Edit tour

Windows Analysis Report
SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe

Overview

General Information

Sample name:SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe
Analysis ID:1669390
MD5:562839ff96784f8ef8b7768534933a2c
SHA1:5f223cf60e5dcfabb80742e1a1c33e8bc590c73b
SHA256:0ba78b87fd8907401f8332f113dcef8f85d6ef4bb560faf03ec3988e91523631
Tags:exeuser-SecuriteInfoCom
Infos:

Detection

Score:48
Range:0 - 100
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Found large amount of non-executed APIs
Program does not show much activity (idle)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeVirustotal: Detection: 63%Perma Link
Source: SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeReversingLabs: Detection: 61%
Source: SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BC2294 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF7C6BC2294
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BA35180_2_00007FF7C6BA3518
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BA10000_2_00007FF7C6BA1000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BBFF7C0_2_00007FF7C6BBFF7C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BC6F1C0_2_00007FF7C6BC6F1C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BB75DC0_2_00007FF7C6BB75DC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BC15A00_2_00007FF7C6BC15A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BC75B80_2_00007FF7C6BC75B8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BC3D680_2_00007FF7C6BC3D68
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BB7D6C0_2_00007FF7C6BB7D6C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BABD280_2_00007FF7C6BABD28
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BADEF00_2_00007FF7C6BADEF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BBA3500_2_00007FF7C6BBA350
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BAAD000_2_00007FF7C6BAAD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BB949C0_2_00007FF7C6BB949C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BA94600_2_00007FF7C6BA9460
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BC52780_2_00007FF7C6BC5278
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BADA780_2_00007FF7C6BADA78
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BC22940_2_00007FF7C6BC2294
Source: classification engineClassification label: mal48.winEXE@1/0@0/0
Source: SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeVirustotal: Detection: 63%
Source: SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeReversingLabs: Detection: 61%
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeSection loaded: kernel.appcore.dllJump to behavior
Source: SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeAPI coverage: 5.2 %
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BC2294 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF7C6BC2294
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BB07B4 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7C6BB07B4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BC34A4 GetProcessHeap,0_2_00007FF7C6BC34A4
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BB07B4 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7C6BB07B4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BB0500 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF7C6BB0500
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BB71E4 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7C6BB71E4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BB0994 SetUnhandledExceptionFilter,0_2_00007FF7C6BB0994
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BC9040 cpuid 0_2_00007FF7C6BC9040
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_2_00007FF7C6BC5808
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: EnumSystemLocalesW,0_2_00007FF7C6BBDFC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF7C6BC606C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: GetLocaleInfoW,0_2_00007FF7C6BC5F14
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: EnumSystemLocalesW,0_2_00007FF7C6BC5B64
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: GetLocaleInfoW,0_2_00007FF7C6BBE354
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF7C6BC5CCC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: EnumSystemLocalesW,0_2_00007FF7C6BC5C34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: GetLocaleInfoW,0_2_00007FF7C6BC611C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF7C6BC6250
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BB0A00 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF7C6BB0A00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exeCode function: 0_2_00007FF7C6BA3518 GetUserNameA,GetFileAttributesA,_invalid_parameter_noinfo_noreturn,0_2_00007FF7C6BA3518
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
DLL Side-Loading
1
DLL Side-Loading
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory2
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager1
Account Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS1
System Owner/User Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials22
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1669390 Sample: SecuriteInfo.com.Win64.Malw... Startdate: 19/04/2025 Architecture: WINDOWS Score: 48 7 Multi AV Scanner detection for submitted file 2->7 5 SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe 2->5         started        process3

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe64%VirustotalBrowse
SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe61%ReversingLabsWin64.Malware.Heuristic
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1669390
Start date and time:2025-04-19 23:06:15 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 1m 54s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:1
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe
Detection:MAL
Classification:mal48.winEXE@1/0@0/0
EGA Information:
  • Successful, ratio: 100%
HCA Information:
  • Successful, ratio: 94%
  • Number of executed functions: 5
  • Number of non-executed functions: 67
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Stop behavior analysis, all processes terminated
No simulations
No context
No context
No context
No context
No context
No created / dropped files found
File type:PE32+ executable (GUI) x86-64, for MS Windows
Entropy (8bit):6.215183182252695
TrID:
  • Win64 Executable GUI (202006/5) 92.65%
  • Win64 Executable (generic) (12005/4) 5.51%
  • Generic Win/DOS Executable (2004/3) 0.92%
  • DOS Executable Generic (2002/1) 0.92%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe
File size:258'048 bytes
MD5:562839ff96784f8ef8b7768534933a2c
SHA1:5f223cf60e5dcfabb80742e1a1c33e8bc590c73b
SHA256:0ba78b87fd8907401f8332f113dcef8f85d6ef4bb560faf03ec3988e91523631
SHA512:6f01d32c204a2a86abdd0b5fb02e1aa1947768dc63f6e0e3078b3261a22b066a67f583238829f1e69422b57c93b910dcc5d3a0bfc64657bdf4cdfe850fb3eb86
SSDEEP:3072:1FIUA2/r2Zl9Yrb4fAj/6tXn/atD0cm53jVnw31fzXom6oxsHFM8CLX5kDsufmbM:1MBoj/6tX/atQJ53jVn2pj0M8Cqs
TLSH:53446B1677A40CF8EDA7923DCC560A4AE7B2BC160771EB4F03A046975F236A19D3E721
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........F.o.'.<.'.<.'.<._.=.'.<._.=''.<._.=.'.<J..=.'.<J..=.'.<._.=.'.<.'.<.'.<J..=.'.<...=.'.<...=.'.<Rich.'.<.......................
