFD75B7D)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000005.00000002.3922060213.0000000007F43000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
    00000005.00000002.3918431665.0000000006B30000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
      00000005.00000002.3918792657.0000000006DA1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
        Process Memory Space: csc.exe PID: 2760JoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
          Process Memory Space: csc.exe PID: 2760JoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
            SourceRuleDescriptionAuthorStrings
            5.2.csc.exe.6b30000.1.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
              5.2.csc.exe.7fca228.2.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security

                System Summary

                barindex
                Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\Users\user\Documents\Elaborate Bytes\HD Tach\hdtach.exe, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\AdobeReaderPDFonline.exe, ProcessId: 5056, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\QualysDLP
                No Suricata rule has matched

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: AdobeReaderPDFonline.exeVirustotal: Detection: 53%Perma Link
                Source: AdobeReaderPDFonline.exeReversingLabs: Detection: 44%
                Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                Source: AdobeReaderPDFonline.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: AdobeReaderPDFonline.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                Source: Binary string: protobuf-net.pdbSHA256}Lq source: csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmp
                Source: Binary string: C:\Source\Repos\DS-Platform\CppInstaller\CppSetup\bin\Win32\Release\CppSetup.pdb source: AdobeReaderPDFonline.exe, hdtach.exe.1.dr
                Source: Binary string: protobuf-net.pdb source: csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmp
                Source: global trafficTCP traffic: 192.168.2.8:49708 -> 181.71.216.203:30203
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: global trafficDNS traffic detected: DNS query: newstaticfreepoint24.ddns-ip.net
                Source: csc.exe, 00000005.00000002.3918792657.0000000007007000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3918792657.0000000006DA1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: http://www.openssl.org/)
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: https://download-lb.utorrent.com/endpoint/utweb/os/riserollout/track/beta
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: https://download-lb.utorrent.com/endpoint/utweb/os/riserollout/track/betahttps://www.bittorrent.com/
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: https://dvpwdfe80sj9.cloudfront.net/f/
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: https://dvpwdfe80sj9.cloudfront.net/o
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: https://dvpwdfe80sj9.cloudfront.net/ohttps://dvpwdfe80sj9.cloudfront.net/zbdhttps://dvpwdfe80sj9.clo
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: https://dvpwdfe80sj9.cloudfront.net/zbd
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: https://github.com/arvidn/libtorrent/blob/master/LICENSE
                Source: csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-net
                Source: csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-netJ
                Source: csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-neti
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: https://github.com/webtorrent/webtorrent/blob/master/LICENSE
                Source: csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/11564914/23354;
                Source: csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3918792657.0000000006DA1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/14436606/23354
                Source: csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/2152978/23354
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: https://www.bittorrent.com/legal/privacy-policy/
                Source: AdobeReaderPDFonline.exe, hdtach.exe.1.drString found in binary or memory: https://www.bittorrent.com/legal/terms-of-use/

                System Summary

                barindex
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeFile dump: hdtach.exe.1.dr 959667331Jump to dropped file
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02603A1D1_2_02603A1D
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E573A1_2_025E573A
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025FE5081_2_025FE508
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F95B41_2_025F95B4
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EAA051_2_025EAA05
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E323F1_2_025E323F
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025FBA3C1_2_025FBA3C
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E723B1_2_025E723B
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F0A211_2_025F0A21
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F12211_2_025F1221
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E22D51_2_025E22D5
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F12CE1_2_025F12CE
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F12C31_2_025F12C3
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EE2821_2_025EE282
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC35D1_2_025EC35D
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F0B6E1_2_025F0B6E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED30E1_2_025ED30E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F0B3F1_2_025F0B3F
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F0B2C1_2_025F0B2C
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E23271_2_025E2327
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F1BDF1_2_025F1BDF
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F0BF71_2_025F0BF7
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025FC3EE1_2_025FC3EE
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EF3901_2_025EF390
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F0BB01_2_025F0BB0
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC8521_2_025EC852
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED8711_2_025ED871
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E48631_2_025E4863
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025FF0611_2_025FF061
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0260282C1_2_0260282C
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F10111_2_025F1011
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EE00A1_2_025EE00A
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED8091_2_025ED809
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F10381_2_025F1038
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED82E1_2_025ED82E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F102F1_2_025F102F
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E48D41_2_025E48D4
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC0C11_2_025EC0C1
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC0BA1_2_025EC0BA
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED9501_2_025ED950
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED96E1_2_025ED96E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026039551_2_02603955
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC1111_2_025EC111
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC90E1_2_025EC90E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC1041_2_025EC104
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E19391_2_025E1939
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E212E1_2_025E212E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED9201_2_025ED920
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F11991_2_025F1199
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E59921_2_025E5992
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026021B01_2_026021B0
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025FE98E1_2_025FE98E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F11A61_2_025F11A6
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC9A11_2_025EC9A1
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02602E781_2_02602E78
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC63D1_2_025EC63D
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC6371_2_025EC637
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F0E2E1_2_025F0E2E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EAEF41_2_025EAEF4
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F5E871_2_025F5E87
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E57451_2_025E5745
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EA76F1_2_025EA76F
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F176D1_2_025F176D
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E1F3C1_2_025E1F3C
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F27DA1_2_025F27DA
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED7D61_2_025ED7D6
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F279E1_2_025F279E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC7851_2_025EC785
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED7BE1_2_025ED7BE
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED7A71_2_025ED7A7
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E2C7B1_2_025E2C7B
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E34731_2_025E3473
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F0C1F1_2_025F0C1F
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EDC301_2_025EDC30
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EDCF61_2_025EDCF6
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E3C951_2_025E3C95
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EDC8E1_2_025EDC8E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EDC861_2_025EDC86
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F2CB81_2_025F2CB8
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F15591_2_025F1559
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F15681_2_025F1568
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EDD241_2_025EDD24
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025FBDD61_2_025FBDD6
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025ED5FF1_2_025ED5FF
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025E65E71_2_025E65E7
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC59E1_2_025EC59E
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026035B91_2_026035B9
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025F25851_2_025F2585
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC5BA1_2_025EC5BA
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EC5A51_2_025EC5A5
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02663E0B1_2_02663E0B
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D7401_2_0266D740
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266788D1_2_0266788D
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026646721_2_02664672
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D6431_2_0266D643
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266464D1_2_0266464D
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266C24D1_2_0266C24D
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02664A581_2_02664A58
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02669A2F1_2_02669A2F
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266BA361_2_0266BA36
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D6351_2_0266D635
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D6E31_2_0266D6E3
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02664AFD1_2_02664AFD
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026686F91_2_026686F9
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02666AD61_2_02666AD6
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026682A41_2_026682A4
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266C6A51_2_0266C6A5
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D6A31_2_0266D6A3
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266C2821_2_0266C282
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D68A1_2_0266D68A
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026686891_2_02668689
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D7771_2_0266D777
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02668B7F1_2_02668B7F
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026687431_2_02668743
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266CF4C1_2_0266CF4C
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266CF511_2_0266CF51
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266835C1_2_0266835C
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026683371_2_02668337
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266A7061_2_0266A706
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266B7EC1_2_0266B7EC
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266CFF41_2_0266CFF4
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266CFFF1_2_0266CFFF
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D3F81_2_0266D3F8
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026697C51_2_026697C5
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026683C81_2_026683C8
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026683D91_2_026683D9
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D3A31_2_0266D3A3
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026697AE1_2_026697AE
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266B7AB1_2_0266B7AB
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026647BA1_2_026647BA
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026697B81_2_026697B8
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02664B811_2_02664B81
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266479B1_2_0266479B
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266C4711_2_0266C471
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02664C481_2_02664C48
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266C4491_2_0266C449
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02664C5A1_2_02664C5A
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266B82D1_2_0266B82D
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266C4291_2_0266C429
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266C4121_2_0266C412
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266481A1_2_0266481A
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026674181_2_02667418
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266C4F51_2_0266C4F5
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D8FE1_2_0266D8FE
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02664C921_2_02664C92
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026651721_2_02665172
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266B1791_2_0266B179
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266854F1_2_0266854F
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266B54F1_2_0266B54F
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266B94A1_2_0266B94A
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026671551_2_02667155
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026699551_2_02669955
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02664D221_2_02664D22
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D93C1_2_0266D93C
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02664D111_2_02664D11
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026649EA1_2_026649EA
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026695FC1_2_026695FC
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266D9D81_2_0266D9D8
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02664DA71_2_02664DA7
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_0266C5A71_2_0266C5A7
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02664DAC1_2_02664DAC
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026685B21_2_026685B2
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_026691821_2_02669182
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_04E930605_2_04E93060
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_04E930545_2_04E93054
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B247985_2_06B24798
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B2C2205_2_06B2C220
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B247885_2_06B24788
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B2C5475_2_06B2C547
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B2D2505_2_06B2D250
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B23E565_2_06B23E56
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B23DB05_2_06B23DB0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B23DE05_2_06B23DE0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B24A4A5_2_06B24A4A
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B249225_2_06B24922
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_093D31205_2_093D3120
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_093D5F805_2_093D5F80
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_093D13F05_2_093D13F0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_093D07D85_2_093D07D8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_093D31135_2_093D3113
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_093D1DB05_2_093D1DB0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_093D1DC05_2_093D1DC0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_093D0B205_2_093D0B20
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_093D32FF5_2_093D32FF
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_095ACB385_2_095ACB38
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_095AE2985_2_095AE298
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_095AE2895_2_095AE289
                Source: AdobeReaderPDFonline.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: classification engineClassification label: mal88.evad.winEXE@3/1@1/1
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeFile created: C:\Users\user\Documents\Elaborate BytesJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMutant created: NULL
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMutant created: \Sessions\1\BaseNamedObjects\mono1234
                Source: AdobeReaderPDFonline.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: AdobeReaderPDFonline.exeVirustotal: Detection: 53%
                Source: AdobeReaderPDFonline.exeReversingLabs: Detection: 44%
                Source: AdobeReaderPDFonline.exeString found in binary or memory: <LAUNCH_CHECKBOX>Launch the application on exit</LAUNCH_CHECKBOX>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: n al cerrar</LAUNCH_CHECKBOX>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: <LAUNCH_RADIO>Launch</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: <LAUNCH_RADIO>Iniciar</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: <LAUNCH_RADIO>Arrancar</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: <LAUNCH_RADIO>Uruchom</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: <LAUNCH_RADIO>Spustit</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: <LAUNCH_RADIO>Start</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: hren</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: </LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: <LAUNCH_RADIO>Lancer</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: <LAUNCH_RADIO>Avvia</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: <LAUNCH_RADIO>Starten</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: lat</LAUNCH_RADIO>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: </LAUNCH_ICON>
                Source: AdobeReaderPDFonline.exeString found in binary or memory: </LAUNCH_BTN>
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeFile read: C:\Users\user\Desktop\AdobeReaderPDFonline.exeJump to behavior
                Source: unknownProcess created: C:\Users\user\Desktop\AdobeReaderPDFonline.exe "C:\Users\user\Desktop\AdobeReaderPDFonline.exe"
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"Jump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: msimg32.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: oledlg.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: version.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: oleacc.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: winmm.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: a.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: mscoree.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: version.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: amsi.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: wbemcomn.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                Source: AdobeReaderPDFonline.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
                Source: AdobeReaderPDFonline.exeStatic file information: File size 5835776 > 1048576
                Source: AdobeReaderPDFonline.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x217c00
                Source: AdobeReaderPDFonline.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x2e2400
                Source: AdobeReaderPDFonline.exeStatic PE information: More than 200 imports for USER32.dll
                Source: AdobeReaderPDFonline.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
                Source: AdobeReaderPDFonline.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
                Source: AdobeReaderPDFonline.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
                Source: AdobeReaderPDFonline.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                Source: AdobeReaderPDFonline.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
                Source: AdobeReaderPDFonline.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
                Source: AdobeReaderPDFonline.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                Source: AdobeReaderPDFonline.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                Source: Binary string: protobuf-net.pdbSHA256}Lq source: csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmp
                Source: Binary string: C:\Source\Repos\DS-Platform\CppInstaller\CppSetup\bin\Win32\Release\CppSetup.pdb source: AdobeReaderPDFonline.exe, hdtach.exe.1.dr
                Source: Binary string: protobuf-net.pdb source: csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmp

                Data Obfuscation

                barindex
                Source: Yara matchFile source: 5.2.csc.exe.6b30000.1.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 5.2.csc.exe.7fca228.2.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000005.00000002.3922060213.0000000007F43000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000005.00000002.3918431665.0000000006B30000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000005.00000002.3918792657.0000000006DA1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: csc.exe PID: 2760, type: MEMORYSTR
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"Jump to behavior
                Source: AdobeReaderPDFonline.exeStatic PE information: real checksum: 0x46342c should be: 0x59eb74
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EEA7E pushad ; iretd 1_2_025EEA7F
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EEA76 pushad ; iretd 1_2_025EEA77
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_025EE458 push E0810001h; iretd 1_2_025EE45D
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_04E965C9 push ecx; iretd 5_2_04E965CC
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_04E971B3 push ecx; ret 5_2_04E971CC
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_06B289AE push es; iretd 5_2_06B289B8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_095ABC90 pushad ; iretd 5_2_095ABC91
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeCode function: 5_2_097D8E9F push E9000002h; ret 5_2_097D8EA4

                Persistence and Installation Behavior

                barindex
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeFile created: C:\Users\user\Documents\Elaborate Bytes\HD Tach\hdtach.exeJump to dropped file
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeFile created: C:\Users\user\Documents\Elaborate Bytes\HD Tach\hdtach.exeJump to dropped file
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run QualysDLPJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run QualysDLPJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                Malware Analysis System Evasion

                barindex
                Source: Yara matchFile source: Process Memory Space: csc.exe PID: 2760, type: MEMORYSTR
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMemory allocated: 4E50000 memory reserve | memory write watchJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMemory allocated: 6DA0000 memory reserve | memory write watchJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMemory allocated: 69C0000 memory reserve | memory write watchJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWindow / User API: threadDelayed 3823Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWindow / User API: threadDelayed 6024Jump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeDropped PE file which has not been started: C:\Users\user\Documents\Elaborate Bytes\HD Tach\hdtach.exeJump to dropped file
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeAPI coverage: 6.1 %
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -23980767295822402s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -60000s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -59875s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 6532Thread sleep count: 3823 > 30Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 6532Thread sleep count: 6024 > 30Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -59766s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -59656s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -59547s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -59433s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -59328s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -59219s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -59094s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -58984s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -58875s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -58766s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -58656s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -58547s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -58438s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -58313s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -58203s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -58086s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -57969s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -57859s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -57750s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -57640s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -57531s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -57422s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -57313s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -57188s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -57069s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -56932s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -56808s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -56703s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -56592s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -56484s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -56375s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -56255s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -56106s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -56000s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -55886s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -55781s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -55610s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -55326s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -55192s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -55063s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -54953s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -54844s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -54734s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -54625s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -54516s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -54406s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -54297s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -54187s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe TID: 7136Thread sleep time: -54077s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 60000Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59875Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59766Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59656Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59547Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59433Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59328Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59219Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 59094Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58984Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58875Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58766Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58656Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58547Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58438Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58313Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58203Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 58086Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57969Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57859Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57750Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57640Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57531Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57422Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57313Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57188Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 57069Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56932Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56808Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56703Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56592Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56484Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56375Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56255Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56106Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 56000Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 55886Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 55781Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 55610Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 55326Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 55192Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 55063Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 54953Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 54844Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 54734Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 54625Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 54516Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 54406Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 54297Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 54187Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeThread delayed: delay time: 54077Jump to behavior
                Source: csc.exe, 00000005.00000002.3923374044.00000000097F0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dlleratC
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeProcess information queried: ProcessInformationJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess token adjusted: DebugJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeMemory allocated: page read and write | page guardJump to behavior