Icon Hash:90cececece8e8eb0
Entrypoint:0x1400100c0
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x140000000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x67FD2C79 [Mon Apr 14 15:40:41 2025 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:6
OS Version Minor:0
File Version Major:6
File Version Minor:0
Subsystem Version Major:6
Subsystem Version Minor:0
Import Hash:bdcc417182aff23aa735853592246a3c
Instruction
dec eax
sub esp, 28h
call 00007F11A8D6EACCh
dec eax
add esp, 28h
jmp 00007F11A8D6E00Fh
int3
int3
dec eax
sub esp, 28h
dec ebp
mov eax, dword ptr [ecx+38h]
dec eax
mov ecx, edx
dec ecx
mov edx, ecx
call 00007F11A8D6E1A2h
mov eax, 00000001h
dec eax
add esp, 28h
ret
int3
int3
int3
inc eax
push ebx
inc ebp
mov ebx, dword ptr [eax]
dec eax
mov ebx, edx
inc ecx
and ebx, FFFFFFF8h
dec esp
mov ecx, ecx
inc ecx
test byte ptr [eax], 00000004h
dec esp
mov edx, ecx
je 00007F11A8D6E1A5h
inc ecx
mov eax, dword ptr [eax+08h]
dec ebp
arpl word ptr [eax+04h], dx
neg eax
dec esp
add edx, ecx
dec eax
arpl ax, cx
dec esp
and edx, ecx
dec ecx
arpl bx, ax
dec edx
mov edx, dword ptr [eax+edx]
dec eax
mov eax, dword ptr [ebx+10h]
mov ecx, dword ptr [eax+08h]
dec eax
mov eax, dword ptr [ebx+08h]
test byte ptr [ecx+eax+03h], 0000000Fh
je 00007F11A8D6E19Dh
movzx eax, byte ptr [ecx+eax+03h]
and eax, FFFFFFF0h
dec esp
add ecx, eax
dec esp
xor ecx, edx
dec ecx
mov ecx, ecx
pop ebx
jmp 00007F11A8D6DB06h
int3
dec eax
mov dword ptr [esp+10h], ebx
dec eax
mov dword ptr [esp+18h], esi
push ebp
push edi
inc ecx
push esi
dec eax
mov ebp, esp
dec eax
sub esp, 10h
xor eax, eax
xor ecx, ecx
cpuid
inc esp
mov eax, ecx
inc esp
mov edx, edx
inc ecx
xor edx, 49656E69h
inc ecx
xor eax, 6C65746Eh
inc esp
mov ecx, ebx
inc esp
mov esi, eax
xor ecx, ecx
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x3ab3c0x3c.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x3f0000x24fc.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x420000x9f4.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x362300x38.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x360f00x140.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x2b0000x2d0.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x29fbc0x2a0004ae98620d798231ae83c5c21c5b6882fFalse0.55322265625data6.456616681569424IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x2b0000x104aa0x1060029db539a915f66ed2b2547ccae501c18False0.3946207061068702data4.7260402613019545IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x3c0000x2d540x1600d461a1acf0d73fdd5355a27bac2e1f2eFalse0.1709872159090909DOS executable (block device driver)2.952461754720926IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.pdata0x3f0000x24fc0x26000f58dd2a82eaf44fc9c32d42ccc602c1False0.4758429276315789data5.328409395697172IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x420000x9f40xa005b5afc5bfb303aad40b6322ab9afefebFalse0.5171875data5.392109284293155IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
DLLImport
ADVAPI32.dllGetUserNameA
KERNEL32.dllFindFirstFileA, FindNextFileA, FindClose, GetFileAttributesA, MultiByteToWideChar, WideCharToMultiByte, LCMapStringEx, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionEx, DeleteCriticalSection, EncodePointer, DecodePointer, CompareStringEx, GetCPInfo, GetStringTypeW, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleW, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, SetEndOfFile, RtlUnwindEx, RtlPcToFileHeader, RaiseException, GetLastError, SetLastError, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, GetProcAddress, LoadLibraryExW, ExitProcess, GetModuleHandleExW, GetModuleFileNameW, GetStdHandle, WriteFile, GetFileSizeEx, SetFilePointerEx, GetFileType, FlushFileBuffers, GetConsoleOutputCP, GetConsoleMode, HeapFree, CloseHandle, HeapReAlloc, HeapAlloc, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, LCMapStringW, GetLocaleInfoW, IsValidLocale, GetUserDefaultLCID, EnumSystemLocalesW, ReadFile, ReadConsoleW, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCommandLineA, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetProcessHeap, SetStdHandle, CreateFileW, HeapSize, WriteConsoleW, RtlUnwind
No network behavior found
Target ID:0
Start time:17:07:13
Start date:19/04/2025
Path:C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe"
Imagebase:0x7ff7c6ba0000
File size:258'048 bytes
MD5 hash:562839FF96784F8EF8B7768534933A2C
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

Execution Graph

Execution Coverage

Dynamic/Packed Code Coverage

Signature Coverage

Execution Coverage:3.4%
Dynamic/Decrypted Code Coverage:0%
Signature Coverage:27%
Total number of Nodes:1110
Total number of Limit Nodes:40
Show Legend
Hide Nodes/Edges
execution_graph 16246 7ff7c6bb75dc 16247 7ff7c6bb7635 16246->16247 16276 7ff7c6bb7bbd 16246->16276 16248 7ff7c6bb765c 16247->16248 16299 7ff7c6bbff7c 16247->16299 16250 7ff7c6bbdf10 _Strcoll 11 API calls 16248->16250 16253 7ff7c6bb7b91 16248->16253 16251 7ff7c6bb7671 16250->16251 16254 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16251->16254 16252 7ff7c6bafac0 _Strcoll 8 API calls 16255 7ff7c6bb7c1e 16252->16255 16257 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16253->16257 16256 7ff7c6bb767d 16254->16256 16259 7ff7c6bbdf10 _Strcoll 11 API calls 16256->16259 16258 7ff7c6bb7b9b 16257->16258 16260 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16258->16260 16261 7ff7c6bb768e 16259->16261 16262 7ff7c6bb7ba3 16260->16262 16263 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16261->16263 16264 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16262->16264 16265 7ff7c6bb7698 16263->16265 16266 7ff7c6bb7bab 16264->16266 16267 7ff7c6bbdf10 _Strcoll 11 API calls 16265->16267 16268 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16266->16268 16269 7ff7c6bb76a2 16267->16269 16271 7ff7c6bb7b4a 16268->16271 16270 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16269->16270 16272 7ff7c6bb76ac 16270->16272 16274 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16271->16274 16273 7ff7c6bbdf10 _Strcoll 11 API calls 16272->16273 16275 7ff7c6bb76b6 16273->16275 16274->16276 16277 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16275->16277 16276->16252 16278 7ff7c6bb76c0 16277->16278 16279 7ff7c6bbdf10 _Strcoll 11 API calls 16278->16279 16280 7ff7c6bb76cd 16279->16280 16281 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16280->16281 16282 7ff7c6bb76d7 16281->16282 16282->16253 16283 7ff7c6bb7719 GetCPInfo 16282->16283 16283->16253 16285 7ff7c6bb7732 __scrt_get_show_window_mode 16283->16285 16285->16253 16334 7ff7c6bc0608 16285->16334 16300 7ff7c6bbffbf 16299->16300 16301 7ff7c6bc0099 16299->16301 16354 7ff7c6bbfe00 16300->16354 16302 7ff7c6bc00a2 16301->16302 16303 7ff7c6bc00dd 16301->16303 16378 7ff7c6bbe354 16302->16378 16310 7ff7c6bbe354 std::_Locinfo::_Locinfo_ctor 6 API calls 16303->16310 16328 7ff7c6bc001a 16303->16328 16308 7ff7c6bc0021 GetLastError 16312 7ff7c6bc0030 16308->16312 16308->16328 16309 7ff7c6bbffde 16313 7ff7c6bbdf10 _Strcoll 11 API calls 16309->16313 16310->16328 16311 7ff7c6bafac0 _Strcoll 8 API calls 16314 7ff7c6bc011d 16311->16314 16315 7ff7c6bbfe00 53 API calls 16312->16315 16317 7ff7c6bbffe9 16313->16317 16314->16248 16318 7ff7c6bc0045 16315->16318 16316 7ff7c6bbdf10 _Strcoll 11 API calls 16319 7ff7c6bc00c3 16316->16319 16320 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16317->16320 16323 7ff7c6bbdf10 _Strcoll 11 API calls 16318->16323 16318->16328 16321 7ff7c6bc007b 16319->16321 16324 7ff7c6bbe354 std::_Locinfo::_Locinfo_ctor 6 API calls 16319->16324 16322 7ff7c6bbfff3 16320->16322 16325 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16321->16325 16322->16328 16369 7ff7c6bc68e0 16322->16369 16327 7ff7c6bc005d 16323->16327 16324->16321 16325->16328 16327->16321 16331 7ff7c6bbfe00 53 API calls 16327->16331 16328->16311 16330 7ff7c6bc012f 16332 7ff7c6bb7500 _invalid_parameter_noinfo_noreturn 17 API calls 16330->16332 16331->16321 16333 7ff7c6bc0143 16332->16333 16335 7ff7c6bb8440 TranslateName 45 API calls 16334->16335 16336 7ff7c6bc062d 16335->16336 16439 7ff7c6bc02d4 16336->16439 16384 7ff7c6bb8440 16354->16384 16357 7ff7c6bbe354 std::_Locinfo::_Locinfo_ctor 6 API calls 16358 7ff7c6bbfe5a 16357->16358 16359 7ff7c6bbfe61 16358->16359 16363 7ff7c6bbff24 16358->16363 16364 7ff7c6bbfe8a _Strcoll 16358->16364 16392 7ff7c6bc0778 16358->16392 16360 7ff7c6bafac0 _Strcoll 8 API calls 16359->16360 16362 7ff7c6bbff61 16360->16362 16362->16308 16362->16309 16363->16359 16365 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 16363->16365 16364->16363 16366 7ff7c6bbe354 std::_Locinfo::_Locinfo_ctor 6 API calls 16364->16366 16365->16359 16367 7ff7c6bbfeea 16366->16367 16367->16363 16399 7ff7c6bc1f30 16367->16399 16374 7ff7c6bc68fd 16369->16374 16370 7ff7c6bc6902 16371 7ff7c6bc0012 16370->16371 16372 7ff7c6bb8408 _Strcoll 11 API calls 16370->16372 16371->16328 16371->16330 16373 7ff7c6bc690c 16372->16373 16375 7ff7c6bb74b0 _invalid_parameter_noinfo 37 API calls 16373->16375 16374->16370 16374->16371 16376 7ff7c6bc694c 16374->16376 16375->16371 16376->16371 16377 7ff7c6bb8408 _Strcoll 11 API calls 16376->16377 16377->16373 16426 7ff7c6bbe03c 16378->16426 16381 7ff7c6bbe397 16381->16316 16381->16328 16383 7ff7c6bbe3be GetLocaleInfoW 16383->16381 16385 7ff7c6bb8464 16384->16385 16391 7ff7c6bb845f 16384->16391 16386 7ff7c6bbc4ec _Getctype 45 API calls 16385->16386 16385->16391 16387 7ff7c6bb847f 16386->16387 16402 7ff7c6bc06a0 16387->16402 16391->16357 16393 7ff7c6bc07c3 16392->16393 16397 7ff7c6bc0787 _Strcoll 16392->16397 16394 7ff7c6bb8408 _Strcoll 11 API calls 16393->16394 16396 7ff7c6bc07c1 16394->16396 16395 7ff7c6bc07aa HeapAlloc 16395->16396 16395->16397 16396->16364 16397->16393 16397->16395 16398 7ff7c6bb890c std::_Facet_Register 2 API calls 16397->16398 16398->16397 16401 7ff7c6bc1f54 WideCharToMultiByte 16399->16401 16403 7ff7c6bc06b5 16402->16403 16404 7ff7c6bb84a2 16402->16404 16403->16404 16410 7ff7c6bc4f90 16403->16410 16406 7ff7c6bc070c 16404->16406 16407 7ff7c6bc0721 16406->16407 16408 7ff7c6bc0734 16406->16408 16407->16408 16423 7ff7c6bc306c 16407->16423 16408->16391 16411 7ff7c6bbc4ec _Getctype 45 API calls 16410->16411 16412 7ff7c6bc4f9f 16411->16412 16413 7ff7c6bc4fea 16412->16413 16422 7ff7c6bb7c88 EnterCriticalSection 16412->16422 16413->16404 16424 7ff7c6bbc4ec _Getctype 45 API calls 16423->16424 16425 7ff7c6bc3075 16424->16425 16427 7ff7c6bbe099 16426->16427 16434 7ff7c6bbe094 __vcrt_InitializeCriticalSectionEx 16426->16434 16427->16381 16436 7ff7c6bbe694 16427->16436 16428 7ff7c6bbe0c9 LoadLibraryExW 16430 7ff7c6bbe19e 16428->16430 16431 7ff7c6bbe0ee GetLastError 16428->16431 16429 7ff7c6bbe1be GetProcAddress 16429->16427 16433 7ff7c6bbe1cf 16429->16433 16430->16429 16432 7ff7c6bbe1b5 FreeLibrary 16430->16432 16431->16434 16432->16429 16433->16427 16434->16427 16434->16428 16434->16429 16435 7ff7c6bbe128 LoadLibraryExW 16434->16435 16435->16430 16435->16434 16437 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16436->16437 16438 7ff7c6bbe6c2 __crtLCMapStringW 16437->16438 16438->16383 16440 7ff7c6bc0315 _Strcoll 16439->16440 16470 7ff7c6bc1ea0 16440->16470 16471 7ff7c6bc1ea9 MultiByteToWideChar 16470->16471 16473 7ff7c6ba27f0 16474 7ff7c6ba2846 __scrt_get_show_window_mode 16473->16474 16487 7ff7c6ba649c 16474->16487 16480 7ff7c6ba2fb7 16524 7ff7c6ba56f8 16480->16524 16482 7ff7c6ba2fca 16485 7ff7c6bafac0 _Strcoll 8 API calls 16482->16485 16483 7ff7c6ba2947 16483->16480 16514 7ff7c6ba7800 16483->16514 16486 7ff7c6ba2fee 16485->16486 16488 7ff7c6bafae8 std::_Facet_Register 41 API calls 16487->16488 16489 7ff7c6ba64eb 16488->16489 16527 7ff7c6baeae8 16489->16527 16493 7ff7c6ba28ef 16499 7ff7c6ba63a8 16493->16499 16494 7ff7c6ba6526 16494->16493 16495 7ff7c6ba2364 std::ios_base::failure::failure 41 API calls 16494->16495 16496 7ff7c6ba65c5 16495->16496 16497 7ff7c6bb1b00 Concurrency::cancel_current_task 2 API calls 16496->16497 16498 7ff7c6ba65d6 16497->16498 16500 7ff7c6bafae8 std::_Facet_Register 41 API calls 16499->16500 16501 7ff7c6ba641d 16500->16501 16502 7ff7c6baeae8 57 API calls 16501->16502 16503 7ff7c6ba642d 16502->16503 16793 7ff7c6ba6080 16503->16793 16506 7ff7c6ba62a8 16507 7ff7c6ba62c9 16506->16507 16513 7ff7c6ba6311 16506->16513 16805 7ff7c6baeeac 16507->16805 16510 7ff7c6ba6080 37 API calls 16511 7ff7c6ba62f3 16510->16511 16813 7ff7c6ba6920 16511->16813 16513->16483 16516 7ff7c6ba782e messages ctype 16514->16516 16515 7ff7c6ba79cc 16515->16480 16516->16515 16517 7ff7c6ba79f2 16516->16517 16519 7ff7c6ba79f7 16516->16519 16520 7ff7c6ba9350 std::ios_base::failure::failure 41 API calls 16516->16520 16523 7ff7c6bafae8 std::_Facet_Register 41 API calls 16516->16523 16518 7ff7c6ba1874 