                HIPS / PFW / Operating System Protection Evasion

                barindex
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 4710000 protect: page readonlyJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 4710000 value starts with: 4D5AJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 4710000Jump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe base: 4858008Jump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_02606565 cpuid 1_2_02606565
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\AdobeReaderPDFonline.exeCode function: 1_2_005CD4D4 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,1_2_005CD4D4
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity InformationAcquire InfrastructureValid Accounts131
                Windows Management Instrumentation
                1
                Registry Run Keys / Startup Folder
                31
                Process Injection
                1
                Masquerading
                OS Credential Dumping1
                System Time Discovery
                Remote Services1
                Archive Collected Data
                1
                Encrypted Channel
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault Accounts2
                Command and Scripting Interpreter
                1
                DLL Side-Loading
                1
                Registry Run Keys / Startup Folder
                11
                Disable or Modify Tools
                LSASS Memory121
                Security Software Discovery
                Remote Desktop ProtocolData from Removable Media1
                Non-Standard Port
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                DLL Side-Loading
                141
                Virtualization/Sandbox Evasion
                Security Account Manager1
                Process Discovery
                SMB/Windows Admin SharesData from Network Shared Drive1
                Non-Application Layer Protocol
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook31
                Process Injection
                NTDS141
                Virtualization/Sandbox Evasion
                Distributed Component Object ModelInput Capture1
                Application Layer Protocol
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                Obfuscated Files or Information
                LSA Secrets1
                Application Window Discovery
                SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                DLL Side-Loading
                Cached Domain Credentials134
                System Information Discovery
                VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                windows-stand
                SourceDetectionScannerLabelLink
                AdobeReaderPDFonline.exe54%VirustotalBrowse
                AdobeReaderPDFonline.exe45%ReversingLabsWin32.Adware.RedCap
                No Antivirus matches
                No Antivirus matches
                No Antivirus matches
                SourceDetectionScannerLabelLink
                https://download-lb.utorrent.com/endpoint/utweb/os/riserollout/track/beta0%Avira URL Cloudsafe
                https://dvpwdfe80sj9.cloudfront.net/f/0%Avira URL Cloudsafe
                https://dvpwdfe80sj9.cloudfront.net/o0%Avira URL Cloudsafe
                https://dvpwdfe80sj9.cloudfront.net/ohttps://dvpwdfe80sj9.cloudfront.net/zbdhttps://dvpwdfe80sj9.clo0%Avira URL Cloudsafe
                https://download-lb.utorrent.com/endpoint/utweb/os/riserollout/track/betahttps://www.bittorrent.com/0%Avira URL Cloudsafe
                https://dvpwdfe80sj9.cloudfront.net/zbd0%Avira URL Cloudsafe
                NameIPActiveMaliciousAntivirus DetectionReputation
                newstaticfreepoint24.ddns-ip.net
                181.71.216.203
                truefalse
                  high
                  NameSourceMaliciousAntivirus DetectionReputation
                  https://download-lb.utorrent.com/endpoint/utweb/os/riserollout/track/betahttps://www.bittorrent.com/AdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://github.com/mgravell/protobuf-neticsc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    https://stackoverflow.com/q/14436606/23354csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3918792657.0000000006DA1000.00000004.00000800.00020000.00000000.sdmpfalse
                      high
                      https://github.com/mgravell/protobuf-netJcsc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmpfalse
                        high
                        https://dvpwdfe80sj9.cloudfront.net/f/AdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://www.bittorrent.com/legal/privacy-policy/AdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                          high
                          https://stackoverflow.com/q/11564914/23354;csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            https://stackoverflow.com/q/2152978/23354csc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              https://github.com/webtorrent/webtorrent/blob/master/LICENSEAdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                                high
                                https://github.com/mgravell/protobuf-netcsc.exe, 00000005.00000003.1715936571.000000000835C000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3922905850.0000000009550000.00000004.08000000.00040000.00000000.sdmp, csc.exe, 00000005.00000003.1715936571.0000000008222000.00000004.00000800.00020000.00000000.sdmpfalse
                                  high
                                  http://www.openssl.org/)AdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                                    high
                                    https://download-lb.utorrent.com/endpoint/utweb/os/riserollout/track/betaAdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namecsc.exe, 00000005.00000002.3918792657.0000000007007000.00000004.00000800.00020000.00000000.sdmp, csc.exe, 00000005.00000002.3918792657.0000000006DA1000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      https://dvpwdfe80sj9.cloudfront.net/zbdAdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://github.com/arvidn/libtorrent/blob/master/LICENSEAdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                                        high
                                        https://www.bittorrent.com/legal/terms-of-use/AdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                                          high
                                          https://dvpwdfe80sj9.cloudfront.net/oAdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          https://dvpwdfe80sj9.cloudfront.net/ohttps://dvpwdfe80sj9.cloudfront.net/zbdhttps://dvpwdfe80sj9.cloAdobeReaderPDFonline.exe, hdtach.exe.1.drfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          • No. of IPs < 25%
                                          • 25% < No. of IPs < 50%
                                          • 50% < No. of IPs < 75%
                                          • 75% < No. of IPs
                                          IPDomainCountryFlagASNASN NameMalicious
                                          181.71.216.203
                                          newstaticfreepoint24.ddns-ip.netColombia
                                          27831ColombiaMovilCOfalse
                                          Joe Sandbox version:42.0.0 Malachite
                                          Analysis ID:1587434
                                          Start date and time:2025-01-10 11:33:09 +01:00
                                          Joe Sandbox product:CloudBasic
                                          Overall analysis duration:0h 9m 17s
                                          Hypervisor based Inspection enabled:false
                                          Report type:full
                                          Cookbook file name:default.jbs
                                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                          Number of analysed new started processes analysed:9
                                          Number of new started drivers analysed:0
                                          Number of existing processes analysed:0
                                          Number of existing drivers analysed:0
                                          Number of injected processes analysed:0
                                          Technologies:
                                          • HCA enabled
                                          • EGA enabled
                                          • AMSI enabled
                                          Analysis Mode:default
                                          Analysis stop reason:Timeout
                                          Sample name:AdobeReaderPDFonline.exe
                                          Detection:MAL
                                          Classification:mal88.evad.winEXE@3/1@1/1
                                          EGA Information:
                                          • Successful, ratio: 100%
                                          HCA Information:
                                          • Successful, ratio: 85%
                                          • Number of executed functions: 268
                                          • Number of non-executed functions: 71
                                          Cookbook Comments:
                                          • Found application associated with file extension: .exe
                                          • Override analysis time to 240000 for current running targets taking high CPU consumption
                                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                                          • Excluded IPs from analysis (whitelisted): 20.109.210.53
                                          • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                          • Not all processes where analyzed, report is missing behavior information
                                          • Report size exceeded maximum capacity and may have missing disassembly code.
                                          • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                          • Report size getting too big, too many NtQueryValueKey calls found.
                                          TimeTypeDescription
                                          05:34:35API Interceptor9611153x Sleep call for process: csc.exe modified
                                          11:34:38AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run QualysDLP C:\Users\user\Documents\Elaborate Bytes\HD Tach\hdtach.exe
                                          11:34:46AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run QualysDLP C:\Users\user\Documents\Elaborate Bytes\HD Tach\hdtach.exe
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          181.71.216.203PDFonlineseguro.exeGet hashmaliciousUnknownBrowse
                                            AdobePremierPDF.exeGet hashmaliciousUnknownBrowse
                                              2LDJIyMl2r.exeGet hashmaliciousRemcosBrowse
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                newstaticfreepoint24.ddns-ip.netPDFonlineseguro.exeGet hashmaliciousUnknownBrowse
                                                • 181.71.216.203
                                                AdobePremierPDF.exeGet hashmaliciousUnknownBrowse
                                                • 181.71.216.203
                                                2LDJIyMl2r.exeGet hashmaliciousRemcosBrowse
                                                • 181.71.216.203
                                                SHROsQyiAd.exeGet hashmaliciousRemcosBrowse
                                                • 181.131.217.244
                                                4JwhvqLe8n.exeGet hashmaliciousRemcosBrowse
                                                • 181.131.217.244
                                                fIPSLgT0lO.exeGet hashmaliciousRemcosBrowse
                                                • 181.131.217.244
                                                3XSXmrEOw7.exeGet hashmaliciousRemcosBrowse
                                                • 181.131.217.244
                                                ozfqy8Ms6t.exeGet hashmaliciousRemcosBrowse
                                                • 181.131.217.244
                                                pPLwX9wSrD.exeGet hashmaliciousRemcosBrowse
                                                • 181.131.217.244
                                                hCJ8gK9kNn.exeGet hashmaliciousRemcosBrowse
                                                • 181.131.217.244
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                ColombiaMovilCOPDFonlineseguro.exeGet hashmaliciousUnknownBrowse
                                                • 181.71.216.203
                                                AdobePremierPDF.exeGet hashmaliciousUnknownBrowse
                                                • 181.71.216.203
                                                1736491685b40eefbc9bdfbc98216071e6ff3a4c19c7e1ab8a144cde35036665da85346b6b949.dat-decoded.exeGet hashmaliciousRemcosBrowse
                                                • 179.15.136.6
                                                6.elfGet hashmaliciousUnknownBrowse
                                                • 181.70.170.80
                                                173634822473cd620521fcc8b42a4aac25bbd1c3f6e30c324045b1411f9747e93f432d0281839.dat-decoded.exeGet hashmaliciousRemcosBrowse
                                                • 179.15.136.6
                                                1736348224ad77cf86e491faad27e4b5decf1eb0bb26f16b0527e5ef488389ba353aa3db79582.dat-decoded.exeGet hashmaliciousRemcosBrowse
                                                • 179.15.136.6
                                                17363482247f60133f013d62aae38c531ac95bb55a200a243b0e15fa7cf8e8923b2a10590f952.dat-decoded.exeGet hashmaliciousRemcosBrowse
                                                • 179.15.136.6
                                                1736348224f7603a5c535b2b2f6cc29730626d73a967c67551d2d14f73b547fe7b5fc10393994.dat-decoded.exeGet hashmaliciousRemcosBrowse
                                                • 179.15.136.6
                                                1736348224bd83df4c8d79407f8e7ac5cf8c08b59746ce37ff95772daa0a6283b50e2b0882115.dat-decoded.exeGet hashmaliciousRemcosBrowse
                                                • 179.15.136.6
                                                17363482249a873460757a9239193679567953c11d17b898ff9845034e34f5d2e7f4521342673.dat-decoded.exeGet hashmaliciousRemcosBrowse
                                                • 179.15.136.6
                                                No context
                                                No context
                                                Process:C:\Users\user\Desktop\AdobeReaderPDFonline.exe
                                                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                Category:dropped
                                                Size (bytes):959667331
                                                Entropy (8bit):0.08625462809460394
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:1ED9B1C1CC1AD0A0002A3CE083DC9D5F
                                                SHA1:CA8788C1C7FA2F39304E8AA2B8276C928B4B7165
                                                SHA-256:50C929F7C263A067D323E03CA02B3F18EDE373CFD53E89DCE9EEF589BB469826
                                                SHA-512:99B974DBD3F000B44C7D2F9245AD17BD909FDCA8CE1E3196BC0162760264CD3C859488847EBFA6ADA03359B4582C248E14E96862B748887F0221DB7A84780B7D
                                                Malicious:true
                                                Reputation:low
                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........7..V...V...V......V......V....."V......V......V...V..U..5...V..5...V..5..YW......V....p..V...V...V......V..Rich.V..........PE..L.....Eg...............'.|!...7...............!...@...........................Y.....,4F...@.................................|.)......`+.4"............E..(...`C.P...p.'.p.....................'.......'.@.............!..............................text.....!......|!................. ..`.rdata........!.......!.............@..@.data.... ...@*......,*.............@....rsrc...4"...`+..$....*.............@..@........................................................................................................................................................................................................................................................................................................................................
                                                File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                Entropy (8bit):7.0634954672891475
                                                TrID:
                                                • Win32 Executable (generic) a (10002005/4) 99.96%
                                                • Generic Win/DOS Executable (2004/3) 0.02%
                                                • DOS Executable Generic (2002/1) 0.02%
                                                • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                File name:AdobeReaderPDFonline.exe
                                                File size:5'835'776 bytes
                                                MD5:af1d0f01b01da4da3a9a54b2bee820e9
                                                SHA1:859814a52ba8c1a67468cce646974be9bdece0cb
                                                SHA256:d883efc9e3f21d039ba1bec082b390432ea3f3608657e9ced8682be27c318ec2
                                                SHA512:5ddcb57d828f1b33bed2c9a72a9eede38f7601fcf9e4e34f69f6b17363db41a2362799b3bf36be61cc0851c9d309137a1210c3d4c916349a2d1724ebb7909c35
                                                SSDEEP:98304:9jYWohHXZ64z3lrxA0+IbvT3916Floj9ghi1RebMIg9Cbk/VFE/nIV3MwBReUcRR:9jYWqXZ6wF3916vojDIg9Cbk/VK/nqbO
                                                TLSH:7246BF327D4A445BD07212716A69E975A13E6D78273202C363E47F3F7831AC2293BE67
                                                File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........7...V...V...V.......V.......V......"V.......V.......V...V...U..5....V..5....V..5...YW.......V....p..V...V...V.......V..Rich.V.
                                                Icon Hash:335092b3b2c66517
                                                Entrypoint:0x5cc6df
                                                Entrypoint Section:.text
                                                Digitally signed:true
                                                Imagebase:0x400000
                                                Subsystem:windows gui
                                                Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                Time Stamp:0x67459109 [Tue Nov 26 09:12:41 2024 UTC]
                                                TLS Callbacks:
                                                CLR (.Net) Version:
                                                OS Version Major:6
                                                OS Version Minor:0
                                                File Version Major:6
                                                File Version Minor:0
                                                Subsystem Version Major:6
                                                Subsystem Version Minor:0
                                                Import Hash:b48ec932e0b94d3910a5e2592ad0d9cf
                                                Signature Valid:
                                                Signature Issuer:
                                                Signature Validation Error:
                                                Error Number:
                                                Not Before, Not After
                                                  Subject Chain
                                                    Version:
                                                    Thumbprint MD5:
                                                    Thumbprint SHA-1:
                                                    Thumbprint SHA-256:
                                                    Serial:
                                                    Instruction
                                                    call 00007F165CC6DDC2h
                                                    jmp 00007F165CC6CDFFh
                                                    cmp ecx, dword ptr [006A5000h]
                                                    jne 00007F165CC6CF83h
                                                    ret
                                                    jmp 00007F165CC6D981h
                                                    push ebp
                                                    mov ebp, esp
                                                    push esi
                                                    mov esi, 006B34E4h
                                                    push esi
                                                    call dword ptr [006192E8h]
                                                    mov eax, dword ptr [ebp+08h]
                                                    push esi
                                                    and dword ptr [eax], 00000000h
                                                    call dword ptr [006192ECh]
                                                    push 006B34E0h
                                                    call dword ptr [006192E4h]
                                                    pop esi
                                                    pop ebp
                                                    ret
                                                    push ebp
                                                    mov ebp, esp
                                                    push esi
                                                    mov esi, 006B34E4h
                                                    push esi
                                                    call dword ptr [006192E8h]
                                                    mov ecx, dword ptr [006A4FF0h]
                                                    mov eax, dword ptr [ebp+08h]
                                                    inc ecx
                                                    mov dword ptr [006A4FF0h], ecx
                                                    push esi
                                                    mov dword ptr [eax], ecx
                                                    mov eax, dword ptr fs:[0000002Ch]
                                                    mov ecx, dword ptr [006B3844h]
                                                    mov ecx, dword ptr [eax+ecx*4]
                                                    mov eax, dword ptr [006A4FF0h]
                                                    mov dword ptr [ecx+00000004h], eax
                                                    call dword ptr [006192ECh]
                                                    push 006B34E0h
                                                    call dword ptr [006192E4h]
                                                    pop esi
                                                    pop ebp
                                                    ret
                                                    push ebp
                                                    mov ebp, esp
                                                    push esi
                                                    push edi
                                                    mov edi, 006B34E4h
                                                    push edi
                                                    call dword ptr [006192E8h]
                                                    mov esi, dword ptr [ebp+08h]
                                                    cmp dword ptr [esi], 00000000h
                                                    jne 00007F165CC6CF8Eh
                                                    or dword ptr [esi], FFFFFFFFh
                                                    jmp 00007F165CC6CFA8h
                                                    call 00007F165CC6CFB1h
                                                    jmp 00007F165CC6CF71h
                                                    cmp dword ptr [esi], FFFFFFFFh
                                                    je 00007F165CC6CF76h
                                                    mov eax, dword ptr fs:[0000002Ch]
                                                    mov ecx, dword ptr [00003844h]
                                                    NameVirtual AddressVirtual Size Is in Section
                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x29fe7c0x1b8.rdata
                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x2b60000x2e2234.rsrc
                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x4586000x2800.rsrc
                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x4360000x2ab50.rsrc
                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x278c700x70.rdata
                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_TLS0x278d000x18.rdata
                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x278bb00x40.rdata
                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_IAT0x2190000xad0.rdata
                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                    .text0x10000x2180000x217c00bf8442e1a060d6a6110e5353f0b7e4f0unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                    .rdata0x2190000x8b0000x8ac00c071b645d904afddfae36d09fbff0a76False0.33050218186936936data5.546535578758396IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                    .data0x2a40000x120000xbc00df682c1e69ad36bfcf32c628e7178a04False0.17351645611702127data5.056360385601096IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                    .rsrc0x2b60000x2e22340x2e24007e9251cd98c2809c7f0a338118d8a199unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                                    AFX_DIALOG_LAYOUT0x2cb1740x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1780x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb17c0x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1800x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1840x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1880x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb18c0x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1900x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1940x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1980x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb19c0x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1a00x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1a40x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1a80x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1ac0x2dataEnglishUnited States5.0
                                                    AFX_DIALOG_LAYOUT0x2cb1b00x2dataEnglishUnited States5.0
                                                    IMAGE_BLOB0x2cb1b40x6182PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9983174425126192
                                                    IMAGE_BLOB20x2d13380x57e4PNG image data, 512 x 512, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9663111111111111
                                                    IMAGE_BLOB30x2d6b1c0x6050PNG image data, 512 x 512, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9756245944192083
                                                    LOCALE0x2dcb6c0xb1fXML 1.0 document, ASCII text, with very long lines (345), with CRLF line terminatorsEnglishUnited States0.4130663856691254
                                                    LOCALE0x2dd68c0xb1fXML 1.0 document, Unicode text, UTF-8 text, with very long lines (344), with CRLF line terminatorsEnglishUnited States0.4260625219529329
                                                    LOCALE0x2de1ac0xa65XML 1.0 document, ASCII text, with very long lines (344), with CRLF line terminatorsEnglishUnited States0.4269071777527245
                                                    LOCALE0x2dec140xac8XML 1.0 document, Unicode text, UTF-8 text, with very long lines (343), with CRLF line terminatorsEnglishUnited States0.43623188405797103
                                                    LOCALE0x2df6dc0xafcXML 1.0 document, Unicode text, UTF-8 text, with very long lines (346), with CRLF line terminatorsEnglishUnited States0.4317211948790896
                                                    LOCALE0x2e01d80xb1aXML 1.0 document, Unicode text, UTF-8 text, with very long lines (367), with CRLF line terminatorsEnglishUnited States0.45918367346938777
                                                    LOCALE0x2e0cf40xaf3XML 1.0 document, Unicode text, UTF-8 text, with very long lines (353), with CRLF line terminatorsEnglishUnited States0.4659293613985016
                                                    LOCALE0x2e17e80xa94XML 1.0 document, Unicode text, UTF-8 text, with very long lines (356), with CRLF line terminatorsEnglishUnited States0.4324224519940916
                                                    LOCALE0x2e227c0xb98XML 1.0 document, Unicode text, UTF-8 text, with very long lines (426), with CRLF line terminatorsEnglishUnited States0.4366576819407008
                                                    LOCALE0x2e2e140xaa2XML 1.0 document, Unicode text, UTF-8 text, with very long lines (349), with CRLF line terminatorsEnglishUnited States0.44305657604702425
                                                    LOCALE0x2e38b80xb6bXML 1.0 document, Unicode text, UTF-8 text, with very long lines (381), with CRLF line terminatorsEnglishUnited States0.43345877523092713
                                                    LOCALE0x2e44240xad7XML 1.0 document, Unicode text, UTF-8 text, with very long lines (365), with CRLF line terminatorsEnglishUnited States0.43963963963963965
                                                    LOCALE0x2e4efc0xb00XML 1.0 document, Unicode text, UTF-8 text, with very long lines (406), with CRLF line terminatorsEnglishUnited States0.43785511363636365
                                                    LOCALE0x2e59fc0xb1aXML 1.0 document, Unicode text, UTF-8 text, with very long lines (367), with CRLF line terminatorsEnglishUnited States0.45918367346938777
                                                    LOCALE0x2e65180xde9XML 1.0 document, Unicode text, UTF-8 text, with very long lines (366), with CRLF line terminatorsEnglishUnited States0.41224375175512495
                                                    LOCALE0x2e73040xadaXML 1.0 document, Unicode text, UTF-8 text, with very long lines (348), with CRLF line terminatorsEnglishUnited States0.4474442044636429
                                                    LOCALE0x2e7de00x1f1fexported SGML document, Unicode text, UTF-8 text, with very long lines (1357), with CRLF line terminatorsEnglishUnited States0.3887285050834693
                                                    PNG0x2e9d000x77PNG image data, 4 x 4, 8-bit/color RGB, non-interlacedEnglishUnited States0.9915966386554622
                                                    PNG0x2e9d780x2f5PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0145310435931307
                                                    PNG0x2ea0700x301PNG image data, 70 x 31, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0143042912873863
                                                    PNG0x2ea3740x287PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.017001545595054
                                                    PNG0x2ea5fc0x36ePNG image data, 22 x 40, 8-bit/color RGB, non-interlacedEnglishUnited States1.0125284738041003
                                                    PNG0x2ea96c0x15dPNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0315186246418337
                                                    PNG0x2eaacc0x13ePNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0345911949685536
                                                    PNG0x2eac0c0x115PNG image data, 30 x 24, 8-bit/color RGB, non-interlacedEnglishUnited States1.03971119133574
                                                    PNG0x2ead240x12aPNG image data, 20 x 40, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0302013422818792
                                                    PNG0x2eae500x20cPNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.0209923664122138
                                                    PNG0x2eb05c0xfdPNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.0276679841897234
                                                    PNG0x2eb15c0xa6PNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                    PNG0x2eb2040x7cPNG image data, 3 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9919354838709677
                                                    PNG0x2eb2800x96PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.0133333333333334
                                                    PNG0x2eb3180x91PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.006896551724138
                                                    PNG0x2eb3ac0x84PNG image data, 15 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States0.9848484848484849
                                                    PNG0x2eb4300xa3PNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0122699386503067
                                                    PNG0x2eb4d40x771PNG image data, 13 x 156, 8-bit/color RGB, non-interlacedEnglishUnited States1.005774278215223
                                                    PNG0x2ebc480x697PNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.006520450503853
                                                    PNG0x2ec2e00x342PNG image data, 30 x 16, 8-bit/color RGBA, non-interlacedEnglishUnited States1.013189448441247
                                                    PNG0x2ec6240x45fPNG image data, 24 x 72, 8-bit/color RGB, non-interlacedEnglishUnited States1.0098302055406614
                                                    PNG0x2eca840x1a3PNG image data, 20 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.026252983293556
                                                    PNG0x2ecc280xac8PNG image data, 24 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0039855072463768
                                                    PNG0x2ed6f00x37cPNG image data, 8 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0123318385650224
                                                    PNG0x2eda6c0xa50PNG image data, 24 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0041666666666667
                                                    PNG0x2ee4bc0x48ePNG image data, 9 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009433962264151
                                                    PNG0x2ee94c0xa50PNG image data, 24 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0041666666666667
                                                    PNG0x2ef39c0x380PNG image data, 8 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0122767857142858
                                                    PNG0x2ef71c0xab0PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0040204678362572
                                                    PNG0x2f01cc0xb1fPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0038637161924833
                                                    PNG0x2f0cec0xa8ePNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0040710584752035
                                                    PNG0x2f177c0xb30PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003840782122905
                                                    PNG0x2f22ac0x3a6PNG image data, 48 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011777301927195
                                                    PNG0x2f26540x111bPNG image data, 38 x 114, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0025119890385932
                                                    PNG0x2f37700x3d1PNG image data, 23 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0112589559877174
                                                    PNG0x2f3b440x21bPNG image data, 11 x 88, 8-bit/color RGB, non-interlacedEnglishUnited States1.0204081632653061
                                                    PNG0x2f3d600xb12PNG image data, 50 x 273, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003881439661256
                                                    PNG0x2f48740x7acPNG image data, 50 x 162, 8-bit/color RGBA, non-interlacedEnglishUnited States1.005600814663951
                                                    PNG0x2f50200xd43PNG image data, 50 x 264, 8-bit/color RGB, non-interlacedEnglishUnited States1.003240058910162
                                                    PNG0x2f5d640x3a4PNG image data, 22 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011802575107296
                                                    PNG0x2f61080x320PNG image data, 14 x 246, 8-bit/color RGBA, non-interlacedEnglishUnited States1.01375
                                                    PNG0x2f64280x31fPNG image data, 14 x 246, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0137672090112642
                                                    PNG0x2f67480x2bdPNG image data, 15 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0156918687589158
                                                    PNG0x2f6a080x273PNG image data, 15 x 76, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0175438596491229
                                                    PNG0x2f6c7c0x2c9PNG image data, 15 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0154277699859748
                                                    PNG0x2f6f480x163PNG image data, 70 x 66, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0112676056338028
                                                    PNG0x2f70ac0x152PNG image data, 41 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.032544378698225
                                                    PNG0x2f72000x38aPNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0121412803532008
                                                    PNG0x2f758c0x532PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082706766917293
                                                    PNG0x2f7ac00x19cPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8810679611650486
                                                    PNG0x2f7c5c0x2296PNG image data, 72 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.001242376327084
                                                    PNG0x2f9ef40x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                    PNG0x2fa5940x1c4PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8252212389380531
                                                    PNG0x2fa7580x522PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.008371385083714
                                                    PNG0x2fac7c0x2475PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.000750026786671
                                                    PNG0x2fd0f40x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                    PNG0x2fd7940x1c3PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8314855875831486
                                                    PNG0x2fd9580x505PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0085603112840467
                                                    PNG0x2fde600x24d3PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0004243131430997
                                                    PNG0x3003340x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                    PNG0x3009d40x1c7PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.832967032967033
                                                    PNG0x300b9c0x536PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082458770614693
                                                    PNG0x3010d40x24f0PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0011632825719121
                                                    PNG0x3035c40x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                    PNG0x303c640x1c5PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8388520971302428
                                                    PNG0x303e2c0x4d9PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.008863819500403
                                                    PNG0x3043080x23d3PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0
                                                    PNG0x3066dc0x189PNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0279898218829517
                                                    PNG0x3068680x1bcPNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States0.7027027027027027
                                                    PNG0x306a240x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                    PNG0x3070c40x1c4PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.827433628318584
                                                    PNG0x3072880x4efPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0087094220110848
                                                    PNG0x3077780x23a2PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0007673755755317
                                                    PNG0x309b1c0xc5PNG image data, 3 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0253807106598984
                                                    PNG0x309be40x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                    PNG0x30a2840x1baPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8212669683257918
                                                    PNG0x30a4400x4e4PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0087859424920127
                                                    PNG0x30a9240x250fPNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0005270369979973
                                                    PNG0x30ce340x69ePNG image data, 52 x 268, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0064935064935066
                                                    PNG0x30d4d40x1c2PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8288888888888889
                                                    PNG0x30d6980x4e9PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0087509944311854
                                                    PNG0x30db840x23c6PNG image data, 76 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.000436776588775
                                                    PNG0x30ff4c0xb5PNG image data, 15 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0165745856353592
                                                    PNG0x3100040x186PNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.028205128205128
                                                    PNG0x31018c0x1b5PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States0.6864988558352403
                                                    PNG0x3103440x66PNG image data, 1 x 46, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9803921568627451
                                                    PNG0x3103ac0xf9PNG image data, 90 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0321285140562249
                                                    PNG0x3104a80x17c3PNG image data, 86 x 240, 8-bit/color RGBA, non-interlacedEnglishUnited States0.992931119513398
                                                    PNG0x311c6c0x283PNG image data, 86 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0171073094867806
                                                    PNG0x311ef00x71PNG image data, 5 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9823008849557522
                                                    PNG0x311f640x71dPNG image data, 16 x 48, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0060406370126305
                                                    PNG0x3126840x794PNG image data, 16 x 48, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0056701030927835
                                                    PNG0x312e180x284PNG image data, 7 x 39, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0170807453416149
                                                    PNG0x31309c0x203PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.021359223300971
                                                    PNG0x3132a00x1b5PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0251716247139588
                                                    PNG0x3134580xb2PNG image data, 2 x 20, 8-bit/color RGB, non-interlacedEnglishUnited States1.0168539325842696
                                                    PNG0x31350c0xd1PNG image data, 11 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9760765550239234
                                                    PNG0x3135e00x21cPNG image data, 21 x 42, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0203703703703704
                                                    PNG0x3137fc0x21cPNG image data, 21 x 42, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0203703703703704
                                                    PNG0x313a180x1aePNG image data, 21 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0186046511627906
                                                    PNG0x313bc80x13aPNG image data, 16 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0222929936305734
                                                    PNG0x313d040x13fPNG image data, 21 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0344827586206897
                                                    PNG0x313e440x135PNG image data, 16 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9967637540453075
                                                    PNG0x313f7c0xdbPNG image data, 21 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0228310502283104
                                                    PNG0x3140580xc6PNG image data, 16 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0252525252525253
                                                    PNG0x3141200x1a9PNG image data, 21 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0141176470588236
                                                    PNG0x3142cc0x19bPNG image data, 16 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0194647201946472
                                                    PNG0x3144680x2296PNG image data, 72 x 125, 8-bit/color RGBA, non-interlacedEnglishUnited States1.001242376327084
                                                    PNG0x3167000x13ePNG image data, 72 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0345911949685536
                                                    PNG0x3168400x115PNG image data, 30 x 24, 8-bit/color RGB, non-interlacedEnglishUnited States1.03971119133574
                                                    PNG0x3169580x83PNG image data, 35 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.0076335877862594
                                                    PNG0x3169dc0xcePNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0242718446601942
                                                    PNG0x316aac0xb30PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003840782122905
                                                    PNG0x3175dc0x25fPNG image data, 72 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0181219110378912
                                                    PNG0x31783c0x79PNG image data, 4 x 4, 8-bit/color RGB, non-interlacedEnglishUnited States0.9752066115702479
                                                    PNG0x3178b80x170PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9755434782608695
                                                    PNG0x317a280x26bPNG image data, 70 x 31, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0177705977382876
                                                    PNG0x317c940x105PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9731800766283525
                                                    PNG0x317d9c0xe6PNG image data, 22 x 38, 8-bit/color RGB, non-interlacedEnglishUnited States1.0260869565217392
                                                    PNG0x317e840x38dPNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012101210121012
                                                    PNG0x3182140x265PNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0179445350734095
                                                    PNG0x31847c0x11aPNG image data, 30 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0319148936170213
                                                    PNG0x3185980xaaPNG image data, 2 x 19, 8-bit/color RGB, non-interlacedEnglishUnited States1.011764705882353
                                                    PNG0x3186440x12aPNG image data, 20 x 40, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0268456375838926
                                                    PNG0x3187700x209PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.021113243761996
                                                    PNG0x31897c0xf5PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.0244897959183674
                                                    PNG0x318a740xa6PNG image data, 54 x 31, 8-bit/color RGB, non-interlacedEnglishUnited States1.0180722891566265
                                                    PNG0x318b1c0x150PNG image data, 54 x 124, 8-bit/color RGB, non-interlacedEnglishUnited States1.0327380952380953
                                                    PNG0x318c6c0xacPNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0174418604651163
                                                    PNG0x318d180x89PNG image data, 3 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0
                                                    PNG0x318da40x98PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.006578947368421
                                                    PNG0x318e3c0x91PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.006896551724138
                                                    PNG0x318ed00x7dPNG image data, 15 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.008
                                                    PNG0x318f500xa6PNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                    PNG0x318ff80xbcPNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0159574468085106
                                                    PNG0x3190b40xa07PNG image data, 13 x 156, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004285157771718
                                                    PNG0x319abc0x1de1PNG image data, 52 x 336, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0014380964832004
                                                    PNG0x31b8a00x1bePNG image data, 38 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0246636771300448
                                                    PNG0x31ba600x53bPNG image data, 30 x 16, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082150858849888
                                                    PNG0x31bf9c0x440PNG image data, 22 x 66, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010110294117647
                                                    PNG0x31c3dc0x12ePNG image data, 20 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0298013245033113
                                                    PNG0x31c50c0x5b1PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0075497597803706
                                                    PNG0x31cac00x408PNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0106589147286822
                                                    PNG0x31cec80x471PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009674582233949
                                                    PNG0x31d33c0x4b7PNG image data, 10 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0091135045567523
                                                    PNG0x31d7f40x481PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0095403295750216
                                                    PNG0x31dc780x3ecPNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0109561752988048
                                                    PNG0x31e0640x452PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0099457504520795
                                                    PNG0x31e4b80x414PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010536398467433
                                                    PNG0x31e8cc0x39ePNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011879049676026
                                                    PNG0x31ec6c0x48dPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009442060085837
                                                    PNG0x31f0fc0x1b3PNG image data, 15 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.025287356321839
                                                    PNG0x31f2b00xeaPNG image data, 32 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0299145299145298
                                                    PNG0x31f39c0x1ae0PNG image data, 38 x 114, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0015988372093023
                                                    PNG0x320e7c0xb43PNG image data, 22 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0038154699965314
                                                    PNG0x3219c00x609PNG image data, 11 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0071197411003237
                                                    PNG0x321fcc0x18aePNG image data, 43 x 234, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0017410572966128
                                                    PNG0x32387c0x1177PNG image data, 43 x 135, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0024602997092373
                                                    PNG0x3249f40x25ecPNG image data, 43 x 330, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0011330861145447
                                                    PNG0x326fe00xacbPNG image data, 22 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0039811798769454
                                                    PNG0x327aac0xbc8PNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036472148541113
                                                    PNG0x3286740xc2ePNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0035279025016035
                                                    PNG0x3292a40x5ddPNG image data, 15 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0073284477015323
                                                    PNG0x3298840x597PNG image data, 15 x 76, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0076869322152342
                                                    PNG0x329e1c0x5f8PNG image data, 15 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.007198952879581
                                                    PNG0x32a4140x237PNG image data, 54 x 69, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0194003527336861
                                                    PNG0x32a64c0x588PNG image data, 22 x 44, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0077683615819208
                                                    PNG0x32abd40x4b6PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0091210613598673
                                                    PNG0x32b08c0x532PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082706766917293