std::ios_base::failure::failure 41 API calls 16517->16518 16518->16519 16521 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16519->16521 16520->16516 16522 7ff7c6ba79fd 16521->16522 16523->16516 17219 7ff7c6ba5474 16524->17219 16526 7ff7c6ba5741 16526->16482 16563 7ff7c6bae524 16527->16563 16529 7ff7c6baeb0a 16531 7ff7c6baeb4e ctype 16529->16531 16567 7ff7c6baece0 16529->16567 16574 7ff7c6bae59c 16531->16574 16533 7ff7c6baeb22 16570 7ff7c6baed10 16533->16570 16534 7ff7c6ba64fb 16538 7ff7c6ba65d8 16534->16538 16537 7ff7c6bb689c _Yarn 13 API calls 16537->16531 16539 7ff7c6bae524 std::_Lockit::_Lockit 6 API calls 16538->16539 16540 7ff7c6ba6608 16539->16540 16607 7ff7c6ba1f6c 16540->16607 16542 7ff7c6ba666a 16543 7ff7c6bae59c std::_Lockit::~_Lockit LeaveCriticalSection 16542->16543 16544 7ff7c6ba66ae 16543->16544 16546 7ff7c6bafac0 _Strcoll 8 API calls 16544->16546 16545 7ff7c6ba6621 16545->16542 16615 7ff7c6ba2154 16545->16615 16547 7ff7c6ba66be 16546->16547 16547->16494 16550 7ff7c6ba6682 16625 7ff7c6baeaa8 16550->16625 16551 7ff7c6ba66d1 16628 7ff7c6ba1ddc 16551->16628 16555 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 16556 7ff7c6ba6714 16555->16556 16557 7ff7c6baeae8 57 API calls 16556->16557 16558 7ff7c6ba672c 16557->16558 16634 7ff7c6ba7014 16558->16634 16560 7ff7c6ba6739 16561 7ff7c6ba65d8 86 API calls 16560->16561 16562 7ff7c6ba6745 16561->16562 16562->16494 16564 7ff7c6bae533 16563->16564 16565 7ff7c6bae538 16563->16565 16578 7ff7c6bb7cf8 16564->16578 16565->16529 16568 7ff7c6bafae8 std::_Facet_Register 41 API calls 16567->16568 16569 7ff7c6baecf2 16568->16569 16569->16533 16571 7ff7c6baed22 16570->16571 16572 7ff7c6baeb2d 16570->16572 16602 7ff7c6baf6f4 16571->16602 16572->16531 16572->16537 16575 7ff7c6bae5a7 LeaveCriticalSection 16574->16575 16577 7ff7c6bae5b0 16574->16577 16577->16534 16581 7ff7c6bbe724 16578->16581 16582 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16581->16582 16583 7ff7c6bbe744 16582->16583 16584 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16583->16584 16585 7ff7c6bbe763 16584->16585 16586 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16585->16586 16587 7ff7c6bbe782 16586->16587 16588 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16587->16588 16589 7ff7c6bbe7a1 16588->16589 16590 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16589->16590 16591 7ff7c6bbe7c0 16590->16591 16592 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16591->16592 16593 7ff7c6bbe7df 16592->16593 16594 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16593->16594 16595 7ff7c6bbe7fe 16594->16595 16596 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16595->16596 16597 7ff7c6bbe81d 16596->16597 16598 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16597->16598 16599 7ff7c6bbe83c 16598->16599 16600 7ff7c6bbe03c __crtLCMapStringW 5 API calls 16599->16600 16601 7ff7c6bbe85b 16600->16601 16603 7ff7c6baf702 EncodePointer 16602->16603 16604 7ff7c6baf729 16602->16604 16603->16572 16605 7ff7c6bb8558 BuildCatchObjectHelperInternal 45 API calls 16604->16605 16606 7ff7c6baf72e 16605->16606 16608 7ff7c6ba1fba 16607->16608 16609 7ff7c6ba1f8a 16607->16609 16611 7ff7c6bafac0 _Strcoll 8 API calls 16608->16611 16610 7ff7c6bae524 std::_Lockit::_Lockit 6 API calls 16609->16610 16612 7ff7c6ba1f96 16610->16612 16613 7ff7c6ba1fca 16611->16613 16614 7ff7c6bae59c std::_Lockit::~_Lockit LeaveCriticalSection 16612->16614 16613->16545 16614->16608 16616 7ff7c6ba2171 16615->16616 16617 7ff7c6ba21e9 16615->16617 16616->16617 16618 7ff7c6bafae8 std::_Facet_Register 41 API calls 16616->16618 16617->16550 16617->16551 16619 7ff7c6ba2181 16618->16619 16654 7ff7c6ba1e64 16619->16654 16626 7ff7c6bafae8 std::_Facet_Register 41 API calls 16625->16626 16627 7ff7c6baeabb 16626->16627 16627->16542 16629 7ff7c6ba1dea std::bad_alloc::bad_alloc 16628->16629 16630 7ff7c6bb1b00 Concurrency::cancel_current_task 2 API calls 16629->16630 16631 7ff7c6ba1dfb 16630->16631 16632 7ff7c6bb183c __std_exception_copy 39 API calls 16631->16632 16633 7ff7c6ba1e25 16632->16633 16633->16555 16635 7ff7c6bae524 std::_Lockit::_Lockit 6 API calls 16634->16635 16636 7ff7c6ba7044 16635->16636 16637 7ff7c6ba1f6c 15 API calls 16636->16637 16640 7ff7c6ba705d 16637->16640 16638 7ff7c6ba70a6 16639 7ff7c6bae59c std::_Lockit::~_Lockit LeaveCriticalSection 16638->16639 16641 7ff7c6ba70ea 16639->16641 16640->16638 16757 7ff7c6ba72c4 16640->16757 16642 7ff7c6bafac0 _Strcoll 8 API calls 16641->16642 16644 7ff7c6ba70fa 16642->16644 16644->16560 16645 7ff7c6ba70b8 16646 7ff7c6ba70be 16645->16646 16647 7ff7c6ba710d 16645->16647 16649 7ff7c6baeaa8 std::_Facet_Register 41 API calls 16646->16649 16648 7ff7c6ba1ddc Concurrency::cancel_current_task 41 API calls 16647->16648 16651 7ff7c6ba7112 16648->16651 16649->16638 16650 7ff7c6ba714f messages 16650->16560 16651->16650 16652 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16651->16652 16653 7ff7c6ba7171 16652->16653 16653->16560 16655 7ff7c6bae524 std::_Lockit::_Lockit 6 API calls 16654->16655 16656 7ff7c6ba1e80 16655->16656 16657 7ff7c6ba1eb4 16656->16657 16658 7ff7c6ba1ece 16656->16658 16690 7ff7c6baec58 16657->16690 16697 7ff7c6bae920 16658->16697 16702 7ff7c6bb8008 16690->16702 16719 7ff7c6bae760 16697->16719 16700 7ff7c6bb1b00 Concurrency::cancel_current_task 2 API calls 16701 7ff7c6bae942 16700->16701 16703 7ff7c6bbe724 std::_Lockit::_Lockit 5 API calls 16702->16703 16704 7ff7c6bb801e 16703->16704 16711 7ff7c6bb7d2c 16704->16711 16718 7ff7c6bb7c88 EnterCriticalSection 16711->16718 16720 7ff7c6bb183c __std_exception_copy 39 API calls 16719->16720 16721 7ff7c6bae794 16720->16721 16721->16700 16758 7ff7c6ba7395 messages 16757->16758 16759 7ff7c6ba72ea 16757->16759 16758->16645 16759->16758 16760 7ff7c6bafae8 std::_Facet_Register 41 API calls 16759->16760 16761 7ff7c6ba72fe 16760->16761 16774 7ff7c6ba2014 16761->16774 16763 7ff7c6ba7313 16764 7ff7c6ba1e64 84 API calls 16763->16764 16765 7ff7c6ba7333 16764->16765 16781 7ff7c6baf180 16765->16781 16768 7ff7c6ba1edc std::_Locinfo::~_Locinfo 81 API calls 16769 7ff7c6ba7360 16768->16769 16769->16758 16770 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16769->16770 16771 7ff7c6ba73b9 16770->16771 16772 7ff7c6ba73cd 16771->16772 16773 7ff7c6ba5eec 37 API calls 16771->16773 16772->16645 16773->16772 16776 7ff7c6ba203b 16774->16776 16777 7ff7c6ba206e messages 16774->16777 16775 