                                                    PNG0x32b5c00x5fePNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0071707953063884
                                                    PNG0x32bbc00xdd3PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9960440802486578
                                                    PNG0x32c9940x7cPNG image data, 1 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9919354838709677
                                                    PNG0x32ca100x13c1PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021752026893416
                                                    PNG0x32ddd40x37dPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0123180291153415
                                                    PNG0x32e1540x395PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0119956379498365
                                                    PNG0x32e4ec0x125ePNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023394300297745
                                                    PNG0x32f74c0x13b4PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021808088818398
                                                    PNG0x330b000x369PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126002290950744
                                                    PNG0x330e6c0x3ccPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0113168724279835
                                                    PNG0x3312380x1320PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002246732026144
                                                    PNG0x3325580x13acPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021842732327244
                                                    PNG0x3339040x364PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012672811059908
                                                    PNG0x333c680x3baPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0115303983228512
                                                    PNG0x3340240x1274PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023285351397122
                                                    PNG0x3352980x139fPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021899263388414
                                                    PNG0x3366380x380PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0122767857142858
                                                    PNG0x3369b80x352PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0129411764705882
                                                    PNG0x336d0c0x1288PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002318718381113
                                                    PNG0x337f940x211PNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0207939508506616
                                                    PNG0x3381a80x2e4PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0148648648648648
                                                    PNG0x33848c0x13adPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021838395870557
                                                    PNG0x33983c0x365PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126582278481013
                                                    PNG0x339ba40x374PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                    PNG0x339f180x126bPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023329798515377
                                                    PNG0x33b1840xd4PNG image data, 3 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.028301886792453
                                                    PNG0x33b2580x1394PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.00219473264166
                                                    PNG0x33c5ec0x374PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                    PNG0x33c9600x3f4PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0108695652173914
                                                    PNG0x33cd540x1304PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0022596548890714
                                                    PNG0x33e0580x1397PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021934197407776
                                                    PNG0x33f3f00x373PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0124575311438277
                                                    PNG0x33f7640x33dPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0132689987937273
                                                    PNG0x33faa40x119ePNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002439024390244
                                                    PNG0x340c440xa6PNG image data, 15 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                    PNG0x340cec0x211PNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0207939508506616
                                                    PNG0x340f000x2f7PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0144927536231885
                                                    PNG0x3411f80x16ePNG image data, 9 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.030054644808743
                                                    PNG0x3413680x73PNG image data, 5 x 5, 8-bit/color RGB, non-interlacedEnglishUnited States0.9826086956521739
                                                    PNG0x3413dc0x117PNG image data, 11 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.021505376344086
                                                    PNG0x3414f40x67PNG image data, 2 x 55, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9902912621359223
                                                    PNG0x34155c0xcePNG image data, 90 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0242718446601942
                                                    PNG0x34162c0xa40PNG image data, 86 x 240, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9733231707317073
                                                    PNG0x34206c0x283PNG image data, 86 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0171073094867806
                                                    PNG0x3422f00x93PNG image data, 5 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0136054421768708
                                                    PNG0x3423840x96aPNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004564315352697
                                                    PNG0x342cf00x99bPNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0044733631557543
                                                    PNG0x34368c0x2f7PNG image data, 11 x 45, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0144927536231885
                                                    PNG0x3439840x1ffPNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0215264187866928
                                                    PNG0x343b840x1f7PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.021868787276342
                                                    PNG0x343d7c0xb6PNG image data, 2 x 20, 8-bit/color RGB, non-interlacedEnglishUnited States1.010989010989011
                                                    PNG0x343e340x94PNG image data, 11 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0135135135135136
                                                    PNG0x343ec80x3e6PNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0110220440881763
                                                    PNG0x3442b00x3e6PNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0110220440881763
                                                    PNG0x3446980x315PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0139416983523448
                                                    PNG0x3449b00x259PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0183028286189684
                                                    PNG0x344c0c0x205PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0212765957446808
                                                    PNG0x344e140x176PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0294117647058822
                                                    PNG0x344f8c0x124PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0136986301369864
                                                    PNG0x3450b00xd7PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0
                                                    PNG0x3451880x28fPNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.016793893129771
                                                    PNG0x3454180x225PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0200364298724955
                                                    PNG0x3456400xdd3PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9960440802486578
                                                    PNG0x3464140x123PNG image data, 72 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0378006872852235
                                                    PNG0x3465380x10bPNG image data, 30 x 24, 8-bit/color RGB, non-interlacedEnglishUnited States1.0337078651685394
                                                    PNG0x3466440x83PNG image data, 35 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.0076335877862594
                                                    PNG0x3466c80x12fPNG image data, 9 x 9, 8-bit/color RGB, non-interlacedEnglishUnited States1.0264026402640265
                                                    PNG0x3467f80x48dPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009442060085837
                                                    PNG0x346c880x261PNG image data, 72 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0180623973727423
                                                    PNG0x346eec0x79PNG image data, 4 x 4, 8-bit/color RGB, non-interlacedEnglishUnited States0.9752066115702479
                                                    PNG0x346f680x1b5PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9931350114416476
                                                    PNG0x3471200x293PNG image data, 70 x 31, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0166919575113809
                                                    PNG0x3473b40x11aPNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9716312056737588
                                                    PNG0x3474d00xdePNG image data, 22 x 38, 8-bit/color RGB, non-interlacedEnglishUnited States1.027027027027027
                                                    PNG0x3475b00x38dPNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012101210121012
                                                    PNG0x3479400x265PNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0179445350734095
                                                    PNG0x347ba80x124PNG image data, 30 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0308219178082192
                                                    PNG0x347ccc0xaaPNG image data, 2 x 19, 8-bit/color RGB, non-interlacedEnglishUnited States1.011764705882353
                                                    PNG0x347d780x12aPNG image data, 20 x 40, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0268456375838926
                                                    PNG0x347ea40x209PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.021113243761996
                                                    PNG0x3480b00xf5PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.0244897959183674
                                                    PNG0x3481a80x9fPNG image data, 54 x 31, 8-bit/color RGB, non-interlacedEnglishUnited States1.0125786163522013
                                                    PNG0x3482480x148PNG image data, 54 x 124, 8-bit/color RGB, non-interlacedEnglishUnited States1.0335365853658536
                                                    PNG0x3483900xacPNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0174418604651163
                                                    PNG0x34843c0x8bPNG image data, 3 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States1.014388489208633
                                                    PNG0x3484c80xa4PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.0
                                                    PNG0x34856c0x94PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.0067567567567568
                                                    PNG0x3486000x87PNG image data, 15 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.0
                                                    PNG0x3486880xa6PNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                    PNG0x3487300xc5PNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0203045685279188
                                                    PNG0x3487f80xa54PNG image data, 13 x 156, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004160363086233
                                                    PNG0x34924c0x1edaPNG image data, 52 x 336, 8-bit/color RGBA, non-interlacedEnglishUnited States1.001392757660167
                                                    PNG0x34b1280x1cbPNG image data, 38 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0239651416122004
                                                    PNG0x34b2f40x53bPNG image data, 30 x 16, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082150858849888
                                                    PNG0x34b8300x4f3PNG image data, 22 x 66, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0086819258089976
                                                    PNG0x34bd240x11aPNG image data, 20 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.024822695035461
                                                    PNG0x34be400x5afPNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0075601374570446
                                                    PNG0x34c3f00x3ffPNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010752688172043
                                                    PNG0x34c7f00x461PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0098126672613739
                                                    PNG0x34cc540x4ccPNG image data, 10 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.008957654723127
                                                    PNG0x34d1200x474PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0096491228070175
                                                    PNG0x34d5940x3efPNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0109235352532273
                                                    PNG0x34d9840x44aPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0100182149362478
                                                    PNG0x34ddd00x41fPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0104265402843602
                                                    PNG0x34e1f00x39bPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0119176598049837
                                                    PNG0x34e58c0x4a1PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009282700421941
                                                    PNG0x34ea300x1b3PNG image data, 15 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.025287356321839
                                                    PNG0x34ebe40xf9PNG image data, 32 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.036144578313253
                                                    PNG0x34ece00x1bfaPNG image data, 38 x 114, 8-bit/color RGBA, non-interlacedEnglishUnited States1.001535883831332
                                                    PNG0x3508dc0xb43PNG image data, 22 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0038154699965314
                                                    PNG0x3514200x609PNG image data, 11 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0071197411003237
                                                    PNG0x351a2c0x18aePNG image data, 43 x 234, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0017410572966128
                                                    PNG0x3532dc0x1177PNG image data, 43 x 135, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0024602997092373
                                                    PNG0x3544540x25ecPNG image data, 43 x 330, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0011330861145447
                                                    PNG0x356a400xac7PNG image data, 22 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0039869517941282
                                                    PNG0x3575080xa82PNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004089219330855
                                                    PNG0x357f8c0xac7PNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0039869517941282
                                                    PNG0x358a540x5d3PNG image data, 15 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0073775989268947
                                                    PNG0x3590280x575PNG image data, 15 x 76, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0078740157480315
                                                    PNG0x3595a00x5eaPNG image data, 15 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0072655217965654
                                                    PNG0x359b8c0x222PNG image data, 54 x 69, 8-bit/color RGBA, non-interlacedEnglishUnited States1.02014652014652
                                                    PNG0x359db00x588PNG image data, 22 x 44, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0077683615819208
                                                    PNG0x35a3380x552PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0080763582966226
                                                    PNG0x35a88c0x532PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082706766917293
                                                    PNG0x35adc00x624PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.006997455470738
                                                    PNG0x35b3e40xf6fPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0027841052898
                                                    PNG0x35c3540x98PNG image data, 1 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.013157894736842
                                                    PNG0x35c3ec0x13c1PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021752026893416
                                                    PNG0x35d7b00x37dPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0123180291153415
                                                    PNG0x35db300x395PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0119956379498365
                                                    PNG0x35dec80xbeaPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036065573770492
                                                    PNG0x35eab40x13b4PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021808088818398
                                                    PNG0x35fe680x369PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126002290950744
                                                    PNG0x3601d40x3ccPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0113168724279835
                                                    PNG0x3605a00xcb2PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0033846153846153
                                                    PNG0x3612540x13acPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021842732327244
                                                    PNG0x3626000x364PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012672811059908
                                                    PNG0x3629640x3baPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0115303983228512
                                                    PNG0x362d200xbffPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0035818951481603
                                                    PNG0x3639200x139fPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021899263388414
                                                    PNG0x364cc00x380PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0122767857142858
                                                    PNG0x3650400x352PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0129411764705882
                                                    PNG0x3653940xbf8PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0035900783289817
                                                    PNG0x365f8c0x1e3PNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0227743271221532
                                                    PNG0x3661700x3d2PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0112474437627812
                                                    PNG0x3665440x13adPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021838395870557
                                                    PNG0x3678f40x365PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126582278481013
                                                    PNG0x367c5c0x374PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                    PNG0x367fd00xb9aPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0037037037037038
                                                    PNG0x368b6c0xd4PNG image data, 3 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.028301886792453
                                                    PNG0x368c400x1394PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.00219473264166
                                                    PNG0x369fd40x374PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                    PNG0x36a3480x3f4PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0108695652173914
                                                    PNG0x36a73c0xc62PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034700315457412
                                                    PNG0x36b3a00x1397PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021934197407776
                                                    PNG0x36c7380x373PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0124575311438277
                                                    PNG0x36caac0x33dPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0132689987937273
                                                    PNG0x36cdec0xb84PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0003392130257802
                                                    PNG0x36d9700xb1PNG image data, 15 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0169491525423728
                                                    PNG0x36da240x1daPNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0232067510548524
                                                    PNG0x36dc000x375PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0124293785310734
                                                    PNG0x36df780x1a5PNG image data, 9 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0261282660332542
                                                    PNG0x36e1200x71PNG image data, 5 x 5, 8-bit/color RGB, non-interlacedEnglishUnited States0.9911504424778761
                                                    PNG0x36e1940x11aPNG image data, 11 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0283687943262412
                                                    PNG0x36e2b00x67PNG image data, 2 x 55, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9902912621359223
                                                    PNG0x36e3180xe0PNG image data, 90 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.03125
                                                    PNG0x36e3f80xa40PNG image data, 86 x 240, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9733231707317073
                                                    PNG0x36ee380x283PNG image data, 86 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0171073094867806
                                                    PNG0x36f0bc0x93PNG image data, 5 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0136054421768708
                                                    PNG0x36f1500x985PNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.00451374640952
                                                    PNG0x36fad80x9caPNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.00438946528332
                                                    PNG0x3704a40x339PNG image data, 11 x 45, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0133333333333334
                                                    PNG0x3707e00x214PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0206766917293233
                                                    PNG0x3709f40x22ePNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0197132616487454
                                                    PNG0x370c240xb3PNG image data, 2 x 20, 8-bit/color RGB, non-interlacedEnglishUnited States1.011173184357542
                                                    PNG0x370cd80x95PNG image data, 11 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9932885906040269
                                                    PNG0x370d700x414PNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010536398467433
                                                    PNG0x3711840x414PNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010536398467433
                                                    PNG0x3715980x1fbPNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0216962524654833
                                                    PNG0x3717940x179PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0159151193633953
                                                    PNG0x3719100x179PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0053050397877985
                                                    PNG0x371a8c0x114PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0289855072463767
                                                    PNG0x371ba00x10ePNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011111111111111
                                                    PNG0x371cb00xb6PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0054945054945055
                                                    PNG0x371d680x17ePNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0287958115183247
                                                    PNG0x371ee80x15cPNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0201149425287357
                                                    PNG0x3720440xf6fPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0027841052898
                                                    PNG0x372fb40x143PNG image data, 72 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0340557275541795
                                                    PNG0x3730f80x110PNG image data, 30 x 24, 8-bit/color RGB, non-interlacedEnglishUnited States1.0294117647058822
                                                    PNG0x3732080x87PNG image data, 35 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.0074074074074073
                                                    PNG0x3732900x13bPNG image data, 9 x 9, 8-bit/color RGB, non-interlacedEnglishUnited States1.0253968253968253
                                                    PNG0x3733cc0x4a1PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009282700421941
                                                    PNG0x3738700x25ePNG image data, 72 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.018151815181518
                                                    PNG0x373ad00x79PNG image data, 4 x 4, 8-bit/color RGB, non-interlacedEnglishUnited States0.9752066115702479
                                                    PNG0x373b4c0x167PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9972144846796658
                                                    PNG0x373cb40x278PNG image data, 70 x 31, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0174050632911393
                                                    PNG0x373f2c0x11aPNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9680851063829787
                                                    PNG0x3740480xd4PNG image data, 22 x 38, 8-bit/color RGB, non-interlacedEnglishUnited States1.0235849056603774
                                                    PNG0x37411c0x38dPNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012101210121012
                                                    PNG0x3744ac0x265PNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0179445350734095
                                                    PNG0x3747140x11aPNG image data, 30 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0319148936170213
                                                    PNG0x3748300xaaPNG image data, 2 x 19, 8-bit/color RGB, non-interlacedEnglishUnited States1.011764705882353
                                                    PNG0x3748dc0x12aPNG image data, 20 x 40, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0268456375838926
                                                    PNG0x374a080x209PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.021113243761996
                                                    PNG0x374c140xf5PNG image data, 10 x 28, 8-bit/color RGB, non-interlacedEnglishUnited States1.0244897959183674
                                                    PNG0x374d0c0xa6PNG image data, 54 x 31, 8-bit/color RGB, non-interlacedEnglishUnited States1.0180722891566265
                                                    PNG0x374db40x150PNG image data, 54 x 124, 8-bit/color RGB, non-interlacedEnglishUnited States1.0327380952380953
                                                    PNG0x374f040xacPNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0174418604651163
                                                    PNG0x374fb00x8bPNG image data, 3 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0
                                                    PNG0x37503c0x98PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.006578947368421
                                                    PNG0x3750d40x91PNG image data, 9 x 8, 8-bit/color RGB, non-interlacedEnglishUnited States1.006896551724138
                                                    PNG0x3751680x7dPNG image data, 15 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.008
                                                    PNG0x3751e80xa6PNG image data, 7 x 7, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                    PNG0x3752900xbdPNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0105820105820107
                                                    PNG0x3753500xa07PNG image data, 13 x 156, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004285157771718
                                                    PNG0x375d580x1de1PNG image data, 52 x 336, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0014380964832004
                                                    PNG0x377b3c0x1bePNG image data, 38 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0246636771300448
                                                    PNG0x377cfc0x53bPNG image data, 30 x 16, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082150858849888
                                                    PNG0x3782380x46cPNG image data, 22 x 66, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0097173144876326
                                                    PNG0x3786a40xafPNG image data, 20 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0171428571428571
                                                    PNG0x3787540x701PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0061349693251533
                                                    PNG0x378e580x498PNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0093537414965987
                                                    PNG0x3792f00x5c1PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0074677528852682
                                                    PNG0x3798b40x539PNG image data, 10 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082273747195214
                                                    PNG0x379df00x5c7PNG image data, 23 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0074374577417173
                                                    PNG0x37a3b80x47fPNG image data, 9 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009556907037359
                                                    PNG0x37a8380x585PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0077848549186128
                                                    PNG0x37adc00x546PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0081481481481482
                                                    PNG0x37b3080x4e1PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0088070456365092
                                                    PNG0x37b7ec0x5b0PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.007554945054945
                                                    PNG0x37bd9c0x1b3PNG image data, 15 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.025287356321839
                                                    PNG0x37bf500xeaPNG image data, 32 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0299145299145298
                                                    PNG0x37c03c0x1ad9PNG image data, 38 x 114, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0016004655899897
                                                    PNG0x37db180xb43PNG image data, 22 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0038154699965314
                                                    PNG0x37e65c0x609PNG image data, 11 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0071197411003237
                                                    PNG0x37ec680x18aePNG image data, 43 x 234, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0017410572966128
                                                    PNG0x3805180x1177PNG image data, 43 x 135, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0024602997092373
                                                    PNG0x3816900x25ecPNG image data, 43 x 330, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0011330861145447
                                                    PNG0x383c7c0xad3PNG image data, 22 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0039696860339227
                                                    PNG0x3847500xbc8PNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036472148541113
                                                    PNG0x3853180xc2ePNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0035279025016035
                                                    PNG0x385f480x5ddPNG image data, 15 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0073284477015323
                                                    PNG0x3865280x597PNG image data, 15 x 76, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0076869322152342
                                                    PNG0x386ac00x5f8PNG image data, 15 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.007198952879581
                                                    PNG0x3870b80x228PNG image data, 54 x 69, 8-bit/color RGBA, non-interlacedEnglishUnited States1.019927536231884
                                                    PNG0x3872e00x588PNG image data, 22 x 44, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0077683615819208
                                                    PNG0x3878680x38aPNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0121412803532008
                                                    PNG0x387bf40x532PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082706766917293
                                                    PNG0x3881280x32fPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0134969325153373
                                                    PNG0x3884580xef8PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9950417536534447
                                                    PNG0x3893500x7cPNG image data, 1 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9919354838709677
                                                    PNG0x3893cc0x13c1PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021752026893416
                                                    PNG0x38a7900x37dPNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0123180291153415
                                                    PNG0x38ab100x395PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0119956379498365
                                                    PNG0x38aea80x125ePNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023394300297745
                                                    PNG0x38c1080x13b4PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021808088818398
                                                    PNG0x38d4bc0x369PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126002290950744
                                                    PNG0x38d8280x3ccPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0113168724279835
                                                    PNG0x38dbf40x1320PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002246732026144
                                                    PNG0x38ef140x13acPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021842732327244
                                                    PNG0x3902c00x364PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012672811059908
                                                    PNG0x3906240x3baPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0115303983228512
                                                    PNG0x3909e00x1274PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023285351397122
                                                    PNG0x391c540x139fPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021899263388414
                                                    PNG0x392ff40x380PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0122767857142858
                                                    PNG0x3933740x352PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0129411764705882
                                                    PNG0x3936c80x1288PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002318718381113
                                                    PNG0x3949500x99dPNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004469727752946
                                                    PNG0x3952f00x2e6PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0148247978436657
                                                    PNG0x3955d80x13adPNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021838395870557
                                                    PNG0x3969880x365PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0126582278481013
                                                    PNG0x396cf00x374PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                    PNG0x3970640x126bPNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023329798515377
                                                    PNG0x3982d00xd4PNG image data, 3 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.028301886792453
                                                    PNG0x3983a40x1394PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.00219473264166
                                                    PNG0x3997380x374PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.012443438914027
                                                    PNG0x399aac0x3f4PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0108695652173914
                                                    PNG0x399ea00x1304PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0022596548890714
                                                    PNG0x39b1a40x1397PNG image data, 52 x 252, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021934197407776
                                                    PNG0x39c53c0x373PNG image data, 80 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0124575311438277
                                                    PNG0x39c8b00x33dPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0132689987937273
                                                    PNG0x39cbf00x119ePNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002439024390244
                                                    PNG0x39dd900xa6PNG image data, 15 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0120481927710843
                                                    PNG0x39de380x99dPNG image data, 100 x 34, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004469727752946
                                                    PNG0x39e7d80x2f7PNG image data, 100 x 136, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0144927536231885
                                                    PNG0x39ead00x17ePNG image data, 9 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0287958115183247
                                                    PNG0x39ec500x71PNG image data, 5 x 5, 8-bit/color RGB, non-interlacedEnglishUnited States0.9911504424778761
                                                    PNG0x39ecc40x117PNG image data, 11 x 24, 8-bit/color RGBA, non-interlacedEnglishUnited States1.021505376344086
                                                    PNG0x39eddc0x67PNG image data, 2 x 55, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9902912621359223
                                                    PNG0x39ee440xd7PNG image data, 90 x 12, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0232558139534884
                                                    PNG0x39ef1c0xa40PNG image data, 86 x 240, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9733231707317073
                                                    PNG0x39f95c0x283PNG image data, 86 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0171073094867806
                                                    PNG0x39fbe00x93PNG image data, 5 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0136054421768708
                                                    PNG0x39fc740x96aPNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.004564315352697
                                                    PNG0x3a05e00x99bPNG image data, 18 x 54, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0044733631557543
                                                    PNG0x3a0f7c0x2f7PNG image data, 11 x 45, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0144927536231885
                                                    PNG0x3a12740x1d3PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.019271948608137
                                                    PNG0x3a14480x1f8PNG image data, 70 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0138888888888888
                                                    PNG0x3a16400x67PNG image data, 2 x 20, 8-bit/color RGB, non-interlacedEnglishUnited States0.9514563106796117
                                                    PNG0x3a16a80x95PNG image data, 11 x 11, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0
                                                    PNG0x3a17400x39dPNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011891891891892
                                                    PNG0x3a1ae00x39dPNG image data, 17 x 32, 8-bit/color RGBA, non-interlacedEnglishUnited States1.011891891891892
                                                    PNG0x3a1e800x1c1PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.024498886414254
                                                    PNG0x3a20440x153PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0324483775811208
                                                    PNG0x3a21980x15fPNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0113960113960114
                                                    PNG0x3a22f80x100PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.03515625
                                                    PNG0x3a23f80x108PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.018939393939394
                                                    PNG0x3a25000xb6PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.010989010989011
                                                    PNG0x3a25b80x151PNG image data, 17 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.032640949554896
                                                    PNG0x3a270c0x135PNG image data, 13 x 60, 8-bit/color RGBA, non-interlacedEnglishUnited States1.029126213592233
                                                    PNG0x3a28440xdd3PNG image data, 57 x 120, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9960440802486578
                                                    PNG0x3a36180x129PNG image data, 72 x 15, 8-bit/color RGB, non-interlacedEnglishUnited States1.0303030303030303
                                                    PNG0x3a37440x10bPNG image data, 30 x 24, 8-bit/color RGB, non-interlacedEnglishUnited States1.0337078651685394
                                                    PNG0x3a38500x87PNG image data, 35 x 3, 8-bit/color RGB, non-interlacedEnglishUnited States1.0074074074074073
                                                    PNG0x3a38d80x12fPNG image data, 9 x 9, 8-bit/color RGB, non-interlacedEnglishUnited States1.0264026402640265
                                                    PNG0x3a3a080x48dPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.009442060085837
                                                    PNG0x3a3e980xdd1PNG image data, 72 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003109980209217
                                                    PNG0x3a4c6c0xd61PNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0032116788321168
                                                    PNG0x3a59d00x265PNG image data, 55 x 22, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0179445350734095
                                                    PNG0x3a5c380xbb9PNG image data, 20 x 40, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036654448517162
                                                    PNG0x3a67f40xc66PNG image data, 10 x 28, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034656584751103
                                                    PNG0x3a745c0xb90PNG image data, 10 x 28, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0037162162162163
                                                    PNG0x3a7fec0xb07PNG image data, 5 x 5, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003896563939072
                                                    PNG0x3a8af40xb50PNG image data, 7 x 7, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0037983425414365
                                                    PNG0x3a96440x2885PNG image data, 42 x 348, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0010604453870626
                                                    PNG0x3abecc0xd8ePNG image data, 38 x 38, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031700288184437
                                                    PNG0x3acc5c0x53bPNG image data, 30 x 16, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0082150858849888
                                                    PNG0x3ad1980x4f3PNG image data, 22 x 66, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0086819258089976
                                                    PNG0x3ad68c0x130fPNG image data, 22 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0022545603607296
                                                    PNG0x3ae99c0xe74PNG image data, 10 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002972972972973
                                                    PNG0x3af8100x11baPNG image data, 22 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002423975319524
                                                    PNG0x3b09cc0xecePNG image data, 11 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0029023746701846
                                                    PNG0x3b189c0x11baPNG image data, 22 x 154, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002423975319524
                                                    PNG0x3b2a580xe74PNG image data, 10 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002972972972973
                                                    PNG0x3b38cc0x1206PNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023840485478976
                                                    PNG0x3b4ad40x11bcPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0024229074889868
                                                    PNG0x3b5c900x112aPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0025034137460174
                                                    PNG0x3b6dbc0x127aPNG image data, 22 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023255813953489
                                                    PNG0x3b80380xd3ePNG image data, 15 x 56, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003244837758112
                                                    PNG0x3b8d780xbacPNG image data, 32 x 8, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036813922356091
                                                    PNG0x3b99240x146aPNG image data, 56 x 69, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0021048603138156
                                                    PNG0x3bad900x122fPNG image data, 22 x 132, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023630504833512
                                                    PNG0x3bbfc00xdecPNG image data, 11 x 110, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0030864197530864
                                                    PNG0x3bcdac0x1100PNG image data, 42 x 228, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0025275735294117
                                                    PNG0x3bdeac0x11edPNG image data, 42 x 140, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023970363913706
                                                    PNG0x3bf09c0x1864PNG image data, 42 x 330, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0003203074951954
                                                    PNG0x3c09000x10b5PNG image data, 22 x 88, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0025718961889174
                                                    PNG0x3c19b80x124bPNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023489216314327
                                                    PNG0x3c2c040x1256PNG image data, 14 x 276, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0023434171282488
                                                    PNG0x3c3e5c0xf2cPNG image data, 15 x 80, 8-bit/color RGBA, non-interlacedEnglishUnited States1.002832131822863
                                                    PNG0x3c4d880xedePNG image data, 15 x 76, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0028901734104045
                                                    PNG0x3c5c680xf69PNG image data, 15 x 84, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0027883396704689
                                                    PNG0x3c6bd40xe20PNG image data, 22 x 44, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0030420353982301
                                                    PNG0x3c79f40xdc7PNG image data, 64 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031187978451943
                                                    PNG0x3c87bc0xbaePNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036789297658864
                                                    PNG0x3c936c0xd91PNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003167290526922
                                                    PNG0x3ca1000xb12PNG image data, 1 x 23, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003881439661256
                                                    PNG0x3cac140xbc3PNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036532713384259
                                                    PNG0x3cb7d80xc9fPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003404518724853
                                                    PNG0x3cc4780xd7dPNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031856356791196
                                                    PNG0x3cd1f80xbf7PNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0035912504080966
                                                    PNG0x3cddf00xc96PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034140285536934
                                                    PNG0x3cea880xd8cPNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031718569780854
                                                    PNG0x3cf8140xbdaPNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036255767963085
                                                    PNG0x3d03f00xca0PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034034653465347
                                                    PNG0x3d10900xd80PNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031828703703705
                                                    PNG0x3d1e100xbe2PNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036160420775806
                                                    PNG0x3d29f40xc8cPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034246575342465
                                                    PNG0x3d36800xd7bPNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031874818893074
                                                    PNG0x3d43fc0xbe7PNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036101083032491
                                                    PNG0x3d4fe40xc94PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034161490683229
                                                    PNG0x3d5c780xd80PNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031828703703705
                                                    PNG0x3d69f80xd4PNG image data, 3 x 26, 8-bit/color RGBA, non-interlacedEnglishUnited States1.028301886792453
                                                    PNG0x3d6acc0xbd0PNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003637566137566
                                                    PNG0x3d769c0xc97PNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034129692832765
                                                    PNG0x3d83340xd7aPNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031884057971014
                                                    PNG0x3d90b00xbdaPNG image data, 3 x 92, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0036255767963085
                                                    PNG0x3d9c8c0xc8fPNG image data, 80 x 19, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003421461897356
                                                    PNG0x3da91c0xd86PNG image data, 13 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031773541305604
                                                    PNG0x3db6a40x1908PNG image data, 50 x 178, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9887640449438202
                                                    PNG0x3dcfac0xb75PNG image data, 3 x 61, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0037504261847938
                                                    PNG0x3ddb240xbd0PNG image data, 9 x 51, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003637566137566
                                                    PNG0x3de6f40x1570PNG image data, 18 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0020043731778425
                                                    PNG0x3dfc640x1623PNG image data, 18 x 72, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0019410622904534
                                                    STYLE_XML0x3e12880x4e01HTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.1839851770243878
                                                    STYLE_XML0x3e608c0x4b09HTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.20396689052006872