7ff7c6ba212b messages 16775->16763 16778 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 16776->16778 16777->16775 16779 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16777->16779 16778->16777 16780 7ff7c6ba214a 16779->16780 16788 7ff7c6bb7578 16781->16788 16784 7ff7c6bb75a8 _Strcoll 45 API calls 16785 7ff7c6baf195 16784->16785 16786 7ff7c6ba734b 16785->16786 16787 7ff7c6bb82b0 _Getcoll 37 API calls 16785->16787 16786->16768 16787->16786 16789 7ff7c6bbc4ec _Getctype 45 API calls 16788->16789 16790 7ff7c6bb7581 16789->16790 16791 7ff7c6bc06a0 _Getctype 45 API calls 16790->16791 16792 7ff7c6baf18e 16791->16792 16792->16784 16794 7ff7c6ba60fa 16793->16794 16797 7ff7c6ba611d 16793->16797 16799 7ff7c6bb617c 16794->16799 16796 7ff7c6bafac0 _Strcoll 8 API calls 16798 7ff7c6ba2930 16796->16798 16797->16796 16798->16506 16800 7ff7c6bb6185 16799->16800 16801 7ff7c6bb6195 16799->16801 16802 7ff7c6bb8408 _Strcoll 11 API calls 16800->16802 16801->16797 16803 7ff7c6bb618a 16802->16803 16804 7ff7c6bb74b0 _invalid_parameter_noinfo 37 API calls 16803->16804 16804->16801 16806 7ff7c6baeef2 16805->16806 16812 7ff7c6ba62d9 16806->16812 16830 7ff7c6bb8110 16806->16830 16810 7ff7c6baef40 16810->16812 16853 7ff7c6bb5df4 16810->16853 16812->16510 16812->16513 16814 7ff7c6bae524 std::_Lockit::_Lockit 6 API calls 16813->16814 16815 7ff7c6ba6950 16814->16815 16816 7ff7c6ba1f6c 15 API calls 16815->16816 16820 7ff7c6ba6969 16816->16820 16817 7ff7c6ba69b2 16818 7ff7c6bae59c std::_Lockit::~_Lockit LeaveCriticalSection 16817->16818 16819 7ff7c6ba69f6 16818->16819 16821 7ff7c6bafac0 _Strcoll 8 API calls 16819->16821 16820->16817 17211 7ff7c6ba73f0 16820->17211 16822 7ff7c6ba6a06 16821->16822 16822->16513 16825 7ff7c6ba69ca 16828 7ff7c6baeaa8 std::_Facet_Register 41 API calls 16825->16828 16826 7ff7c6ba6a19 16827 7ff7c6ba1ddc Concurrency::cancel_current_task 41 API calls 16826->16827 16829 7ff7c6ba6a1e 16827->16829 16828->16817 16831 7ff7c6bb8054 16830->16831 16832 7ff7c6bb8071 16831->16832 16835 7ff7c6bb809d 16831->16835 16833 7ff7c6bb8408 _Strcoll 11 API calls 16832->16833 16834 7ff7c6bb8076 16833->16834 16836 7ff7c6bb74b0 _invalid_parameter_noinfo 37 API calls 16834->16836 16837 7ff7c6bb80a2 16835->16837 16838 7ff7c6bb80af 16835->16838 16841 7ff7c6baef25 16836->16841 16839 7ff7c6bb8408 _Strcoll 11 API calls 16837->16839 16857 7ff7c6bbdb88 16838->16857 16839->16841 16841->16812 16849 7ff7c6bb7090 16841->16849 16850 7ff7c6bb70c0 16849->16850 17188 7ff7c6bb6d88 16850->17188 16852 7ff7c6bb70dc 16852->16810 16854 7ff7c6bb5e24 16853->16854 17200 7ff7c6bb5cd0 16854->17200 16856 7ff7c6bb5e3d 16856->16812 16870 7ff7c6bb7c88 EnterCriticalSection 16857->16870 17189 7ff7c6bb6df2 17188->17189 17190 7ff7c6bb6db2 17188->17190 17189->17190 17191 7ff7c6bb6dfe 17189->17191 17192 7ff7c6bb73e4 _invalid_parameter_noinfo_noreturn 37 API calls 17190->17192 17199 7ff7c6bb61c4 EnterCriticalSection 17191->17199 17194 7ff7c6bb6dd9 17192->17194 17194->16852 17201 7ff7c6bb5d19 17200->17201 17202 7ff7c6bb5ceb 17200->17202 17204 7ff7c6bb5d0b 17201->17204 17210 7ff7c6bb61c4 EnterCriticalSection 17201->17210 17203 7ff7c6bb73e4 _invalid_parameter_noinfo_noreturn 37 API calls 17202->17203 17203->17204 17204->16856 17212 7ff7c6ba69c4 17211->17212 17213 7ff7c6ba740d 17211->17213 17212->16825 17212->16826 17213->17212 17214 7ff7c6bafae8 std::_Facet_Register 41 API calls 17213->17214 17215 7ff7c6ba741d 17214->17215 17216 7ff7c6ba1e64 84 API calls 17215->17216 17217 7ff7c6ba7451 17216->17217 17218 7ff7c6ba1edc std::_Locinfo::~_Locinfo 81 API calls 17217->17218 17218->17212 17220 7ff7c6ba5491 17219->17220 17222 7ff7c6ba54ce messages 17220->17222 17223 7ff7c6ba6174 17220->17223 17222->16526 17224 7ff7c6ba6191 17223->17224 17230 7ff7c6ba61dc 17223->17230 17231 7ff7c6ba5fb8 17224->17231 17225 7ff7c6ba6080 37 API calls 17227 7ff7c6ba61f0 17225->17227 17227->17222 17229 7ff7c6bb5df4 74 API calls 17229->17230 17230->17225 17234 7ff7c6ba5fdb 17231->17234 17235 7ff7c6ba601e 17231->17235 17232 7ff7c6bafac0 _Strcoll 8 API calls 17233 7ff7c6ba6036 17232->17233 17233->17229 17234->17235 17237 7ff7c6bb654c 17234->17237 17235->17232 17238 7ff7c6bb657c 17237->17238 17241 7ff7c6bb629c 17238->17241 17240 7ff7c6bb659a 17240->17235 17242 7ff7c6bb62bc 17241->17242 17247 7ff7c6bb62e9 17241->17247 17243 7ff7c6bb62f1 17242->17243 17244 7ff7c6bb62c6 17242->17244 17242->17247 17248 7ff7c6bb61dc 17243->17248 17245 7ff7c6bb73e4 _invalid_parameter_noinfo_noreturn 37 API calls 17244->17245 17245->17247 17247->17240 17255 7ff7c6bb61c4 EnterCriticalSection 17248->17255 17279 7ff7c6bb9fe8 17282 7ff7c6bb9db4 17279->17282 17289 7ff7c6bb7c88 EnterCriticalSection 17282->17289 17413 7ff7c6ba1000 17414 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 17413->17414 17415 7ff7c6ba104d 17414->17415 17416 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 17415->17416 17417 7ff7c6ba1075 17416->17417 17418 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 17417->17418 17419 7ff7c6ba1098 17418->17419 17420 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 17419->17420 17421 7ff7c6ba10bc 17420->17421 17422 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 17421->17422 17423 7ff7c6ba10df 17422->17423 17424 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 17423->17424 17425 7ff7c6ba1102 17424->17425 17426 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 17425->17426 17427 7ff7c6ba1125 17426->17427 17428 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 17427->17428 17429 7ff7c6ba1148 17428->17429 17430 7ff7c6bafae8 std::_Facet_Register 41 API calls 17429->17430 17431 7ff7c6ba1161 17430->17431 17432 7ff7c6ba12dc 17431->17432 17433 7ff7c6ba1296 17431->17433 17434 7ff7c6bafae8 std::_Facet_Register 41 API calls 17431->17434 17444 7ff7c6ba6ce0 41 API calls std::ios_base::failure::failure 17431->17444 17473 7ff7c6ba26d4 17432->17473 17476 7ff7c6bafde0 17433->17476 17434->17431 17440 7ff7c6bafe25 17444->17431 17474 7ff7c6bae8d8 std::ios_base::failure::failure 41 API calls 17473->17474 17475 7ff7c6ba26e4 17474->17475 17477 7ff7c6bafdfa 17476->17477 17479 7ff7c6bafdf3 17476->17479 17480 7ff7c6bb97e8 17477->17480 17479->17440 17483 7ff7c6bb9424 17480->17483 17490 7ff7c6bb7c88 EnterCriticalSection 17483->17490 17632 7ff7c6bcad9c 17633 7ff7c6bcadb5 17632->17633 17634 7ff7c6bcadab 17632->17634 17636 7ff7c6bb7cdc LeaveCriticalSection 