                                                    STYLE_XML0x3eab980x4aa6HTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.20460491889063318
                                                    STYLE_XML0x3ef6400x4a18HTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.20397511598481655
                                                    STYLE_XML0x3f40580x1955HTML document, ASCII text, with CRLF line terminatorsEnglishUnited States0.1918272937548188
                                                    RT_CURSOR0x3f59b00x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"EnglishUnited States0.4805194805194805
                                                    RT_CURSOR0x3f5ae40xb4Targa image data - Map 32 x 65536 x 1 +16 "\001"EnglishUnited States0.7
                                                    RT_CURSOR0x3f5b980x134AmigaOS bitmap font "(", fc_YSize 4294967264, 5120 elements, 2nd "\377\360?\377\377\370\177\377\377\374\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rdEnglishUnited States0.36363636363636365
                                                    RT_CURSOR0x3f5ccc0x134Targa image data - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.35714285714285715
                                                    RT_CURSOR0x3f5e000x134dataEnglishUnited States0.37337662337662336
                                                    RT_CURSOR0x3f5f340x134dataEnglishUnited States0.37662337662337664
                                                    RT_CURSOR0x3f60680x134Targa image data 64 x 65536 x 1 +32 "\001"EnglishUnited States0.36688311688311687
                                                    RT_CURSOR0x3f619c0x134Targa image data 64 x 65536 x 1 +32 "\001"EnglishUnited States0.37662337662337664
                                                    RT_CURSOR0x3f62d00x134Targa image data - Mono - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.36688311688311687
                                                    RT_CURSOR0x3f64040x134Targa image data - RGB - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.38636363636363635
                                                    RT_CURSOR0x3f65380x134dataEnglishUnited States0.44155844155844154
                                                    RT_CURSOR0x3f666c0x134dataEnglishUnited States0.4155844155844156
                                                    RT_CURSOR0x3f67a00x134AmigaOS bitmap font "(", fc_YSize 4294966847, 3840 elements, 2nd "\377?\374\377\377\300\003\377\377\300\003\377\377\340\007\377\377\360\017\377\377\370\037\377\377\374?\377\377\376\177\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rdEnglishUnited States0.5422077922077922
                                                    RT_CURSOR0x3f68d40x134dataEnglishUnited States0.2662337662337662
                                                    RT_CURSOR0x3f6a080x134dataEnglishUnited States0.2824675324675325
                                                    RT_CURSOR0x3f6b3c0x134dataEnglishUnited States0.3246753246753247
                                                    RT_CURSOR0x3f6c700x134dataEnglishUnited States0.20454545454545456
                                                    RT_CURSOR0x3f6da40x134dataEnglishUnited States0.2857142857142857
                                                    RT_CURSOR0x3f6ed80x134dataEnglishUnited States0.4675324675324675
                                                    RT_CURSOR0x3f700c0x134dataEnglishUnited States0.2532467532467532
                                                    RT_CURSOR0x3f71400x134Targa image data - RLE 64 x 65536 x 1 +32 "\001"EnglishUnited States0.40584415584415584
                                                    RT_CURSOR0x3f72740x134dataEnglishUnited States0.4383116883116883
                                                    RT_CURSOR0x3f73a80x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.4967532467532468
                                                    RT_CURSOR0x3f74dc0x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.39285714285714285
                                                    RT_CURSOR0x3f76100x134Targa image data - Mono 64 x 65536 x 1 +32 "\001"EnglishUnited States0.4512987012987013
                                                    RT_CURSOR0x3f77440x134dataEnglishUnited States0.37337662337662336
                                                    RT_CURSOR0x3f78780x134dataEnglishUnited States0.4448051948051948
                                                    RT_CURSOR0x3f79ac0x134dataEnglishUnited States0.525974025974026
                                                    RT_BITMAP0x3f7ae00xc3e8Device independent bitmap graphic, 348 x 36 x 32, image size 00.37799090764077203
                                                    RT_BITMAP0x403ec80x27a18Device independent bitmap graphic, 966 x 42 x 32, image size 162288, resolution 3582 x 3582 px/m0.32244591198068107
                                                    RT_BITMAP0x42b8e00x62cDevice independent bitmap graphic, 324 x 9 x 4, image size 1476EnglishUnited States0.2430379746835443
                                                    RT_BITMAP0x42bf0c0xe8Device independent bitmap graphic, 16 x 16 x 4, image size 128EnglishUnited States0.5818965517241379
                                                    RT_BITMAP0x42bff40x4a0Device independent bitmap graphic, 144 x 15 x 4, image size 1080EnglishUnited States0.3783783783783784
                                                    RT_BITMAP0x42c4940x197aDevice independent bitmap graphic, 144 x 15 x 24, image size 6482, resolution 2834 x 2834 px/mEnglishUnited States0.380098129408157
                                                    RT_BITMAP0x42de100xc8Device independent bitmap graphic, 13 x 12 x 4, image size 96EnglishUnited States0.51
                                                    RT_BITMAP0x42ded80xc8Device independent bitmap graphic, 13 x 12 x 4, image size 96EnglishUnited States0.515
                                                    RT_BITMAP0x42dfa00xc8Device independent bitmap graphic, 13 x 12 x 4, image size 96EnglishUnited States0.43
                                                    RT_BITMAP0x42e0680xc8Device independent bitmap graphic, 13 x 12 x 4, image size 96EnglishUnited States0.44
                                                    RT_BITMAP0x42e1300x182aDevice independent bitmap graphic, 128 x 16 x 24, image size 6146, resolution 2834 x 2834 px/mEnglishUnited States0.2924345295829292
                                                    RT_BITMAP0x42f95c0x468Device independent bitmap graphic, 128 x 16 x 4, image size 1024EnglishUnited States0.3058510638297872
                                                    RT_BITMAP0x42fdc40x528Device independent bitmap graphic, 16 x 16 x 8, image size 256EnglishUnited States0.4803030303030303
                                                    RT_BITMAP0x4302ec0x528Device independent bitmap graphic, 16 x 16 x 8, image size 256EnglishUnited States0.4765151515151515
                                                    RT_BITMAP0x4308140x158Device independent bitmap graphic, 32 x 15 x 4, image size 240EnglishUnited States0.41569767441860467
                                                    RT_BITMAP0x43096c0x188Device independent bitmap graphic, 48 x 12 x 4, image size 288EnglishUnited States0.39285714285714285
                                                    RT_BITMAP0x430af40x1e8Device independent bitmap graphic, 48 x 16 x 4, image size 384EnglishUnited States0.5081967213114754
                                                    RT_BITMAP0x430cdc0xad2Device independent bitmap graphic, 29 x 31 x 24, image size 2730, resolution 2834 x 2834 px/mEnglishUnited States0.18736462093862816
                                                    RT_BITMAP0x4317b00xad2Device independent bitmap graphic, 29 x 31 x 24, image size 2730, resolution 2834 x 2834 px/mEnglishUnited States0.1844765342960289
                                                    RT_BITMAP0x4322840xb0aDevice independent bitmap graphic, 31 x 29 x 24, image size 2786, resolution 2834 x 2834 px/mEnglishUnited States0.19497523000707714
                                                    RT_BITMAP0x432d900x7e2Device independent bitmap graphic, 25 x 26 x 24, image size 1978, resolution 2834 x 2834 px/mEnglishUnited States0.24033696729435083
                                                    RT_BITMAP0x4335740xb0aDevice independent bitmap graphic, 31 x 29 x 24, image size 2786, resolution 2834 x 2834 px/mEnglishUnited States0.1935598018400566
                                                    RT_BITMAP0x4340800x134Device independent bitmap graphic, 17 x 17 x 4, image size 204EnglishUnited States0.37337662337662336
                                                    RT_BITMAP0x4341b40x928Device independent bitmap graphic, 48 x 16 x 24, image size 0, resolution 2834 x 2834 px/mEnglishUnited States0.533703071672355
                                                    RT_BITMAP0x434adc0x32aDevice independent bitmap graphic, 16 x 16 x 24, image size 770, resolution 2834 x 2834 px/mEnglishUnited States0.7518518518518519
                                                    RT_BITMAP0x434e080x32aDevice independent bitmap graphic, 16 x 16 x 24, image size 770, resolution 2834 x 2834 px/mEnglishUnited States0.3790123456790123
                                                    RT_BITMAP0x4351340xc2aDevice independent bitmap graphic, 64 x 16 x 24, image size 3074, resolution 2834 x 2834 px/mEnglishUnited States0.42485549132947975
                                                    RT_BITMAP0x435d600x20aDevice independent bitmap graphic, 13 x 12 x 24, image size 482, resolution 2834 x 2834 px/mEnglishUnited States0.9367816091954023
                                                    RT_BITMAP0x435f6c0x20aDevice independent bitmap graphic, 13 x 12 x 24, image size 482, resolution 2834 x 2834 px/mEnglishUnited States0.4482758620689655
                                                    RT_BITMAP0x4361780x20aDevice independent bitmap graphic, 13 x 12 x 24, image size 482, resolution 2834 x 2834 px/mEnglishUnited States0.33524904214559387
                                                    RT_BITMAP0x4363840x20aDevice independent bitmap graphic, 13 x 12 x 24, image size 482, resolution 2834 x 2834 px/mEnglishUnited States0.3371647509578544
                                                    RT_BITMAP0x4365900x32aDevice independent bitmap graphic, 16 x 16 x 24, image size 770, resolution 2834 x 2834 px/mEnglishUnited States0.6320987654320988
                                                    RT_BITMAP0x4368bc0x2256Device independent bitmap graphic, 324 x 9 x 24, image size 8750, resolution 2834 x 2834 px/mEnglishUnited States0.0608646188850967
                                                    RT_BITMAP0x438b140x602aDevice independent bitmap graphic, 192 x 32 x 32, image size 24578, resolution 2834 x 2834 px/mEnglishUnited States0.2250385896498497
                                                    RT_BITMAP0x43eb400x2028Device independent bitmap graphic, 128 x 16 x 32, image size 0EnglishUnited States0.24708454810495628
                                                    RT_BITMAP0x440b680x13daDevice independent bitmap graphic, 35 x 36 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.11570247933884298
                                                    RT_BITMAP0x441f440x13daDevice independent bitmap graphic, 35 x 36 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.10999606454151908
                                                    RT_BITMAP0x4433200x13daDevice independent bitmap graphic, 36 x 35 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.11511216056670602
                                                    RT_BITMAP0x4446fc0xeb2Device independent bitmap graphic, 31 x 30 x 32, image size 3722, resolution 2834 x 2834 px/mEnglishUnited States0.13157894736842105
                                                    RT_BITMAP0x4455b00x13daDevice independent bitmap graphic, 36 x 35 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.11983471074380166
                                                    RT_BITMAP0x44698c0x13daDevice independent bitmap graphic, 35 x 36 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.27371113734750097
                                                    RT_BITMAP0x447d680x13daDevice independent bitmap graphic, 35 x 36 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.2699724517906336
                                                    RT_BITMAP0x4491440x13daDevice independent bitmap graphic, 36 x 35 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.2426210153482881
                                                    RT_BITMAP0x44a5200xeb2Device independent bitmap graphic, 31 x 30 x 32, image size 3722, resolution 2834 x 2834 px/mEnglishUnited States0.3413078149920255
                                                    RT_BITMAP0x44b3d40x13daDevice independent bitmap graphic, 36 x 35 x 32, image size 5042, resolution 2834 x 2834 px/mEnglishUnited States0.23868555686737505
                                                    RT_BITMAP0x44c7b00x5a66Device independent bitmap graphic, 77 x 75 x 32, image size 23102, resolution 2834 x 2834 px/mEnglishUnited States0.046365914786967416
                                                    RT_BITMAP0x4522180xb8Device independent bitmap graphic, 12 x 10 x 4, image size 80EnglishUnited States0.44565217391304346
                                                    RT_BITMAP0x4522d00x144Device independent bitmap graphic, 33 x 11 x 4, image size 220EnglishUnited States0.37962962962962965
                                                    RT_ICON0x4524140x10828Device independent bitmap graphic, 128 x 256 x 32, image size 675840.37968768484561694
                                                    RT_ICON0x462c3c0xcd63PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.8166568401833432
                                                    RT_ICON0x46f9a00x518c9PC bitmap, Windows 3.x format, 42286 x 2 x 47, image size 334966, cbSize 334025, bits offset 540.9976259262031285
                                                    RT_ICON0x4c126c0x42028Device independent bitmap graphic, 256 x 512 x 32, image size 2703360.3634124330561884
                                                    RT_ICON0x5032940x6841PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishGreat Britain1.0003746862003073
                                                    RT_ICON0x509ad80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishGreat Britain0.3674273858921162
                                                    RT_ICON0x50c0800x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishGreat Britain0.5044559099437148
                                                    RT_ICON0x50d1280x988Device independent bitmap graphic, 24 x 48 x 32, image size 2400EnglishGreat Britain0.6098360655737705
                                                    RT_ICON0x50dab00x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishGreat Britain0.7881205673758865
                                                    RT_ICON0x50df180x988Device independent bitmap graphic, 24 x 48 x 32, image size 2400EnglishGreat Britain0.6098360655737705
                                                    RT_ICON0x50e8a00x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishGreat Britain0.7881205673758865
                                                    RT_ICON0x50ed080x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 640EnglishUnited States0.33198924731182794
                                                    RT_ICON0x50eff00x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishUnited States0.41216216216216217
                                                    RT_ICON0x50f1180x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishUnited States0.42905405405405406
                                                    RT_ICON0x50f2400x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 640EnglishUnited States0.2661290322580645
                                                    RT_ICON0x50f5280x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512EnglishUnited States0.18010752688172044
                                                    RT_ICON0x50f8100x128Device independent bitmap graphic, 16 x 32 x 4, image size 128EnglishUnited States0.35135135135135137
                                                    RT_ICON0x50f9380x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsEnglishUnited States0.06092057761732852
                                                    RT_ICON0x5101e00x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsEnglishUnited States0.07658959537572255
                                                    RT_ICON0x5107480xca8Device independent bitmap graphic, 32 x 64 x 24, image size 3072EnglishUnited States0.042901234567901236
                                                    RT_ICON0x5113f00x368Device independent bitmap graphic, 16 x 32 x 24, image size 768EnglishUnited States0.10550458715596331
                                                    RT_ICON0x5117580x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.6400709219858156
                                                    RT_ICON0x511bc00x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishUnited States0.5
                                                    RT_MENU0x511ce80x11cdataEnglishUnited States0.573943661971831
                                                    RT_DIALOG0x511e040x140dataEnglishUnited States0.553125
                                                    RT_DIALOG0x511f440x190dataEnglishUnited States0.475
                                                    RT_DIALOG0x5120d40x134dataEnglishUnited States0.6038961038961039
                                                    RT_DIALOG0x5122080xf0dataEnglishUnited States0.6125
                                                    RT_DIALOG0x5122f80x148dataEnglishUnited States0.5640243902439024
                                                    RT_DIALOG0x5124400x2fcdataEnglishUnited States0.39397905759162305
                                                    RT_DIALOG0x51273c0x1e2dataEnglishUnited States0.4979253112033195
                                                    RT_DIALOG0x5129200x198dataEnglishUnited States0.5416666666666666
                                                    RT_DIALOG0x512ab80x1fedataEnglishUnited States0.4666666666666667
                                                    RT_DIALOG0x512cb80x190dataEnglishUnited States0.485
                                                    RT_DIALOG0x512e480x198dataEnglishUnited States0.5416666666666666
                                                    RT_DIALOG0x512fe00x222dataEnglishUnited States0.46886446886446886
                                                    RT_DIALOG0x5132040x276dataEnglishUnited States0.42063492063492064
                                                    RT_DIALOG0x51347c0x218dataEnglishUnited States0.42723880597014924
                                                    RT_DIALOG0x5136940x238dataEnglishUnited States0.3961267605633803
                                                    RT_DIALOG0x5138cc0x4fcdataEnglishUnited States0.26880877742946707
                                                    RT_DIALOG0x513dc80x13cdataEnglishUnited States0.5949367088607594
                                                    RT_DIALOG0x513f040x1a4dataEnglishUnited States0.5380952380952381
                                                    RT_DIALOG0x5140a80xe6dataEnglishUnited States0.6347826086956522
                                                    RT_DIALOG0x5141900x390dataEnglishUnited States0.4418859649122807
                                                    RT_DIALOG0x5145200x21cdataEnglishUnited States0.5037037037037037
                                                    RT_DIALOG0x51473c0x390dataEnglishUnited States0.4692982456140351
                                                    RT_DIALOG0x514acc0x1dcdataEnglishUnited States0.5441176470588235
                                                    RT_DIALOG0x514ca80x346dataEnglishUnited States0.46897374701670647
                                                    RT_DIALOG0x514ff00x334dataEnglishUnited States0.43658536585365854
                                                    RT_DIALOG0x5153240x58dataEnglishUnited States0.8068181818181818
                                                    RT_DIALOG0x51537c0x23cdataEnglishUnited States0.5122377622377622
                                                    RT_DIALOG0x5155b80x1c2dataEnglishUnited States0.5066666666666667
                                                    RT_DIALOG0x51577c0x160dataEnglishUnited States0.5994318181818182
                                                    RT_DIALOG0x5158dc0xb2dataEnglishUnited States0.7191011235955056
                                                    RT_DIALOG0x5159900x3d4dataEnglishUnited States0.3408163265306122
                                                    RT_DIALOG0x515d640x19edataEnglishUnited States0.6280193236714976
                                                    RT_DIALOG0x515f040x1a2dataEnglishUnited States0.5741626794258373
                                                    RT_DIALOG0x5160a80x34dataEnglishUnited States0.8076923076923077
                                                    RT_DIALOG0x5160dc0x2a8dataEnglishUnited States0.5338235294117647
                                                    RT_DIALOG0x5163840x382dataEnglishUnited States0.48552338530066813
                                                    RT_DIALOG0x5167080xe8dataEnglishUnited States0.6336206896551724
                                                    RT_DIALOG0x5167f00x34dataEnglishUnited States0.9038461538461539
                                                    RT_STRING0x5168240x44dataEnglishUnited States0.6323529411764706
                                                    RT_STRING0x5168680x32cdataEnglishUnited States0.4125615763546798
                                                    RT_STRING0x516b940x248dataEnglishUnited States0.5085616438356164
                                                    RT_STRING0x516ddc0x84dataEnglishUnited States0.5833333333333334
                                                    RT_STRING0x516e600x2a8dataEnglishUnited States0.36176470588235293
                                                    RT_STRING0x5171080x20edataEnglishUnited States0.3155893536121673
                                                    RT_STRING0x5173180x24cdataEnglishUnited States0.4370748299319728
                                                    RT_STRING0x5175640x3cdataEnglishUnited States0.65
                                                    RT_STRING0x5175a00x16edataEnglishUnited States0.39344262295081966
                                                    RT_STRING0x5177100xa6Matlab v4 mat-file (little endian) T, numeric, rows 0, columns 0EnglishUnited States0.7228915662650602
                                                    RT_STRING0x5177b80x184dataEnglishUnited States0.4742268041237113
                                                    RT_STRING0x51793c0x66dataEnglishUnited States0.696078431372549
                                                    RT_STRING0x5179a40x1d6Matlab v4 mat-file (little endian) S, numeric, rows 0, columns 0EnglishUnited States0.35319148936170214
                                                    RT_STRING0x517b7c0x186dataEnglishUnited States0.5384615384615384
                                                    RT_STRING0x517d040xb2dataEnglishUnited States0.6179775280898876
                                                    RT_STRING0x517db80x48Matlab v4 mat-file (little endian) a, numeric, rows 0, columns 0EnglishUnited States0.7083333333333334
                                                    RT_STRING0x517e000x18cdataEnglishUnited States0.398989898989899
                                                    RT_STRING0x517f8c0x82StarOffice Gallery theme p, 536899072 objects, 1st nEnglishUnited States0.7153846153846154
                                                    RT_STRING0x5180100x2adataEnglishUnited States0.5476190476190477
                                                    RT_STRING0x51803c0x184dataEnglishUnited States0.48711340206185566
                                                    RT_STRING0x5181c00x4eedataEnglishUnited States0.375594294770206
                                                    RT_STRING0x5186b00x264dataEnglishUnited States0.3333333333333333
                                                    RT_STRING0x5189140x2dadataEnglishUnited States0.3698630136986301
                                                    RT_STRING0x518bf00x8adataEnglishUnited States0.6594202898550725
                                                    RT_STRING0x518c7c0xacdataEnglishUnited States0.45348837209302323
                                                    RT_STRING0x518d280xdedataEnglishUnited States0.536036036036036
                                                    RT_STRING0x518e080x4a8dataEnglishUnited States0.3221476510067114
                                                    RT_STRING0x5192b00x228dataEnglishUnited States0.4003623188405797
                                                    RT_STRING0x5194d80x2cdataEnglishUnited States0.5227272727272727
                                                    RT_STRING0x5195040x53edataEnglishUnited States0.2965722801788376
                                                    RT_RCDATA0x519a440x11dabDelphi compiled form 'TfFolderProperties'0.5081565956981308
                                                    RT_RCDATA0x52b7f00xce6bDelphi compiled form 'TFormMD'0.5119126468974131
                                                    RT_RCDATA0x53865c0xa9cbDelphi compiled form 'TfSHistory'0.4406331239791106
                                                    RT_RCDATA0x5430280x1b681Delphi compiled form 'TMsgBoxForm'0.5739686611970746
                                                    RT_MESSAGETABLE0x55e6ac0x2840data0.5283385093167702
                                                    RT_GROUP_CURSOR0x560eec0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
                                                    RT_GROUP_CURSOR0x560f000x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560f140x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560f280x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560f3c0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560f500x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560f640x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560f780x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560f8c0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560fa00x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560fb40x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560fc80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x560fdc0x22Lotus unknown worksheet or configuration, revision 0x2EnglishUnited States1.0294117647058822
                                                    RT_GROUP_CURSOR0x5610000x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5610140x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5610280x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x56103c0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5610500x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5610640x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5610780x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x56108c0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5610a00x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5610b40x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5610c80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5610dc0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5610f00x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_CURSOR0x5611040x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                                    RT_GROUP_ICON0x5611180x68dataEnglishGreat Britain0.6442307692307693
                                                    RT_GROUP_ICON0x5611800x22dataEnglishUnited States1.0588235294117647
                                                    RT_GROUP_ICON0x5611a40x22dataEnglishUnited States1.0588235294117647
                                                    RT_GROUP_ICON0x5611c80x5adataEnglishUnited States0.7555555555555555
                                                    RT_GROUP_ICON0x5612240x22dataEnglishUnited States1.1176470588235294
                                                    RT_VERSION0x5612480x254dataEnglishUnited States0.4748322147651007
                                                    RT_ANIICON0x56149c0x36b6ePC bitmap, Windows 3.x format, 28224 x 2 x 54, image size 224986, cbSize 224110, bits offset 540.9941144973450537
                                                    None0x59800c0x1f1dataEnglishUnited States0.17706237424547283
                                                    None0x5982000x1cdataEnglishUnited States1.2857142857142858
                                                    None0x59821c0x18dataEnglishUnited States1.2916666666666667
                                                    DLLImport
                                                    KERNEL32.dllGetDateFormatW, GetConsoleMode, GetConsoleOutputCP, SetFilePointerEx, GetTimeZoneInformation, ExitProcess, GetStdHandle, GetFileType, SetStdHandle, VirtualQuery, VirtualAlloc, GetSystemInfo, HeapQueryInformation, GetCommandLineW, GetCommandLineA, FreeLibraryAndExitThread, ExitThread, CreateThread, RtlUnwind, GetCPInfo, CompareStringEx, LCMapStringW, GetDriveTypeW, LCMapStringEx, GetStringTypeW, GetModuleHandleExW, CloseThreadpoolWork, SubmitThreadpoolWork, CreateThreadpoolWork, FreeLibraryWhenCallbackReturns, TryAcquireSRWLockExclusive, QueryPerformanceFrequency, InitOnceBeginInitialize, InitOnceComplete, AreFileApisANSI, FindFirstFileExW, FormatMessageA, RaiseException, GetTimeFormatW, IsValidLocale, EnumSystemLocalesW, IsValidCodePage, GetACP, GetOEMCP, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableW, WriteConsoleW, GetStartupInfoW, IsDebuggerPresent, InitializeSListHead, GetSystemTimeAsFileTime, QueryPerformanceCounter, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, IsProcessorFeaturePresent, SleepConditionVariableSRW, WakeAllConditionVariable, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, GetUserDefaultLCID, SearchPathW, GetProfileIntW, GetTickCount64, GetWindowsDirectoryW, ReadConsoleW, FindResourceExW, SetErrorMode, GetFileTime, GetFileSizeEx, GetFileAttributesExW, GetCurrentDirectoryW, GetFileAttributesW, VirtualProtect, GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetLocaleInfoW, GlobalFlags, LocalReAlloc, GlobalHandle, GlobalReAlloc, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, InitializeCriticalSection, GlobalGetAtomNameW, InitializeCriticalSectionAndSpinCount, GetThreadLocale, lstrcmpiW, DuplicateHandle, WriteFile, UnlockFile, SetFilePointer, SetEndOfFile, ReadFile, LockFile, GetVolumeInformationW, GetFullPathNameW, GetFileSize, FlushFileBuffers, CreateFileW, FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime, FileTimeToLocalFileTime, lstrcpyW, WritePrivateProfileStringW, GetPrivateProfileStringW, GetPrivateProfileIntW, lstrcmpA, GetCurrentThread, ResumeThread, SetThreadPriority, CompareStringW, GlobalFindAtomW, GlobalAddAtomW, lstrcmpW, GlobalDeleteAtom, LoadLibraryW, LoadLibraryA, LoadLibraryExW, GetProcAddress, GetModuleHandleA, FreeLibrary, GetSystemDirectoryW, GetCurrentThreadId, EncodePointer, OutputDebugStringA, GetCurrentProcessId, CopyFileW, MulDiv, GlobalSize, SetLastError, GetExitCodeProcess, IsWow64Process, GetModuleHandleW, CreateProcessW, GlobalFree, GetVersionExW, LocalAlloc, WaitForSingleObject, FindClose, GetModuleFileNameW, GetCurrentProcess, FindNextFileW, FindFirstFileW, GlobalMemoryStatusEx, SizeofResource, Process32FirstW, GetDiskFreeSpaceExW, Process32NextW, CreateToolhelp32Snapshot, GetUserDefaultLocaleName, GetLocaleInfoEx, GetTickCount, VerifyVersionInfoW, VerSetConditionMask, LocalFree, FormatMessageW, GlobalUnlock, GlobalLock, GlobalAlloc, MoveFileExW, CloseHandle, OutputDebugStringW, CreateMutexW, RemoveDirectoryW, GetTempFileNameW, DeleteFileW, MultiByteToWideChar, GetTempPathW, GetEnvironmentVariableW, CreateDirectoryW, WideCharToMultiByte, GetProcessHeap, DeleteCriticalSection, DecodePointer, HeapAlloc, FindResourceW, LoadResource, HeapReAlloc, LockResource, GetLastError, Sleep, HeapSize, InitializeCriticalSectionEx, LeaveCriticalSection, EnterCriticalSection, HeapFree
                                                    USER32.dllGetKeyNameTextW, EnumDisplayMonitors, SystemParametersInfoW, LoadCursorW, SetLayeredWindowAttributes, MapDialogRect, SetWindowContextHelpId, SetCursor, ShowOwnedPopups, PostQuitMessage, DrawIconEx, IsRectEmpty, InflateRect, DrawFocusRect, GetSysColorBrush, SetWindowRgn, DrawFrameControl, DrawEdge, GetCursorPos, TranslateMessage, GetMessageW, SetMenuItemInfoW, GetMenuCheckMarkDimensions, SetMenuItemBitmaps, EnableMenuItem, CheckMenuItem, OffsetRect, SetRectEmpty, SendDlgItemMessageA, LoadMenuW, GetDesktopWindow, GetActiveWindow, GetNextDlgTabItem, EndDialog, CreateDialogIndirectParamW, IsDialogMessageW, SetWindowTextW, CheckDlgButton, MoveWindow, LockWindowUpdate, MapVirtualKeyW, GetDoubleClickTime, GetIconInfo, CopyIcon, GetMenuDefaultItem, UnregisterClassW, EnableWindow, ShowWindow, GetMonitorInfoW, MonitorFromWindow, WinHelpW, GetScrollInfo, SetScrollInfo, CallNextHookEx, UnhookWindowsHookEx, SetWindowsHookExW, GetWindow, GetTopWindow, GetClassLongW, SetWindowLongW, PtInRect, EqualRect, CopyRect, MapWindowPoints, AdjustWindowRectEx, GetWindowTextLengthW, GetWindowTextW, RemovePropW, GetPropW, SetPropW, ShowScrollBar, SetMenuDefaultItem, SetClipboardData, EmptyClipboard, SetParent, MonitorFromPoint, IsZoomed, SetCapture, ReleaseCapture, DeleteMenu, MessageBeep, WindowFromPoint, NotifyWinEvent, SetCursorPos, SetRect, UnionRect, BringWindowToTop, DestroyMenu, SetScrollRange, GetScrollPos, GetMenuItemInfoW, CharUpperW, IntersectRect, RealChildWindowFromPoint, CopyImage, GetAsyncKeyState, CreatePopupMenu, TrackMouseEvent, DestroyIcon, LoadImageW, OpenClipboard, EnableScrollBar, SendMessageW, IsIconic, AppendMenuW, GetClientRect, RemoveMenu, LoadIconW, DrawIcon, GetSystemMetrics, GetWindowRect, PostMessageW, GetSystemMenu, InvalidateRect, KillTimer, SetTimer, GetParent, GetMenuStringW, GetMenuState, GetSubMenu, GetMenuItemID, GetMenuItemCount, InsertMenuW, IsWindowEnabled, MessageBoxW, GetWindowLongW, GetWindowThreadProcessId, GetLastActivePopup, DrawTextW, DrawTextExW, GrayStringW, TabbedTextOutW, GetDC, GetWindowDC, ReleaseDC, BeginPaint, EndPaint, ClientToScreen, ScreenToClient, GetSysColor, FillRect, DrawStateW, UpdateWindow, GetClassNameW, LoadBitmapW, RegisterWindowMessageW, DispatchMessageW, PeekMessageW, GetMessagePos, GetMessageTime, DefWindowProcW, CallWindowProcW, RegisterClassW, GetClassInfoW, GetClassInfoExW, CreateWindowExW, IsWindow, IsMenu, IsChild, DestroyWindow, SetWindowPos, GetWindowPlacement, SetWindowPlacement, BeginDeferWindowPos, DeferWindowPos, EndDeferWindowPos, IsWindowVisible, GetDlgItem, GetDlgCtrlID, SetFocus, GetFocus, GetKeyState, GetCapture, GetMenu, SetMenu, TrackPopupMenu, SetActiveWindow, GetForegroundWindow, SetForegroundWindow, ValidateRect, RedrawWindow, ScrollWindow, SetScrollPos, ModifyMenuW, DestroyAcceleratorTable, SetClassLongW, GetUpdateRect, CloseClipboard, WaitMessage, CharNextW, CopyAcceleratorTableW, InvalidateRgn, GetNextDlgGroupItem, IsClipboardFormatAvailable, ToUnicodeEx, GetKeyboardLayout, GetKeyboardState, LoadAcceleratorsW, CreateAcceleratorTableW, UpdateLayeredWindow, HideCaret, InvertRect, FrameRect, SubtractRect, RegisterClipboardFormatW, CharUpperBuffW, TranslateAcceleratorW, InsertMenuItemW, UnpackDDElParam, ReuseDDElParam, PostThreadMessageW, IsCharLowerW, MapVirtualKeyExW, DrawMenuBar, DefFrameProcW, DefMDIChildProcW, TranslateMDISysAccel, GetComboBoxInfo, CreateMenu, DestroyCursor, GetWindowRgn, GetScrollRange
                                                    GDI32.dllLineTo, PtVisible, RectVisible, RestoreDC, SaveDC, SelectClipRgn, ExtSelectClipRgn, SelectObject, SelectPalette, SetBkColor, SetBkMode, SetMapMode, SetLayout, SetPolyFillMode, SetROP2, SetTextColor, SetTextAlign, MoveToEx, TextOutW, ExtTextOutW, SetViewportExtEx, SetViewportOrgEx, SetWindowExtEx, SetWindowOrgEx, OffsetViewportOrgEx, OffsetWindowOrgEx, ScaleViewportExtEx, ScaleWindowExtEx, CombineRgn, CreateEllipticRgn, CreateRectRgnIndirect, Ellipse, GetBkColor, GetTextColor, GetTextExtentPoint32W, IntersectClipRect, CreatePolygonRgn, Polygon, Polyline, GetTextMetricsW, CreateCompatibleBitmap, CreateDIBitmap, EnumFontFamiliesW, GetTextCharsetInfo, GetMapMode, SetRectRgn, DPtoLP, RealizePalette, SetPixel, StretchBlt, CreateDIBSection, SetDIBColorTable, CreateRoundRectRgn, Rectangle, GetRgnBox, OffsetRgn, RoundRect, CreatePalette, GetPaletteEntries, EnumFontFamiliesExW, GetNearestPaletteIndex, GetSystemPaletteEntries, LPtoDP, ExtFloodFill, SetPaletteEntries, FillRgn, FrameRgn, GetBoundsRect, PtInRegion, GetViewportOrgEx, GetWindowOrgEx, SetPixelV, GetTextFaceW, GetWindowExtEx, GetViewportExtEx, GetStockObject, GetPixel, GetObjectType, GetClipBox, ExcludeClipRect, Escape, DeleteObject, CreateRectRgn, CreatePatternBrush, CreatePen, CreateHatchBrush, DeleteDC, CreateFontIndirectW, CreateSolidBrush, GetObjectW, CopyMetaFileW, CreateDCW, GetDeviceCaps, BitBlt, CreateBitmap, CreateCompatibleDC, PatBlt, GetLayout
                                                    MSIMG32.dllAlphaBlend, TransparentBlt
                                                    WINSPOOL.DRVDocumentPropertiesW, OpenPrinterW, ClosePrinter
                                                    ADVAPI32.dllCryptDestroyHash, RegQueryValueExA, RegEnumValueW, RegQueryValueW, RegEnumKeyW, RegDeleteValueW, RegDeleteKeyW, CryptAcquireContextW, CryptCreateHash, CryptHashData, RegOpenKeyExA, CryptGetHashParam, CryptReleaseContext, RegCreateKeyExW, RegSetValueExW, RegQueryInfoKeyW, RegEnumKeyExW, RegOpenKeyExW, RegGetValueW, RegQueryValueExW, RegCloseKey
                                                    SHELL32.dllDragFinish, DragQueryFileW, SHAppBarMessage, SHGetFileInfoW, SHGetDesktopFolder, SHBrowseForFolderW, SHGetSpecialFolderLocation, SHGetPathFromIDListW, SHGetMalloc, ShellExecuteW, SHGetKnownFolderPath, SHGetFolderPathW
                                                    COMCTL32.dllInitCommonControlsEx
                                                    SHLWAPI.dllPathRemoveFileSpecW, StrFormatKBSizeW, PathStripToRootW, PathIsUNCW, PathFindFileNameW, PathFindExtensionW, PathAppendW, PathIsDirectoryEmptyW, PathFileExistsW, PathIsDirectoryW
                                                    UxTheme.dllDrawThemeText, IsAppThemed, OpenThemeData, CloseThemeData, GetThemePartSize, GetThemeSysColor, DrawThemeBackground, GetThemeColor, GetCurrentThemeName, DrawThemeParentBackground, GetWindowTheme, IsThemeBackgroundPartiallyTransparent
                                                    ole32.dllRegisterDragDrop, IsAccelerator, OleTranslateAccelerator, OleDestroyMenuDescriptor, OleCreateMenuDescriptor, OleUninitialize, OleInitialize, CoFreeUnusedLibraries, CoInitializeEx, OleLockRunning, RevokeDragDrop, CoLockObjectExternal, OleGetClipboard, DoDragDrop, OleIsCurrentClipboard, CreateILockBytesOnHGlobal, StgOpenStorageOnILockBytes, StgCreateDocfileOnILockBytes, CoGetClassObject, CoDisconnectObject, CLSIDFromProgID, CLSIDFromString, CoCreateGuid, ReleaseStgMedium, OleDuplicateData, CoTaskMemAlloc, CoCreateInstance, CoUninitialize, CoInitialize, CreateStreamOnHGlobal, CoTaskMemFree, CoRevokeClassObject, CoRegisterMessageFilter, OleFlushClipboard
                                                    OLEAUT32.dllSafeArrayDestroy, VariantCopy, VariantTimeToSystemTime, SystemTimeToVariantTime, VariantChangeType, VariantClear, VariantInit, SysAllocStringLen, SysFreeString, SysAllocStringByteLen, SysAllocString, SysStringLen, OleCreateFontIndirect, LoadTypeLib, VarBstrFromDate
                                                    oledlg.dllOleUIBusyW
                                                    gdiplus.dllGdipSetInterpolationMode, GdipCreateBitmapFromHBITMAP, GdipDrawImageI, GdipBitmapUnlockBits, GdipBitmapLockBits, GdipCreateBitmapFromScan0, GdipGetImagePaletteSize, GdipGetImagePalette, GdipGetImagePixelFormat, GdipGetImageHeight, GdipGetImageWidth, GdipGetImageGraphicsContext, GdipCreateBitmapFromStream, GdiplusShutdown, GdiplusStartup, GdipLoadImageFromStream, GdipDeleteGraphics, GdipCreateFromHDC, GdipFree, GdipDisposeImage, GdipDrawImageRectI, GdipAlloc, GdipCloneImage
                                                    WINHTTP.dllWinHttpQueryDataAvailable, WinHttpCloseHandle, WinHttpSetOption, WinHttpConnect, WinHttpCrackUrl, WinHttpSendRequest, WinHttpOpenRequest, WinHttpReadData, WinHttpQueryHeaders, WinHttpOpen, WinHttpReceiveResponse, WinHttpAddRequestHeaders
                                                    WININET.dllInternetOpenW, HttpQueryInfoW, InternetCloseHandle, InternetReadFile, InternetOpenUrlW
                                                    VERSION.dllVerQueryValueW
                                                    ntdll.dllRtlGetVersion
                                                    OLEACC.dllAccessibleObjectFromWindow, LresultFromObject, CreateStdAccessibleObject
                                                    IMM32.dllImmReleaseContext, ImmGetOpenStatus, ImmGetContext
                                                    WINMM.dllPlaySoundW
                                                    Language of compilation systemCountry where language is spokenMap
                                                    EnglishUnited States
                                                    EnglishGreat Britain
                                                    TimestampSource PortDest PortSource IPDest IP
                                                    Jan 10, 2025 11:34:36.477385044 CET4970830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:34:36.482224941 CET3020349708181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:34:36.482372046 CET4970830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:34:36.533483982 CET4970830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:34:36.538310051 CET3020349708181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:34:36.540683985 CET4970830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:34:36.546595097 CET3020349708181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:34:57.878804922 CET3020349708181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:34:57.878885984 CET4970830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:34:57.891272068 CET4970830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:34:57.896035910 CET3020349708181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:34:58.003422022 CET4970930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:34:58.008307934 CET3020349709181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:34:58.008398056 CET4970930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:34:58.009429932 CET4970930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:34:58.014194012 CET3020349709181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:34:58.014282942 CET4970930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:34:58.019100904 CET3020349709181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:35:19.357760906 CET3020349709181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:35:19.361056089 CET4970930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:19.361207962 CET4970930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:19.365910053 CET3020349709181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:35:19.472197056 CET4971130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:19.477089882 CET3020349711181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:35:19.477637053 CET4971130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:19.478239059 CET4971130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:19.483026981 CET3020349711181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:35:19.483705997 CET4971130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:19.488581896 CET3020349711181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:35:40.875828028 CET3020349711181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:35:40.875957966 CET4971130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:40.876197100 CET4971130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:40.880913973 CET3020349711181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:35:40.988352060 CET4971530203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:40.993264914 CET3020349715181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:35:40.993382931 CET4971530203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:40.994167089 CET4971530203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:40.998997927 CET3020349715181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:35:40.999149084 CET4971530203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:35:41.004002094 CET3020349715181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:02.374875069 CET3020349715181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:02.374953032 CET4971530203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:02.375133991 CET4971530203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:02.379872084 CET3020349715181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:02.489751101 CET4971630203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:02.494585037 CET3020349716181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:02.494683027 CET4971630203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:02.496150970 CET4971630203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:02.500884056 CET3020349716181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:02.500936031 CET4971630203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:02.505681038 CET3020349716181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:09.082622051 CET4971630203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:09.087585926 CET3020349716181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:09.087657928 CET4971630203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:09.092533112 CET3020349716181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:18.128926992 CET4971630203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:18.133755922 CET3020349716181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:18.141215086 CET4971630203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:18.145992994 CET3020349716181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:23.862848997 CET3020349716181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:23.863038063 CET4971630203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:23.863209963 CET4971630203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:23.868000031 CET3020349716181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:23.972765923 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:23.977649927 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:23.979827881 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:23.979827881 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:23.984627008 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:23.990833998 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:23.995754957 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:29.961304903 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:29.966114998 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:29.966223001 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:29.971031904 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:31.769467115 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:31.774336100 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:31.774391890 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:31.779211044 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:32.862766981 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:32.867623091 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:32.867714882 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:32.872545004 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:45.363238096 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:45.363320112 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:45.363523006 CET4971730203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:45.368333101 CET3020349717181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:45.472752094 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:45.477622986 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:45.477735996 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:45.478856087 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:45.483658075 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:45.483715057 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:45.488535881 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:46.175221920 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:46.180191040 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:46.180363894 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:46.185194969 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:57.644216061 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:57.649178982 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:36:57.649234056 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:36:57.654057026 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:07.497226954 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:07.497247934 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:07.497307062 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:07.497334957 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:07.497379065 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:07.497423887 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:07.497451067 CET4971830203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:07.502255917 CET3020349718181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:07.613116980 CET4971930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:07.618294954 CET3020349719181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:07.618391991 CET4971930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:07.619137049 CET4971930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:07.623982906 CET3020349719181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:07.624047041 CET4971930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:07.628917933 CET3020349719181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:11.144452095 CET4971930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:11.149386883 CET3020349719181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:11.149446011 CET4971930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:11.154359102 CET3020349719181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:28.989156008 CET3020349719181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:28.989619017 CET4971930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:28.989908934 CET4971930203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:28.994657993 CET3020349719181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:29.114896059 CET4972030203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:29.119868994 CET3020349720181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:29.119955063 CET4972030203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:29.121458054 CET4972030203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:29.126208067 CET3020349720181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:29.126261950 CET4972030203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:29.131066084 CET3020349720181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:43.848562956 CET4972030203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:43.853518009 CET3020349720181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:43.853583097 CET4972030203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:43.858769894 CET3020349720181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:44.253432035 CET4972030203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:44.258399010 CET3020349720181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:44.258965015 CET4972030203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:44.263708115 CET3020349720181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:50.501497984 CET3020349720181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:50.501730919 CET4972030203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:50.501893044 CET4972030203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:50.506740093 CET3020349720181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:50.613679886 CET4972130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:50.618575096 CET3020349721181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:50.618885994 CET4972130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:50.619565010 CET4972130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:50.624336958 CET3020349721181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:50.624422073 CET4972130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:50.629163980 CET3020349721181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:55.035042048 CET4972130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:55.039915085 CET3020349721181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:37:55.040148020 CET4972130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:37:55.045003891 CET3020349721181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:38:05.708224058 CET4972130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:38:05.713083982 CET3020349721181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:38:05.713179111 CET4972130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:38:05.718498945 CET3020349721181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:38:12.005848885 CET3020349721181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:38:12.005908966 CET4972130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:38:12.006161928 CET4972130203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:38:12.011136055 CET3020349721181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:38:12.113303900 CET4972230203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:38:12.118125916 CET3020349722181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:38:12.118236065 CET4972230203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:38:12.119105101 CET4972230203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:38:12.123889923 CET3020349722181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:38:12.123958111 CET4972230203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:38:12.128726006 CET3020349722181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:38:19.165263891 CET4972230203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:38:19.170177937 CET3020349722181.71.216.203192.168.2.8
                                                    Jan 10, 2025 11:38:19.170298100 CET4972230203192.168.2.8181.71.216.203
                                                    Jan 10, 2025 11:38:19.175090075 CET3020349722181.71.216.203192.168.2.8
                                                    TimestampSource PortDest PortSource IPDest IP
                                                    Jan 10, 2025 11:34:36.457285881 CET6197653192.168.2.81.1.1.1
                                                    Jan 10, 2025 11:34:36.473789930 CET53619761.1.1.1192.168.2.8
                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                    Jan 10, 2025 11:34:36.457285881 CET192.168.2.81.1.1.10x2aa3Standard query (0)newstaticfreepoint24.ddns-ip.netA (IP address)IN (0x0001)false
                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                    Jan 10, 2025 11:34:36.473789930 CET1.1.1.1192.168.2.80x2aa3No error (0)newstaticfreepoint24.ddns-ip.net181.71.216.203A (IP address)IN (0x0001)false

                                                    Click to jump to process

                                                    Click to jump to process

                                                    Click to dive into process behavior distribution

                                                    Click to jump to process

                                                    Target ID:1
                                                    Start time:05:34:10
                                                    Start date:10/01/2025
                                                    Path:C:\Users\user\Desktop\AdobeReaderPDFonline.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:"C:\Users\user\Desktop\AdobeReaderPDFonline.exe"
                                                    Imagebase:0x400000
                                                    File size:5'835'776 bytes
                                                    MD5 hash:AF1D0F01B01DA4DA3A9A54B2BEE820E9
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:low
                                                    Has exited:true

                                                    Target ID:5
                                                    Start time:05:34:32
                                                    Start date:10/01/2025
                                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe"
                                                    Imagebase:0x110000
                                                    File size:2'141'552 bytes
                                                    MD5 hash:EB80BB1CA9B9C7F516FF69AFCFD75B7D
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Yara matches:
                                                    • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000005.00000002.3922060213.0000000007F43000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                    • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000005.00000002.3918431665.0000000006B30000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                                                    • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000005.00000002.3918792657.0000000006DA1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                    Reputation:moderate
                                                    Has exited:false

                                                    Reset < >

                                                      Execution Graph

                                                      Execution Coverage:0.6%
                                                      Dynamic/Decrypted Code Coverage:100%
                                                      Signature Coverage:20.3%
                                                      Total number of Nodes:79
                                                      Total number of Limit Nodes:5
                                                      execution_graph 27740 25f1bdf 27741 25f1c38 Wow64GetThreadContext 27740->27741 27743 25f1c5c 27741->27743 27744 25f223b 27743->27744 27747 25f30bb 27743->27747 27750 25f2334 ReadProcessMemory ReadProcessMemory ReadProcessMemory 27744->27750 27751 25f368b ReadProcessMemory 27747->27751 27752 2667ca7 27753 2667cad CreateDirectoryW 27752->27753 27757 2667d28 27753->27757 27758 2667d3e CreateDirectoryW 27757->27758 27760 2667e61 27758->27760 27761 25ebdbc 27762 25ebdec CreateProcessW 27761->27762 27764 25ebe47 27762->27764 27765 266c145 27766 266c0eb 27765->27766 27767 266c158 RegSetValueExW 27765->27767 27768 266c22f 27767->27768 27769 266a0a2 27770 266a0a9 RegOpenKeyExW 27769->27770 27772 266a110 27770->27772 27773 25fb913 27774 25fb944 VirtualAlloc 27773->27774 27776 25fb9ca 27774->27776 27777 25fbda3 27774->27777 27780 25fb9d3 27776->27780 27801 25fba29 36 API calls 27776->27801 27779 25fbdcc 27803 25fc1cb 36 API calls 27779->27803 27780->27777 27780->27779 27802 25fbdd6 36 API calls 27780->27802 27802->27779 27804 25fdff1 27805 25fe014 WriteProcessMemory 27804->27805 27807 25fe05e 27805->27807 27808 25fe059 27805->27808 27807->27808 27809 25fe071 27807->27809 27814 25fe0a8 17 API calls 27809->27814 27815 25e6aaf 27816 25e6ad8 VirtualAlloc 27815->27816 27818 25e6b09 27816->27818 27819 25ea76f 27820 25ff5bc 27819->27820 27821 25ff88d 27820->27821 27825 25ff803 27820->27825 27822 25ffef6 ReadProcessMemory 27821->27822 27823 25fff21 27822->27823 27830 25ff81a 27825->27830 27827 25ff811 27828 25ffef6 ReadProcessMemory 27827->27828 27829 25fff21 27828->27829 27829->27820 27831 25ff8c9 27830->27831 27832 25ffef6 ReadProcessMemory 27831->27832 27833 25fff21 27832->27833 27833->27827 27834 2603cb6 27835 2603ce1 Wow64SetThreadContext 27834->27835 27837 2603dbc 27835->27837 27838 2667e1f CreateDirectoryW 27839 2667e61 27838->27839 27840 25f37e3 27841 25f37e7 ReadProcessMemory 27840->27841 27843 25f3c04 27841->27843 27844 266e05b 27845 266e05e CloseHandle 27844->27845 27847 266e0af 27845->27847 27848 25f95a1 27851 25f95b4 27848->27851 27853 25f95df 27851->27853 27852 25f9a7e VirtualProtectEx 27854 25f9ab0 27852->27854 27853->27852 27855 25f977e 27853->27855 27854->27854 27856 25efc41 27857 25efc44 27856->27857 27859 25efc64 VirtualAlloc 27857->27859 27862 25efc6b 27857->27862 27861 25efcda 27859->27861 27867 25efc7c 27862->27867 27866 25efcda 27866->27859 27868 25efcab VirtualAlloc 27867->27868 27870 25efc73 VirtualAlloc 27868->27870 27870->27866

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: M$MIMK$O4:2$P$R$R$_V$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 0-127553305
                                                      • Opcode ID: 4b91097f457b63b63a7f751f9f8793481fcf1dab363cf3a22e310d5746cf24c4
                                                      • Instruction ID: f8e95e5c20d8779398b7451ca748cdc3a6591b8dcfdeb20a691595782525701d
                                                      • Opcode Fuzzy Hash: 4b91097f457b63b63a7f751f9f8793481fcf1dab363cf3a22e310d5746cf24c4
                                                      • Instruction Fuzzy Hash: 56F154A2D089A48EF7208B24DC54BEB7B76EF81310F0481FED54D97281E6791AC5CF66

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 4f9abf4db52cd044cb545b692a2a7a2cf35f04f166506c23455d59c779f8689a
                                                      • Instruction ID: 656e8d0a66aedeebccaf336048d1301f784e8d2f3a9e86064969e002e9b4af51
                                                      • Opcode Fuzzy Hash: 4f9abf4db52cd044cb545b692a2a7a2cf35f04f166506c23455d59c779f8689a
                                                      • Instruction Fuzzy Hash: B8E146B2D046949FF7208628DC58BEB7B79EF81310F0481FAD54D97680D67A4AC5CF62

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 0-3061001137
                                                      • Opcode ID: e1c221bc52062d45e6f046c7828969b7b4cb86fda0cae94f55a7e19a11ddb90a
                                                      • Instruction ID: f2d1ddfa62d573b2669716a85ac38383b0b0cddfc45f3871006e0fcb3f8dd4be
                                                      • Opcode Fuzzy Hash: e1c221bc52062d45e6f046c7828969b7b4cb86fda0cae94f55a7e19a11ddb90a
                                                      • Instruction Fuzzy Hash: 6DE100B1D089A48BF720CA28DC94BEB7B75EF81301F0841FAD54DA7281D6795AC5CF62

                                                      Control-flow Graph

                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 9faf7a50581138339ae4a081f12b030bfce7dc37ba3eb101fa84b815c36da5d7
                                                      • Instruction ID: f6260d7aaf2ce04cc33102996e71ea79d3b74491cdf0302e1a7dac4fe87613ec
                                                      • Opcode Fuzzy Hash: 9faf7a50581138339ae4a081f12b030bfce7dc37ba3eb101fa84b815c36da5d7
                                                      • Instruction Fuzzy Hash: 8BE1E1B1D086948BF7208A24DC54BEB7B7AEB81310F0481FAD94D97281D67A5EC5CF62

                                                      Control-flow Graph

                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 844acb77baab3334217359fd4bd7146508c1f0573df98ef6f0fcbd0fdb792f02
                                                      • Instruction ID: 229d32340a32a1490438c6f9b937779faa8eac729c3d705fd4b31c2a30dd239d
                                                      • Opcode Fuzzy Hash: 844acb77baab3334217359fd4bd7146508c1f0573df98ef6f0fcbd0fdb792f02
                                                      • Instruction Fuzzy Hash: 20D12471D086A88AE7218B28CC54BEBBB75EF81314F0441FAD54CA7291E6794BC5CF52

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: ad9246120097d03c1fcde15b0df210fc02c864022a60e2cdd9f72abdb5056d98
                                                      • Instruction ID: 1144d124f6b66c51d8d2251a208369dc6852110ffb9eb935fa42295f15555c3e
                                                      • Opcode Fuzzy Hash: ad9246120097d03c1fcde15b0df210fc02c864022a60e2cdd9f72abdb5056d98
                                                      • Instruction Fuzzy Hash: CFC165A1E08A94CEF7208628DC58BEB7B75EF91300F0481FAD54C97681D67A5AC5CF62

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: ec17dff62597b6a56d606bb1627ea0af0afdf44167222fee6fc6000b538e854d
                                                      • Instruction ID: 1665e632765aca8fd8b62f505c0d2254bba37b12a8381d3abebdfac4d4492b15
                                                      • Opcode Fuzzy Hash: ec17dff62597b6a56d606bb1627ea0af0afdf44167222fee6fc6000b538e854d
                                                      • Instruction Fuzzy Hash: 86C146A1E08A94CEF7208628DC58BEB7B75EF91300F0441FAD54C97681D67A5AC5CF62

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 77100f7d9f386dfce3410828bc7566292ac64bea5d821fc376af2cac4c212ac8
                                                      • Instruction ID: 028705ca23fd4164b1708d5be8c4b4d457f4a637763d060f72c9f6167bb5aa50
                                                      • Opcode Fuzzy Hash: 77100f7d9f386dfce3410828bc7566292ac64bea5d821fc376af2cac4c212ac8
                                                      • Instruction Fuzzy Hash: 5AB156A1D08A948EF720C728DC58BEB7B75EF92300F0440FAD54D97281E67A4AC5CF62

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 450a28ff0971309f2bcbee9528c331083f677f107c0e6b732b32f2ed8d4abd08
                                                      • Instruction ID: 884d47b80dc28cc9f8ff9032f94df1da216298a53285a19e9e2722bf17467227
                                                      • Opcode Fuzzy Hash: 450a28ff0971309f2bcbee9528c331083f677f107c0e6b732b32f2ed8d4abd08
                                                      • Instruction Fuzzy Hash: 12B143A1D08A948EF720C728DC58BEB7B75EF91310F0480FAD54D97281E67A5AC5CF62

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 6b352f522020a5d3b62cd0d01a9c5dbe7ac3a43daff5323f8a211830601bc714
                                                      • Instruction ID: 8ce6d640800f68668cc9c6ab4ead18f8a1377d19abe334dd0ebb504d9aae183f
                                                      • Opcode Fuzzy Hash: 6b352f522020a5d3b62cd0d01a9c5dbe7ac3a43daff5323f8a211830601bc714
                                                      • Instruction Fuzzy Hash: 98B133A1D08A948EF720CB28DC54BEB7B75EF91300F0481FAD54D97281E67A5AC5CF62

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 7ae49a5e9895490fa8d78dc0634f2fba44b2f46e4b7574fb95dbbe602f4080e3
                                                      • Instruction ID: 6cd30ad9482765cee0c751f4218bd696e1fdc17a2d1ae67414fd64897e2db519
                                                      • Opcode Fuzzy Hash: 7ae49a5e9895490fa8d78dc0634f2fba44b2f46e4b7574fb95dbbe602f4080e3
                                                      • Instruction Fuzzy Hash: 43B143A1D08A948EF720CB28DC58BEB7B75EF91310F0480FAD54C97281D67A5AC5CF62

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: a68b88ba80c756c6d3376b203e6367bb91a31999e76156b31795c67d9675c94e
                                                      • Instruction ID: b4a42ff9ce9895c2ffe5ba4fff2723ef57966bec80769a80aa68cd0a44310415
                                                      • Opcode Fuzzy Hash: a68b88ba80c756c6d3376b203e6367bb91a31999e76156b31795c67d9675c94e
                                                      • Instruction Fuzzy Hash: 45A114B1D08A948AF7208628DC54BEB7B75EF81310F0480FAD54D97281D67E5BC5CF62

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 4dc115ffeb37aafbb2e463a6b0d351b07e23a2d30ee89e178fb50e0f0a8d98e4
                                                      • Instruction ID: 2500e1dd25975d5ae3c61f2e1b9a1ab52bfb1a69f3a7696b11deb4d3d586d5d2
                                                      • Opcode Fuzzy Hash: 4dc115ffeb37aafbb2e463a6b0d351b07e23a2d30ee89e178fb50e0f0a8d98e4
                                                      • Instruction Fuzzy Hash: 54B144A1D08A948EF720CB28DC54BEB7B75EF91300F0481FAD54D97281D67A5AC5CF62

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: eb602ab7a5bd0a0f96ed443d38e08708acdc1dc6f3f35ce2c2f0980cf2525c6a
                                                      • Instruction ID: b7a899d97010512ae843a5773e3bcb31ffab55ad80a2aa5f3b41362b4124b049
                                                      • Opcode Fuzzy Hash: eb602ab7a5bd0a0f96ed443d38e08708acdc1dc6f3f35ce2c2f0980cf2525c6a
                                                      • Instruction Fuzzy Hash: BFA123B1D08A94CAF7208628DC54BEB7B79EF81311F0484FAD54D9B280D67A4AC5CF66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 428ac052a11de3c078f9d5d5212d8a1d832b49f95c74f54b736ba9323b8c0072
                                                      • Instruction ID: 9aaf9068e02ce2f328c63287398bb2e0b230c33533f524d7ebb98096081e0b22
                                                      • Opcode Fuzzy Hash: 428ac052a11de3c078f9d5d5212d8a1d832b49f95c74f54b736ba9323b8c0072
                                                      • Instruction Fuzzy Hash: 33A135A1D08A98CAF720C628DC54BEB7B79EF81311F0485FAD54D97280D67A4E85CF62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 03ab64d6063661881393cc00a5524f68bbb2e81e346ac86748cd5ec091c39a41
                                                      • Instruction ID: a51679be02b918c84c090750d2227d021afca82756aeaf6b5052505ff1ed4e9a
                                                      • Opcode Fuzzy Hash: 03ab64d6063661881393cc00a5524f68bbb2e81e346ac86748cd5ec091c39a41
                                                      • Instruction Fuzzy Hash: 93A124A1D08A98CAF720C628DC54BEB7B79EF81311F0480FAD54D97280D67A4A85CF62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 6b39e11121b392127d06cf377709e9d89d143386aba3d7696546a4fe9b077b66
                                                      • Instruction ID: 462682e2632d8591faae96c15b8f01cb2c60f5e53af5b4eda3fcde23c3d69b67
                                                      • Opcode Fuzzy Hash: 6b39e11121b392127d06cf377709e9d89d143386aba3d7696546a4fe9b077b66
                                                      • Instruction Fuzzy Hash: EDA123A1D08A94CAF720CA28DC54BEB7B75EF81310F0481FAD54D9B281D67A4B85CF66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 6ccafa5a5aee1c6d9ed91c0494dc628e9c5212c18d4d6f9c060404cd3aaaa9c1
                                                      • Instruction ID: 87fc902dce17c25ad4ce076adfc84d3c0cc3cb2dcf6b6195095dd57fb4d47afa
                                                      • Opcode Fuzzy Hash: 6ccafa5a5aee1c6d9ed91c0494dc628e9c5212c18d4d6f9c060404cd3aaaa9c1
                                                      • Instruction Fuzzy Hash: 1DA123A1D08A94CAF720CB28DC54BEB7B75EF81310F0480FAD54D9B281D67A4B85CF66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: c3ba95c9985a528c8395025ee777458acef502c17568c998b85545f98975520e
                                                      • Instruction ID: 754c89c3b9d1beeeaa4fb57900c5aa949df66466ec29ebe91f3f3f4e6f61e55d
                                                      • Opcode Fuzzy Hash: c3ba95c9985a528c8395025ee777458acef502c17568c998b85545f98975520e
                                                      • Instruction Fuzzy Hash: A8A115A1D08A94CAF720C728DC54BEB7B75EF81311F0480FAD54D9B281D67A4B85CF66
                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 262c9e69a9af4f7a6771bf3a41cd071edb71207ecbf4ae50d51cc4e12f1610d1
                                                      • Instruction ID: 95e82223ee598a739a58c38a4db2832b38ce4b78a13aec56d97b5baae4071804
                                                      • Opcode Fuzzy Hash: 262c9e69a9af4f7a6771bf3a41cd071edb71207ecbf4ae50d51cc4e12f1610d1
                                                      • Instruction Fuzzy Hash: C59113A1D08A98CAF720C728DC547EB7B76EF91300F0481FAD58D97281D67A5AC5CF26
                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: f4366d7d480c33f4f1ba2575da66eff30d07d3e7dccff87c809ef680102040f6
                                                      • Instruction ID: 0ccb0a9581f7b5cdc7ca06eeda8a976b90ff83b08010a78fc6fa23c3198e3244
                                                      • Opcode Fuzzy Hash: f4366d7d480c33f4f1ba2575da66eff30d07d3e7dccff87c809ef680102040f6
                                                      • Instruction Fuzzy Hash: 968123A1D08A988BF720C728DC547EB7B75EF91310F0480FAD54C972C1E6BA5A85CF66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: C$F$H8=C$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 0-237805612
                                                      • Opcode ID: 00c59835e8e1050ecda41eeea107b807dfeafe649c26c04a9c72a3e119238141
                                                      • Instruction ID: 84e33b69c7c36dc27146422eb43f0a8463a6c52a88a0be91bb266a1a8f5ce981
                                                      • Opcode Fuzzy Hash: 00c59835e8e1050ecda41eeea107b807dfeafe649c26c04a9c72a3e119238141
                                                      • Instruction Fuzzy Hash: E5D135B2D041549FE7248A24DC58BFB7B79EB82310F1841BED84D56280EA795AC5CFA3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$F;G=$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-3879827509
                                                      • Opcode ID: 6a0874f6a96ba9ad920a94acfb1c6de61c696c6c3bd7bfc6a37e03b425dc2eea
                                                      • Instruction ID: 6929ccd2a11e3d727de4350b86b3063ee9fa45746a10c35e0f94a6c3d589d136
                                                      • Opcode Fuzzy Hash: 6a0874f6a96ba9ad920a94acfb1c6de61c696c6c3bd7bfc6a37e03b425dc2eea
                                                      • Instruction Fuzzy Hash: C68145B2D081649FF7248A24DC4CBFB7B69EB52310F1841FAD84D56281D6395AC6CBA3
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2762100914
                                                      • Opcode ID: c2660635d0efa29323aea206999c3c5358ab896eddd1afe683cc5fb7140cfaa0
                                                      • Instruction ID: 7c415c2d9035f0bd2f7d56dc8bd13a3ea1e16617b9b2777af22be193bdceac77
                                                      • Opcode Fuzzy Hash: c2660635d0efa29323aea206999c3c5358ab896eddd1afe683cc5fb7140cfaa0
                                                      • Instruction Fuzzy Hash: BC1238B2E041649FF7248A14DC98BFB7B79EB81314F1440FAD84D97280D6395EC6CE62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: C$F$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 0-2762100914
                                                      • Opcode ID: 3d8f094e8f90a333e05ed6f011ed24216db16322cda782de8138d18670aabaff
                                                      • Instruction ID: f97a9a79bbc955d8df8f65836e15623a53060055f78abd5cbf12399c39905324
                                                      • Opcode Fuzzy Hash: 3d8f094e8f90a333e05ed6f011ed24216db16322cda782de8138d18670aabaff
                                                      • Instruction Fuzzy Hash: 00C105B2D041549FE7248A24DC58BFB7B79EB81310F1881FED84D56280EA795EC5CFA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: C$F$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 0-2762100914
                                                      • Opcode ID: 9fdbb2f0118defb4edc0d81d104ee07fa9c9432a95b9f09d5718fd3e8c55a5fa
                                                      • Instruction ID: 7eb8e3bfa5e1322231933f6f796427228ac9e6ffbe0f619561875f1b5f16773d
                                                      • Opcode Fuzzy Hash: 9fdbb2f0118defb4edc0d81d104ee07fa9c9432a95b9f09d5718fd3e8c55a5fa
                                                      • Instruction Fuzzy Hash: 6BB123B2D041549FE7248A24DC58BFB7B79EB81310F1881FED84D56280EA795EC5CFA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: C$F$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 0-2762100914
                                                      • Opcode ID: 9fefafab28df8df4b5e843904999e313636231e0d8ddd652684e5b72142e3c68
                                                      • Instruction ID: 3f4c28ad9c4f3064c48f0c6378d4ae3dc797cf39c68615c033de8ff8bb0e5e97
                                                      • Opcode Fuzzy Hash: 9fefafab28df8df4b5e843904999e313636231e0d8ddd652684e5b72142e3c68
                                                      • Instruction Fuzzy Hash: F2B126A2D041645FF7248A24DC58BFB7B79EB81310F1881FED84D56680EA395EC5CBA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: C$F$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 0-2762100914
                                                      • Opcode ID: 96b7814d178f63d1576fa13cf4ae031935ecf2038c7d45d255c394c1c043f7cb
                                                      • Instruction ID: 92401aff5483e21390c35c2fcd847941f17f5e112e22c3b8871ec7224a5282fb
                                                      • Opcode Fuzzy Hash: 96b7814d178f63d1576fa13cf4ae031935ecf2038c7d45d255c394c1c043f7cb
                                                      • Instruction Fuzzy Hash: EE8116B2E081549FF7248624DC48BFB7B79EB42314F1841FAD84D16681D6395AC5CFA3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2762100914
                                                      • Opcode ID: 34729be37f6c3bd406fd90a105da1bcf0d4d4435e21c33022e09b02d02dc0367
                                                      • Instruction ID: f0ac4596c856e78170d2d4474639b3ecce7c4d2ca4911124afb4a187fafd8852
                                                      • Opcode Fuzzy Hash: 34729be37f6c3bd406fd90a105da1bcf0d4d4435e21c33022e09b02d02dc0367
                                                      • Instruction Fuzzy Hash: 228145B2D081649FF7248A24DC4CBFB7B69EB52314F0841FAD84D56241D6395AC6CBA3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2762100914
                                                      • Opcode ID: 2e23f332cf63429ca4a26cfec203cd53bf8d6e816ebed2cc19355ed3ad1b9437
                                                      • Instruction ID: 21a7a2d134e7b46f626b04e03e69cffd520bbbe1619338c39d23658e69207ca0
                                                      • Opcode Fuzzy Hash: 2e23f332cf63429ca4a26cfec203cd53bf8d6e816ebed2cc19355ed3ad1b9437
                                                      • Instruction Fuzzy Hash: 817145B2D041649FF7248624DC4CBFB7B69EB82324F0841FAD84D56241D6395AD6CFA3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2762100914
                                                      • Opcode ID: f805b92a8df69b882ac700561a16d1355f248f72cbfa867d9881f1a808b9ef1a
                                                      • Instruction ID: d63135beb24a6b16e871fbf198dabeeea2358f79ef8566b5578116ad02e43e40
                                                      • Opcode Fuzzy Hash: f805b92a8df69b882ac700561a16d1355f248f72cbfa867d9881f1a808b9ef1a
                                                      • Instruction Fuzzy Hash: F77157B2D081A49BF7248624CC4CBFB7B69EB52314F0841FED88D56241D6395AC6CFA3
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$^S$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2762100914
                                                      • Opcode ID: ff6721c2aa13f1da27ba2afcfea939601ae9df158979821c7f65d3d399faf5d2
                                                      • Instruction ID: 42015c4d11165324d112faf97ddb9b32e468b8239cc183b4cbaeaec1ae1d67c8
                                                      • Opcode Fuzzy Hash: ff6721c2aa13f1da27ba2afcfea939601ae9df158979821c7f65d3d399faf5d2
                                                      • Instruction Fuzzy Hash: 066135B2D081A49BF7248624DC4CBFB7B69EB52314F0841FAD84D56281D6395AC6CFA3
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: 12d4ac92812902d35f11563bf134e8cec607426211f35c7d6c45573c4d62ab76
                                                      • Instruction ID: bf8f96e514b5353f64015f9d4a9e736baef951ace2a50a7afe1500989a9891c2
                                                      • Opcode Fuzzy Hash: 12d4ac92812902d35f11563bf134e8cec607426211f35c7d6c45573c4d62ab76
                                                      • Instruction Fuzzy Hash: 5D7124B2D045649EFB248625DC88BFB7A79EB81310F0481FAD84C56681D63D5FC6CFA2
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: 0963571aca47cc684f492eecebc47fdd7829cf7d167129590bc02a9dfd95ca83
                                                      • Instruction ID: 0daa4b92ddfc69b635fcebea8c0d5121743e03b70cf1f4162b8e4f8fce435517
                                                      • Opcode Fuzzy Hash: 0963571aca47cc684f492eecebc47fdd7829cf7d167129590bc02a9dfd95ca83
                                                      • Instruction Fuzzy Hash: 027102B2D045649EF7248624DC8CBFBBB79EB81314F0480FAD84C56680D6395BC5CF62
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: d748881329fcc699b7eff3dbd0337168da592cad4379649b7d7258a8b5b846e7
                                                      • Instruction ID: ce20e196e0fee3a89faf8dea2c3a5de7593d8d033f906db669dfdf1a71409261
                                                      • Opcode Fuzzy Hash: d748881329fcc699b7eff3dbd0337168da592cad4379649b7d7258a8b5b846e7
                                                      • Instruction Fuzzy Hash: 8B7127B2D085649AF7248624CC4CBFB7B39EB82314F0481FAD84D66681D6395FC5CFA2
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: e07dcfd96d2cdcffd84f4207917f34735266ddea4115ee044be62df936208b28
                                                      • Instruction ID: adc6d135d092ed245951475d9600139faad11ba5029857085e7177e8fa6b38ad
                                                      • Opcode Fuzzy Hash: e07dcfd96d2cdcffd84f4207917f34735266ddea4115ee044be62df936208b28
                                                      • Instruction Fuzzy Hash: 1F6124B2D081589AF7248624DC88BFB7B79EB81314F0481FAD84C56681D63D5FC6CFA2
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: 4f5e601d6170a687474205e62f0dd72f00cc7031b49dcb9bd09c47f6c99f16a2
                                                      • Instruction ID: 33ac3e273b9c96de3d2bbef2e8a54f6b9c88d5f63d96735dfb82c2a6efcf5c19
                                                      • Opcode Fuzzy Hash: 4f5e601d6170a687474205e62f0dd72f00cc7031b49dcb9bd09c47f6c99f16a2
                                                      • Instruction Fuzzy Hash: 0A6115B2D045649AF7248625DC4CBFBBB79EB81310F0481FAD84C56680D63D5BC5CF62
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: e|$jjjj$3
                                                      • API String ID: 963392458-3664671931
                                                      • Opcode ID: 3dba41fc32f6e05c665d24cecdc361cbec0803541761e3f51412b788bc7c96c6
                                                      • Instruction ID: 316da7f59538240f5af058948c97cf7bf062741ec584898f82da4a9bd9dec851
                                                      • Opcode Fuzzy Hash: 3dba41fc32f6e05c665d24cecdc361cbec0803541761e3f51412b788bc7c96c6
                                                      • Instruction Fuzzy Hash: C5F19EB1D042699BEB288B14DD95BEAB7B5FF85304F0481FAD80EA3240D6799FC1CE51
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: HOK8$Qj@h
                                                      • API String ID: 0-1820051497
                                                      • Opcode ID: c7aff2d1236d7e88610a91171504af3979652f6d5e6f6fdfdc99b12935a21c3c
                                                      • Instruction ID: 1b72033d778d045be44fb88aaa5a767f3a2254f73b943e84cff3ecc87d7eadf5
                                                      • Opcode Fuzzy Hash: c7aff2d1236d7e88610a91171504af3979652f6d5e6f6fdfdc99b12935a21c3c
                                                      • Instruction Fuzzy Hash: 82E102B2D015259BEB648A15DC84BEBBB75FF80310F0440FAD90D66680E6785FC1CFA5
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: 48G7$[W
                                                      • API String ID: 0-2613270748
                                                      • Opcode ID: a6b5139e280069978d9ca34c33c6342866b36cd27806f56c680c101bf1cfd011
                                                      • Instruction ID: 0a506768f3b6120e6c6938e4b86a8e74ca6cc5fdad893f2c369a0284c21293e7
                                                      • Opcode Fuzzy Hash: a6b5139e280069978d9ca34c33c6342866b36cd27806f56c680c101bf1cfd011
                                                      • Instruction Fuzzy Hash: 4C8178B2D006145EF7148B64DC84BFB7779EB80310F1441FAD90DA6A80E67D6FC1CA66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: HOK8$Qj@h
                                                      • API String ID: 0-1820051497
                                                      • Opcode ID: 98066c8ae52f604843d6b1fd0d87446528c330490a37089092e9a8eb25c32d44
                                                      • Instruction ID: 7e72365a8dceeb2f4bd53f959d58b057d972039ddc0cab00bff69659d07fc2d9
                                                      • Opcode Fuzzy Hash: 98066c8ae52f604843d6b1fd0d87446528c330490a37089092e9a8eb25c32d44
                                                      • Instruction Fuzzy Hash: CA910FB1D016698BEB688B18DC50BEABB75FB81304F0440FAD54EA7281E6385FC1CF55
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: APMD$Qh?
                                                      • API String ID: 71445658-3826885610
                                                      • Opcode ID: 167adee28c880babfaa74f7941a2c221eba143b42238af1e88efce5925f70ed0
                                                      • Instruction ID: 927881980dace9c0d8b2bc515390265386814b822721e38c7c2b64b84e602fb2
                                                      • Opcode Fuzzy Hash: 167adee28c880babfaa74f7941a2c221eba143b42238af1e88efce5925f70ed0
                                                      • Instruction Fuzzy Hash: D87136A2D146249BF7208A24DC88BF77779EF91310F1440BAD94D97281D27D5FC6CBA2
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID: :O=O
                                                      • API String ID: 4241100979-1235163547
                                                      • Opcode ID: b7490c10584c8ba5c28c84b1d3d716211eac9895d26977e3e5d13635d7d9961f
                                                      • Instruction ID: 5ac9027744b01eeca8d44894ee76b3f78c6c9f2f64b04097ef3c1261d550352c
                                                      • Opcode Fuzzy Hash: b7490c10584c8ba5c28c84b1d3d716211eac9895d26977e3e5d13635d7d9961f
                                                      • Instruction Fuzzy Hash: 0EF1C2F2D041649FF7258B14DC99BFAB779EB80314F1441FAE949A6240E6386FC2CA91
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: [W
                                                      • API String ID: 0-2887293924
                                                      • Opcode ID: 135efd5f9b170df56fc45e8e61961e0456c4ac0460e2d60b1f62092de0cd6adc
                                                      • Instruction ID: dd2ea9c14ea2a6b8c0cf52f90c6d6f80f0671a9a0a49639bbe1148e274bafb79
                                                      • Opcode Fuzzy Hash: 135efd5f9b170df56fc45e8e61961e0456c4ac0460e2d60b1f62092de0cd6adc
                                                      • Instruction Fuzzy Hash: DED158E2D142149AF7648A24EC49AFB7779FF80310F0441BAE90D97A80E6795FC1CB66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: b43673e0d0d64f63a420768b71839fe48d162405696a74acec7a03a0c9f5c81c
                                                      • Instruction ID: e8388196c4ec51592e101fb87e6e8466cc66eda1d9c6b2a355ea86d55f8650cd
                                                      • Opcode Fuzzy Hash: b43673e0d0d64f63a420768b71839fe48d162405696a74acec7a03a0c9f5c81c
                                                      • Instruction Fuzzy Hash: 4DB12AA2D146289BF7248A24DC48BFB7779EF90310F0440BAD84D97280E67D5EC5CF66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: 48fd78297c41da2610b927695faf6bd15d34286bcc2f98b97441e76f891340ee
                                                      • Instruction ID: c29056377bf9555acac9a3da86d97000bbe891ecde03bf179252df179dcc6696
                                                      • Opcode Fuzzy Hash: 48fd78297c41da2610b927695faf6bd15d34286bcc2f98b97441e76f891340ee
                                                      • Instruction Fuzzy Hash: 0EB139A2D046689AF7208B24DC88BFB7B75EF91310F0441FAD94D97281E67D1EC5CB62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: MA=5
                                                      • API String ID: 0-87635094
                                                      • Opcode ID: a6312808692b1f1b699c53d0535f4c5b76d37a8d75a27af7a8ae56b2ded731da
                                                      • Instruction ID: 00a703a417adc857fce6794f4662f23ce6622d99952829a43fb8e9480420fc2e
                                                      • Opcode Fuzzy Hash: a6312808692b1f1b699c53d0535f4c5b76d37a8d75a27af7a8ae56b2ded731da
                                                      • Instruction Fuzzy Hash: CBB114F2E051249BE7288A14DC84AFB7779EFC1311F1481FAD80E96780E6785FD2CA52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: f4f81889b03a9f5161e3f212acfe2d5f51fc9e55ad3ba89e5638efb347f5b5ae
                                                      • Instruction ID: 8c8c511af1ff6a33ba7a0a1e64a4a7ab9819bdce11b6d61da4778dd7d4e5a21a
                                                      • Opcode Fuzzy Hash: f4f81889b03a9f5161e3f212acfe2d5f51fc9e55ad3ba89e5638efb347f5b5ae
                                                      • Instruction Fuzzy Hash: BE9137A2D146249BF7248A24DC88BF77779EF90310F0480BAD80D97281D27D5FC6CBA2
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,?), ref: 025FFF17
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID: LL<P
                                                      • API String ID: 1726664587-2443076662
                                                      • Opcode ID: 140d349709f0c188a45a753ea468bdd23ee5d111cf0563b88cae3c81dbf1d2af
                                                      • Instruction ID: d5c6a29f415000909df1b510c9be8d6a9ea8187d0acae10591a4153ce7d8daaf
                                                      • Opcode Fuzzy Hash: 140d349709f0c188a45a753ea468bdd23ee5d111cf0563b88cae3c81dbf1d2af
                                                      • Instruction Fuzzy Hash: A19157F1C052659EE7608B60CC95AFABB74FF41310F1480FED98D96690E2396EC5CB62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: c3f54e879e29621184847182744fdc9b3c4e75ffabb6fa9adb560d714531102d
                                                      • Instruction ID: ae27175cd5e597af0d9c46359e73a6d74bf1efc58a7f23f1ebfef4b66f950000
                                                      • Opcode Fuzzy Hash: c3f54e879e29621184847182744fdc9b3c4e75ffabb6fa9adb560d714531102d
                                                      • Instruction Fuzzy Hash: 19814AA2D006649BF7248A24DC48BF77A38EF91310F0441BAD94D976C1E67D5FC6CBA2
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 5aa22d61769fb6425d8b90f67b7e038c0045611de96a62be7ff71977fbe81d6c
                                                      • Instruction ID: 80b69f1c1b0d43b6b69f77199f25afc784650c53a1b798e7687403ee0b534357
                                                      • Opcode Fuzzy Hash: 5aa22d61769fb6425d8b90f67b7e038c0045611de96a62be7ff71977fbe81d6c
                                                      • Instruction Fuzzy Hash: AA8124B2C056249FF7288A14DC88BFBBB79EF44310F0441BADD4E66680E6391EC1CE52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: cc4ac58f0ea004a15037403d0605ae9a7d8642fae7b2974e8debeb759e1155f7
                                                      • Instruction ID: 816ccdd1b8763ee5ad045cd037e9c354f2abf8f777ec39f62d08def3ae58f89d
                                                      • Opcode Fuzzy Hash: cc4ac58f0ea004a15037403d0605ae9a7d8642fae7b2974e8debeb759e1155f7
                                                      • Instruction Fuzzy Hash: BB8128A2D046249BF7208A24DC48BF77B39EF91310F1441BAD84DA7281D27D5FC6CBA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: f188b4904d59c0088afb34655b009d17616b34ac658a029cb1d9d615047c51d4
                                                      • Instruction ID: b99b48eb553dfcb8d144a4aaf9c2162949f061c86ef061494dc10c4191b7be18
                                                      • Opcode Fuzzy Hash: f188b4904d59c0088afb34655b009d17616b34ac658a029cb1d9d615047c51d4
                                                      • Instruction Fuzzy Hash: BE7125B2D156249EF7288A15DC88BFBBB78EF44311F0441BADD0E66280E6781EC1CF52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: 4d9858ad6bbb029d9ab5dbe0eaaf46d71c6d0f0bd1886e624933c3c2f9b6954d
                                                      • Instruction ID: 1278313b2a039718437f41e42b23bf59d118bcf1338fbb1b0eb6a460edeaa240
                                                      • Opcode Fuzzy Hash: 4d9858ad6bbb029d9ab5dbe0eaaf46d71c6d0f0bd1886e624933c3c2f9b6954d
                                                      • Instruction Fuzzy Hash: C17139A2D042689BF7208A64DC88BFB7A79EF91310F0041BBD94D972C1D6795FC5CB62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: cdf9eb6f4b8743255cdc78b4b680ae2e7960c797c81e83628a7952e3ad9dd269
                                                      • Instruction ID: 6e145baa54ca789c1e58c769a3570f3809fbc965ba45ef8ba412cb806e46ec55
                                                      • Opcode Fuzzy Hash: cdf9eb6f4b8743255cdc78b4b680ae2e7960c797c81e83628a7952e3ad9dd269
                                                      • Instruction Fuzzy Hash: 997148A2D042649BF7248A24DC88BF77B35EF91310F0441BAD54D672C1E6795FC6CB62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: ef1f894bd7de6b5c5357bded858276bcb0d49cf3a38b8bbd6c22435cb5206894
                                                      • Instruction ID: 21a5bc4fde54e950bf73d58fe1c2dae45f38773e627eedbbe7caade335ba1b96
                                                      • Opcode Fuzzy Hash: ef1f894bd7de6b5c5357bded858276bcb0d49cf3a38b8bbd6c22435cb5206894
                                                      • Instruction Fuzzy Hash: 7D7113B2D156249EF7288A14DC88BFBBB78EF45310F0441BADD4E66680E6781EC5CF52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: dbc7fcbb021754ba02121b2d7054a2945ad6d210af2909f92f1353d23594d1a3
                                                      • Instruction ID: 517dc4573cf55b832b5b9e09ec6b5942f923f131bcfd10fb5b7c7938d90aedfe
                                                      • Opcode Fuzzy Hash: dbc7fcbb021754ba02121b2d7054a2945ad6d210af2909f92f1353d23594d1a3
                                                      • Instruction Fuzzy Hash: 547112B2D156249EF7288A14DC88BFBBB78EF44310F0441BADD4E66280E6781EC5CF52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: 7df50ef1ead95016a3011bea91cbca48bf0bc159ba4a31cac764b7adb977cd33
                                                      • Instruction ID: 9d4aac82701a5d7320011d3cee362fa46577089078641baf57ee677dd31e7786
                                                      • Opcode Fuzzy Hash: 7df50ef1ead95016a3011bea91cbca48bf0bc159ba4a31cac764b7adb977cd33
                                                      • Instruction Fuzzy Hash: 2E7117B2D056249EE7248B65DC88BFBBB75EF45311F0401BADC4D66281E6781EC1CFA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 64e73b324a754662f6397a4c49ee7515b7ee6af3abf85df74695dbba4c72fa27
                                                      • Instruction ID: f40bebb7a12ff33dad7fab7fe72f84440b48b285ab17b4c854cf456d5f5fed33
                                                      • Opcode Fuzzy Hash: 64e73b324a754662f6397a4c49ee7515b7ee6af3abf85df74695dbba4c72fa27
                                                      • Instruction Fuzzy Hash: 576137A2D04264ABF7208A64DC88BE77A79EF91310F0041BAD54D972C1D6795FC6CB62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: bdc32cf3d8bb217a39d6c2c2d29b6ab9e2e8835a8293f2f266288eec2ff1c12e
                                                      • Instruction ID: 57d947996dc4da14bcb0f2b9446870fa4fac8eed0e9ffba1d1d160cc9835d132
                                                      • Opcode Fuzzy Hash: bdc32cf3d8bb217a39d6c2c2d29b6ab9e2e8835a8293f2f266288eec2ff1c12e
                                                      • Instruction Fuzzy Hash: CE6148A2D042649BF7208A64DC88BF77A39EF91310F0041BAD94D972C1D2795FC6CB63
                                                      APIs
                                                      • VirtualProtectEx.KERNELBASE(?,?,00001000,00000040,?), ref: 025F9AA6
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ProtectVirtual
                                                      • String ID: Qj@h
                                                      • API String ID: 544645111-2762301250
                                                      • Opcode ID: 3717cbc6e8c0853333f6f627db32d5dcb435c8902d2bf3379e64c43ca49130ac
                                                      • Instruction ID: 0346a668a835caa0d714a0b958a16fbe7a4e57c96fde5624b7f3e646792cb6cc
                                                      • Opcode Fuzzy Hash: 3717cbc6e8c0853333f6f627db32d5dcb435c8902d2bf3379e64c43ca49130ac
                                                      • Instruction Fuzzy Hash: 9F7112B2D096189FE754CA28CC80AEAB7B9FF85300F1480FAD94D57685D6386EC1CE61
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID: :O=O
                                                      • API String ID: 4241100979-1235163547
                                                      • Opcode ID: 8648a33ec8c010cb08e916d5a6a5ee664dab7af7847df3e183da176a33de1e3d
                                                      • Instruction ID: c73b9dc7e0eac78755061f0cba3f568537f24a67d49cc22c4ec848f3ec3cfd0c
                                                      • Opcode Fuzzy Hash: 8648a33ec8c010cb08e916d5a6a5ee664dab7af7847df3e183da176a33de1e3d
                                                      • Instruction Fuzzy Hash: A0515BF2D041545FF7258A24DC89AFBBB79EF81314F0440BEE84D96640E539ABC6CE62
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 613611480924e13e69686bd9e5aadd932961cdc189dc9b231654ba47b64b8a74
                                                      • Instruction ID: a725ca0e9280250df2edd56f86651c7834a127ba03fa2ef27ed45b5a1cefcefd
                                                      • Opcode Fuzzy Hash: 613611480924e13e69686bd9e5aadd932961cdc189dc9b231654ba47b64b8a74
                                                      • Instruction Fuzzy Hash: DA5126A2D04268AAE7248B25CC58BFB7779EF81300F1040F9D98D67240E6785EC6CF62
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: fa11ac3b6f2baedc44f03ad66f4aeb87b5c5fc57b0ad4d4cf41d8eec483e9db4
                                                      • Instruction ID: 82f6fbe6607a8a31f149bd361900a84896237fdff2bd06ba32ca2197cfa69fc4
                                                      • Opcode Fuzzy Hash: fa11ac3b6f2baedc44f03ad66f4aeb87b5c5fc57b0ad4d4cf41d8eec483e9db4
                                                      • Instruction Fuzzy Hash: 415105F3D106296FF3248A14DC88BF77A68EB91314F0540BAD90D66680D67D5FC18EA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: BE?@$uCV
                                                      • API String ID: 0-1269530686
                                                      • Opcode ID: 7e20158170f11d7449429adae57f0f38aa0d1dbe5898be55dc8d1b8f63c02f0a
                                                      • Instruction ID: fb99ac1309c5331736e0a11b89d34cd46664e627b01899bf07c6d70bf6ef148f
                                                      • Opcode Fuzzy Hash: 7e20158170f11d7449429adae57f0f38aa0d1dbe5898be55dc8d1b8f63c02f0a
                                                      • Instruction Fuzzy Hash: 3352B512E2466987DB78CB39DC116AFA2B3EF58300F05D4FD940DE7664F6704A899B0A
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: uCV
                                                      • API String ID: 0-3959665651
                                                      • Opcode ID: 23d58b488787481adfdcf1e5d9fb0c6fd92abbf23af05cb47b6cb62d2484896d
                                                      • Instruction ID: 5be224e718d0c6561667481bf28c5e092aab85c7bb65fb979a33879328525eb9
                                                      • Opcode Fuzzy Hash: 23d58b488787481adfdcf1e5d9fb0c6fd92abbf23af05cb47b6cb62d2484896d
                                                      • Instruction Fuzzy Hash: FB52B512E2466987DB78CB39DC116AFA2B3EF58300F05D4FD940DE7664F6704AC99B0A
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: uCV
                                                      • API String ID: 0-3959665651
                                                      • Opcode ID: 74a83ff51e6cb037361ef7cd7d432925d8366120107e6349fb4a6035ecb5944b
                                                      • Instruction ID: 19c363f33c0c6ee0236730c862d008d5a4efe4fe7c4c8c63e99a3b8815b11aa8
                                                      • Opcode Fuzzy Hash: 74a83ff51e6cb037361ef7cd7d432925d8366120107e6349fb4a6035ecb5944b
                                                      • Instruction Fuzzy Hash: 4452C512E2466987DB78CB39DC116AFA2B3EF58300F05D4FD940DE7664F6704AC99B0A
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: uCV
                                                      • API String ID: 0-3959665651
                                                      • Opcode ID: c3de9c4c0d85e25a716f76ce3e7cb6f307d614f17d08f5a3893c167765f33851
                                                      • Instruction ID: 3c82fceb85a017f8008ca74d83d5306541af25bfcae04f3da165a85cfcdaec70
                                                      • Opcode Fuzzy Hash: c3de9c4c0d85e25a716f76ce3e7cb6f307d614f17d08f5a3893c167765f33851
                                                      • Instruction Fuzzy Hash: F252B612E2466987DB78CB39DC1169FA2B3EF58300F05D4FD940DE7664F6704A899B0E
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: uCV
                                                      • API String ID: 0-3959665651
                                                      • Opcode ID: 4d4103673ccb6d33ac9df3bb48d9cfd2c2432435b8c4ba2e8ade471748871692
                                                      • Instruction ID: 5f3f54c273c1a739ebd9890d84cac5f1404e0a6086b5feeec767870d7951a1c5
                                                      • Opcode Fuzzy Hash: 4d4103673ccb6d33ac9df3bb48d9cfd2c2432435b8c4ba2e8ade471748871692
                                                      • Instruction Fuzzy Hash: C952B512E2466987DB78CB39DC116AFA2B3EF58300F05D4FD940DE7664F6704A899B0E
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: uCV
                                                      • API String ID: 0-3959665651
                                                      • Opcode ID: 892c261b7b1d5bb0688400d1fff9cba0ae01cce9dd37d30fa1fe7d070eeec8b8
                                                      • Instruction ID: e8069d1286fcc7ff1f9cf6331f804de045f082e095c2810cf200129a67b9b2ac
                                                      • Opcode Fuzzy Hash: 892c261b7b1d5bb0688400d1fff9cba0ae01cce9dd37d30fa1fe7d070eeec8b8
                                                      • Instruction Fuzzy Hash: CE52B512E2466987DB78CB39DC1169FA2B3EF58300F05D8FD940DE7664F6704A899B0E
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: uCV
                                                      • API String ID: 0-3959665651
                                                      • Opcode ID: 8be073f0a1baad99046e8a43ec4a45ab7dc1f7d127048612cfb83b5a67bbf133
                                                      • Instruction ID: c6da4a4dac591d15c24a711ba80f8303f9594ad5aff4b51d79e43adb7a9f4c0a
                                                      • Opcode Fuzzy Hash: 8be073f0a1baad99046e8a43ec4a45ab7dc1f7d127048612cfb83b5a67bbf133
                                                      • Instruction Fuzzy Hash: 6C52B512E2466987DB78CB39DC1169FA2B3EF58300F05D8FD940DE7664F6704A899B0E
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: e4060d40adc3fd9f9ed1e4c773bfb6e8265e28c089cea169c4f019777d9c2072
                                                      • Instruction ID: aa222cf1bdf92c42e798bdf789b9c44d54de58644ca6f9a4f45aa97e301313ee
                                                      • Opcode Fuzzy Hash: e4060d40adc3fd9f9ed1e4c773bfb6e8265e28c089cea169c4f019777d9c2072
                                                      • Instruction Fuzzy Hash: FA81C0B1D006699FEB24CB14DC98BFABBB5EB44304F1481FAD909A7241D638AFC1CE55
                                                      APIs
                                                      • Wow64SetThreadContext.KERNEL32(?,?), ref: 02603D9D
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID:
                                                      • API String ID: 983334009-0
                                                      • Opcode ID: abcf63d8226c3dbeb080eb768e63af40779c3bb78f66a8427a3b78640d74467b
                                                      • Instruction ID: df9d4b7d41c8c8cfcdd98cc4638f72901962cf20bde09275c0f3000ca053b8c9
                                                      • Opcode Fuzzy Hash: abcf63d8226c3dbeb080eb768e63af40779c3bb78f66a8427a3b78640d74467b
                                                      • Instruction Fuzzy Hash: 7D51D4B1D041289BE728CA15CDC4EEBB775EF85315F0481FAD90D66780DA386ED2CE91
                                                      APIs
                                                      • Wow64SetThreadContext.KERNEL32(?,?), ref: 02603D9D
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID:
                                                      • API String ID: 983334009-0
                                                      • Opcode ID: 341ff460e2f77d12f63157f66db0c08ed40ac0c723c1733ba32e94161a2d06eb
                                                      • Instruction ID: 13d8a58adc88bfb5a88380dfcf50c672c9d910c7d35814d8a7a88c5f2a7c242b
                                                      • Opcode Fuzzy Hash: 341ff460e2f77d12f63157f66db0c08ed40ac0c723c1733ba32e94161a2d06eb
                                                      • Instruction Fuzzy Hash: 6951E4B1D041188BEB28CA15CD91AEBB775EB81301F0481FAD90E67780D678AFD2CF51
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025E6AF4
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 93444332c1aa5a8f9d50233748abbb2f679c7cd79ccba3a6c88cbf5bd95cd00f
                                                      • Instruction ID: cb8cce624b28b0bfd0cddc19eb89a3c285de4a0380e7885faa09f06ef7c7c9f0
                                                      • Opcode Fuzzy Hash: 93444332c1aa5a8f9d50233748abbb2f679c7cd79ccba3a6c88cbf5bd95cd00f
                                                      • Instruction Fuzzy Hash: F6B1DEB2D005249FFB288A04DC94BFB7B79FB90354F1481FAD90E56680DA385EC5CE96
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 11af34889a470fcc8d3430187de7d69d5551f8e1e489104c391bd929b849914f
                                                      • Instruction ID: 43326b6547a9596237ce74ba411255a736c7e0474260ff41dd57f69129849960
                                                      • Opcode Fuzzy Hash: 11af34889a470fcc8d3430187de7d69d5551f8e1e489104c391bd929b849914f
                                                      • Instruction Fuzzy Hash: 5D7120F2C001159FFB288A14DC99BFB7B69FB90318F1441FAD90A96180D7795EC6CE16
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025E6AF4
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: fc6b240b6f351846ffd7a7794550524a6f3ac805bb9cb14504d8c3c7ee1fbdb1
                                                      • Instruction ID: 977ece7d310fe28d597abec8acd61c2fbd2067633e18065c5cdf1b1ed5d77367
                                                      • Opcode Fuzzy Hash: fc6b240b6f351846ffd7a7794550524a6f3ac805bb9cb14504d8c3c7ee1fbdb1
                                                      • Instruction Fuzzy Hash: 6D6133B2C041199EFB288A10EC98BF7776DFB90358F1441BAD80A966C0D77D5EC4CE56
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: fb6cd54db9be411a05a742f554497d9800039274be18cd1bdd1adc06b5a97e37
                                                      • Instruction ID: 030000cdb02d69d31ec4b867f1090daf53d22426b582100dc708646206e9453b
                                                      • Opcode Fuzzy Hash: fb6cd54db9be411a05a742f554497d9800039274be18cd1bdd1adc06b5a97e37
                                                      • Instruction Fuzzy Hash: 6D42A512A2466987DB78DB79DC1129FA2B3EF58300F04D8FD940DE7664F6704AC99B0E
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 498e567e7dbefb98ab3da0dd403db206ebe1e9db4f5ba87e310e0d4cf3e87e22
                                                      • Instruction ID: 199088dfb531efa13309c6e59d16ca0a6d7bc37a9ce801aefdb1afdd0adae4c5
                                                      • Opcode Fuzzy Hash: 498e567e7dbefb98ab3da0dd403db206ebe1e9db4f5ba87e310e0d4cf3e87e22
                                                      • Instruction Fuzzy Hash: 9E429412A2466987DB78DB79DC1129FA2B3AF58300F04D8FD940DE7664F6704A899B0E
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 07ff73659fe7e3f0c7468fab5d9e9dcf90faffb637ec7c4c2459f30e688cc82c
                                                      • Instruction ID: 9bdddbe948fa03a7417f7104a761f9d8d76aa7b68ce3120afb97be612c284933
                                                      • Opcode Fuzzy Hash: 07ff73659fe7e3f0c7468fab5d9e9dcf90faffb637ec7c4c2459f30e688cc82c
                                                      • Instruction Fuzzy Hash: 5A42A412A2466987DB78CB79DC1129FA2B3EF58300F04D8FD940DE7664F6704AC99B0E
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 9e5aeab3714a05b3a0dae3d9a99c49b617bd5c1769e61475138dde2c4926b365
                                                      • Instruction ID: 6e2ff7cdea0e98dbd85c3a0d6c5f81dc4dcf9f4d3aa6c70ec031abc710f0b1fa
                                                      • Opcode Fuzzy Hash: 9e5aeab3714a05b3a0dae3d9a99c49b617bd5c1769e61475138dde2c4926b365
                                                      • Instruction Fuzzy Hash: 5E42A312A2466987DB78CB79DC1129FA2B3EF58300F04D8FD940DF7664F6704A899B0E
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: f2102b9983f4e5aad6f780c3bb305f90e62864f9985524531b830f2548971782
                                                      • Instruction ID: 95e50642ab74a282c46c7936d4cb4b902189b3e9483688fecc6109fb5251bb28
                                                      • Opcode Fuzzy Hash: f2102b9983f4e5aad6f780c3bb305f90e62864f9985524531b830f2548971782
                                                      • Instruction Fuzzy Hash: 2A429412A2466987DB78DB79DC1129FA2B3AF58300F04D8FD940DF7664F6704AC99B0E
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: fa28c16bd5c256e6bb1e9407130cf279fec226ada43d4b248d4ca1568f9c8d07
                                                      • Instruction ID: e155a5eb197ec93464d528eef020e5faf95454865efb7ef8ff87e970bf370559
                                                      • Opcode Fuzzy Hash: fa28c16bd5c256e6bb1e9407130cf279fec226ada43d4b248d4ca1568f9c8d07
                                                      • Instruction Fuzzy Hash: 19429412A2466987DB78DB79DC1129FA2B3EF58300F04D8FD940DE7664F6704AC99B0E
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 37b8f89c78f365d4ba023b48e339609bc778936a7baa0c0225d04682052b6e89
                                                      • Instruction ID: 58cbaeb18998b5173a8801c8872933f8955c88bac099a1fd603b4b249b23e86f
                                                      • Opcode Fuzzy Hash: 37b8f89c78f365d4ba023b48e339609bc778936a7baa0c0225d04682052b6e89
                                                      • Instruction Fuzzy Hash: 81429312A2466987DB78DB79DC1129FA2B3AF58300F04D8FD940DF7664F6704AC99B0E
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: fac0700508e457a88d76806ff6e9a546318000cdd52a18213e7c793b4d9c6468
                                                      • Instruction ID: 1e346ac22f926a0d72e3d45a34440e40e767742f44e70f8fcda27d754cf9a12a
                                                      • Opcode Fuzzy Hash: fac0700508e457a88d76806ff6e9a546318000cdd52a18213e7c793b4d9c6468
                                                      • Instruction Fuzzy Hash: 4F429312A2466987DB78DB79DC1129FA2B3AF58300F04D8FD940DF7664F6704AC99B0E
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 470462819948c91e2f6baf302f4ac4256563253d9730faf572d35be2f27591d7
                                                      • Instruction ID: 38fabeac188fee7d45c005d42cc4da9c6197b93b09d0988ccfc83a28555125d3
                                                      • Opcode Fuzzy Hash: 470462819948c91e2f6baf302f4ac4256563253d9730faf572d35be2f27591d7
                                                      • Instruction Fuzzy Hash: 76429312A2466987DB78DB79DC1129FA2B3AF58300F04D8FD940DE7664F6704A899B0E
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 3e6431742f447d855927a9c7bea5268b0ba3367f8daed63d1cfa17a3f6bf0ef4
                                                      • Instruction ID: 0348b4b023edc7e27ebb442790926a6513d06457c939fa4ea049722cb45cb25d
                                                      • Opcode Fuzzy Hash: 3e6431742f447d855927a9c7bea5268b0ba3367f8daed63d1cfa17a3f6bf0ef4
                                                      • Instruction Fuzzy Hash: B2429312A2466987DB78DB79DC1129FA2B3AF58300F04D8FD940DF7664F6704A899B0E
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 4ea489bf442f2e2140d18fc83fb3d288ef5cbf678d14eca11dcdfaa47c780e6a
                                                      • Instruction ID: fa29968a63d574e83ccacf219ccb7519236a7f996cd925c88243ae80ddf8cc71
                                                      • Opcode Fuzzy Hash: 4ea489bf442f2e2140d18fc83fb3d288ef5cbf678d14eca11dcdfaa47c780e6a
                                                      • Instruction Fuzzy Hash: 76429312A2466987DB78DB79DC1129FA2B3AF58300F04D8FD940DE7664F6704AC99B0E