17634->17636 17697 7ff7c6bc7fc0 17700 7ff7c6bc300c 17697->17700 17701 7ff7c6bc305e 17700->17701 17702 7ff7c6bc3019 17700->17702 17706 7ff7c6bbc5c0 17702->17706 17707 7ff7c6bbc5d1 FlsGetValue 17706->17707 17708 7ff7c6bbc5ec FlsSetValue 17706->17708 17709 7ff7c6bbc5e6 17707->17709 17710 7ff7c6bbc5de 17707->17710 17708->17710 17711 7ff7c6bbc5f9 17708->17711 17709->17708 17712 7ff7c6bbc5e4 17710->17712 17713 7ff7c6bb8558 BuildCatchObjectHelperInternal 45 API calls 17710->17713 17714 7ff7c6bbdf10 _Strcoll 11 API calls 17711->17714 17726 7ff7c6bc2ce4 17712->17726 17715 7ff7c6bbc661 17713->17715 17716 7ff7c6bbc608 17714->17716 17717 7ff7c6bbc626 FlsSetValue 17716->17717 17718 7ff7c6bbc616 FlsSetValue 17716->17718 17719 7ff7c6bbc632 FlsSetValue 17717->17719 17720 7ff7c6bbc644 17717->17720 17721 7ff7c6bbc61f 17718->17721 17719->17721 17723 7ff7c6bbc29c _Strcoll 11 API calls 17720->17723 17722 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17721->17722 17722->17710 17724 7ff7c6bbc64c 17723->17724 17725 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17724->17725 17725->17712 17749 7ff7c6bc2f54 17726->17749 17731 7ff7c6bc2d36 17731->17701 17732 7ff7c6bc0778 _fread_nolock 12 API calls 17733 7ff7c6bc2d47 17732->17733 17734 7ff7c6bc2d4f 17733->17734 17736 7ff7c6bc2d5e 17733->17736 17735 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17734->17735 17735->17731 17736->17736 17767 7ff7c6bc3088 17736->17767 17739 7ff7c6bc2e5a 17740 7ff7c6bb8408 _Strcoll 11 API calls 17739->17740 17742 7ff7c6bc2e5f 17740->17742 17741 7ff7c6bc2eb5 17744 7ff7c6bc2f1c 17741->17744 17778 7ff7c6bc2814 17741->17778 17745 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17742->17745 17743 7ff7c6bc2e74 17743->17741 17746 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17743->17746 17748 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17744->17748 17745->17731 17746->17741 17748->17731 17750 7ff7c6bc2f77 17749->17750 17753 7ff7c6bc2f81 17750->17753 17793 7ff7c6bb7c88 EnterCriticalSection 17750->17793 17754 7ff7c6bc2d19 17753->17754 17756 7ff7c6bb8558 BuildCatchObjectHelperInternal 45 API calls 17753->17756 17760 7ff7c6bc29e4 17754->17760 17758 7ff7c6bc300b 17756->17758 17761 7ff7c6bb8440 TranslateName 45 API calls 17760->17761 17762 7ff7c6bc29f8 17761->17762 17763 7ff7c6bc2a16 17762->17763 17764 7ff7c6bc2a04 GetOEMCP 17762->17764 17765 7ff7c6bc2a2b 17763->17765 17766 7ff7c6bc2a1b GetACP 17763->17766 17764->17765 17765->17731 17765->17732 17766->17765 17768 7ff7c6bc29e4 47 API calls 17767->17768 17769 7ff7c6bc30b5 17768->17769 17770 7ff7c6bc320b 17769->17770 17772 7ff7c6bc30f2 IsValidCodePage 17769->17772 17777 7ff7c6bc310c __scrt_get_show_window_mode 17769->17777 17771 7ff7c6bafac0 _Strcoll 8 API calls 17770->17771 17773 7ff7c6bc2e51 17771->17773 17772->17770 17774 7ff7c6bc3103 17772->17774 17773->17739 17773->17743 17775 7ff7c6bc3132 GetCPInfo 17774->17775 17774->17777 17775->17770 17775->17777 17794 7ff7c6bc2afc 17777->17794 17805 7ff7c6bb7c88 EnterCriticalSection 17778->17805 17795 7ff7c6bc2b39 GetCPInfo 17794->17795 17796 7ff7c6bc2c2f 17794->17796 17795->17796 17797 7ff7c6bc2b4c 17795->17797 17798 7ff7c6bafac0 _Strcoll 8 API calls 17796->17798 17799 7ff7c6bc0144 std::_Locinfo::_Locinfo_ctor 48 API calls 17797->17799 17800 7ff7c6bc2cce 17798->17800 17801 7ff7c6bc2bc3 17799->17801 17800->17770 17802 7ff7c6bc0608 54 API calls 17801->17802 17803 7ff7c6bc2bf6 17802->17803 17804 7ff7c6bc0608 54 API calls 17803->17804 17804->17796 18889 7ff7c6ba4ab8 18890 7ff7c6ba4ad0 18889->18890 18891 7ff7c6ba4aea 18889->18891 18890->18891 18893 7ff7c6bb5c68 18890->18893 18894 7ff7c6bb5c76 18893->18894 18895 7ff7c6bb5c7d 18893->18895 18899 7ff7c6bb5aa0 18894->18899 18897 7ff7c6bb5c7b 18895->18897 18902 7ff7c6bb5a60 18895->18902 18897->18891 18909 7ff7c6bb597c 18899->18909 18917 7ff7c6bb61c4 EnterCriticalSection 18902->18917 18916 7ff7c6bb7c88 EnterCriticalSection 18909->18916 18052 7ff7c6bbc36c 18053 7ff7c6bbc371 18052->18053 18054 7ff7c6bbc386 18052->18054 18058 7ff7c6bbc38c 18053->18058 18059 7ff7c6bbc3d6 18058->18059 18060 7ff7c6bbc3ce 18058->18060 18061 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18059->18061 18062 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18060->18062 18063 7ff7c6bbc3e3 18061->18063 18062->18059 18064 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18063->18064 18065 7ff7c6bbc3f0 18064->18065 18066 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18065->18066 18067 7ff7c6bbc3fd 18066->18067 18068 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18067->18068 18069 7ff7c6bbc40a 18068->18069 18070 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18069->18070 18071 7ff7c6bbc417 18070->18071 18072 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18071->18072 18073 7ff7c6bbc424 18072->18073 18074 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18073->18074 18075 7ff7c6bbc431 18074->18075 18076 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18075->18076 18077 7ff7c6bbc441 18076->18077 18078 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18077->18078 18079 7ff7c6bbc451 18078->18079 18084 7ff7c6bbc23c 18079->18084 18098 7ff7c6bb7c88 EnterCriticalSection 18084->18098 18192 7ff7c6bb6120 18193 7ff7c6bb612b 18192->18193 18201 7ff7c6bbe8e8 18193->18201 18214 7ff7c6bb7c88 EnterCriticalSection 18201->18214 15485 7ff7c6bb8c31 15497 7ff7c6bb8984 15485->15497 15487 7ff7c6bb8c36 15488 7ff7c6bb8ca7 15487->15488 15489 7ff7c6bb8c5d GetModuleHandleW 15487->15489 15490 7ff7c6bb8b34 11 API calls 15488->15490 15489->15488 15495 7ff7c6bb8c6a 15489->15495 15491 7ff7c6bb8ce3 15490->15491 15492 7ff7c6bb8cea 15491->15492 15493 7ff7c6bb8d00 11 API calls 15491->15493 15494 7ff7c6bb8cfc 15493->15494 15495->15488 15496 7ff7c6bb8d58 GetModuleHandleExW GetProcAddress FreeLibrary 15495->15496 15496->15488 15502 7ff7c6bbc4ec GetLastError 15497->15502 15503 7ff7c6bbc510 FlsGetValue 15502->15503 15504 7ff7c6bbc52d FlsSetValue 15502->15504 15505 7ff7c6bbc527 15503->15505 15507 7ff7c6bbc51d SetLastError 15503->15507 15506 7ff7c6bbc53f 15504->15506 15504->15507 15505->15504 15533 7ff7c6bbdf10 15506->15533 15510 7ff7c6bb898d 15507->15510 15511 7ff7c6bbc5b9 15507->15511 15524 7ff7c6bb8558 15510->15524 15513 7ff7c6bb8558 BuildCatchObjectHelperInternal 38 API calls 15511->15513 15512 7ff7c6bbc54e 15514 7ff7c6bbc56c FlsSetValue 15512->15514 15515 7ff7c6bbc55c