                                                      Control-flow Graph

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: 7C=X$M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3634595442
                                                      • Opcode ID: bf5b08b61f1f49335c4ba1961894fdaa3af5ef3f80f58a27d04ca77409556135
                                                      • Instruction ID: d2db50670711ecb9c5d67c7f9647e65381f8d468cfade8a484a70cafa1d0479c
                                                      • Opcode Fuzzy Hash: bf5b08b61f1f49335c4ba1961894fdaa3af5ef3f80f58a27d04ca77409556135
                                                      • Instruction Fuzzy Hash: C19102A1D08A988EF721C728DC547EB7B75EF91300F0480FAD54D97281E6BA5AC5CF26
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: db7eb60b99b1cdce69def50a63989aa54ac694bb237113558e5e1f59828d6909
                                                      • Instruction ID: a694d73d3b35fd312532a1e806cefcb3ddf75005ce7feaf0e32571dd5d33d38d
                                                      • Opcode Fuzzy Hash: db7eb60b99b1cdce69def50a63989aa54ac694bb237113558e5e1f59828d6909
                                                      • Instruction Fuzzy Hash: D99115A1D08A94CAF720CB28DC54BEB7B75EF81300F0440FAD54D9B281D67A5B85CF66
                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: eb34d95d95800202ab416b5984b4af080cc07e3db2fcd57dd2615fdc96d9259e
                                                      • Instruction ID: d84b7a41671b776f9b18bfbb093b60b99812e5eead752b5d09271a112527cb9e
                                                      • Opcode Fuzzy Hash: eb34d95d95800202ab416b5984b4af080cc07e3db2fcd57dd2615fdc96d9259e
                                                      • Instruction Fuzzy Hash: DB8124A1D08A988EF721CB28DC547EB7BB5EF81300F0440FAD54C9B291D67A5AC5CF22
                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 23c4838bbbab62424123fe109bb222c9ea99670f931ba2b2bea959848843be8a
                                                      • Instruction ID: 40f4877b9b9737d294e50635e4d185539b569dcfef6617b18da5817366548d12
                                                      • Opcode Fuzzy Hash: 23c4838bbbab62424123fe109bb222c9ea99670f931ba2b2bea959848843be8a
                                                      • Instruction Fuzzy Hash: 1781F5A1D08A948AF720C628DC147EB7B75EF91301F0480FAD54D972C1E6BE5A85CF66
                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 2ce7c5bcb4186651efda36c16a3f51d79a116bc30f7e7bf0a099a578f207d204
                                                      • Instruction ID: 60554824a66f7389bf9bc114af5c2158ca96b732a16f0fc0c73487dfd25b06ed
                                                      • Opcode Fuzzy Hash: 2ce7c5bcb4186651efda36c16a3f51d79a116bc30f7e7bf0a099a578f207d204
                                                      • Instruction Fuzzy Hash: 218123A1D08A948AF720C728DC54BEB7B75EF91301F0440FAD54D9B281E6BA5BC5CF26
                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 6cf07029c6afb5e60930422e282b57c01c388124ddf09f8b1a2e7bf0a2b2e766
                                                      • Instruction ID: b5e72cd4a13c72e35c7aa2583a1e2417bf4660724cf597a2a391997a8689cc5d
                                                      • Opcode Fuzzy Hash: 6cf07029c6afb5e60930422e282b57c01c388124ddf09f8b1a2e7bf0a2b2e766
                                                      • Instruction Fuzzy Hash: 108123A1D08A98CAF721C728DC547EB7B76EF91300F0480FAD54D97281D67A5AC5CF26
                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 0ff6de46a3414543cb7f0df893307e144931cbdfd716928f3cd0b777ba6b7b2f
                                                      • Instruction ID: d48e65f5ead60de5fe0bab67f3435678755f64823eec3ab916024491564153e7
                                                      • Opcode Fuzzy Hash: 0ff6de46a3414543cb7f0df893307e144931cbdfd716928f3cd0b777ba6b7b2f
                                                      • Instruction Fuzzy Hash: DB8122A1D08A988AF720C728DC547EB7B75EF91300F0480FAD54D9B281D67E5A85CF26
                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 6c0707995ebd23d25e52c71895fac481955ae37f310cd51f85951da0009297ef
                                                      • Instruction ID: de4fd9d70a6475d221df6d056611bcea98e25b970e8360df6e2ad581c2b83f33
                                                      • Opcode Fuzzy Hash: 6c0707995ebd23d25e52c71895fac481955ae37f310cd51f85951da0009297ef
                                                      • Instruction Fuzzy Hash: F08114A1D08A94CAF720C728DC547EB7B75EF91301F0480FAD54D9B281D6BE5A85CF26
                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: b4628df3ade875b58f57b8968671842ecf493c8174b45dc6aa282c95754c1a57
                                                      • Instruction ID: b0d1088f8a2d0dc6ba1dccbe81fe61950df8d7625090174cd12efe394ad6283c
                                                      • Opcode Fuzzy Hash: b4628df3ade875b58f57b8968671842ecf493c8174b45dc6aa282c95754c1a57
                                                      • Instruction Fuzzy Hash: 288103A1D08A988AF720C728DC547EB7B75EF91301F0440FAD54D97281E6BA5F85CF26
                                                      APIs
                                                      • Wow64GetThreadContext.KERNEL32(?,?), ref: 025F1C52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: M$MIMK$P$R$a$c$d$e$e$e$m$o$o$r$r$s$s$y
                                                      • API String ID: 983334009-3061001137
                                                      • Opcode ID: 6c549fdd83ce4fa6faef8d5ee1ebda0060369e573b31a995d64be48a2a7bdf62
                                                      • Instruction ID: 948e6b043dea83f16162e4e53e584b2fc6befe2f4ec1fe950ab408ff685c551a
                                                      • Opcode Fuzzy Hash: 6c549fdd83ce4fa6faef8d5ee1ebda0060369e573b31a995d64be48a2a7bdf62
                                                      • Instruction Fuzzy Hash: 578113A1D08A98CAF720C728DC547EB7B75EF91300F0440FAD54D97281D6BA5A85CF26
                                                      APIs
                                                      • RegSetValueExW.KERNELBASE(?,?,00000000,00000001,?,?,?,?,?,0266BA35,?,?,?), ref: 0266C1BF
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Value
                                                      • String ID: C$H$a$d$e$e$l$l$n$o$s
                                                      • API String ID: 3702945584-2848555115
                                                      • Opcode ID: cbef2520bba153b37245a345eb1ee0d53128b10a4a4e7e34548f024ea34203ee
                                                      • Instruction ID: d8ba575165e4552f637fad663ce71e82a975fde16f369d0369d7e0e4673188ea
                                                      • Opcode Fuzzy Hash: cbef2520bba153b37245a345eb1ee0d53128b10a4a4e7e34548f024ea34203ee
                                                      • Instruction Fuzzy Hash: 2D319570C04A988ADB28CA18CC587EBBBB5EB51706F0440EA958897281D67A4FC6CF21
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: 1bc4ff69569e447e81788698f77d4a667e7364999969ad586fae02f950d619ca
                                                      • Instruction ID: fa22b78ea57256f8b2d06771be78e4984f0acf433ba98ab6a00dcb01b313632c
                                                      • Opcode Fuzzy Hash: 1bc4ff69569e447e81788698f77d4a667e7364999969ad586fae02f950d619ca
                                                      • Instruction Fuzzy Hash: BC412572D085A49BE7248624CC4CBFB7F75AB92310F0841FED88D16241D6395AC6CF63
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: 8c84eb2498c86c831e44ad618b3076780d47a53b7a973434160624bcbf70a3fd
                                                      • Instruction ID: 44ec404572e90e5fc93d5f3c2f024e3f420d309a822e663b10a715212c312a32
                                                      • Opcode Fuzzy Hash: 8c84eb2498c86c831e44ad618b3076780d47a53b7a973434160624bcbf70a3fd
                                                      • Instruction Fuzzy Hash: 205124B2D081989FE7248624DC4CBFB7B79DB42314F0841FAD84C16281D63A5ED68B62
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: 9aeb634126e464a417390af33ae9a276c8398577c5f151e692fc43bb257f99b8
                                                      • Instruction ID: 3a25e879331c9abf391c06addf8c60bbabb7fca19e9bea1fb4473967eecfd0d9
                                                      • Opcode Fuzzy Hash: 9aeb634126e464a417390af33ae9a276c8398577c5f151e692fc43bb257f99b8
                                                      • Instruction Fuzzy Hash: AC4105B2D081A49FF7248624DC4CBEB7B69AB52314F0841FAD84C16641D63A5FD6CF63
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: a5389604e7e75adf474e2d26d3ac21f29f28ff98541596f2f3c9b5f9bcc8bc35
                                                      • Instruction ID: 867c010ae068b0b7bd565441fd0354e74710bf58ee9e2a6c62610a77605af0ad
                                                      • Opcode Fuzzy Hash: a5389604e7e75adf474e2d26d3ac21f29f28ff98541596f2f3c9b5f9bcc8bc35
                                                      • Instruction Fuzzy Hash: 0D41F4B2D081A49BE7248624DC4CBEB7B699B52314F0841FAD84C16641D63A5FD6CBA3
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: 555ebb2c78ca7e751645a3c70289a98963d1babe1acb9d1b93f300c726800cf5
                                                      • Instruction ID: 08c50140240d2150905e6230b9b1c7c994cd72e45b20e96fda8fb61aa254329a
                                                      • Opcode Fuzzy Hash: 555ebb2c78ca7e751645a3c70289a98963d1babe1acb9d1b93f300c726800cf5
                                                      • Instruction Fuzzy Hash: 45412762D085A49AF7248624DC4CBEB7E25DB52314F0841FAD84C16681D63A5BD5CBA3
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: f57878aa0251c2b76495e3a0355d15fdbd722b7843ba6bdf00a1748985cce884
                                                      • Instruction ID: cdf623041d5011fd5913d05faf420f4b262f177aaf59454889392a084223bcec
                                                      • Opcode Fuzzy Hash: f57878aa0251c2b76495e3a0355d15fdbd722b7843ba6bdf00a1748985cce884
                                                      • Instruction Fuzzy Hash: 67412672D085A89FE7248624CC4CBFB7B75EB52310F0441EAD84C56241D6395BD5CF62
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: bd52a6b4f6fe0edd6ff13beabf53667afb404ee7a5e905785d05ab6062f3e9f8
                                                      • Instruction ID: 312139fc944f5118c034d48a40b317707233c3ddcc8fa92c32362a68a933358a
                                                      • Opcode Fuzzy Hash: bd52a6b4f6fe0edd6ff13beabf53667afb404ee7a5e905785d05ab6062f3e9f8
                                                      • Instruction Fuzzy Hash: 7D412676D085949FEB248624CC4CBFB7B75EB82310F0441FAD84C16681D63A5BD6CF62
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: d29299a2858a487889b8c10b5bc62c567a88827b6e0d4df4337995951086fa90
                                                      • Instruction ID: dc13eab23cbe4c4a8b04fff4a317af1c379f26fcca671f0577beb2915d3b58d5
                                                      • Opcode Fuzzy Hash: d29299a2858a487889b8c10b5bc62c567a88827b6e0d4df4337995951086fa90
                                                      • Instruction Fuzzy Hash: 3F411476D085A89FEB248624CC4CBFB7B75AB92310F0441FED88C16641D63A5BD5CF62
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: f9e346c2e89f0537d4b5c67fb704638c1b343bb696ac10321ff18a756b12a826
                                                      • Instruction ID: 8c97a28028d9ad36527d0d65c9949d40dc276429160c5103538ed71db7a49a17
                                                      • Opcode Fuzzy Hash: f9e346c2e89f0537d4b5c67fb704638c1b343bb696ac10321ff18a756b12a826
                                                      • Instruction Fuzzy Hash: 6F412672D085A88FEB248624CC4CBFBBB75DB82310F0441FAD84C16641D63A5BD6CF62
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: a9f0259b580f5ddedbd784bdd0bddb6f1970d8d654decb34d67e0f31ea2598a9
                                                      • Instruction ID: 47a4d39aea0ccf0b94513d0f5d8f550d60e0a731213bc79072ccade8b53574b1
                                                      • Opcode Fuzzy Hash: a9f0259b580f5ddedbd784bdd0bddb6f1970d8d654decb34d67e0f31ea2598a9
                                                      • Instruction Fuzzy Hash: BE412572D081A88FEB248628DC4CBFB7B759B42310F0441FAD84C16641DA3A5BD6CF63
                                                      APIs
                                                      • CloseHandle.KERNELBASE(?), ref: 0266E09D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CloseHandle
                                                      • String ID: C$F$W$a$e$e$e$i$l$r$t
                                                      • API String ID: 2962429428-2654231525
                                                      • Opcode ID: 186b481fa8fff59492b683387c446c8e19f02964b8e9c8b2395c442cf51e0ebd
                                                      • Instruction ID: 1a9421251be0fd9f44fea4378332e9620be5935b5ffdf7cf77076585a7d632ea
                                                      • Opcode Fuzzy Hash: 186b481fa8fff59492b683387c446c8e19f02964b8e9c8b2395c442cf51e0ebd
                                                      • Instruction Fuzzy Hash: BE411476D081A89FEB248624CC4CBEB7B75AB52310F0441EAD84C56641D63A5BD5CF62
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,?), ref: 025FFF17
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID: 23HP$e|$3
                                                      • API String ID: 1726664587-2865655517
                                                      • Opcode ID: 885aeaa3b46716b2708c94a56eb1deb35aa8dc26139e4152923be4ed88c0baa8
                                                      • Instruction ID: eb10d7525c9efbba8a64ccbb0ec9c80a63c879d0a10e1f3d38f73707bc2eac60
                                                      • Opcode Fuzzy Hash: 885aeaa3b46716b2708c94a56eb1deb35aa8dc26139e4152923be4ed88c0baa8
                                                      • Instruction Fuzzy Hash: E16168B4D093688AEB25CB18CC996E9BBB1BF48300F0081EAE94DA2251E7355FC5CF55
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?$e|$3
                                                      • API String ID: 71445658-1848868468
                                                      • Opcode ID: 43adf9ce3df25287de86ff1f92c1a20395fa8c7c4a7a0c0e2f1928a3ddad7e39
                                                      • Instruction ID: db0f03af62ebd09748b7898e2897b6a4b6691891e6c5e80dc6b974ff9f15ae46
                                                      • Opcode Fuzzy Hash: 43adf9ce3df25287de86ff1f92c1a20395fa8c7c4a7a0c0e2f1928a3ddad7e39
                                                      • Instruction Fuzzy Hash: 4E616BB4D056688AEB25CF28CC456E9BBB5AF98344F0482E9E44CA3341EB314FC5CF51
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: HOK8$Qj@h
                                                      • API String ID: 0-1820051497
                                                      • Opcode ID: 5797d47e3d45096d2ab2e2a3f614386586d4d7beb0c27eb8db74e82377ebf8cd
                                                      • Instruction ID: fb9004fbbd1b1258e13db13c6124cfea7d7239d9694d678260cbdbda55f6babf
                                                      • Opcode Fuzzy Hash: 5797d47e3d45096d2ab2e2a3f614386586d4d7beb0c27eb8db74e82377ebf8cd
                                                      • Instruction Fuzzy Hash: D86144B2D056684BEB648A14DC54BEABB76FB81314F0480FAD94E67281E2386FC1CF55
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID: e|$3
                                                      • API String ID: 3559483778-1726640827
                                                      • Opcode ID: 37a8176889d54da0810ae87b4cd2c319062a7f4580416b6c1f5b7cec5845b3c7
                                                      • Instruction ID: 0caa5170f12efc80b0c2c45f60f4b50940f4a7f0147ad6a16ae8aae29bbbfed6
                                                      • Opcode Fuzzy Hash: 37a8176889d54da0810ae87b4cd2c319062a7f4580416b6c1f5b7cec5845b3c7
                                                      • Instruction Fuzzy Hash: C26125B5D086698BDB25CB18CD84AEABBB5BF88301F0041EA990DA2350E7745FC6CF15
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,?), ref: 025FFF17
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID: [W
                                                      • API String ID: 1726664587-2887293924
                                                      • Opcode ID: bec1b086f5ef79acea4f300e557c00f465b246422cf87361c0fa5fcc1a3c6acc
                                                      • Instruction ID: 21e2779b9d5713760c556467381bf48c95c40c87e0398105cf050fbf8b90edb6
                                                      • Opcode Fuzzy Hash: bec1b086f5ef79acea4f300e557c00f465b246422cf87361c0fa5fcc1a3c6acc
                                                      • Instruction Fuzzy Hash: 61611BF2D041146FF3108625EC88AEB7B68FBC1320F0445B6E90D96AC0E77D5FD58A92
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 30402d284302e3696be83f5c15edeeb3d8aa04938408c520dbf496c2bd36f427
                                                      • Instruction ID: b2c108187cb8e8b965bc81a8443953717c1497181e4eaa74a8fb74f11ef78acd
                                                      • Opcode Fuzzy Hash: 30402d284302e3696be83f5c15edeeb3d8aa04938408c520dbf496c2bd36f427
                                                      • Instruction Fuzzy Hash: 737127B2E042559BEB28CA24DC95BFB7B35FF80305F0044FAE80F56680E6785AC1CE95
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID: =EHN
                                                      • API String ID: 3559483778-4237302225
                                                      • Opcode ID: b2dccd75884a243e7b0995a71ce5a884080f2bad788a15255211fc85f831127a
                                                      • Instruction ID: c2edb65b23394dcebacddb43269bcc9ebc4d6659c72e5d50e1135d2edaef64bc
                                                      • Opcode Fuzzy Hash: b2dccd75884a243e7b0995a71ce5a884080f2bad788a15255211fc85f831127a
                                                      • Instruction Fuzzy Hash: 765105F1D041299AE764CB15DC44AFB7774FB84311F1481FBEA0E92280E6386EC1CA66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: ca80d1b092c2e76a4f8d3a268542948fc67f50f55c68a78ff0f554b05843d91e
                                                      • Instruction ID: ded29eddc4ca51833718fa0ee4c6ce0574ee7a364783809f21dbcfd61692b714
                                                      • Opcode Fuzzy Hash: ca80d1b092c2e76a4f8d3a268542948fc67f50f55c68a78ff0f554b05843d91e
                                                      • Instruction Fuzzy Hash: E45138A2D046689BF7208A64DC88BF77A39EF91310F0041BAD54D972C1D6795FC6CB63
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: MA=5
                                                      • API String ID: 0-87635094
                                                      • Opcode ID: 3484a149acf8b9bd23113b7725f1a6915742a1557b31e80e80e80d6ee415ba19
                                                      • Instruction ID: a9b72843eda67b415c6559bad99c01fb36eeb7461f48aaf2b0e88e2ce9109145
                                                      • Opcode Fuzzy Hash: 3484a149acf8b9bd23113b7725f1a6915742a1557b31e80e80e80d6ee415ba19
                                                      • Instruction Fuzzy Hash: 875102F2D051649FF7188A14DCC8AEBB735EBD1310F1880FAE80D56780D6785AD6CE92
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 769dfc5479b34093fbd938f5462167455917f8c90236e24adc20cd1ec19a95f1
                                                      • Instruction ID: 1b0d3d6712251054d8f73e03310262b6a1ddd14fa58075aaceb4adf61b25108f
                                                      • Opcode Fuzzy Hash: 769dfc5479b34093fbd938f5462167455917f8c90236e24adc20cd1ec19a95f1
                                                      • Instruction Fuzzy Hash: 025121B2D156289EE7288A54DC88BFBBB74EF45311F0441BADD4D67280E6781EC1CF92
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 1b2f2cc62cb6aceb973296cc5bf960a721fc72d89e47e12a65d62f3e97bed3e8
                                                      • Instruction ID: 7d6a89d434902debc0c1d77853e865632c24752d6229c033b0bcb834015f7864
                                                      • Opcode Fuzzy Hash: 1b2f2cc62cb6aceb973296cc5bf960a721fc72d89e47e12a65d62f3e97bed3e8
                                                      • Instruction Fuzzy Hash: 705111B2D15628AEE7248A14DC88BFBBB74EF45311F0441BADD4D63280E6781EC1CF92
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 558ad554517b06e62e993fea7c0cdb79856e6adc527f4ed2bb4ae7f17f870b95
                                                      • Instruction ID: 3876eadd40d9a3413f92cfcc27c461e1d910b60b29b940d10edcb1f60d0de363
                                                      • Opcode Fuzzy Hash: 558ad554517b06e62e993fea7c0cdb79856e6adc527f4ed2bb4ae7f17f870b95
                                                      • Instruction Fuzzy Hash: B35105A1E041659ADB288B25CC45BFFBB75FF81705F0484FAE44F66680E6780AC1CE59
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 943dea929cea9a30c71205d9528983141f2eed110c22b70dfa04f79cf7ee7929
                                                      • Instruction ID: df558709fdc132b2801e9fe9be67ef836c1abdfac9d5a13ad4c9efd46adea77a
                                                      • Opcode Fuzzy Hash: 943dea929cea9a30c71205d9528983141f2eed110c22b70dfa04f79cf7ee7929
                                                      • Instruction Fuzzy Hash: 955128B2D046249FF7148A24DC49BFB7775FB81310F0482BAD94D27281D2795AC5CE92
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID: LL<P
                                                      • API String ID: 1726664587-2443076662
                                                      • Opcode ID: 9d20e80ca32713fc7ea563ad6e6067c3dd0679396dcfb8f15a763a49a1d29f54
                                                      • Instruction ID: 3cf491aea8f4d7e484dbe21192eb649ae88cd12823c6eee74d2a4a8113face29
                                                      • Opcode Fuzzy Hash: 9d20e80ca32713fc7ea563ad6e6067c3dd0679396dcfb8f15a763a49a1d29f54
                                                      • Instruction Fuzzy Hash: 2C5134B2D05229AAE7608B60DC81BFAB775FF45300F0440FED98D93290E2791EC1CB66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID: [W
                                                      • API String ID: 1726664587-2887293924
                                                      • Opcode ID: cbd1dc4e7e2db0a78cbfb5d415d084fd2644671992db45e4a98cd2c9aa232a99
                                                      • Instruction ID: bd0c4824fbd3d7b40516ee83f71657b17d1936609a417b552e07ecab9330164e
                                                      • Opcode Fuzzy Hash: cbd1dc4e7e2db0a78cbfb5d415d084fd2644671992db45e4a98cd2c9aa232a99
                                                      • Instruction Fuzzy Hash: AE4116F2D14114AFF7548A14EC85BFB7768EB40310F0442BADD0D96AC0E6796EC4CE66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: a1d1f61210c74bcc7e4e048a86169ac3897476971b913546bc833e5342df15fa
                                                      • Instruction ID: c0dcedf65969946326ca2e60853991563388922eb90eb897ce1e25cf21d26f75
                                                      • Opcode Fuzzy Hash: a1d1f61210c74bcc7e4e048a86169ac3897476971b913546bc833e5342df15fa
                                                      • Instruction Fuzzy Hash: DD4114B2D156389EE7248A54DC88BFBBB74EB45310F0441BADD4E22280D6781FC1CF92
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Qh?
                                                      • API String ID: 0-2306691335
                                                      • Opcode ID: fd2a86186ef3ded7bca25fd179ccf78587e938a036ed516a57fa69dcf5f17430
                                                      • Instruction ID: 85bf110575949eaad723cd4236b08252c66b8576341fbc12d6c9adde62bddb97
                                                      • Opcode Fuzzy Hash: fd2a86186ef3ded7bca25fd179ccf78587e938a036ed516a57fa69dcf5f17430
                                                      • Instruction Fuzzy Hash: 6F41F3B6D11628AEE7288A54DC88BFBBB74EB45311F0441BADD4E22280D6785FC1CF91
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 92930af427c3645a1dd84830d59a085b58162def3d1eb16d9d2f5ad841d19811
                                                      • Instruction ID: a5148a3841b997324f83c404e66457242710d4006eccb0fc8861aaef9d9d2af8
                                                      • Opcode Fuzzy Hash: 92930af427c3645a1dd84830d59a085b58162def3d1eb16d9d2f5ad841d19811
                                                      • Instruction Fuzzy Hash: 4741E3B6C156286FE7248A54DC88BF7BB78EB05315F0440BADD4E27280D6795EC1CEA1
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 0bdfb7418cfcd304e516a12610c02201f39009fb654208a06b519eeb2c8b895b
                                                      • Instruction ID: 51869d82ecfff689aa1f819a43db9720bfc6825cf52f64c6c477428df558ebdc
                                                      • Opcode Fuzzy Hash: 0bdfb7418cfcd304e516a12610c02201f39009fb654208a06b519eeb2c8b895b
                                                      • Instruction Fuzzy Hash: 034134B2D05628AFE7248A54DC88BFBBB64EF41311F0441FADD8D22281E6380FC1CE91
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 1b7ef68ceb34b8b185dbc36cf90a250f94183f321910802406ded164342d8e13
                                                      • Instruction ID: 06f12cfa863313b9c821598bd2010eb0e1a23567e94b336a3963cd7a4805bb45
                                                      • Opcode Fuzzy Hash: 1b7ef68ceb34b8b185dbc36cf90a250f94183f321910802406ded164342d8e13
                                                      • Instruction Fuzzy Hash: 953155B6C056286FE3188A54DCC8BF7BB74EF01315F0440BADD8E26181DA795EC1CEA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 67461d5f78eb5148845866bd8ba2a5a8ecc51fad9fe4c54c56f53f6087bf46e6
                                                      • Instruction ID: aedf4ec437897f09851b7adc9906452c14d12acd87b5ee4a67301114a1868550
                                                      • Opcode Fuzzy Hash: 67461d5f78eb5148845866bd8ba2a5a8ecc51fad9fe4c54c56f53f6087bf46e6
                                                      • Instruction Fuzzy Hash: D93118B2D046549FF7249A24CC88BF77B78EF81314F1441FAD98957582D2784ACACE62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 7b1aed36e4f6648ac15c7e0b9e2ab4c3d32a383bb103470a92bfad966952cf7a
                                                      • Instruction ID: 4c90511ff0687d703844d664b83cb684909f0e865e12b9c835183fe342ff7296
                                                      • Opcode Fuzzy Hash: 7b1aed36e4f6648ac15c7e0b9e2ab4c3d32a383bb103470a92bfad966952cf7a
                                                      • Instruction Fuzzy Hash: 263118B2D046589FF7209A24CC88BF77B78EF81314F1041FAD98957582D2785ACACE62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID: [W
                                                      • API String ID: 1726664587-2887293924
                                                      • Opcode ID: d5544b00bc3a20930a5eeec20deb0d4fb9ecfefdfe6b5d3149f44d7d8d8e2af8
                                                      • Instruction ID: db3ffb2d066d9c7239a9f5dbe4c15f744ae45e17e0abd5947e5d75ffc6b86aa0
                                                      • Opcode Fuzzy Hash: d5544b00bc3a20930a5eeec20deb0d4fb9ecfefdfe6b5d3149f44d7d8d8e2af8
                                                      • Instruction Fuzzy Hash: 953146F2D141046EF7108A20EC84AFB7769EB80310F1446FAED0DD66C0E639AEC48E62
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: dbb9490b557edc37c87d883943e31b85d57583aa1f50c3fc47fcdec5c3b86081
                                                      • Instruction ID: 2dcb6c76733cf4b2690c86a48c6726c6043417b6d729c5277ac8523fc43d1b55
                                                      • Opcode Fuzzy Hash: dbb9490b557edc37c87d883943e31b85d57583aa1f50c3fc47fcdec5c3b86081
                                                      • Instruction Fuzzy Hash: E73124B7D116286FF7148A54DC84BE7BB64EB51314F0540BADD4D23280E6795FC1CEA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID: LL<P
                                                      • API String ID: 1726664587-2443076662
                                                      • Opcode ID: 7f802a30c2e25667122b528bbb034c5eca29c66ba90d7536cb3ca7ed7c1fb0e9
                                                      • Instruction ID: 298c33f9ce19558fd13aca53423c9e803d9eb33d4502563ce8978d72e5cacecd
                                                      • Opcode Fuzzy Hash: 7f802a30c2e25667122b528bbb034c5eca29c66ba90d7536cb3ca7ed7c1fb0e9
                                                      • Instruction Fuzzy Hash: 113146B1C05228AAE7648B50CC42BFAB775FF41300F0444AEDA4A92690E2795ED5CB66
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 023a3a73e499194d867a955f35edb11dc2da50ab6cfd0ff680d9f287f221b1da
                                                      • Instruction ID: 69534c6d13a532f5fb197900804ce83eee346c9b892d784ac594aa6d9c744f1d
                                                      • Opcode Fuzzy Hash: 023a3a73e499194d867a955f35edb11dc2da50ab6cfd0ff680d9f287f221b1da
                                                      • Instruction Fuzzy Hash: 163136F6C146286FF7248A54DC84FF7BB64EB41314F0580BADA4D62180D6795FC1CEA2
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: b9a7ebc8fd64bad2885d8b455ba278d9c71992c015b376a4c5bc19adede32528
                                                      • Instruction ID: 2d2ec655cc64252679c877c213adb303cb2a7691a52e7e592b904a16abb44926
                                                      • Opcode Fuzzy Hash: b9a7ebc8fd64bad2885d8b455ba278d9c71992c015b376a4c5bc19adede32528
                                                      • Instruction Fuzzy Hash: 5F3104B6C156286FF7148A54DC88BF7BB64EB01315F0440BADD8E26180DA795FC1CEA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID: [W
                                                      • API String ID: 1726664587-2887293924
                                                      • Opcode ID: 084eb78004c2125f89bf9b6f988016031bfcc04ea0150d6885918fc362b36e38
                                                      • Instruction ID: 310350a2e37b4305f07195bb8b31cd386cdf20d68f3b803a93b68477b5bb68fa
                                                      • Opcode Fuzzy Hash: 084eb78004c2125f89bf9b6f988016031bfcc04ea0150d6885918fc362b36e38
                                                      • Instruction Fuzzy Hash: AF3136F2D14114AEF7108A24EC85BFB7768E740320F0442FAED0DD6680E6796EC4CE62
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: a7875312b4e34521d017ecf491e3a63468339a6a369db67c94ad885a0606a3c6
                                                      • Instruction ID: 4f5a51bf8ee8015ab5a50a793e3826b0f273e85a5db7e4e572f848657d31288e
                                                      • Opcode Fuzzy Hash: a7875312b4e34521d017ecf491e3a63468339a6a369db67c94ad885a0606a3c6
                                                      • Instruction Fuzzy Hash: 5F31E1B6D116286FF7148A54DC84BE7BB64EB01315F0440BADD4D26180EA795EC1CEA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID: 8:6L
                                                      • API String ID: 4241100979-3411145690
                                                      • Opcode ID: bea7cdc8f0d48112c5a7bd4519dcd82ec1b75920ed7dd749a99f66d16b9c35d9
                                                      • Instruction ID: 20704e02a8e2279528ff325a7c6478d2f60556939f364d7416648cbb67d9f159
                                                      • Opcode Fuzzy Hash: bea7cdc8f0d48112c5a7bd4519dcd82ec1b75920ed7dd749a99f66d16b9c35d9
                                                      • Instruction Fuzzy Hash: 6B31C4B2C105149FE7298A10DC59BFAB778EB44314F1445EFD90ED6680EA385AC6CE51
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 5c38d01b89e9604197e0aa0dda88d903d72c0a2ff538e24851c6b0f437aaff93
                                                      • Instruction ID: 2c3a760bda4540e7e900accc34b3890b3a2287f1f80c1e1b5ba5cdf9d3de97ed
                                                      • Opcode Fuzzy Hash: 5c38d01b89e9604197e0aa0dda88d903d72c0a2ff538e24851c6b0f437aaff93
                                                      • Instruction Fuzzy Hash: 033128B2D04654AEF7209A64CC88BFB7778EF81314F1042BAD54956181D3795BCACE63
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 04ef872a5672946a00a5e7fb1c4ecf82b76187ad5f682f67ec3230b4f0eaabce
                                                      • Instruction ID: 9a17fa331c30749184dea59c97543791246a7819ea53269fc5478b2664337a2d
                                                      • Opcode Fuzzy Hash: 04ef872a5672946a00a5e7fb1c4ecf82b76187ad5f682f67ec3230b4f0eaabce
                                                      • Instruction Fuzzy Hash: 3E2149B1D00668AEE7208A20DC88BFB7B39EF41314F5080B9E98D57181D6784FC9CE62
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: e2e89f894d7ccd57c86a926372e6d4a7d22ef590d37698632ca266af40e3dbe1
                                                      • Instruction ID: 85163a71c142fae2acfba59d9a03a6af0d7ca24dbfda789040ebeea9adea6a32
                                                      • Opcode Fuzzy Hash: e2e89f894d7ccd57c86a926372e6d4a7d22ef590d37698632ca266af40e3dbe1
                                                      • Instruction Fuzzy Hash: 9A2108B1E05219DAEF3C8A20CD85BBEB774FB81705F1481FAE94B651C0E2741AC1CE99
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 447510e471d8e653604afe92ea0f52fbf9ccd84cdaeaa3ae9f8466ce23e4547c
                                                      • Instruction ID: af5f6d8b35873c4e602272750c177af56ac0e2d7112ee8786eedf32f59edf47b
                                                      • Opcode Fuzzy Hash: 447510e471d8e653604afe92ea0f52fbf9ccd84cdaeaa3ae9f8466ce23e4547c
                                                      • Instruction Fuzzy Hash: 042128B1D00668AEE7208A21DC88BFB7B79EF41314F1080B9E94D66180D2791FC9CF72
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 8912f77004fc56047085964ed70859d903cbafa1e544fdee7e0268db15693c38
                                                      • Instruction ID: b2935e736d2dbabd5de25e69008bacc552ea0e366267f02b552d8e9d5ef0728e
                                                      • Opcode Fuzzy Hash: 8912f77004fc56047085964ed70859d903cbafa1e544fdee7e0268db15693c38
                                                      • Instruction Fuzzy Hash: 372126B2D041686EF7249664DC48BFB7B78EF81314F1081BAD58962182D7794BC9CEB3
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: d58d6050f6131b8cb9a4588b3c616b91ba8bfa38f688f9e758cbf4a689221903
                                                      • Instruction ID: 4c7aa9c93df0f34c30d09ac3c9d5a1e9b8b6957c8a5b1ecfb33af6bd19781e43
                                                      • Opcode Fuzzy Hash: d58d6050f6131b8cb9a4588b3c616b91ba8bfa38f688f9e758cbf4a689221903
                                                      • Instruction Fuzzy Hash: C721E5B1E042199AEF388A20CD45BBEB774FB81715F5041FAE94F295C0E7741AC0CE56
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 6745c9b35739f10d83bc45156d748d8edbc216264f4a3d2847c90588b9d6c374
                                                      • Instruction ID: 6b7e891bff9068f01ef1a7b66302efe7ee0dba50f6a411fdd896005eacabe2ac
                                                      • Opcode Fuzzy Hash: 6745c9b35739f10d83bc45156d748d8edbc216264f4a3d2847c90588b9d6c374
                                                      • Instruction Fuzzy Hash: C12126B6C50A686FE7248A90DCC4BF7B768EB15305F0440FADD4962180E6795FC1CFA1
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 0af62815f5a79fa1b5caa5a4adaa1903241c72d9eb15825178db34137f4e1766
                                                      • Instruction ID: c8727b819a25c6197b10acce31f55c29fd512dac92d93eea7b40e8d6402aae96
                                                      • Opcode Fuzzy Hash: 0af62815f5a79fa1b5caa5a4adaa1903241c72d9eb15825178db34137f4e1766
                                                      • Instruction Fuzzy Hash: 5D21D4B2E002199AFB2C8A10CC56FBAB775F790301F1041FEE60B665C0EA746B818E95
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID: FO2I
                                                      • API String ID: 4241100979-109952837
                                                      • Opcode ID: 28a76ae94ecfc523ec208d1e8aeabd4dd53b1e28abc2de5d7a16b2706a787514
                                                      • Instruction ID: e142c0ba6215cec35d8815d488c742218700ef30deaf2dec3cf6a3d713958119
                                                      • Opcode Fuzzy Hash: 28a76ae94ecfc523ec208d1e8aeabd4dd53b1e28abc2de5d7a16b2706a787514
                                                      • Instruction Fuzzy Hash: B02192B1D04698AFEB29CB14DC98BFBBB75EB81305F1041EED50996240DA385BC5CE12
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 465a664ed79c1796c8153db21da7dad2b7587b2afe758822aa71124ac86f34c6
                                                      • Instruction ID: 62050ea82ab0aa2f8d93ba0f7a719a3f246e7b24a36a353ce76714cecf088e6d
                                                      • Opcode Fuzzy Hash: 465a664ed79c1796c8153db21da7dad2b7587b2afe758822aa71124ac86f34c6
                                                      • Instruction Fuzzy Hash: 492102B1D046649FD7189B60CC547EAB7B5EB45310F1090FED98A66542DA344EC2CF52
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: e58d26c821afaca48e1837d20c3534c1c078d5945edf79eeed687231f7ade99e
                                                      • Instruction ID: 0fd1ea64f2882f878763e7d3d7ad9b8aaed514ded9b69d8e963c56d1d0eefa59
                                                      • Opcode Fuzzy Hash: e58d26c821afaca48e1837d20c3534c1c078d5945edf79eeed687231f7ade99e
                                                      • Instruction Fuzzy Hash: 19110AF1C006146EE7148A50CC847FA7678FF90304F0480FAE94D66981E6785FC9CF62
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 884852042968d472e06b90c661e6c219fd68666ce7b0dcea05e54b1664578eda
                                                      • Instruction ID: fd2488b0a749dfe934fb1221b19adddd00b1cc8033f76caad228b19f0f1869c4
                                                      • Opcode Fuzzy Hash: 884852042968d472e06b90c661e6c219fd68666ce7b0dcea05e54b1664578eda
                                                      • Instruction Fuzzy Hash: B911B672E04209AAEF388950CD85FBAB774F781706F1081EAE91B251C0A6741AC0CE95
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID: ;8<E
                                                      • API String ID: 3559483778-1498667124
                                                      • Opcode ID: 83c522e124519b2576fb96f6802b9d2247139f4be6003f6f8d40d18d60e4b216
                                                      • Instruction ID: d0d6e85aa9e2e1e5b247adb5e8d9395e2fd1b0746b781219bdefc98c085e8ce1
                                                      • Opcode Fuzzy Hash: 83c522e124519b2576fb96f6802b9d2247139f4be6003f6f8d40d18d60e4b216
                                                      • Instruction Fuzzy Hash: FE11E6B2D061299BDF64CB18CD846E6B7B9EF89300F0082EAD90E67245E6345EC1CE56
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 2920202b9100f2fbf9e256c5c8f69290b928c8b2e4da5a0fc9b73d5f878e602c
                                                      • Instruction ID: eff85fa15e1f75e83bcf3526e9072b974eaa65f59b463af8c934d637536fbaab
                                                      • Opcode Fuzzy Hash: 2920202b9100f2fbf9e256c5c8f69290b928c8b2e4da5a0fc9b73d5f878e602c
                                                      • Instruction Fuzzy Hash: 431125B6C15128AFEB188B10CC59BFAB674EB00304F4081FAD94AA2680EB355FC5CF52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 0f7a587f9bebe1680b2e4bda51bcb12b890d158bce2842984c073a4b94f6e194
                                                      • Instruction ID: a59e9791765a02f8468c60056976284eaecf2b77a0c41baf9e1f580003120c86
                                                      • Opcode Fuzzy Hash: 0f7a587f9bebe1680b2e4bda51bcb12b890d158bce2842984c073a4b94f6e194
                                                      • Instruction Fuzzy Hash: D611A5B1E452199BEF3C8A40CD41FBEB774FB80706F1045EAE5076A1C0E6715A81DF98
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 190dfb89c2f5b2b5214b9178c61f1a6bcd29ec48627ddc76a38eff377c497469
                                                      • Instruction ID: 29a8175cca96ca3e0d90001b4a1d18aa28c54bf6ea9a9580f8b8e4e445589347
                                                      • Opcode Fuzzy Hash: 190dfb89c2f5b2b5214b9178c61f1a6bcd29ec48627ddc76a38eff377c497469
                                                      • Instruction Fuzzy Hash: 1211C8B1E452599BDF3CDA50CC41FAEB774BB80706F1041EAE6066A1C0E6715B80DF99
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: ad5ab85afbabe5c9927960b5048d7b2e556ce489564152368fb7e9c33ee39519
                                                      • Instruction ID: 37d42e0107d56a4e9afc583b567add572c08cb2b1c32b638993c2286225ce4dc
                                                      • Opcode Fuzzy Hash: ad5ab85afbabe5c9927960b5048d7b2e556ce489564152368fb7e9c33ee39519
                                                      • Instruction Fuzzy Hash: 4501C470E442599AEB388A018C41FEABB74FB81702F1041EBE5466A1C0D6741F81DF94
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: c6a9b5a49fbb2ed3f238918e29ca6f3fb0b356dbb50a44f5f1bdcb43daf9e752
                                                      • Instruction ID: 1d17c4f1908a4b5fb19d31f039fec84c4cb39e72cc7d8a1d4bf71cecc0f345cd
                                                      • Opcode Fuzzy Hash: c6a9b5a49fbb2ed3f238918e29ca6f3fb0b356dbb50a44f5f1bdcb43daf9e752
                                                      • Instruction Fuzzy Hash: 7601F5B2C005686EF7108660DC88BFBB638EF40304F1080B6D98D66081D2B94BC9CEB3
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 84fd88272bbf54c76785662682db57004640d6bd7b98009543c9d657c2e0db14
                                                      • Instruction ID: 3c3a738b590cb8fa378b172c8d3887c9d1ff90f6e2daa9cd202e1e97024b8e8d
                                                      • Opcode Fuzzy Hash: 84fd88272bbf54c76785662682db57004640d6bd7b98009543c9d657c2e0db14
                                                      • Instruction Fuzzy Hash: 1F01D8B1C005646DE7149665DC88BF7BA78EF40314F5440B5D58D66181D3794BC9CEB3
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 57e0e39b7af198fdd2f1940dead677eda914dbc41397ef33ceaecf5d066ade67
                                                      • Instruction ID: b91f498f63e80019b38c264c358e7b4f196de8e6d02680e28cb47dac8568b5a8
                                                      • Opcode Fuzzy Hash: 57e0e39b7af198fdd2f1940dead677eda914dbc41397ef33ceaecf5d066ade67
                                                      • Instruction Fuzzy Hash: 670184B1F40218AAFB388900CC52FFAB778F784711F1480EAEA0B661C0D6756B809E95
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 9b5a409d5f21339a04df0fb112713fe01b70773addd509ee3419bf0b62dd1f4d
                                                      • Instruction ID: 588073cfa6fb946ca5fadef872d134a121dc649376a8e106f7942770986d7e3d
                                                      • Opcode Fuzzy Hash: 9b5a409d5f21339a04df0fb112713fe01b70773addd509ee3419bf0b62dd1f4d
                                                      • Instruction Fuzzy Hash: FD01D6B0E45259ABEF3CCA10CC41FAEB774BB80701F1040EAE5062A1C0D6715B80DF98
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: e4948841e146847b7892702a3ba53391e232a3fb7d1c2cf4fa8e76654a1f52a7
                                                      • Instruction ID: 2e323281c19e5160084bf9a32bbfe6d9b0350db50753f6edd92da79852e02f62
                                                      • Opcode Fuzzy Hash: e4948841e146847b7892702a3ba53391e232a3fb7d1c2cf4fa8e76654a1f52a7
                                                      • Instruction Fuzzy Hash: 9601A7B1D045686DF7149A61DC88BFBB678EF41304F5080B9D58D62181D7B94BC9CEB3
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 6605e9a65e9b0995115a8765ad675870b4a60d7628556fee09434a6b22ac97f7
                                                      • Instruction ID: 1ec5189603f2dbc69c63818687a14cc477f83ec5f81a8fb33423a78f68ca1e63
                                                      • Opcode Fuzzy Hash: 6605e9a65e9b0995115a8765ad675870b4a60d7628556fee09434a6b22ac97f7
                                                      • Instruction Fuzzy Hash: ED01F771F45395AAEB388910CC41FBDB774B781704F2080EAE50B6A0C0E6741B80DA99
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 49c9454b0a8f7b6d6400761cabe18a6722f7851e0abb5c0a255e32d12ee65501
                                                      • Instruction ID: c51388f436c2f8029d59d96fac911892d838ab27d9af3ad7b49e90f85c4c882e
                                                      • Opcode Fuzzy Hash: 49c9454b0a8f7b6d6400761cabe18a6722f7851e0abb5c0a255e32d12ee65501
                                                      • Instruction Fuzzy Hash: DF01D270A443699AEB38CF54CC45BB9B774FB00706F1041EAE90AAA1C0E6311B80DF85
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 8974cdee5f4309174262b650528cd6e5d96a0b53257b28daa40a9c364071a2b0
                                                      • Instruction ID: f9c16044d93100dd25c73f45f2860b98759491029c2c68eb193ac7e26cfdf09e
                                                      • Opcode Fuzzy Hash: 8974cdee5f4309174262b650528cd6e5d96a0b53257b28daa40a9c364071a2b0
                                                      • Instruction Fuzzy Hash: 86016771F45219AAEB3CCA45CC42FE9B774BB40701F5041DAEA0A6A1C0D6715B81DF99
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 3ee9aff3615a1e9f2655ff5586982b845b17a383a03afed9a88a0de0ca05b107
                                                      • Instruction ID: c5cfa2296787554de4921ced25fc8a4a550116bb1b5944ff6adf8f6b14006f84
                                                      • Opcode Fuzzy Hash: 3ee9aff3615a1e9f2655ff5586982b845b17a383a03afed9a88a0de0ca05b107
                                                      • Instruction Fuzzy Hash: 6C016771F45259AAEF3CCA41CC46FAEB774BB40705F1040EAE90A6A1C0D6716B81DF99
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 6aa474a68c517cea3b7c2707b72907d931bf483dd5f4404c0a8d4b473e13df34
                                                      • Instruction ID: 66ae1d4f2c1c6688fd62fdac65357dbadc6bd60ff8db5b211dd541ddfad3a197
                                                      • Opcode Fuzzy Hash: 6aa474a68c517cea3b7c2707b72907d931bf483dd5f4404c0a8d4b473e13df34
                                                      • Instruction Fuzzy Hash: D201A270A44259AAEF38CA40CC82BEDF7B4BB40706F5085DAE90A6A1C0D2705F80DF99
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 5013b31e68d0e3dacbee03726d172abf77e5a551457c8a9ae9ea04ab40c315dc
                                                      • Instruction ID: 44fcf9c79205566c3d71ce04028a1316862f0ddc537d4157c97af546bc0840cb
                                                      • Opcode Fuzzy Hash: 5013b31e68d0e3dacbee03726d172abf77e5a551457c8a9ae9ea04ab40c315dc
                                                      • Instruction Fuzzy Hash: 70012675D046A8AFDB159AA0CC04BFAB635EF85305F0081EA958972582E7754FC2CF52
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 0c0db9ad6520692e47a99f350c12272abfa75d40149ff8300014f7bb69d8b5df
                                                      • Instruction ID: 5ff184680b6ecb1c68c8ac04ea5ba1df8fd1edf8d1147580afe24bd25dc6829d
                                                      • Opcode Fuzzy Hash: 0c0db9ad6520692e47a99f350c12272abfa75d40149ff8300014f7bb69d8b5df
                                                      • Instruction Fuzzy Hash: 56F0A471B44358A6EF38C9408C46FB9B774BB41705F5040DAEA4B6A1C0D6706B40DF99
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 2d869a87a9432875386d20bb4a128d66437bff56a3fdff17328c89d610dfa849
                                                      • Instruction ID: 9023ea541c5b909186f315e84ab174fb798fa24fce27ef1f0f4f716fb838abdf
                                                      • Opcode Fuzzy Hash: 2d869a87a9432875386d20bb4a128d66437bff56a3fdff17328c89d610dfa849
                                                      • Instruction Fuzzy Hash: D5018670E442189ADF38CA40CC42FE9B774BB44701F1040DAE90A6A1C0D6716B80DF89
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 72430d2a72336538967316c6b49b0ad372e8b77a4fa4b76e9517d87c59e9bc9f
                                                      • Instruction ID: be304bd024d065151d1d1c82a415efc8f84188383717934011bc11ec2bc5b23e
                                                      • Opcode Fuzzy Hash: 72430d2a72336538967316c6b49b0ad372e8b77a4fa4b76e9517d87c59e9bc9f
                                                      • Instruction Fuzzy Hash: 4EF0F475D006686FE7149A90CC44BFAB674EF80301F4080EA958962542E6710FC1CF52
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: c62228ed11c07527b4682aafd3d5cfa691f441b594b33f4b8ed5e4f747459ccc
                                                      • Instruction ID: 427c15c5de33260016645d7d1519f0c46de6c03bdbad5c9f0496cbcdce9408d0
                                                      • Opcode Fuzzy Hash: c62228ed11c07527b4682aafd3d5cfa691f441b594b33f4b8ed5e4f747459ccc
                                                      • Instruction Fuzzy Hash: 1FF02279C04668AEEB189B50CC147FAFBB4EF01300F40A1EA9A8A72181DA710FC1CF50
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: b7d204fcefa36bf6091c6081d17b1d2fac2f58ca29226cad36e8a09dbb2e8084
                                                      • Instruction ID: e872b96c77d66a6886e7854ca57c86e2fd62ceeaabc1011ae2a36ca0fd998a32
                                                      • Opcode Fuzzy Hash: b7d204fcefa36bf6091c6081d17b1d2fac2f58ca29226cad36e8a09dbb2e8084