FlsSetValue 15512->15515 15518 7ff7c6bbc5be 15513->15518 15516 7ff7c6bbc58a 15514->15516 15517 7ff7c6bbc578 FlsSetValue 15514->15517 15519 7ff7c6bbc565 15515->15519 15546 7ff7c6bbc29c 15516->15546 15517->15519 15540 7ff7c6bbd8a8 15519->15540 15594 7ff7c6bc1bd4 15524->15594 15534 7ff7c6bbdf21 _Strcoll 15533->15534 15535 7ff7c6bbdf72 15534->15535 15536 7ff7c6bbdf56 HeapAlloc 15534->15536 15551 7ff7c6bb890c 15534->15551 15554 7ff7c6bb8408 15535->15554 15536->15534 15537 7ff7c6bbdf70 15536->15537 15537->15512 15541 7ff7c6bbd8de 15540->15541 15542 7ff7c6bbd8ad HeapFree 15540->15542 15541->15507 15542->15541 15543 7ff7c6bbd8c8 GetLastError 15542->15543 15544 7ff7c6bbd8d5 Concurrency::details::SchedulerProxy::DeleteThis 15543->15544 15545 7ff7c6bb8408 _Strcoll 9 API calls 15544->15545 15545->15541 15580 7ff7c6bbc174 15546->15580 15557 7ff7c6bb894c 15551->15557 15563 7ff7c6bbc664 GetLastError 15554->15563 15556 7ff7c6bb8411 15556->15537 15562 7ff7c6bb7c88 EnterCriticalSection 15557->15562 15564 7ff7c6bbc6a5 FlsSetValue 15563->15564 15568 7ff7c6bbc688 15563->15568 15565 7ff7c6bbc6b7 15564->15565 15569 7ff7c6bbc695 15564->15569 15567 7ff7c6bbdf10 _Strcoll 5 API calls 15565->15567 15566 7ff7c6bbc711 SetLastError 15566->15556 15570 7ff7c6bbc6c6 15567->15570 15568->15564 15568->15569 15569->15566 15571 7ff7c6bbc6e4 FlsSetValue 15570->15571 15572 7ff7c6bbc6d4 FlsSetValue 15570->15572 15573 7ff7c6bbc702 15571->15573 15574 7ff7c6bbc6f0 FlsSetValue 15571->15574 15575 7ff7c6bbc6dd 15572->15575 15576 7ff7c6bbc29c _Strcoll 5 API calls 15573->15576 15574->15575 15577 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 5 API calls 15575->15577 15578 7ff7c6bbc70a 15576->15578 15577->15569 15579 7ff7c6bbd8a8 Concurrency::details::SchedulerProxy::DeleteThis 5 API calls 15578->15579 15579->15566 15592 7ff7c6bb7c88 EnterCriticalSection 15580->15592 15628 7ff7c6bc1b8c 15594->15628 15633 7ff7c6bb7c88 EnterCriticalSection 15628->15633 19841 7ff7c6bbca44 19852 7ff7c6bb7c88 EnterCriticalSection 19841->19852 15698 7ff7c6baff4c 15719 7ff7c6bafc30 15698->15719 15701 7ff7c6bb0098 15945 7ff7c6bb07b4 IsProcessorFeaturePresent 15701->15945 15702 7ff7c6baff68 __scrt_acquire_startup_lock 15704 7ff7c6bb00a2 15702->15704 15709 7ff7c6baff86 __scrt_release_startup_lock 15702->15709 15705 7ff7c6bb07b4 7 API calls 15704->15705 15707 7ff7c6bb00ad BuildCatchObjectHelperInternal 15705->15707 15706 7ff7c6baffab 15708 7ff7c6bb0031 15725 7ff7c6bb08fc 15708->15725 15709->15706 15709->15708 15934 7ff7c6bb8dfc 15709->15934 15711 7ff7c6bb0036 15728 7ff7c6ba3518 GetUserNameA 15711->15728 15717 7ff7c6bb0059 15717->15707 15941 7ff7c6bafdb4 15717->15941 15720 7ff7c6bafc38 15719->15720 15721 7ff7c6bafc44 __scrt_dllmain_crt_thread_attach 15720->15721 15722 7ff7c6bafc4d 15721->15722 15723 7ff7c6bafc51 15721->15723 15722->15701 15722->15702 15723->15722 15952 7ff7c6bb1e10 15723->15952 15979 7ff7c6bc9c30 15725->15979 15729 7ff7c6ba357b 15728->15729 15932 7ff7c6ba3573 15728->15932 15981 7ff7c6ba5c10 15729->15981 15730 7ff7c6bafac0 _Strcoll 8 API calls 15731 7ff7c6ba4828 15730->15731 15939 7ff7c6bb0940 GetModuleHandleW 15731->15939 15737 7ff7c6ba35c8 15993 7ff7c6ba6c20 15737->15993 15739 7ff7c6ba362d 15740 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15739->15740 15741 7ff7c6ba3657 15740->15741 15742 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15741->15742 15743 7ff7c6ba3699 15742->15743 15744 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15743->15744 15745 7ff7c6ba36f5 15744->15745 15746 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15745->15746 15747 7ff7c6ba371b 15746->15747 15748 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15747->15748 15749 7ff7c6ba3757 15748->15749 15750 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15749->15750 15751 7ff7c6ba37b3 15750->15751 15752 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15751->15752 15753 7ff7c6ba37d9 15752->15753 15754 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15753->15754 15755 7ff7c6ba3818 15754->15755 15756 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15755->15756 15757 7ff7c6ba3874 15756->15757 15758 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15757->15758 15759 7ff7c6ba389a 15758->15759 15760 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15759->15760 15761 7ff7c6ba38d9 15760->15761 15762 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15761->15762 15763 7ff7c6ba3935 15762->15763 15764 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15763->15764 15765 7ff7c6ba395b 15764->15765 15766 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15765->15766 15767 7ff7c6ba39a6 15766->15767 15768 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15767->15768 15769 7ff7c6ba3a09 15768->15769 15770 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15769->15770 15771 7ff7c6ba3a34 15770->15771 15772 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15771->15772 15773 7ff7c6ba3a5f 15772->15773 15774 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15773->15774 15775 7ff7c6ba3a8d 15774->15775 15776 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15775->15776 15777 7ff7c6ba3ab3 15776->15777 15778 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15777->15778 15779 7ff7c6ba3b01 15778->15779 15780 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15779->15780 15781 7ff7c6ba3b5d 15780->15781 15782 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15781->15782 15783 7ff7c6ba3b83 15782->15783 15784 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15783->15784 15785 7ff7c6ba3bce 15784->15785 15786 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15785->15786 15787 7ff7c6ba3c2a 15786->15787 15788 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15787->15788 15789 7ff7c6ba3c50 15788->15789 15790 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15789->15790 15791 7ff7c6ba3c9b 15790->15791 15792 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15791->15792 15793 7ff7c6ba3cf7 15792->15793 15794 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15793->15794 15795 7ff7c6ba3d1d 15794->15795 15796 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15795->15796 15797 7ff7c6ba3d6b 15796->15797 15798 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15797->15798 15799 7ff7c6ba3dc7 15798->15799 15800 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15799->15800 