                                                      • Instruction Fuzzy Hash: 6FF0C875C00168AEE7159A90CC457FBF674EF00300F50D1EA958E72181EA715FC1CF62
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: d1784a182fe4fc0f76f1ead8a2cdc31c09633cbbc542e615999e33711cf0bcfa
                                                      • Instruction ID: 7e50333fffb6067d8ba3463f3bc87065bf84c111a30005e9dd3e890550a7e4c4
                                                      • Opcode Fuzzy Hash: d1784a182fe4fc0f76f1ead8a2cdc31c09633cbbc542e615999e33711cf0bcfa
                                                      • Instruction Fuzzy Hash: 03F09671B44254A6EF3CC9408C46FB9B364BB00705F5044DAE60A6A1C0E7706B40DF89
                                                      APIs
                                                      • CreateProcessW.KERNELBASE(?,00000000,00000000,00000000,00000000,00000002,00000000,00000000,?,?), ref: 025EBE3D
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateProcess
                                                      • String ID: jjjj
                                                      • API String ID: 963392458-48926182
                                                      • Opcode ID: 0088f9c9e97fdce36b44278cc3f7b21b271c927ad6c2899e1025e02ce64d1710
                                                      • Instruction ID: 2a2ac5b402daa15c1f4f929263661ace02d13095273d7b539657bdae2f79593e
                                                      • Opcode Fuzzy Hash: 0088f9c9e97fdce36b44278cc3f7b21b271c927ad6c2899e1025e02ce64d1710
                                                      • Instruction Fuzzy Hash: 1FF03170A44219AADF38CA408C42FA9B774BB44705F5041DAE90A6A1C0D6716B40DF98
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: cc5b4f80057970750d651b21fd8dae9fafab2b7c90477c308b0c4f99a8933433
                                                      • Instruction ID: e5b34f51681f08d8fa9a2f8c3d4f039e44b8c33c67cb304f4b4723f93b8424c5
                                                      • Opcode Fuzzy Hash: cc5b4f80057970750d651b21fd8dae9fafab2b7c90477c308b0c4f99a8933433
                                                      • Instruction Fuzzy Hash: 1DF0AF75C00668AFDB25DA90CC44BFAF670EF14301F4091EA958966581E6714FC2CF51
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: d26aec081cc13689d014647cf177262627ebc10dba551f4c44104b54e1a9ccc7
                                                      • Instruction ID: 4c5a7e29f4c8cb240716d4baed93fd879948cb6475f55b003cc656e43cd53d18
                                                      • Opcode Fuzzy Hash: d26aec081cc13689d014647cf177262627ebc10dba551f4c44104b54e1a9ccc7
                                                      • Instruction Fuzzy Hash: BCF0AF79C14668AED7199B50CC557FAFB74EB00304F4091EA968A66181DA751FC0CF51
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: cae05b065dc31734be6012c4aee8e06e05f5f217a8910526f3c4f3538a5d8e36
                                                      • Instruction ID: 55e71807d0746bee9a23786b62286b301d26e2300b2e0a7579b3a327687c5c12
                                                      • Opcode Fuzzy Hash: cae05b065dc31734be6012c4aee8e06e05f5f217a8910526f3c4f3538a5d8e36
                                                      • Instruction Fuzzy Hash: 67F09A75D04668AECB25EA90CC047FAFBB4EF05301F5091DA998972141E6714FC1CF92
                                                      APIs
                                                      • RegOpenKeyExW.KERNELBASE(80000001,?,00000000,000F003F,?), ref: 0266A0FB
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: Open
                                                      • String ID: Qh?
                                                      • API String ID: 71445658-2306691335
                                                      • Opcode ID: 6b6ddf504ceeb00984e906d8a74b42f68c153ac5e15e1fd6d503070b52e846b2
                                                      • Instruction ID: 79ac938dfb7023554adc18dcfa5c0e400dd10eb12f1caeb97668da42499dae1e
                                                      • Opcode Fuzzy Hash: 6b6ddf504ceeb00984e906d8a74b42f68c153ac5e15e1fd6d503070b52e846b2
                                                      • Instruction Fuzzy Hash: E8F05E75C04268AFDB259B90CC447FAFAB4EF04345F4091DA958972541E6715FC1CF61
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID: @>L8
                                                      • API String ID: 4275171209-3765172012
                                                      • Opcode ID: 27e5f61869a4cc2918a222878dff6a466a1542e61b0d5a565d71aa4ab99d49b4
                                                      • Instruction ID: 30edee02100a4c0f6675a888f699ed6d785cd469a309b73f7539c95536f208d8
                                                      • Opcode Fuzzy Hash: 27e5f61869a4cc2918a222878dff6a466a1542e61b0d5a565d71aa4ab99d49b4
                                                      • Instruction Fuzzy Hash: 88318CF2D442556EF7284620EC89FF77B2CFB81324F0400BAED4A46580EA6D5AC1C6A6
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 5ae1c07eafdd42a009318edd91fee17cde6048e6b9dacafe7ceddd7d8d873c87
                                                      • Instruction ID: d2aa21e9db263a602aac0d4df88ca8cd6bcb0c2de72aad760b585b15a47102c1
                                                      • Opcode Fuzzy Hash: 5ae1c07eafdd42a009318edd91fee17cde6048e6b9dacafe7ceddd7d8d873c87
                                                      • Instruction Fuzzy Hash: 896112B2D105199AE768CB24DC45AFB7774FB84311F0442FFDA0E92281E6386EC1CA66
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 723d354e8e14d1830cb4a01a312809bf6096ce1868144c218cebd151a4dc6ff7
                                                      • Instruction ID: 22488a106f2a983a9254b107ac393700e5134c97d9114134f0bc17467dcabf5e
                                                      • Opcode Fuzzy Hash: 723d354e8e14d1830cb4a01a312809bf6096ce1868144c218cebd151a4dc6ff7
                                                      • Instruction Fuzzy Hash: 155113B1D046699BEB28CB18DD94BFABB76EF80305F1441FAD90996241D7386FC1CE11
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: c0d37c860bd6b7e204c85832fc1e0f2da8956581ca43c1923b7ff5af58578889
                                                      • Instruction ID: 8d4dca1d44027f8f9c37c134ac5b2570f1e09d994a5e5416f783859b75793c57
                                                      • Opcode Fuzzy Hash: c0d37c860bd6b7e204c85832fc1e0f2da8956581ca43c1923b7ff5af58578889
                                                      • Instruction Fuzzy Hash: 2F41C5B1D042699FE725CB14DC48EFABB78EB80314F1441BED40EA7241D6349EC6CE91
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID:
                                                      • API String ID: 3559483778-0
                                                      • Opcode ID: 1e38d38803093b57ec7c45ae60c7a66d8ea75c025a5f47934377517ab0958d9f
                                                      • Instruction ID: a30efbf4416c4775765a52f9e2109a69d2a55bf4b8cfafbe3279f79c12010088
                                                      • Opcode Fuzzy Hash: 1e38d38803093b57ec7c45ae60c7a66d8ea75c025a5f47934377517ab0958d9f
                                                      • Instruction Fuzzy Hash: B951F7B2E055189BE764CB18CC85EEBB7B9FB85300F0441EAD90D57680E7396EC1CE55
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 33c390bc7514d1fb132dbb0ff143a4eb5538bbe36bd32670e38a7ecf0b4442a0
                                                      • Instruction ID: ed6f2bbd3d00942a5fd1fcb8b6e7059669c4fc5b976f512a8940db61524a660b
                                                      • Opcode Fuzzy Hash: 33c390bc7514d1fb132dbb0ff143a4eb5538bbe36bd32670e38a7ecf0b4442a0
                                                      • Instruction Fuzzy Hash: 4F4190B2C106689BE7268B54DC59BEAB7B4FF54354F0441FAD94C62250EB385BC2CE90
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 5818ab04ed411e793b0510a8010452a450c48c20be4c262f8d5b2e4fdd7745d0
                                                      • Instruction ID: 1dd067b491475ac10e902414744423ed5b3193f7943404beaeaa39f9490ed76d
                                                      • Opcode Fuzzy Hash: 5818ab04ed411e793b0510a8010452a450c48c20be4c262f8d5b2e4fdd7745d0
                                                      • Instruction Fuzzy Hash: 6A41D3709046999FDB25CF24CD94BFABBB6EF41309F1441EAD50996242D7346BC1CF01
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 94acdd7046306cc1ce09bae373ce67f23892ec8a636ae381fee8c1b49d8fbb82
                                                      • Instruction ID: 198ee2189ca1a966121f17ce5c6e64d2119c2b816d9bb5a5172fc7dde0705a55
                                                      • Opcode Fuzzy Hash: 94acdd7046306cc1ce09bae373ce67f23892ec8a636ae381fee8c1b49d8fbb82
                                                      • Instruction Fuzzy Hash: 2841B6B1D080588BDB28CA14CDD1AFFB775EB42301F1885EAD90DA2380D6749FD29F91
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID:
                                                      • API String ID: 3559483778-0
                                                      • Opcode ID: 32e49de105c81fb51075cff88d018bf37409175de985f16f9ca2d53a5a95fa28
                                                      • Instruction ID: 1aa60f4adf170263f10fe05a48f7112b5dd5ea824dd434a4a13ada5620d1faff
                                                      • Opcode Fuzzy Hash: 32e49de105c81fb51075cff88d018bf37409175de985f16f9ca2d53a5a95fa28
                                                      • Instruction Fuzzy Hash: 0B3116B2D045189FE758CA54DC84BE777B8FB84311F0445FBD90E96280D679AEC1CEA2
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 3f7d287a3b7927d639a2d31eff373e4bb324ef36486d9b5db45e1e7c755321dd
                                                      • Instruction ID: 331507048a6d049c641313e65e64205a1952c1db980d6af5083e62c0ebcaadd1
                                                      • Opcode Fuzzy Hash: 3f7d287a3b7927d639a2d31eff373e4bb324ef36486d9b5db45e1e7c755321dd
                                                      • Instruction Fuzzy Hash: 1031E4F2C105249FE7288B10DC59BFAB779EB44314F0441FBD90EE6680EA389AC2CE51
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID:
                                                      • API String ID: 3559483778-0
                                                      • Opcode ID: 0db9b6d82796771e3f271b1e8e29c12adbd45e18244651b25d4b1e5c7abf94fa
                                                      • Instruction ID: d84420ff329db1dd9c4b562cfee66cf9c8122520e8d248cbd07cc056ec025bc2
                                                      • Opcode Fuzzy Hash: 0db9b6d82796771e3f271b1e8e29c12adbd45e18244651b25d4b1e5c7abf94fa
                                                      • Instruction Fuzzy Hash: A841E4B1D091688FEB64CF10DC84BEAB7B8FB49301F0041EAD94D97241E6356E82CF96
                                                      APIs
                                                      • Wow64SetThreadContext.KERNEL32(?,?), ref: 02603D9D
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID:
                                                      • API String ID: 983334009-0
                                                      • Opcode ID: 7e36b43588be708a25aec69ed8f2cb46dbd332646b8490b3e2100b1a845ff098
                                                      • Instruction ID: c9f1f43eaee1e89729c77a75f50a93d359a372367dc8581f4db53b63b0b25f86
                                                      • Opcode Fuzzy Hash: 7e36b43588be708a25aec69ed8f2cb46dbd332646b8490b3e2100b1a845ff098
                                                      • Instruction Fuzzy Hash: 8231F5B2D441949AF72C8A24DC99DF77728DB45311F0446BEE90A912C0EA78AEC18E61
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID:
                                                      • API String ID: 3559483778-0
                                                      • Opcode ID: a86dc6dab49da26fd5ba1de83926fa8b1ace01b2958d74b230ff90915db49d64
                                                      • Instruction ID: bfc3e4a9a250c9a1175fac81a937628af49e37e7f5204e26d7673b3a883a96ac
                                                      • Opcode Fuzzy Hash: a86dc6dab49da26fd5ba1de83926fa8b1ace01b2958d74b230ff90915db49d64
                                                      • Instruction Fuzzy Hash: A531C5B2D041189BEB64CA14DC44BE7BB68FB85321F0441FBE90E52280D7795AC6CE56
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: abe88195ec8b41b1911ea0e4fda6955d6ad2a301614a5b0557240996d269dcb0
                                                      • Instruction ID: 6fc155a248d6bd1a71118255f9e3567e87b52c35f3be63b836c627f9624d5b70
                                                      • Opcode Fuzzy Hash: abe88195ec8b41b1911ea0e4fda6955d6ad2a301614a5b0557240996d269dcb0
                                                      • Instruction Fuzzy Hash: 8B31AEB2D016249BE7248B25DC45AEAB776FFC8320F1441EAD80C67280E6795ED5CF91
                                                      APIs
                                                      • Wow64SetThreadContext.KERNEL32(?,?), ref: 02603D9D
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID:
                                                      • API String ID: 983334009-0
                                                      • Opcode ID: ab2cf5e0a99862d331bbe021ba7a88fadd7a32d487754110311e38ccc6509099
                                                      • Instruction ID: 72c028efd365a06d6486f29cba1980fe18155a5881f129c7d0624d564d239de8
                                                      • Opcode Fuzzy Hash: ab2cf5e0a99862d331bbe021ba7a88fadd7a32d487754110311e38ccc6509099
                                                      • Instruction Fuzzy Hash: 5E31D5B2E040588BE728CA15DCD4AEBB7B1BB81311F1441EAD80EA72C0D6745AD2CF55
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 3202789951141966e755cfd2f3ef133e5af9111a6fede2649fdff73d4b5cff84
                                                      • Instruction ID: 318bae2aeef97503918a9b3d9527b8bb96454eb92a9b73efc9958b332c06d2e9
                                                      • Opcode Fuzzy Hash: 3202789951141966e755cfd2f3ef133e5af9111a6fede2649fdff73d4b5cff84
                                                      • Instruction Fuzzy Hash: 8721D3B3C102649FE7258B64CC49BEABB78EB45314F0841FBD94DA6680EA385AC1CE55
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID:
                                                      • API String ID: 3559483778-0
                                                      • Opcode ID: 358a9df255d67324d74783619c77a96e8d7b979100947e1adf5cb8a9a06656d2
                                                      • Instruction ID: 711264fa34e6b6345f784d6b5dc2d2ae3e2e5df3ca724497f2632e40f95ea59a
                                                      • Opcode Fuzzy Hash: 358a9df255d67324d74783619c77a96e8d7b979100947e1adf5cb8a9a06656d2
                                                      • Instruction Fuzzy Hash: 2121D3B2E041289BE764CA00DC85BF77B78FB84315F0405FBEA0E96180D7795AC6CE56
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 64e8709f401173f9cbb12c563574c390a167f0c520ac7dc832b31b20ad8a43c9
                                                      • Instruction ID: 940570e596214ac9001837c448c9ccd4921e1cfcf3c676b7f314b6e0e4176c25
                                                      • Opcode Fuzzy Hash: 64e8709f401173f9cbb12c563574c390a167f0c520ac7dc832b31b20ad8a43c9
                                                      • Instruction Fuzzy Hash: E521D1F2C106249FE7298B10DC49BFAB775EB44314F1845EED90D96680EA385BC1CE51
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID:
                                                      • API String ID: 3559483778-0
                                                      • Opcode ID: f4de6fa07ef37c4819f24d0e7d6f64d81a65eeda84d1293568a9ea3f0661aac8
                                                      • Instruction ID: 75a9140ca492ce951a08bf049fbad4c12674bf07feeb45a41d4d18bfafd345ff
                                                      • Opcode Fuzzy Hash: f4de6fa07ef37c4819f24d0e7d6f64d81a65eeda84d1293568a9ea3f0661aac8
                                                      • Instruction Fuzzy Hash: 2931C871D051249BEB64CB14CD849E7B7B9EF85310F1082FAD90D63241E7356F82CE95
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 30be580cdf52eae77c0960a9245593c5e9d32fb04f59a24812dcec7a3ab022c2
                                                      • Instruction ID: 7a96424f8f617d733e05b1f8df950961006a5b7b8eb2c0c40602728c4d0f21d5
                                                      • Opcode Fuzzy Hash: 30be580cdf52eae77c0960a9245593c5e9d32fb04f59a24812dcec7a3ab022c2
                                                      • Instruction Fuzzy Hash: A421A1B1D046589FEB258B24CC88BEBBB76EB81315F1445F6D40C96280D6785BC68E11
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: df5f891e5f78035c49b4ab2e7dfb5fd7ba64a41a09bfb88992be4ddde27fd011
                                                      • Instruction ID: ec06788865eabc48db92ca18dbf3a401cbf62d386120a2bce1aeab2fc0e618a3
                                                      • Opcode Fuzzy Hash: df5f891e5f78035c49b4ab2e7dfb5fd7ba64a41a09bfb88992be4ddde27fd011
                                                      • Instruction Fuzzy Hash: 912192B2C106689FE7298B20DC49BFABB74EB45314F0841EFD50D96680EA385BC5CE51
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 8a7c076b87e03250fc692d9ffa9021332041326df9547bb99610c17aed8dd365
                                                      • Instruction ID: 797733f7ad24276cba417605f4b9d7179638f79d7dbe6acb98e1434cd7a3e648
                                                      • Opcode Fuzzy Hash: 8a7c076b87e03250fc692d9ffa9021332041326df9547bb99610c17aed8dd365
                                                      • Instruction Fuzzy Hash: E02192F2C106289FE7258B20DC49BEABB74EB45314F0841EFD50D96680EA385BC5CE51
                                                      APIs
                                                      • Wow64SetThreadContext.KERNEL32(?,?), ref: 02603D9D
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID:
                                                      • API String ID: 983334009-0
                                                      • Opcode ID: de3c6c2439602a0da0f8c27fdfbf8945bb086daf06633c0c52689965facca623
                                                      • Instruction ID: da37f879ed1f3c58753eff77935cbb6b41340cc10af5d14e00003ea5514d868d
                                                      • Opcode Fuzzy Hash: de3c6c2439602a0da0f8c27fdfbf8945bb086daf06633c0c52689965facca623
                                                      • Instruction Fuzzy Hash: A921B6B2E041589BF7288A15DC85AEBB776EBC1311F1441FAD80E622C0D6785FD2CF51
                                                      APIs
                                                      • Wow64SetThreadContext.KERNEL32(?,?), ref: 02603D9D
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID:
                                                      • API String ID: 983334009-0
                                                      • Opcode ID: 4efca36d41d4855e17f93d7c2c100251c4119793ba10525e669df14ae59c90a1
                                                      • Instruction ID: ca1912a0d00478da764ee7c4991d095d9e318a4020f5c4a309db35ce274b6a2a
                                                      • Opcode Fuzzy Hash: 4efca36d41d4855e17f93d7c2c100251c4119793ba10525e669df14ae59c90a1
                                                      • Instruction Fuzzy Hash: 1621D4F2D581189FE71C8A50DCD5AEB7774EB44310F1482FEE90E52381E6385E92CE51
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: a6994a2b9e0bdf6e37d0b2ee0df14fff032b5f44f7d7760caa6eb1df44289159
                                                      • Instruction ID: 0279f094e200be049fc91dde05e1c0b449facec9d5fa89827bdc4151927338e9
                                                      • Opcode Fuzzy Hash: a6994a2b9e0bdf6e37d0b2ee0df14fff032b5f44f7d7760caa6eb1df44289159
                                                      • Instruction Fuzzy Hash: 2D11D5B1E016699BE725CA14CC48FFAB725EBC0314F0046FFC409A7241E6344EC6CE90
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: 304b19aa56b8399ecd2dcb29679e5a0db0c72aac571b488797fed343e23cb299
                                                      • Instruction ID: f410700a235d3170aa1dd01ad26d11655c00dcefa36bf7a0ebcce9c26a2abb70
                                                      • Opcode Fuzzy Hash: 304b19aa56b8399ecd2dcb29679e5a0db0c72aac571b488797fed343e23cb299
                                                      • Instruction Fuzzy Hash: 5D11DAB1E042959BF7248A15DC95BA7B775FB80310F0441FFD94996280E6759AC0CF91
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: ff20238f9ee6342f8d40886462b2f367549671c602fc6ff715d23fc856d6eb58
                                                      • Instruction ID: 55e2ec543957da0f79e94ca0a2dc022ca24a9de32b7060cee1ae7da668f158f8
                                                      • Opcode Fuzzy Hash: ff20238f9ee6342f8d40886462b2f367549671c602fc6ff715d23fc856d6eb58
                                                      • Instruction Fuzzy Hash: CB1193B5E016699BD724DB24CC44BE9BB75EB80315F0046FEC449A6241D6349EC6CE90
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 5f0f3c811927c4dada9d89e16870849aa04028c22023c5e6b54821fedcbb4dc4
                                                      • Instruction ID: 278a90547aa14ba5642ecff19866c7ba284727ec1b432005b2226ccb24f56d98
                                                      • Opcode Fuzzy Hash: 5f0f3c811927c4dada9d89e16870849aa04028c22023c5e6b54821fedcbb4dc4
                                                      • Instruction Fuzzy Hash: 4C11B2B1D006699FDB25DB24CC48BF9B775EB84314F0086FEC40AA7241D6349EC6CE90
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 3f02ce8d9ba885e2862fcbeb5f61a37b5d8d2c257a8c487e60a92c7360c8b0c3
                                                      • Instruction ID: 773a4ee82f50b6d89b44b0fa611d1c6ae926abf171f8869515e495a6c0974f65
                                                      • Opcode Fuzzy Hash: 3f02ce8d9ba885e2862fcbeb5f61a37b5d8d2c257a8c487e60a92c7360c8b0c3
                                                      • Instruction Fuzzy Hash: DA118270D046689FEB29CB14DC98BFABB75EB81305F1045EAD509A6281DB345BC2CE11
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: f6359761f0532f0b9835c76b7dd74dd981b85c5cbe7c898436c898bb3f9faa03
                                                      • Instruction ID: dde54638f7e583075c57c110270b22bb99b007594bf1044f7bbc8e224af37687
                                                      • Opcode Fuzzy Hash: f6359761f0532f0b9835c76b7dd74dd981b85c5cbe7c898436c898bb3f9faa03
                                                      • Instruction Fuzzy Hash: E4119170D046689FEB25CB24CC98BFABB76EF85305F1044EAD50DA6241DB385BC1CE11
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 2b58670b13de16a26b8b85da5f995baedbc91b2613fcce4dd04bc8033a8e34f7
                                                      • Instruction ID: e9361e5fb93e33745c36545a1bb63ade2875eab4cb934601dec26a281dee81a3
                                                      • Opcode Fuzzy Hash: 2b58670b13de16a26b8b85da5f995baedbc91b2613fcce4dd04bc8033a8e34f7
                                                      • Instruction Fuzzy Hash: E61186B1D04268DFE725CB14DC88AFABF78EB45314F1081EAD50DA6254DA344FC6CE51
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: ce9257200bfee343aeda19c206c26eebacd43fa020076e48b88178fe13b63558
                                                      • Instruction ID: d0bace4e0eb245ed60ab0d56c3ed3f4ed6d539632c9a1eb977bd97e82d3e90ec
                                                      • Opcode Fuzzy Hash: ce9257200bfee343aeda19c206c26eebacd43fa020076e48b88178fe13b63558
                                                      • Instruction Fuzzy Hash: CA118EB1D046689FE725CB14DC88BFABF74EB45314F0082EAD50DA6244EA384FC6CE91
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 149edab8be7ea5483773db2512c14c6bcce0db8b677506ff7d10478b95b2a08d
                                                      • Instruction ID: f1db26736e30e1abe437f55be371bdc9aa89e3defc10e0f576cac7f5673e1445
                                                      • Opcode Fuzzy Hash: 149edab8be7ea5483773db2512c14c6bcce0db8b677506ff7d10478b95b2a08d
                                                      • Instruction Fuzzy Hash: 7711A1B2D002689FE725CB14CC88BFABF75EB45314F0082EAD54DA6240EA344FC6CE90
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: 9ae0ce748537884bf816f1c404bfc4f6111eca96ad8e15d905ae31a03cf23b5d
                                                      • Instruction ID: b988bd7793b267bf7c07ee7425aff86965da593306d36f10d13d72949db32610
                                                      • Opcode Fuzzy Hash: 9ae0ce748537884bf816f1c404bfc4f6111eca96ad8e15d905ae31a03cf23b5d
                                                      • Instruction Fuzzy Hash: 2D0100F2909245AFE7208A60CC42BF673A9FB85301F0441FADA49D65C0E3795A95CF52
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 3f946bfb4987aee25611bd27198e5fa45b27c04ce6e48d3efe2fc0d941b96548
                                                      • Instruction ID: ccfdd7d2ec096b0b8dfa8b9ed6d030c9c509488aa00c758859dcba3d92f3506b
                                                      • Opcode Fuzzy Hash: 3f946bfb4987aee25611bd27198e5fa45b27c04ce6e48d3efe2fc0d941b96548
                                                      • Instruction Fuzzy Hash: F61184B1D016689FEB25CB24DC48AEABB74EB45714F0082EAD50DA6240DA344EC6CF90
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,?), ref: 025FFF17
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: 214d091fa04b46cd2d0b0a60b5621f12d55b3461e985066842f8b9f179ce5eb3
                                                      • Instruction ID: 690bca3a8df7f6dd37e5276bb76fe09e9230136a6c7d8fa0bf47dc1d2c8d28b4
                                                      • Opcode Fuzzy Hash: 214d091fa04b46cd2d0b0a60b5621f12d55b3461e985066842f8b9f179ce5eb3
                                                      • Instruction Fuzzy Hash: ED0184F2D191149BE724C640DC41BF672B9F794311F0445EAD90E91680F3796A94CE56
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,?), ref: 025FFF17
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: 11cb8807eb17062f059065f5fafddf635ff116c78eed47c7567a87d90a97826b
                                                      • Instruction ID: 5abc00d85f5b15c5a72946c48ab1d8a77041e7ea7e2bfe3545a7b722946184df
                                                      • Opcode Fuzzy Hash: 11cb8807eb17062f059065f5fafddf635ff116c78eed47c7567a87d90a97826b
                                                      • Instruction Fuzzy Hash: 2601A7F2D08104ABF724C640DC46BF672A4F794315F0445AAD90DD15C0F37D6AD48E56
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,?), ref: 025FFF17
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: b8b706ce64710e60c3f347da5b988c7a2e6aac3aa857b0ec478af8fd37546913
                                                      • Instruction ID: 8d84cef0d7a9f139b4f217d722d42715b1d50427c702583f1af0420e56954245
                                                      • Opcode Fuzzy Hash: b8b706ce64710e60c3f347da5b988c7a2e6aac3aa857b0ec478af8fd37546913
                                                      • Instruction Fuzzy Hash: 8201A2F2D08104ABF724C640DC46BF672A8FB94311F0445AAE90ED15C0F3796AD5CE56
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: bcae67c3d9b9acdf09f8975b3812972c845503f0829d52fce55444e68ba6f908
                                                      • Instruction ID: 1e58d92d268a8ba2b8081de56cf08dfabe140f94449e2efe5b532b297fecbd18
                                                      • Opcode Fuzzy Hash: bcae67c3d9b9acdf09f8975b3812972c845503f0829d52fce55444e68ba6f908
                                                      • Instruction Fuzzy Hash: 57F0A4B18003585FEB289A24ED5DBFABA34FB40300F0042BED609551C1EA781AC2CE11
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,00000000), ref: 025F3BFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: 83f8953fb278223d6eb01589413b0805e1ebe4477ef4b99c4dc3caea40f87506
                                                      • Instruction ID: 14ec22d79050566dced9f8d30a9ecfdb6af4a832acce75a555ebda72ec21d125
                                                      • Opcode Fuzzy Hash: 83f8953fb278223d6eb01589413b0805e1ebe4477ef4b99c4dc3caea40f87506
                                                      • Instruction Fuzzy Hash: 64F096B1E442999BF764CE14CC41BBAB375FB84300F1081FBE90957280E6356E91CE59
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID:
                                                      • API String ID: 3559483778-0
                                                      • Opcode ID: 135e001c787a82d035a94c887df20ab25cafb799b5ad27b119333aac90e82db9
                                                      • Instruction ID: 38331eba580dc0d89064ed1ffa6e4b13775978c0f37d6f75a85a7e2124a97305
                                                      • Opcode Fuzzy Hash: 135e001c787a82d035a94c887df20ab25cafb799b5ad27b119333aac90e82db9
                                                      • Instruction Fuzzy Hash: 5DF068B1A050189BE754CA54DD45BF7B3B4FF48300F0441DEE50E52190E6316E91CE96
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 448d189ead53b3def959def02216cc2e1f4d3aa8ebab3d5930795281ddf1cd26
                                                      • Instruction ID: 59c248ef61f40b5b8cc142a010f7b2bd83c89abf7ee3d818f8fafd8ea2f3d3d1
                                                      • Opcode Fuzzy Hash: 448d189ead53b3def959def02216cc2e1f4d3aa8ebab3d5930795281ddf1cd26
                                                      • Instruction Fuzzy Hash: 01F08CB1D006A89FDB25CB24CC84AE9BB79EB85304F0081DAD54867240DA315BC6CF50
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: fe7e609af3292c3546857f3cf121255dc13b01611b01fd423a6f311fc9692a3b
                                                      • Instruction ID: f25e283b2339a035e7c9d7324860875f83e46b30b8f77a5a2c2e9125495f490d
                                                      • Opcode Fuzzy Hash: fe7e609af3292c3546857f3cf121255dc13b01611b01fd423a6f311fc9692a3b
                                                      • Instruction Fuzzy Hash: B6F044B0D002589FD725DB14CC48AFABB75EF84314F0045EFD50DA6140DA745AC5CF50
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 68c5489cf6d1d8e22ae64941a9d19762e68c9932267ce05407d5b74b5735c244
                                                      • Instruction ID: fb107c65734d7cb1bbdb1f88c2ec2f733b517d08c11b837c20cd2990395c8720
                                                      • Opcode Fuzzy Hash: 68c5489cf6d1d8e22ae64941a9d19762e68c9932267ce05407d5b74b5735c244
                                                      • Instruction Fuzzy Hash: 72F04970900668AFDB25CB20CC48AE9BB75FB84301F0089DAD559EA240DA354BC1CE00
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID:
                                                      • API String ID: 3559483778-0
                                                      • Opcode ID: 0e40751da3ef764ee18f16ec1b8a89ff408a0814cb9b74e6a84c8518c117d3f7
                                                      • Instruction ID: 185af36dddb04e4cff4b2acf5c3af91451055831326b6ab4149fdcffacec4ba9
                                                      • Opcode Fuzzy Hash: 0e40751da3ef764ee18f16ec1b8a89ff408a0814cb9b74e6a84c8518c117d3f7
                                                      • Instruction Fuzzy Hash: A2F0F4B1E051189BDB64CA54DD84AE6B3B4FF89300F5442D9DA0DA3250E7315F81CF96
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 3faad0f40d220c8ec74d9f26f34309b2635928add10916f9569ec1832ec9ec43
                                                      • Instruction ID: 5b67df0dca07e438ad15dca9ba4bccb65d9c3b30cb10135cc901245d846ec1b1
                                                      • Opcode Fuzzy Hash: 3faad0f40d220c8ec74d9f26f34309b2635928add10916f9569ec1832ec9ec43
                                                      • Instruction Fuzzy Hash: 8EF067B0D00368AFDB25CF20CC84AEABB79FB84310F0081DAC109A6280EA304AC2CF10
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID:
                                                      • API String ID: 3559483778-0
                                                      • Opcode ID: b1aff16b8bdcd31f3f37d4aae3db6e8b714624298fb7c20f2b34d5e9c875f76e
                                                      • Instruction ID: d81809ed227f19af1f9e4682637c10b3a7a2a327ceb246907ebf2a25646db70e
                                                      • Opcode Fuzzy Hash: b1aff16b8bdcd31f3f37d4aae3db6e8b714624298fb7c20f2b34d5e9c875f76e
                                                      • Instruction Fuzzy Hash: E6F0FFB1E051189BDB64CA54CD84AEAB3B8AF89300F0442DAA90DA3250E7316E81CF56
                                                      APIs
                                                      • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 025FE04F
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessWrite
                                                      • String ID:
                                                      • API String ID: 3559483778-0
                                                      • Opcode ID: e2f63ffd29e5d94cba0bec690c390b3efab864b9805de005b0cf9e1a53b3a520
                                                      • Instruction ID: 3bb341104573d3396fcb4b46b7d06881d778f4dc42696d985ab7bae6cf63ba87
                                                      • Opcode Fuzzy Hash: e2f63ffd29e5d94cba0bec690c390b3efab864b9805de005b0cf9e1a53b3a520
                                                      • Instruction Fuzzy Hash: 11F01DB1E051289FDF64CA54DD84AEAB3B8BF89300F4441DAE90DA3250E7316E81CF96
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: d0be28a2835c93afe184093d53773b2c52e427bc5cadba6ec79f2428fadb03f1
                                                      • Instruction ID: 7ef4dae732be48b6468205f9bead502f232250545619a633b066cff0d33ca45c
                                                      • Opcode Fuzzy Hash: d0be28a2835c93afe184093d53773b2c52e427bc5cadba6ec79f2428fadb03f1
                                                      • Instruction Fuzzy Hash: BDF01DB0D007689FDB26CF14CC44AE9B775FF84311F0085EAD109A6240EA344AC2CF10
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,00000000), ref: 025F3BFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: 68e805f99a01c02851e8d8f578f6ff4c95bd416216e4e4208ba65a1eae89be69
                                                      • Instruction ID: 6e86597be26821f25e31bcce97c3701c9a242bfd445467cc394f5c08e0d7448b
                                                      • Opcode Fuzzy Hash: 68e805f99a01c02851e8d8f578f6ff4c95bd416216e4e4208ba65a1eae89be69
                                                      • Instruction Fuzzy Hash: A2F08970A442599BDB28CF15CC81FA9B3B5FF48300F5041EAD50997290EA356D90CF45
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 270a9b3a9af1d5b4578dbf262818f00e60c35a067b39fcfdf32ac48afd64c1ff
                                                      • Instruction ID: 4534b1a05b8f917d0ed5735ddbd6d1566b58b8bf0bb1a9def0954dc8b9480e63
                                                      • Opcode Fuzzy Hash: 270a9b3a9af1d5b4578dbf262818f00e60c35a067b39fcfdf32ac48afd64c1ff
                                                      • Instruction Fuzzy Hash: CBF03AB0D10668AFDB29DB14CC88AE9BB75EB84715F0081EED509A6280EA355BC6CF10
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,00000000), ref: 025F3BFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: a05081bcd1f2b28f2c9ab6a4d541706f79151fa330375731944a5fcfb281f714
                                                      • Instruction ID: 4fbf8c347304d3682eff120a3ad5280a9a6b028836d80d0ea95283cae4b9baf1
                                                      • Opcode Fuzzy Hash: a05081bcd1f2b28f2c9ab6a4d541706f79151fa330375731944a5fcfb281f714
                                                      • Instruction Fuzzy Hash: A9F03771E442599BDB28CE14CC81FB9B775FB44601F4041DAD909A7280EA316E90CF55
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000), ref: 02667CFA
                                                        • Part of subcall function 02667D28: CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 2be231e7c47b203d3ab4ee8215e99433f34df57f34a1c791668247d8cc72e55d
                                                      • Instruction ID: 44b36792aa799ea23048c0de0271292f1fd6251590e6b8d34fa4ec6f04e465bd
                                                      • Opcode Fuzzy Hash: 2be231e7c47b203d3ab4ee8215e99433f34df57f34a1c791668247d8cc72e55d
                                                      • Instruction Fuzzy Hash: 06F030B1900368AFEB25DF20CC49BEABB75FB44305F0085DED149A6180EA755AC5CF10
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,00000000), ref: 025F3BFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: 792b60c2d4b6dc0eadc9e5702d048cccf3db3187c7f0cd0b7ac3c4acabbecc96
                                                      • Instruction ID: 75b5914b2c7ce5a8aca41b5141664ae72981bde1b963837ba71c597d82ac3df9
                                                      • Opcode Fuzzy Hash: 792b60c2d4b6dc0eadc9e5702d048cccf3db3187c7f0cd0b7ac3c4acabbecc96
                                                      • Instruction Fuzzy Hash: 63E0D8B1B442489BE724CA15CC85FA9B3A5FB40300F0001D7EA0AE71C0EAB569D0DF9A
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,00000000), ref: 025F3BFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: 38a4ba94fee793d57ed5484c0a5f21a4b923d31a6608decea36dca74e7c8f150
                                                      • Instruction ID: e4b15fec1f6cab72e9992dfb4633b29a5778de7161347a252b3c36f11d953c7c
                                                      • Opcode Fuzzy Hash: 38a4ba94fee793d57ed5484c0a5f21a4b923d31a6608decea36dca74e7c8f150
                                                      • Instruction Fuzzy Hash: 54E0D8B1A44258A7E724CA14DC81FA5B3A5FB04200F5001DBEA0AA72C0EA366990CF9A
                                                      APIs
                                                      • ReadProcessMemory.KERNELBASE(?,?,?,00000004,00000000), ref: 025F3BFA
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: MemoryProcessRead
                                                      • String ID:
                                                      • API String ID: 1726664587-0
                                                      • Opcode ID: fa1fab9af295c091cb70130e66672ae43538fbf161cf5234f9f5aaf769a9250f
                                                      • Instruction ID: de695c6f843a529c61e9446749ead80b09048bffabde0908699c72886c6123a4
                                                      • Opcode Fuzzy Hash: fa1fab9af295c091cb70130e66672ae43538fbf161cf5234f9f5aaf769a9250f
                                                      • Instruction Fuzzy Hash: E5F06570E8425EDBDB28CF10CC81FB9B775FB44601F0041DAD909A7280EA316E90CF59
                                                      APIs
                                                      • CreateDirectoryW.KERNELBASE(?,00000000,?,?,?,?,?,?,?,?,?,?), ref: 02667E45
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: CreateDirectory
                                                      • String ID:
                                                      • API String ID: 4241100979-0
                                                      • Opcode ID: 02674f7c98431bbd9e2ea608363d93232d170d753f83e375fa5e566f5abdc42d
                                                      • Instruction ID: 5661f35b2e025565a6a2b56f8b79f77bb370a088264df5abe2032236d4798514
                                                      • Opcode Fuzzy Hash: 02674f7c98431bbd9e2ea608363d93232d170d753f83e375fa5e566f5abdc42d
                                                      • Instruction Fuzzy Hash: 61E06DF0840368AFEB208B51DC84AEBBBB4FB44710F1145EAE548A6541E6745FC4CF52
                                                      APIs
                                                      • Wow64SetThreadContext.KERNEL32(?,?), ref: 02603D9D
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID:
                                                      • API String ID: 983334009-0
                                                      • Opcode ID: 22eb1ef79d5092128ceb8db3efc50112a16ed5853035b7caad7f132885c71ae8
                                                      • Instruction ID: 7920c926b9686ae9027d5e98fe7e6916299f7ce6ae66def7ee6a1ecdca4a2fea
                                                      • Opcode Fuzzy Hash: 22eb1ef79d5092128ceb8db3efc50112a16ed5853035b7caad7f132885c71ae8
                                                      • Instruction Fuzzy Hash: 50E0EDB19591189BDB28DB54DC84AEAB374BB48311F1041CAE80E632C0DA709E91DF95
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025FB9B1
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 312f2eb45a709e00064cea34ef16a9697ac4e7d29ae3293fe0c717a75fee07bd
                                                      • Instruction ID: e8b25179ced0b951ee627798ce37ba3dbf7513f1c6aab59cb0336f919a23454b
                                                      • Opcode Fuzzy Hash: 312f2eb45a709e00064cea34ef16a9697ac4e7d29ae3293fe0c717a75fee07bd
                                                      • Instruction Fuzzy Hash: D171F2B2D052249FE764CA14CCC0BEA77B5FB84318F1841FAD90D56640D2396FC1CE96
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 58d65d6c63d75e496629591fbeefeb18ba06b48bf27562f2e3faf3580362e04f
                                                      • Instruction ID: b72a64760c8e87d007992535b930e55779642c484c0dfc240f7c64cc97d521f7
                                                      • Opcode Fuzzy Hash: 58d65d6c63d75e496629591fbeefeb18ba06b48bf27562f2e3faf3580362e04f
                                                      • Instruction Fuzzy Hash: 066100F2C00114AFFB288A14DD98BFB776DEB80319F1482BAD90A96580D77D5FC5CA16
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 354c5609520c40c95d15a2865492b763bdb5f1730b22de0494fa2aefd643f007
                                                      • Instruction ID: 42fd59107ce04734aaac4ba054498a855479e933f5f16d6241884d8c185f5f78
                                                      • Opcode Fuzzy Hash: 354c5609520c40c95d15a2865492b763bdb5f1730b22de0494fa2aefd643f007
                                                      • Instruction Fuzzy Hash: CF610FB2C001249FFB288A14DD98BFB7B6DEB80358F0441BAD90E96180D7795FC5CE56
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 1b7e08e8bd2293582f6d98d0f66cd7f8fd2fb4a2b2ff81d38336ebbc7974b741
                                                      • Instruction ID: a66ee3b2cebf53d6075e198d73cf496e38d69497162436b831dd200d350a5aef
                                                      • Opcode Fuzzy Hash: 1b7e08e8bd2293582f6d98d0f66cd7f8fd2fb4a2b2ff81d38336ebbc7974b741
                                                      • Instruction Fuzzy Hash: 946120B2C001149FFB288A14DD98BF7776DFB80318F1441FAE90A9A280D7795EC5CE16
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 02a6fe4f141a858dc833e010f837b794eed4285fb79b615b99c1127e3da61924
                                                      • Instruction ID: 21fb87108c936c4bf38e02ec1a3d50cb0835312cc730f05a9c2b5cca98dd2c30
                                                      • Opcode Fuzzy Hash: 02a6fe4f141a858dc833e010f837b794eed4285fb79b615b99c1127e3da61924
                                                      • Instruction Fuzzy Hash: E0511EB2D001149FFB288A14DD88BFB776DFB90309F1481FAD90A96280D7795EC5CE16
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: f064f53823ab122bafbdb8a69dd860cd804adcc1e31eb380120065bad1fdcdc1
                                                      • Instruction ID: 6864a7df6d9771549983b0f01f3887158ac91bcf679d825fca546800d3479c32
                                                      • Opcode Fuzzy Hash: f064f53823ab122bafbdb8a69dd860cd804adcc1e31eb380120065bad1fdcdc1
                                                      • Instruction Fuzzy Hash: D0510FB2C001149FFB288A14DD98BFB77ADFB80359F1441FAE90A96280D7795EC5CE16
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 230894005fec40ac139e58c6a83b9c590f44580cb3c758bf65232b5b3b127b0c
                                                      • Instruction ID: bf5e33f074acd9cf804a28c09141d4c16eba39647fdf66c0b683c24c4ca90b57
                                                      • Opcode Fuzzy Hash: 230894005fec40ac139e58c6a83b9c590f44580cb3c758bf65232b5b3b127b0c
                                                      • Instruction Fuzzy Hash: FF5110B2C001149FFB288A14DD98BFB776DFB80349F1441FAD90A96180D7795EC5CE16
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025E6AF4
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 0a0f527f4ee5f169ca7f9049ab2e0377e5d370517538585429f81be7e27a8506
                                                      • Instruction ID: c6f0e0effeefa4c00865c6c667e9e7958108366901e531e1472cdb2156c37fc4
                                                      • Opcode Fuzzy Hash: 0a0f527f4ee5f169ca7f9049ab2e0377e5d370517538585429f81be7e27a8506
                                                      • Instruction Fuzzy Hash: 30510EB2D00118AEFB288A14DD88BFB7B69EB90358F0441FAD90A56280D63D5EC5CA56
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025E6AF4
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: f446aabc4ac296d4dfbb825df3d3c535c451b6edb825beffc38f802254278cbe
                                                      • Instruction ID: 72da85644193fa22adf6c87b09d3b38c5d6676f205c42bf76445683683958fc9
                                                      • Opcode Fuzzy Hash: f446aabc4ac296d4dfbb825df3d3c535c451b6edb825beffc38f802254278cbe
                                                      • Instruction Fuzzy Hash: 3351DDB2D00129AEFB288A04DD88BFB776DFB90359F0401FAD90A56280D7795EC5CE56
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025E6AF4
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 38f06009eda9c9bad395465b44af1f9589143142f52ce03b2eb72327f50918dd
                                                      • Instruction ID: 5442ab54727ff7150f366ff96869a8969b4345e12f6cf37f31b5707b4212568d
                                                      • Opcode Fuzzy Hash: 38f06009eda9c9bad395465b44af1f9589143142f52ce03b2eb72327f50918dd
                                                      • Instruction Fuzzy Hash: 8A51E0B29001159EFB288A14DD98BFB7B7DEB80358F0441BAD90A96280C77D5EC4CA56
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025E6AF4
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: baf54a6f768b6373811f33f8ce411b798ae8017b041eac41a2233635892c3b62
                                                      • Instruction ID: d13e36e89736988dc9ff70ce9f8b73aca4eb942188b18f09e8e34a021f795c71
                                                      • Opcode Fuzzy Hash: baf54a6f768b6373811f33f8ce411b798ae8017b041eac41a2233635892c3b62
                                                      • Instruction Fuzzy Hash: 4D512FB2900115AFFB288A04EC88BFB7B6DFB80358F0441FAD90A56280C77D5EC5CE56
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025E6AF4
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: d54e8d0d13bd3efd467713e876ffd5fee0b5793c6a594bdc1af3b72e7b90627d
                                                      • Instruction ID: 81ca1357a50bd0eaa8af63d10ce60bdfc40dc6f18e48140c5d17ccfb1cdb253d
                                                      • Opcode Fuzzy Hash: d54e8d0d13bd3efd467713e876ffd5fee0b5793c6a594bdc1af3b72e7b90627d
                                                      • Instruction Fuzzy Hash: 4B51FDB29001199EFB288A14DD88BFB776DFB80359F0401FAD90A56280C7795EC4CE16
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025E6AF4
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: a4456b2b4088a4e605b348bbf2e3e39d63734f1f33fe99ed6eb20fb36aa9cd15
                                                      • Instruction ID: 06380551cd22fb5da31077aea1d0b85cc2ca02b63cc638ba04826f4cb206ceeb
                                                      • Opcode Fuzzy Hash: a4456b2b4088a4e605b348bbf2e3e39d63734f1f33fe99ed6eb20fb36aa9cd15
                                                      • Instruction Fuzzy Hash: CB41FDB2900119AFFB288A14DD88BFB777DFB90359F0401FAD90A56280C7795EC4CE16
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025FB9B1
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 908937f9e69040dcfeda65bee689a249c3571e81e6f9c6f14399b0c8dd40d4ca
                                                      • Instruction ID: d782d2aed40cf2eaa5a8e24d188e32ed404bdab339af75e5aef9f30d3a484bbe
                                                      • Opcode Fuzzy Hash: 908937f9e69040dcfeda65bee689a249c3571e81e6f9c6f14399b0c8dd40d4ca
                                                      • Instruction Fuzzy Hash: 8041E4B2E05218DFE7A48A14CC84BEB7B75FB94318F1481FADA0D66240E3385AC1CE56
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 583b744148275876dffe04835bd5f2a85a0dcb0707f91dfe8c87b98b43b16a0f
                                                      • Instruction ID: 25a41c7d3a2329aaed93adc0cbd878282100382a42c334b74bd62f6154f03ae1
                                                      • Opcode Fuzzy Hash: 583b744148275876dffe04835bd5f2a85a0dcb0707f91dfe8c87b98b43b16a0f
                                                      • Instruction Fuzzy Hash: 2D4179B3D0A2689FE7648A14CC88BE77B71FB85318F0505F6C90D96181D2385AC6CF42
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 5f700b2fd179c74b3c5da152240e003de131c4a611fc4ae1014553920706e933
                                                      • Instruction ID: f13a0ed7dbf77512a25d36b0570cc2c1f03137036d6a7f4a38568d8e80c440f9
                                                      • Opcode Fuzzy Hash: 5f700b2fd179c74b3c5da152240e003de131c4a611fc4ae1014553920706e933
                                                      • Instruction Fuzzy Hash: 1B3159B3E062589FE7648614CC88BEB7B71FB85328F0442F6C90D67280D23C5AC5CE92
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: f8d83f6c26e90f5461e2ab91cac58bae0207c9db580c86ae674b9c6a69047613
                                                      • Instruction ID: 6201bf1e95ca31756bc4aeef303100275338a8e8ac1630e471a48c20a8707129
                                                      • Opcode Fuzzy Hash: f8d83f6c26e90f5461e2ab91cac58bae0207c9db580c86ae674b9c6a69047613
                                                      • Instruction Fuzzy Hash: A52109F2D442249FF7248A24DD85BE77B74FB80325F1081B6D90E66AC0D6791EC0CE95
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 918570a39286bdcee2f66152ec622b364b7e033d8de73e406d43bb9f2aa301ca
                                                      • Instruction ID: 3c5d7edc8405adf3646126e2206feeb8e190359be598714fd3ffca1e147fee8b
                                                      • Opcode Fuzzy Hash: 918570a39286bdcee2f66152ec622b364b7e033d8de73e406d43bb9f2aa301ca
                                                      • Instruction Fuzzy Hash: 602134B09042158FFB288A20DD40BFBB778FB84315F2040FAD84A62680CB755EC0CE56
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004), ref: 025FB9B1
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 23aa8d0411e6f79c08fcd945bb8308b3c23dd9a569cd6f5cbe0bc154b10bab36
                                                      • Instruction ID: ea76bd574d2994c157bd5efee0911b71716dc0ff18a2800d0b9c18fbc1c99a0a
                                                      • Opcode Fuzzy Hash: 23aa8d0411e6f79c08fcd945bb8308b3c23dd9a569cd6f5cbe0bc154b10bab36
                                                      • Instruction Fuzzy Hash: 3911B2A1D09218EAFB608A15DC88BEABB74EB84318F0441B7DD0D55180D3751AC5CE57
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 0961451b79378e9aa9167288cb439646d552bf000e5f055744d09c066d829e5e
                                                      • Instruction ID: 1d1fc8d3a38e0b97573fb0c1c110f6cdd3f0baf52cb4eed1b67f66df29042652
                                                      • Opcode Fuzzy Hash: 0961451b79378e9aa9167288cb439646d552bf000e5f055744d09c066d829e5e
                                                      • Instruction Fuzzy Hash: 4B01D6B2D452298FEB388A24CC45BE677B0F744319F1041F6DA4EA76C0CA394DC0CE85
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: f33aa0f522f5223469725de58cee0f5e68a97a8a709dae92ae86d5f2692a1b25
                                                      • Instruction ID: 749b33e5a1e89c626e988f8669abf6368271fed850447bd2e8bcca7b2ed5d046
                                                      • Opcode Fuzzy Hash: f33aa0f522f5223469725de58cee0f5e68a97a8a709dae92ae86d5f2692a1b25
                                                      • Instruction Fuzzy Hash: 1901A1B2D452258FEB388A24CD45BDA7BB0FB04315F1041FADA4E676C1C6394DC0CE85
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 43bb41686f7f0f7ac6d7483c08cb66978dbe318e1d40c45293ca5861db9e423e
                                                      • Instruction ID: 5bf66d0ffad945e1f319c3f90ce70c28077acbf0c6f9123c28b6260c60564315
                                                      • Opcode Fuzzy Hash: 43bb41686f7f0f7ac6d7483c08cb66978dbe318e1d40c45293ca5861db9e423e
                                                      • Instruction Fuzzy Hash: 860104B0C4C3A98FDB249B20CC45B99BBB0BF05319F1001EAD94E665C1DB7109C0CF9A
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 9970fd5587f6cdcabfed28c56e8c3b5fb5f1449a5326cbaed996bc5ba3c56ac5
                                                      • Instruction ID: c576dde8b7917593336c5e0de5b6b7e51dc48279410b909cbdf16ae7f3ab4c01
                                                      • Opcode Fuzzy Hash: 9970fd5587f6cdcabfed28c56e8c3b5fb5f1449a5326cbaed996bc5ba3c56ac5
                                                      • Instruction Fuzzy Hash: 8901FC71D052298BEB284A21CC09FA6F770BB04315F0041F7EC4E661C0DB740A80CF85
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: a82df661c526cf609cf7618d10d447e7171659dfc1904b298681c9d246505047
                                                      • Instruction ID: f9edbefc8011be117fecb5774bc59cae614cb90320de336146ea2d69d683ad47
                                                      • Opcode Fuzzy Hash: a82df661c526cf609cf7618d10d447e7171659dfc1904b298681c9d246505047
                                                      • Instruction Fuzzy Hash: 90F02BB2E8D3595FEB245A208C457AA7B20BB41325F2501EBDF8A250C3DB750981CF8A
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: d3e79a509dcacd0b0be86c35c5286a1d36554314773393c82342e62197d46432
                                                      • Instruction ID: b859a6687764ae53b41fc230a6b7bf5012ad1a55c0651e9cbeb20a5ce837e801
                                                      • Opcode Fuzzy Hash: d3e79a509dcacd0b0be86c35c5286a1d36554314773393c82342e62197d46432
                                                      • Instruction Fuzzy Hash: 27F05C72D4826D5EF7240661DC09F67BB60F701329F0002B7DD8E265C08BB50991CFCA
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: e3887bd73793430547e485f1c66a1f45bc202ae95103271211f30a2646146339
                                                      • Instruction ID: 54b028a6d6617bc9ed9daf7d4a70a274079c86368aff3a7fe1c9859fcefc55de
                                                      • Opcode Fuzzy Hash: e3887bd73793430547e485f1c66a1f45bc202ae95103271211f30a2646146339
                                                      • Instruction Fuzzy Hash: 2EF0B471E882199FEB2C9A108C45B76B6A0F744315F6046EAD94B155C0CB7009C1CF89
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 0f70e15cee615d5c0914786b8c9c03c99b80ae370ab9aae99e752b8f5f4747c4
                                                      • Instruction ID: 7c2efababd3d8558dd4efc5d4ae48ea2cc798c0c22c86742d0f2c12acf0da2e5
                                                      • Opcode Fuzzy Hash: 0f70e15cee615d5c0914786b8c9c03c99b80ae370ab9aae99e752b8f5f4747c4
                                                      • Instruction Fuzzy Hash: 51F0A770D882199FEB289E10CC45BAAB670FB44315F5042DAEA4F662C0CB710DC0CE89
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: c974bed44b97bc14f19a46e553caabb9276d068b924b1d6257c3b92a031f52c8
                                                      • Instruction ID: c994b5448394ff743ad7cc15e39f6787176d778a12143f2980c077341985ea97
                                                      • Opcode Fuzzy Hash: c974bed44b97bc14f19a46e553caabb9276d068b924b1d6257c3b92a031f52c8
                                                      • Instruction Fuzzy Hash: C4F089B1D4822A9EEB349A208C457A9B670B745729F1041E6DD0F765C0DB705DC0CEDA
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 69e55553f5854c4274b12718ced71b61ab473e4b7902bb1f02f495ff8c8b4686
                                                      • Instruction ID: 6c711ddd30fc2a13e8117b333ff1d6cfcfe312bad0b10afff53a6f9572068710
                                                      • Opcode Fuzzy Hash: 69e55553f5854c4274b12718ced71b61ab473e4b7902bb1f02f495ff8c8b4686
                                                      • Instruction Fuzzy Hash: E7F0ECB098C3469EE72446105C097557BA0BB4532DF5401EBDD4A591C1D7F606D2CF87
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: 8acfb94772938270645ce94d82b41fffa0a4a94a6e0e34f9d4c1651f84cacd7b
                                                      • Instruction ID: 086aa46fb73daaac7a5bf3e9054f129a321564eb480178f47df08f9ea075e00c
                                                      • Opcode Fuzzy Hash: 8acfb94772938270645ce94d82b41fffa0a4a94a6e0e34f9d4c1651f84cacd7b
                                                      • Instruction Fuzzy Hash: FAE092B3F892059AF7245510CC09BA9B660B740729F6501F7DA4E2A5C0DBB50980CD8A
                                                      APIs
                                                      • VirtualAlloc.KERNELBASE(00000000,000002CC,00001000,00000004), ref: 025EFCC5
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: AllocVirtual
                                                      • String ID:
                                                      • API String ID: 4275171209-0
                                                      • Opcode ID: b1df66e949bb2929a3f2d09d53f7f20a228648c06dc240de354995ee2ac55112
                                                      • Instruction ID: b448dd699f0dd027418cc9863f81697b80c5ee0b4b4e16f7e8a2fcf82608193e
                                                      • Opcode Fuzzy Hash: b1df66e949bb2929a3f2d09d53f7f20a228648c06dc240de354995ee2ac55112
                                                      • Instruction Fuzzy Hash: DFF03771D892299EDB349A148C457A5B670B704319F5001E6DE0E266C0DB711EC0CEC9
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID: ContextThreadWow64
                                                      • String ID: E$G$H$M$OBIN$W$a$d$d$e$e$e$l$l$n$o$t$u$x$3$3
                                                      • API String ID: 983334009-780640683
                                                      • Opcode ID: ef19a461417219580b49e34330e332657820c932d5e9ee369dcbd88367777d9a
                                                      • Instruction ID: 8cd15c41e86776787ab4de1063db6f4296612a46876cc84f2b72da105c4a254b
                                                      • Opcode Fuzzy Hash: ef19a461417219580b49e34330e332657820c932d5e9ee369dcbd88367777d9a
                                                      • Instruction Fuzzy Hash: 1DF17DB0D086A88AEB258B18DC446EABBB5FF95304F0480EAD94DA7340E7354FC5CF56
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: E$G$H$M$OBIN$W$a$d$d$e$e$e$l$l$n$o$t$u$x$3
                                                      • API String ID: 0-2996905995
                                                      • Opcode ID: 40de5ef9a87081e6dbb5c1b22fcac0fce8441a0b8ddaad7123897580292125ea
                                                      • Instruction ID: a21410a49189768955b1aa6d8ad310db8d3f01962daf54df4b50983a551cf5ca
                                                      • Opcode Fuzzy Hash: 40de5ef9a87081e6dbb5c1b22fcac0fce8441a0b8ddaad7123897580292125ea
                                                      • Instruction Fuzzy Hash: 1DC1A2B0C086A89AFB258B28DC457EAB7B5FF55304F0480EAD94DA6240E7354FC5CF56
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: E$G$H$M$OBIN$W$a$d$d$e$e$e$l$l$n$o$t$u$x
                                                      • API String ID: 0-4042089635
                                                      • Opcode ID: b07f4c8c97c9992f836295cdd634e58df32fd1d06033568697540060a1ea597c
                                                      • Instruction ID: 2ea7341b482382b235ef1badb8b8703cc84158901a3268a130d72c4fe15d71aa
                                                      • Opcode Fuzzy Hash: b07f4c8c97c9992f836295cdd634e58df32fd1d06033568697540060a1ea597c
                                                      • Instruction Fuzzy Hash: 2A8148A1C086989AF7258728DC04BEB7B75FF51304F0480F9D98D96680EB3A4FC5CB66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: E$G$H$M$OBIN$W$a$d$d$e$e$e$l$l$n$o$t$u$x
                                                      • API String ID: 0-4042089635
                                                      • Opcode ID: e4ff268003b007ecac77b725dd5b4c817b49aac8575833741f8b4c68098075f3
                                                      • Instruction ID: 7df339c51316687ef16dfb5fc10ef9b1c294bc2d8e27e7533c31f85cd161b51b
                                                      • Opcode Fuzzy Hash: e4ff268003b007ecac77b725dd5b4c817b49aac8575833741f8b4c68098075f3
                                                      • Instruction Fuzzy Hash: E28148A1C086989AF7258728DC04BEB7775FF51304F0480FDD58DA6680E77A0FC58B66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: M$P$W$c$e$e$e$i$m$o$o$r$r$r$s$s$t$y
                                                      • API String ID: 0-3267982596
                                                      • Opcode ID: 7ee22ebd26bf88c3ce5de3eaf8d08a57ed8d73b853d9e0b6721cf98a685b79ee
                                                      • Instruction ID: 39decef06ab4d4b0c92828a094998eed32aaa0cc6be10bc26a452fba16afa58c
                                                      • Opcode Fuzzy Hash: 7ee22ebd26bf88c3ce5de3eaf8d08a57ed8d73b853d9e0b6721cf98a685b79ee
                                                      • Instruction Fuzzy Hash: DBF10FB1D082688BE764CA24DC84BEABBB1FB81304F0441FAD54D67281D7795EC5CF66
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: M$P$W$c$e$e$e$i$m$o$o$r$r$r$s$s$t$y
                                                      • API String ID: 0-3267982596
                                                      • Opcode ID: ba0d12c59aa6b29438d33a573197b07fd1cbbd5332d2f918b5c5a989eaad19c0
                                                      • Instruction ID: bd30b1f8c55495b11a3190c6e4126a2ba63d3cacffea806fc87e5a1179682cf8
                                                      • Opcode Fuzzy Hash: ba0d12c59aa6b29438d33a573197b07fd1cbbd5332d2f918b5c5a989eaad19c0
                                                      • Instruction Fuzzy Hash: 1FE1AC71D082A88AEB24CB24CC44BEABBB1FB91304F0481FAD64D67681E7795EC5CF55
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$e|$i$l$l$l$o$r$t$u$3
                                                      • API String ID: 0-3593921935
                                                      • Opcode ID: 864b623ad92583d1d32c4f2bdc1cb40b0008d94fbf0e5d947ff8f97d006108e6
                                                      • Instruction ID: da75492237ca9e84406ad6acb0146c6561cbc6083fda6d28ff0e5220dfe90ba9
                                                      • Opcode Fuzzy Hash: 864b623ad92583d1d32c4f2bdc1cb40b0008d94fbf0e5d947ff8f97d006108e6
                                                      • Instruction Fuzzy Hash: 6C0224B1D046A88AEB288B28DC44BEABBB5FF95310F0441FAD84E62240D7795FC5CF55
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$P<9<$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-168012158
                                                      • Opcode ID: 8aec9e0363bdaf6517de40211b68d7c78934613deb7e37bc0f5d88b25753bb78
                                                      • Instruction ID: df54bba7a627f0961891dc0fab83f6abbc221cd796df5e15912d66c08ae538a7
                                                      • Opcode Fuzzy Hash: 8aec9e0363bdaf6517de40211b68d7c78934613deb7e37bc0f5d88b25753bb78
                                                      • Instruction Fuzzy Hash: 3D6138E2C142949FF7258A24EC88BE77B7DE741310F0481FAD84E66281D6BD5BC5CB22
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: 3f6d07aba9e066f48e6f6173bbf332e236dfc53c706cd1f05506384c77fd7c68
                                                      • Instruction ID: 4d90c0f43cb2554958f1f2abc6b729d2786abbf7aefb1523dabcaad9d599cef8
                                                      • Opcode Fuzzy Hash: 3f6d07aba9e066f48e6f6173bbf332e236dfc53c706cd1f05506384c77fd7c68
                                                      • Instruction Fuzzy Hash: 3E8119A2D042949FF7258A24EC48BEB7B7DEB51310F0441FAD84E66281D6BD5BC5CB21
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: f7c39a011319857aea736b4b0473959a64fd7a67f1eeca68179632505c0e4c8a
                                                      • Instruction ID: ae20af05746fac18b582e9386440ee1a2a788956e88dc5ea11bf0aa2a0262bb7
                                                      • Opcode Fuzzy Hash: f7c39a011319857aea736b4b0473959a64fd7a67f1eeca68179632505c0e4c8a
                                                      • Instruction Fuzzy Hash: D28125F2C052549FFB198A14DC94BABBB79EB90310F0441FAD80E66281D6795FC5CB22
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: 215c1d359ad557557f1a944552d987be852ef1db03d46ffc6e410ed519f8f010
                                                      • Instruction ID: 8afde8403aad0f8b5c3c658e410a272dd26f71fc2bd54c6af9aab7c280baee48
                                                      • Opcode Fuzzy Hash: 215c1d359ad557557f1a944552d987be852ef1db03d46ffc6e410ed519f8f010
                                                      • Instruction Fuzzy Hash: 21812DF2C086989FEB198624DC98BEB7B79FB41310F0441FAD84A56181D6BD1BC5CB21
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: 83560c9bf57c878a92a3416a016677e3cf433627fde5dc5484187aa81d08f6f4
                                                      • Instruction ID: f05d07fea0bf5696684491d12c37eee31e86fddc17bf86665cf64b6c3beb637d
                                                      • Opcode Fuzzy Hash: 83560c9bf57c878a92a3416a016677e3cf433627fde5dc5484187aa81d08f6f4
                                                      • Instruction Fuzzy Hash: 386158A2C082999FFB258624DC48BEA7F79EB51310F0441FBD44E66281C6BD5BC5CB22
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: b010b89f30c46c9ea7478c22374f36ee93c059c94952ea263ac54bd311d2f0bd
                                                      • Instruction ID: ad9085237d38518fc99abf3a09925a822290fd34684e1aee2b143ab87266cc42
                                                      • Opcode Fuzzy Hash: b010b89f30c46c9ea7478c22374f36ee93c059c94952ea263ac54bd311d2f0bd
                                                      • Instruction Fuzzy Hash: A8615AE2C046989FFB258624DC48BEB7B79E791310F0441FAD44A66281C6BD5BC5CB26
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: 57e3bc91208c1cb33b5f29efdd93e7e9cd4b4073133240901ff69a30f01817bb
                                                      • Instruction ID: d6a73087bb8386174d46a4b0291087975880d487f1dba19754d33aac71a93b84
                                                      • Opcode Fuzzy Hash: 57e3bc91208c1cb33b5f29efdd93e7e9cd4b4073133240901ff69a30f01817bb
                                                      • Instruction Fuzzy Hash: E36107A2C082949FFB294624EC48BEB7B7CE751350F0441FAD84E66281D2BD5BC5CB26
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: bd13571ac05a3531159b9afadcd6f729cb7c64f988b5043535aafa9be9f5ac8d
                                                      • Instruction ID: 8e9da9cca1b5d3f7dc230f31f5565400548af0a60512dd1eabcd7fd7bd8a59dd
                                                      • Opcode Fuzzy Hash: bd13571ac05a3531159b9afadcd6f729cb7c64f988b5043535aafa9be9f5ac8d
                                                      • Instruction Fuzzy Hash: D651F6A2C182949FF7258624EC48BEB7B7CE751350F0441FAD84E66281D6BD1BC5CB62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: 75e0cf030b77695c62329ea366a167ee81c6e767b013dc9edfe978ef69fe8433
                                                      • Instruction ID: ea5912725ee2e7388929911d9a2da438a9b8d6e4538e2185d8a5917fe0933188
                                                      • Opcode Fuzzy Hash: 75e0cf030b77695c62329ea366a167ee81c6e767b013dc9edfe978ef69fe8433
                                                      • Instruction Fuzzy Hash: C5612BF1C086989FFB298624DC987EA7F79EB41310F0441FED44A66181D67D1BC5CB22
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: efb18092e994a782d30061788c1ea73f570b800d442da8242da99f6e532384ab
                                                      • Instruction ID: 60e49c2c1922b89cdcd3a23328678f40037c175e6321520f44a7f21cb855a92d
                                                      • Opcode Fuzzy Hash: efb18092e994a782d30061788c1ea73f570b800d442da8242da99f6e532384ab
                                                      • Instruction Fuzzy Hash: 7E614DE1C086989FFB258624DC587EA7F79EB41310F0441FED44A66281D67D1BC5CB22
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: 3a04f05199b8dc80ac94702b3c6223843eb84109c29a00cdd6c9c8d6dc43ef1d
                                                      • Instruction ID: 676ffffdda3e7072293375b6c515905db1910f714405b23c88ca336e069d8485
                                                      • Opcode Fuzzy Hash: 3a04f05199b8dc80ac94702b3c6223843eb84109c29a00cdd6c9c8d6dc43ef1d
                                                      • Instruction Fuzzy Hash: B7513BE2C182989FFB258624DC58BEA7F7DEB51310F0440FED44A66181D6BD5BC5CB22
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: 0cf56c97f2ca01c4a2ae2d89b346f45776ab32d83a46015ad9d49bcf20298dd3
                                                      • Instruction ID: 2cb98f1f9102814f70e928ab75ed2d32d716d80de65ba61d09df5eca8be76315
                                                      • Opcode Fuzzy Hash: 0cf56c97f2ca01c4a2ae2d89b346f45776ab32d83a46015ad9d49bcf20298dd3
                                                      • Instruction Fuzzy Hash: 59514AE2C042989FFB258624DC48BEA7F69E751310F0840FAD44A66281C6BD5BC5CB26
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: bbd7c913bc11fc58f33c4b518efd0c96e7b09b6db9993d02e93b76c8006595cc
                                                      • Instruction ID: f87f7020d1b419af024e3a40f6cb05632ab22d586ff0c6e84065e1061a61d274
                                                      • Opcode Fuzzy Hash: bbd7c913bc11fc58f33c4b518efd0c96e7b09b6db9993d02e93b76c8006595cc
                                                      • Instruction Fuzzy Hash: 17513BE2C082989FFB258624DC48BEB7F79E751314F0841FBD44A66281C6BD5BC5CB26
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: 423ed3db2635845648250a2f6e7b933d0fe3270bca9173c8a446d30727f5e3b9
                                                      • Instruction ID: 7afc45bdc24e3d2ea9568d571c8cd2d9a5f56526ea424008eed9c977b11f22e9
                                                      • Opcode Fuzzy Hash: 423ed3db2635845648250a2f6e7b933d0fe3270bca9173c8a446d30727f5e3b9
                                                      • Instruction Fuzzy Hash: 92511AA2C182989FF7258624EC48BEB7F7DE751310F0440FAD84E66281C6BD1BC5CB62
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: c416d0231ad9f83988a6a5e7cdad11fba59c72f638c1f12b4b6d6a7d91472061
                                                      • Instruction ID: 8ba69f38281fc351b4444bd4108c79fa63ee78ef267ae187b7c87466a77b0757
                                                      • Opcode Fuzzy Hash: c416d0231ad9f83988a6a5e7cdad11fba59c72f638c1f12b4b6d6a7d91472061
                                                      • Instruction Fuzzy Hash: 405129E2C182989FF7158624EC58BA77F7CE751310F0441FAD44E66281D6BD1BC5CB26
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: 719d44db2a8cee1fe50de257dfcf9122b620852640b4824127cd1521110388d9
                                                      • Instruction ID: baebd7af4b26dacaed9a1840b0b749fab6fe9aec867344d7500ae9f2f2fb02d5
                                                      • Opcode Fuzzy Hash: 719d44db2a8cee1fe50de257dfcf9122b620852640b4824127cd1521110388d9
                                                      • Instruction Fuzzy Hash: 875128E2C182989FF7258624EC58BE77B6CE751310F0440FAD84E66281D6BD5BC5CB26
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: e6e22356fc6080e0fe48eb9d395d3ea7c5c57d19d050d6de8daf6192a00a06cd
                                                      • Instruction ID: 7f2b4912e7e244ab6e308c4825cb777badeeeb862b1dc100dc59aad20173879a
                                                      • Opcode Fuzzy Hash: e6e22356fc6080e0fe48eb9d395d3ea7c5c57d19d050d6de8daf6192a00a06cd
                                                      • Instruction Fuzzy Hash: E35139E2C182989FF7258624EC48BEA7F7DE751310F0441FAD84E66281C6BD1BC5CB22
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: d22379301c28db30f1d4161d659939aac742bb1c1e0e7d33b551be9371f5a487
                                                      • Instruction ID: 8832ef03b325a446ec1a6f89188a9d3cc606e93c17799de0074d2aa67e3bb72f
                                                      • Opcode Fuzzy Hash: d22379301c28db30f1d4161d659939aac742bb1c1e0e7d33b551be9371f5a487
                                                      • Instruction Fuzzy Hash: E1515DE2C182989FF7258624DC487E67F6CE751314F0840FAD44A66281C6BD5BC5CB22
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: A$V$a$c$i$l$l$l$o$r$t$u
                                                      • API String ID: 0-1474867871
                                                      • Opcode ID: ab14c8ba6b8ec7c28ede62265899ec88fb53fd6d075de9f9d242f0770388c027
                                                      • Instruction ID: d21faa9d9da34e771b0b641e5ea3285dfa19a8cdf054f2b293d4f311ff9eda33
                                                      • Opcode Fuzzy Hash: ab14c8ba6b8ec7c28ede62265899ec88fb53fd6d075de9f9d242f0770388c027
                                                      • Instruction Fuzzy Hash: 46511AE2C182989FF7158624EC587EA7F7DE751310F0440FAD54A66281D6BD1BC5CB22
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: 7B;2$Q$YQ
                                                      • API String ID: 0-2086112649
                                                      • Opcode ID: c5d3e086991dd111372fa0117f3f856af8c142f812b310752429494378cc2e11
                                                      • Instruction ID: 0fd5df67854d24ee86032ceeba2d95ea1afe32b379bd3c10323a3155cf12195b
                                                      • Opcode Fuzzy Hash: c5d3e086991dd111372fa0117f3f856af8c142f812b310752429494378cc2e11
                                                      • Instruction Fuzzy Hash: 33A139B2C041158FEB24CB20DC95AEBBB75FF81315F1481FAD80A97241D639AE86CE52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: M=M9$e|$3
                                                      • API String ID: 0-2436971195
                                                      • Opcode ID: 027230caaf09b0343f382333043eecf9ab2e128ff17492a5cecb8ec26c5603e3
                                                      • Instruction ID: e8e0674a102db2752fcb78c5c90b9568d1f51ea9704b72c333bec94ec795f499
                                                      • Opcode Fuzzy Hash: 027230caaf09b0343f382333043eecf9ab2e128ff17492a5cecb8ec26c5603e3
                                                      • Instruction Fuzzy Hash: 89916DB1D056689BEB29CB18DC856EABBB5FF98310F1481EAD90E63240D7345BC5CE05
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: e|$3
                                                      • API String ID: 0-1726640827
                                                      • Opcode ID: 33e0ba9de31bb772fd2bf121173325c4fdd2daf1386223d4182eba6863268429
                                                      • Instruction ID: eb24d137ca4546e03b1ef311e8fd9b4223e2a29c153cc424fcd4ae9c0fdf236b
                                                      • Opcode Fuzzy Hash: 33e0ba9de31bb772fd2bf121173325c4fdd2daf1386223d4182eba6863268429
                                                      • Instruction Fuzzy Hash: D1D1D4B1C052688BEB288B28DC986EBBBB5EF45314F0441FAD84D63381E6355EC5DF51
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: e|$3
                                                      • API String ID: 0-1726640827
                                                      • Opcode ID: 67b296f1e1022dd70b3d1fae0ced1e46ac05f8f08e708a2e6d05d07fd6d4c57f
                                                      • Instruction ID: 7d6524d63633d90d29ecb7690dbd8ceb4b76daf33a5015d8293c36844b230b3b
                                                      • Opcode Fuzzy Hash: 67b296f1e1022dd70b3d1fae0ced1e46ac05f8f08e708a2e6d05d07fd6d4c57f
                                                      • Instruction Fuzzy Hash: 4BA1ADB5D086A99FEB25CB18CD446EABBB5FF88310F1481EAD94DA3241D7740AC2CF51
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: D
                                                      • API String ID: 0-2746444292
                                                      • Opcode ID: eef1a1bb66c2f6e54e867d6151cf76f9ba4dd2906c29cdb5fdf94b8ae38f496b
                                                      • Instruction ID: 577d6c5ab90d075eb496d4b629a0acbbd5501315cd2d1182d7c036f1654a42dc
                                                      • Opcode Fuzzy Hash: eef1a1bb66c2f6e54e867d6151cf76f9ba4dd2906c29cdb5fdf94b8ae38f496b
                                                      • Instruction Fuzzy Hash: 36727435E2866887DB28DB799C511DBA2B3EF58300F04E5FD940DE7264F7714A898F0A
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: 4@@M
                                                      • API String ID: 0-3598929666
                                                      • Opcode ID: 832a97a9a68d86c5617f994e34397d5d08dbc7fd7552123d80ac13ea1608cd02
                                                      • Instruction ID: eeb51bee1fd36da24127b37744ba82215448f89c90d52021f7e03ccaba931d52
                                                      • Opcode Fuzzy Hash: 832a97a9a68d86c5617f994e34397d5d08dbc7fd7552123d80ac13ea1608cd02
                                                      • Instruction Fuzzy Hash: 93B125B2D141649AE7188B20DC94BFB7735EF41310F1481FAD94DA7680E6785ED2CBA2
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: M=M9
                                                      • API String ID: 0-2119929983
                                                      • Opcode ID: 4f7b1bad0cbf184d7320e8896b604e6dad6f4db04e23f4a1950f35e6cae172bd
                                                      • Instruction ID: f4f51a9d2db9b04c0756a8234230a2387df1abd69ebd7fc5824e1b8a4488ae4c
                                                      • Opcode Fuzzy Hash: 4f7b1bad0cbf184d7320e8896b604e6dad6f4db04e23f4a1950f35e6cae172bd
                                                      • Instruction Fuzzy Hash: 1571F5F2D04158ABFB248A14DC84AFB7779FB84314F1581FAE80E57241E6395EC58E52
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: IF7C
                                                      • API String ID: 0-3432876487
                                                      • Opcode ID: 63053362f7ef531a3bb37ae1c5be2ac6f276c94fa08a0c5d18e0f8e159573144
                                                      • Instruction ID: 4d5d98f3f369cd8a1f004a5b22f3a543fd4bf2f6b2a6d8fac3e2a49f0c80f620
                                                      • Opcode Fuzzy Hash: 63053362f7ef531a3bb37ae1c5be2ac6f276c94fa08a0c5d18e0f8e159573144
                                                      • Instruction Fuzzy Hash: 7D6189F2D090C4AFF3948A20DC59AE77B6AFBD1310F1400FAD90A86641D63C5AC7CA26
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: M=M9
                                                      • API String ID: 0-2119929983
                                                      • Opcode ID: 5f6dfe6656d05d5c77311201abe6937b2c7b814d2d60bc2640ebc93997525557
                                                      • Instruction ID: 345e004521c12ab24056d38c2a9050edaf6929cbc0a9c9876d8b047bd88f498a
                                                      • Opcode Fuzzy Hash: 5f6dfe6656d05d5c77311201abe6937b2c7b814d2d60bc2640ebc93997525557
                                                      • Instruction Fuzzy Hash: C861E3F2D15168ABFB288A14EC85BF77628FB84310F0481FAD80E27280E6395FC1CE51
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: dbcbf61d6519938a428950d48cf22ed505fe968738b6aad921b0f9c1bc58da74
                                                      • Instruction ID: 0e65a20ff16c1cef2782af1f445a475532ac320585dd9870a77771d1c7622793
                                                      • Opcode Fuzzy Hash: dbcbf61d6519938a428950d48cf22ed505fe968738b6aad921b0f9c1bc58da74
                                                      • Instruction Fuzzy Hash: 409108F2D006249FF7148A15ED88BFB7779EB81314F0440BAE80DA6641D6795FC2CEA2
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 8b3728ccc3bf93d45df689d46ad46ee000bfe91000339ac80b55cc4b8e914044
                                                      • Instruction ID: 347730a09dc5d64a3c47bb4e6c8421d65974a39d76e9906029eedabe560a9062
                                                      • Opcode Fuzzy Hash: 8b3728ccc3bf93d45df689d46ad46ee000bfe91000339ac80b55cc4b8e914044
                                                      • Instruction Fuzzy Hash: B691D3B2C04224DFE7289F24DC986FA7B75FF41314F0441BAD949A7241EA395AC2CF51
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: b7246a1d404e66029266c6615454d62c0c9ac66bcf03f9471059c226d7adeb86
                                                      • Instruction ID: 31f1beb3080bf3d722574ccc8f2c9684d7979eed337db10b787d1b599bc9ee0d
                                                      • Opcode Fuzzy Hash: b7246a1d404e66029266c6615454d62c0c9ac66bcf03f9471059c226d7adeb86
                                                      • Instruction Fuzzy Hash: 5D8149A2D045149AF7248B24DC58BFB7739EFC5310F1481BBD84D9B680EA395EC2CB66
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: eafdc3d0c1037afdbe2557e6979a63caa958ea4c4f597ccd10abb72028856147
                                                      • Instruction ID: a31fb50709316702896fbe0eb2ddafd00de0c314b53f323fe3dfddec174432ba
                                                      • Opcode Fuzzy Hash: eafdc3d0c1037afdbe2557e6979a63caa958ea4c4f597ccd10abb72028856147
                                                      • Instruction Fuzzy Hash: 9F9124B2E046649BE728CA14CC94BFB77BAFF81304F0841F9D80957681D6386EC2CE51
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: a09234d393006b1d09469bccea57a69f3151c80b7a8c5a9a903070e182b64fce
                                                      • Instruction ID: e74e35057518fb74f180b6b33933383c1c572a33229bd517b7eccfb3cd2fb5d2
                                                      • Opcode Fuzzy Hash: a09234d393006b1d09469bccea57a69f3151c80b7a8c5a9a903070e182b64fce
                                                      • Instruction Fuzzy Hash: 408111B2D041649BF72C8A15CCD4EEBBB79EB81315F1441F9D80EA6380C6386BD2CE91
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: d1f66fbdd50418afce6a7894e5834d053b0120113502038820f6ed489a22edf2
                                                      • Instruction ID: 23623c02a3b259e0b68c8f916ec9743b95ec94727719845f5279b007157b1554
                                                      • Opcode Fuzzy Hash: d1f66fbdd50418afce6a7894e5834d053b0120113502038820f6ed489a22edf2
                                                      • Instruction Fuzzy Hash: 9381C2B2D04224DFE7289B24DC986FABB75FF41314F0441BAD949A7241EA395AC2CF51
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: e7c785207dbfd6d284ab69db40cdd4a5b3d2c0f3e2d6bb50f33bbae08ec56c63
                                                      • Instruction ID: b4c30e4966fbc86cb89007b7cd32ec7b6b72fc6594726ddce231ea7bb688438d
                                                      • Opcode Fuzzy Hash: e7c785207dbfd6d284ab69db40cdd4a5b3d2c0f3e2d6bb50f33bbae08ec56c63
                                                      • Instruction Fuzzy Hash: 297135A2D145249AF7248B25DC18BFB7739EFC5710F1081BBD84D9B280E6395EC2CB66
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 55ce2cbe5ef3519eb2ba7a36699fcf2af22e058ad6eb6714585e46ed32a4a626
                                                      • Instruction ID: 4eeb8791a5ae1dc83d04e713d3bd3e1ee4ccf157e9657bfdc1344e221829690d
                                                      • Opcode Fuzzy Hash: 55ce2cbe5ef3519eb2ba7a36699fcf2af22e058ad6eb6714585e46ed32a4a626
                                                      • Instruction Fuzzy Hash: 146157A2D082555AF7108A64DC94AF77B39FF81314F0441BADA4D87681E23E4EC3CB66
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: c034a050d03e35f8f5a45c4282cfb00d45845de0673cc62d4177922b16ef066e
                                                      • Instruction ID: d30f9f91f1307e466acb565ab94b2ccf45220b1d870c9db8ef7695baf40a3e5d
                                                      • Opcode Fuzzy Hash: c034a050d03e35f8f5a45c4282cfb00d45845de0673cc62d4177922b16ef066e
                                                      • Instruction Fuzzy Hash: 1E71E1B2D04268DBD7289F24DC886FABB75FF42314F0441BAD94DA7241EA395AC2CB51
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 6a6ee27ad006e39c14ae60f1092e0e18143e25f1cd0897977e32d6183db2cebf
                                                      • Instruction ID: 589c2a772660e607d9a90032f267e5fdf74c91be5bbf895ef400bc3788d17e07
                                                      • Opcode Fuzzy Hash: 6a6ee27ad006e39c14ae60f1092e0e18143e25f1cd0897977e32d6183db2cebf
                                                      • Instruction Fuzzy Hash: A361F6B3D04624DFF7148A15ED88AFB7779EB81314F0440BAE80DA6640E67D5FC6CA62
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: ceeb025372b7be7e730cd278c151f2a8012b6699722c6483c231a9270987f322
                                                      • Instruction ID: 3b75f5709e709478e7759738657d4274905c7c0e3ecad5fb79877231c25727ff
                                                      • Opcode Fuzzy Hash: ceeb025372b7be7e730cd278c151f2a8012b6699722c6483c231a9270987f322
                                                      • Instruction Fuzzy Hash: E37124A2D141298AFB288B20DC51BFA7675FF94311F1040BFE60E97680E67D5EC2CB16
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 9bbacd8796875ce1b9c7562de7bc1f15ceae9d7c800ead50439ef262d8dbc109
                                                      • Instruction ID: 3c24c88c0f8017a928fb853b069e3bfa4b52d911b52803506c63bc935de36f25
                                                      • Opcode Fuzzy Hash: 9bbacd8796875ce1b9c7562de7bc1f15ceae9d7c800ead50439ef262d8dbc109
                                                      • Instruction Fuzzy Hash: AE6117A2D105249AF7248B25DC18BFB7779EFC4710F1081BBD84D97280E6395EC2CB66
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 2b5874255093db914e1c3f9a2d880605ba7dbbdb8cc23e60c43ed4774db5e3a1
                                                      • Instruction ID: 278de900cbbf0793c959810d5df3cbd1240ea92142a415f27a5eb4022eee1dbc
                                                      • Opcode Fuzzy Hash: 2b5874255093db914e1c3f9a2d880605ba7dbbdb8cc23e60c43ed4774db5e3a1
                                                      • Instruction Fuzzy Hash: E271E3B2C04264DBD7289F24DC886FBBB75FB42314F0441BED949A6241EA395EC2CF51
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 832d98851e0777dd2c62b64c93ea7a4164bec38ea830c896cbdafa3668d789cd
                                                      • Instruction ID: 39e35c5aab468c5930e6f6c32235ee324734b2cbde7b3a88a33350f8a9280068
                                                      • Opcode Fuzzy Hash: 832d98851e0777dd2c62b64c93ea7a4164bec38ea830c896cbdafa3668d789cd
                                                      • Instruction Fuzzy Hash: 71612792D105249AF7248B29DC18BFB773AEFC4710F1081BBD84D97280E6395EC2CB66
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 1b9cb821d65bbde9f3eb1e7800ac856a15f8ab2747194cc6fe64a82ee2deb985
                                                      • Instruction ID: e42033d23b7e6d72e90aea881a91aea72508b733083d52daa6c6ad1ba83f23d7
                                                      • Opcode Fuzzy Hash: 1b9cb821d65bbde9f3eb1e7800ac856a15f8ab2747194cc6fe64a82ee2deb985
                                                      • Instruction Fuzzy Hash: 2D614792E145649AF7248B25DC18BFB763AEFC4710F1081BBD44D97680E63D4EC2CB66
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 25d6f13d96f0329ce9fb6529ccff2f4e0c937e5930e3c0a21d265d3ea7deaefb
                                                      • Instruction ID: a85d4199dd39a8f8ee4072e7c303996e425305b78df24d80dc934c6412569853
                                                      • Opcode Fuzzy Hash: 25d6f13d96f0329ce9fb6529ccff2f4e0c937e5930e3c0a21d265d3ea7deaefb
                                                      • Instruction Fuzzy Hash: C96109A3D005245BFB248B28EC44AF77779FF84310F1482B6E80E97690EA7D5EC5CA95
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: f659bf2f27c9f901cb09c8f9d879e7767306be3c59a08a150f39c56f89879215
                                                      • Instruction ID: 66ec7c992389e076165d09c8f5648305fca1862598402e242bd9e3ebf9542e0d
                                                      • Opcode Fuzzy Hash: f659bf2f27c9f901cb09c8f9d879e7767306be3c59a08a150f39c56f89879215
                                                      • Instruction Fuzzy Hash: 2461E3B2C04268DBDB289F24DC886FABB75FB41314F0441BAD94DA6241EA395AC2CF51
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 91e8bd2bd82c5572c0409a98e75a57955b75263376d4c9a4362373276991b4fa
                                                      • Instruction ID: c42c200e22e048e4224589bd9ab52196be30ff2cedd6ffe1c30334d874b9cd5c
                                                      • Opcode Fuzzy Hash: 91e8bd2bd82c5572c0409a98e75a57955b75263376d4c9a4362373276991b4fa
                                                      • Instruction Fuzzy Hash: 13514892E105649AF7248B29DC18BFB773AEFC5710F1081BBD44D97280E6395EC2CB66
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 0137ab2d450b1a22e458c0f053bb61cfa111a451ec261a45b788261a1d578b04
                                                      • Instruction ID: f7dd055428a5550e142d94753d35ce83f477dc438a987a431adb67a15ec4db72
                                                      • Opcode Fuzzy Hash: 0137ab2d450b1a22e458c0f053bb61cfa111a451ec261a45b788261a1d578b04
                                                      • Instruction Fuzzy Hash: A75114E2C151149AFB288B24DC45BFB7739FB84311F0082BBE80F66680E6385EC1CE16
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: be0fac538c12bcbe271e6dd786a1e62ab624e7b4cd7ce265b4bdcfc12f23cb41
                                                      • Instruction ID: 31eecdf9cff17d353e716392d4899f699987a53f06a921cf0be47b66ea942e02
                                                      • Opcode Fuzzy Hash: be0fac538c12bcbe271e6dd786a1e62ab624e7b4cd7ce265b4bdcfc12f23cb41
                                                      • Instruction Fuzzy Hash: 295128A3D152285BFB288B64EC85BEB7765FF81320F0541F6D84D66240E63C5EC2CA96
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: ef77fe375ce3e86d625b1025a709553aaa9c9c7d5860eb1d35f4ce1907362c02
                                                      • Instruction ID: 1834f93856758e9bfd930e8dce04b41aa8ddfdab50f98bfccf6a4e9b96ccd1e0
                                                      • Opcode Fuzzy Hash: ef77fe375ce3e86d625b1025a709553aaa9c9c7d5860eb1d35f4ce1907362c02
                                                      • Instruction Fuzzy Hash: 4D5113E2D042644BF7648B24DC91BF73779FB81310F0481FAD94E86281E7385EC6CA56
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 39694448570a9b7b7df6466aa16ed544fae18be8f7586eb1856326a5de89df35
                                                      • Instruction ID: 7ae5b0b007790306b177e661912448d9e6c63d58ee66a1e3fb4310001e465d6f
                                                      • Opcode Fuzzy Hash: 39694448570a9b7b7df6466aa16ed544fae18be8f7586eb1856326a5de89df35
                                                      • Instruction Fuzzy Hash: D85147A2E045549AF3208B64DC4CBB73A3ADF81310F1481BBD84DCB681D57E9EC78B62
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: f0bcb3cc996609ea270a97a8d58a6f82270d96b31bc194f9983395b1fbd93eb6
                                                      • Instruction ID: 3abb2121c273681f473a5cfb7299e601bb13e21909605e4e11b1b4dc691ab2ca
                                                      • Opcode Fuzzy Hash: f0bcb3cc996609ea270a97a8d58a6f82270d96b31bc194f9983395b1fbd93eb6
                                                      • Instruction Fuzzy Hash: 8C51F4A28151259AFB288B65DC44BFBB776FB84711F10C1FBD40E65680E6389EC1CE25
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: d45e4b58fb94d4d30b053a54e20d213344342fee7f6df475364ad046ee1cec3a
                                                      • Instruction ID: 339af7443f6d3527b4237513f3011c07e953330bbfc265a316a4fd154324b6a2
                                                      • Opcode Fuzzy Hash: d45e4b58fb94d4d30b053a54e20d213344342fee7f6df475364ad046ee1cec3a
                                                      • Instruction Fuzzy Hash: 4D5125A2D092549FF7288B61DC59AFB7775EB44310F0480FED90E66280E63D6EC2CE52
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: bf3d29b8a02d2230f063a557fdccbe5a0738f2fc64115db09a3911d2643a0b5d
                                                      • Instruction ID: 6bd4c51555ebbb1fdfebff7886fc0f392656c768be5558750180b72f194fdd83
                                                      • Opcode Fuzzy Hash: bf3d29b8a02d2230f063a557fdccbe5a0738f2fc64115db09a3911d2643a0b5d
                                                      • Instruction Fuzzy Hash: 18512791E145159AF7248B24DD1CBFB7639EF84700F1081BBD44DD7280E63A5EC1CB66
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 7153ce8a0d988c54a6124e676f1b62ef68f0e23671f24698c29c2eb49b126b95
                                                      • Instruction ID: d1d013c3a5b628e8f2fcb7ae6cf4101a1e31a53badb9bb350a1151cd6193682e
                                                      • Opcode Fuzzy Hash: 7153ce8a0d988c54a6124e676f1b62ef68f0e23671f24698c29c2eb49b126b95
                                                      • Instruction Fuzzy Hash: 5F5149A2E145555AF7208B25DC08BB7373AEF81310F1081BBD80DC7685D63E9EC28B62
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 2c99d1672ed1c770a0994a562f9736a1b6421944077d8dd958796ef2ee7928ff
                                                      • Instruction ID: 294acfe2d38ec1f0d3170a5449f4e99dea76b389ce19acd1abf0c52db4c1d600
                                                      • Opcode Fuzzy Hash: 2c99d1672ed1c770a0994a562f9736a1b6421944077d8dd958796ef2ee7928ff
                                                      • Instruction Fuzzy Hash: 7B518FB1911615CFEB18CF59D9C17AABBF4FB48305F248429C511EB390D3B8AA10DF54
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726075395.0000000002660000.00000040.00001000.00020000.00000000.sdmp, Offset: 02660000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_2660000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: fe1196be9691b295e79d5c6987db17e17c954d86ec434230c486cf5f600f44aa
                                                      • Instruction ID: 06237c5d40318ff9588214b81713e9f6a5b91543d3e4c6f5fd57f4998a927617
                                                      • Opcode Fuzzy Hash: fe1196be9691b295e79d5c6987db17e17c954d86ec434230c486cf5f600f44aa
                                                      • Instruction Fuzzy Hash: 674127A2E041649AE7258B26DC44AFFB7B5EFC5714F1081FAD44D96280E63C4AC2CF56
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 50b83d284abb6a08a95ceb79507c8ba4ec19232c9a96bd1d2d1d03073eaf3fab
                                                      • Instruction ID: 32e8f6e40d5387b29ab39e26e518eb8a1038334c91c7fcd66075b0fd352f3bbf
                                                      • Opcode Fuzzy Hash: 50b83d284abb6a08a95ceb79507c8ba4ec19232c9a96bd1d2d1d03073eaf3fab
                                                      • Instruction Fuzzy Hash: DE41D3A28151259AFB288B29DC44BFBB775FB84711F00C6FBD40EA6684E6385EC1CF15
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 9786eeda9ff16d8fc223fd39e3999591cda13721f48248c8b5b21c460bfea866
                                                      • Instruction ID: 500500db01a649bc6556eb5e100357a4fb1e49bfa4098554f29e5e2f1a4ff85e
                                                      • Opcode Fuzzy Hash: 9786eeda9ff16d8fc223fd39e3999591cda13721f48248c8b5b21c460bfea866
                                                      • Instruction Fuzzy Hash: DA41B1B2D011385AE7248B14DC90BFBB67AFF84314F0440FAE90D63280E6785EC1CAA6
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 81f5c3a184a8814c7ea1d5ed56103c383d90568fa819f7f39f058a410a2ff9a9
                                                      • Instruction ID: 799037c059331d0c3f4b070e94da80f7be8c1b1f0b3df3e6f5664cdc8f6ea608
                                                      • Opcode Fuzzy Hash: 81f5c3a184a8814c7ea1d5ed56103c383d90568fa819f7f39f058a410a2ff9a9
                                                      • Instruction Fuzzy Hash: BA41D372D080349BEB648A14DC94BEB7BB9FF41314F1841FADA4D26A80D7396EC0CA95
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 452c5824668edf7bbe0322207991df14b56860d3730b3ba7ea94afae636e8716
                                                      • Instruction ID: a8dd72ea60d577856b8f27c62543b5014853ada3a2f9b5cf49e87f66b8eae77f
                                                      • Opcode Fuzzy Hash: 452c5824668edf7bbe0322207991df14b56860d3730b3ba7ea94afae636e8716
                                                      • Instruction Fuzzy Hash: B04129F2C04155AFFB188E20DD84BBB7769EB85320F0481FBD8065A680E579AEC1CE56
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 8016b5b95b5a54ff1c093efdf719769a78a3d575d7dd3fa75ed35e1191afe7cc
                                                      • Instruction ID: 6072aaada2ea4f122293a94adddfa34ef08a78608104664bab256b71a47895a8
                                                      • Opcode Fuzzy Hash: 8016b5b95b5a54ff1c093efdf719769a78a3d575d7dd3fa75ed35e1191afe7cc
                                                      • Instruction Fuzzy Hash: 394135A2D051149BF7288A25DC84FEB7B79FFC5320F1581BAD84D4B681C13D5AC3CA12
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: e7049b93cf88e84cff4947081ba4ffdcc86ef9cf3618d7bb1a50d0d9e124730a
                                                      • Instruction ID: 5b4ee0d80802b40d7b88280aa8d863bbd394e024feaa26949143f4b7234ced8f
                                                      • Opcode Fuzzy Hash: e7049b93cf88e84cff4947081ba4ffdcc86ef9cf3618d7bb1a50d0d9e124730a
                                                      • Instruction Fuzzy Hash: 494102E28151159AFB288B29DC44BFBA676FB84711F00C5FAD40EA5684E6389EC1CB25
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 0be83ebf1ae0e5c55cbd1350b25ea90fdb32308c23beaa246a83b3a1421bc53f
                                                      • Instruction ID: 266ab801ba8038a7b932ba78169d4f09b39153c38f35682a3664f3bbae85d103
                                                      • Opcode Fuzzy Hash: 0be83ebf1ae0e5c55cbd1350b25ea90fdb32308c23beaa246a83b3a1421bc53f
                                                      • Instruction Fuzzy Hash: D34102E28111159AFB248B25DC40BFBB376FF84701F10C1BAD44EA6684E6389EC1CF26
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.1726014711.00000000025E0000.00000040.00001000.00020000.00000000.sdmp, Offset: 025E0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_25e0000_AdobeReaderPDFonline.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 34ea49b75e61007fe92157f368dcae0a7d1e605d9751c44a0b1432f1fe6bd8a3
                                                      • Instruction ID: 1e289ea841ad98feff1c4512da15a9634537433e83fbd01e6806633e2a1f34ca
                                                      • Opcode Fuzzy Hash: 34ea49b75e61007fe92157f368dcae0a7d1e605d9751c44a0b1432f1fe6bd8a3
                                                      • Instruction Fuzzy Hash: 404126A2D251688AEB248F64DC81BE7B771FF85310F0441FAD84DA7240E6385EC2CB92