15801 7ff7c6ba3ded 15800->15801 15802 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15801->15802 15803 7ff7c6ba3e3b 15802->15803 15804 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15803->15804 15805 7ff7c6ba3e97 15804->15805 15806 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15805->15806 15807 7ff7c6ba3ebd 15806->15807 15808 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15807->15808 15809 7ff7c6ba3f08 15808->15809 15810 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15809->15810 15811 7ff7c6ba3f6b 15810->15811 15812 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15811->15812 15813 7ff7c6ba3f96 15812->15813 15814 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15813->15814 15815 7ff7c6ba3fc1 15814->15815 15816 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15815->15816 15817 7ff7c6ba3fef 15816->15817 15818 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15817->15818 15819 7ff7c6ba4015 15818->15819 15820 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15819->15820 15821 7ff7c6ba4063 15820->15821 15822 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15821->15822 15823 7ff7c6ba40bf 15822->15823 15824 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15823->15824 15825 7ff7c6ba40e5 15824->15825 15826 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15825->15826 15827 7ff7c6ba4121 15826->15827 15828 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15827->15828 15829 7ff7c6ba417d 15828->15829 15830 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15829->15830 15831 7ff7c6ba41a3 15830->15831 15832 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15831->15832 15833 7ff7c6ba41df 15832->15833 15834 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15833->15834 15835 7ff7c6ba423b 15834->15835 15836 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15835->15836 15837 7ff7c6ba4261 15836->15837 15838 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15837->15838 15839 7ff7c6ba42a0 15838->15839 15840 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15839->15840 15841 7ff7c6ba42f6 15840->15841 15842 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15841->15842 15843 7ff7c6ba431a 15842->15843 15844 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15843->15844 15845 7ff7c6ba435e 15844->15845 15846 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15845->15846 15847 7ff7c6ba43b1 15846->15847 15848 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15847->15848 15849 7ff7c6ba43d4 15848->15849 15850 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15849->15850 15851 7ff7c6ba4415 15850->15851 15852 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15851->15852 15853 7ff7c6ba4478 15852->15853 15854 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15853->15854 15855 7ff7c6ba44a3 15854->15855 15856 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15855->15856 15857 7ff7c6ba44ce 15856->15857 16003 7ff7c6ba4860 15857->16003 15859 7ff7c6ba450c messages 15860 7ff7c6ba4849 15859->15860 15861 7ff7c6ba45f2 messages 15859->15861 16035 7ff7c6bb74d0 15860->16035 15867 7ff7c6ba4642 messages 15861->15867 16025 7ff7c6ba1848 15861->16025 15866 7ff7c6ba4671 15868 7ff7c6ba5b28 37 API calls 15866->15868 16020 7ff7c6ba5b28 15867->16020 15869 7ff7c6ba467d 15868->15869 15870 7ff7c6ba5b28 37 API calls 15869->15870 15871 7ff7c6ba4686 15870->15871 15872 7ff7c6ba5b28 37 API calls 15871->15872 15873 7ff7c6ba4692 15872->15873 15874 7ff7c6ba5b28 37 API calls 15873->15874 15875 7ff7c6ba469b 15874->15875 15876 7ff7c6ba5b28 37 API calls 15875->15876 15877 7ff7c6ba46a7 15876->15877 15878 7ff7c6ba5b28 37 API calls 15877->15878 15879 7ff7c6ba46b3 15878->15879 15880 7ff7c6ba5b28 37 API calls 15879->15880 15881 7ff7c6ba46bf 15880->15881 15882 7ff7c6ba5b28 37 API calls 15881->15882 15883 7ff7c6ba46cb 15882->15883 15884 7ff7c6ba5b28 37 API calls 15883->15884 15885 7ff7c6ba46d7 15884->15885 15886 7ff7c6ba5b28 37 API calls 15885->15886 15887 7ff7c6ba46e3 15886->15887 15888 7ff7c6ba5b28 37 API calls 15887->15888 15889 7ff7c6ba46ef 15888->15889 15890 7ff7c6ba5b28 37 API calls 15889->15890 15891 7ff7c6ba46fb 15890->15891 15892 7ff7c6ba5b28 37 API calls 15891->15892 15893 7ff7c6ba4707 15892->15893 15894 7ff7c6ba5b28 37 API calls 15893->15894 15895 7ff7c6ba4713 15894->15895 15896 7ff7c6ba5b28 37 API calls 15895->15896 15897 7ff7c6ba471f 15896->15897 15898 7ff7c6ba5b28 37 API calls 15897->15898 15899 7ff7c6ba472b 15898->15899 15900 7ff7c6ba5b28 37 API calls 15899->15900 15901 7ff7c6ba4737 15900->15901 15902 7ff7c6ba5b28 37 API calls 15901->15902 15903 7ff7c6ba4743 15902->15903 15904 7ff7c6ba5b28 37 API calls 15903->15904 15905 7ff7c6ba474f 15904->15905 15906 7ff7c6ba5b28 37 API calls 15905->15906 15907 7ff7c6ba475b 15906->15907 15908 7ff7c6ba5b28 37 API calls 15907->15908 15909 7ff7c6ba4767 15908->15909 15910 7ff7c6ba5b28 37 API calls 15909->15910 15911 7ff7c6ba4770 15910->15911 15912 7ff7c6ba5b28 37 API calls 15911->15912 15913 7ff7c6ba477c 15912->15913 15914 7ff7c6ba5b28 37 API calls 15913->15914 15915 7ff7c6ba4785 15914->15915 15916 7ff7c6ba5b28 37 API calls 15915->15916 15917 7ff7c6ba4791 15916->15917 15918 7ff7c6ba5b28 37 API calls 15917->15918 15919 7ff7c6ba479a 15918->15919 15920 7ff7c6ba5b28 37 API calls 15919->15920 15921 7ff7c6ba47a6 15920->15921 15922 7ff7c6ba5b28 37 API calls 15921->15922 15923 7ff7c6ba47af 15922->15923 15924 7ff7c6ba5b28 37 API calls 15923->15924 15925 7ff7c6ba47bb 15924->15925 15926 7ff7c6ba5b28 37 API calls 15925->15926 15927 7ff7c6ba47c7 15926->15927 15928 7ff7c6ba5b28 37 API calls 15927->15928 15933 7ff7c6ba47d3 15928->15933 15929 7ff7c6ba480b 16030 7ff7c6ba5eec 15929->16030 15930 7ff7c6ba47ef GetFileAttributesA 15930->15933 15932->15730 15933->15929 15933->15930 15935 7ff7c6bb8e34 15934->15935 15936 7ff7c6bb8e13 15934->15936 15937 7ff7c6bb8984 __GSHandlerCheck_EH 45 API calls 15935->15937 15936->15708 15938 7ff7c6bb8e39 15937->15938 15940 7ff7c6bb0951 15939->15940 15940->15717 15943 7ff7c6bafdc5 15941->15943 15942 7ff7c6bafdd5 15942->15706 15943->15942 15944 7ff7c6bb1e10 7 API calls 15943->15944 15944->15942 15946 7ff7c6bb07da __scrt_get_show_window_mode BuildCatchObjectHelperInternal 15945->15946 15947 7ff7c6bb07f9 RtlCaptureContext RtlLookupFunctionEntry 15946->15947 15948 7ff7c6bb0822 RtlVirtualUnwind 15947->15948 15949 7ff7c6bb085e __scrt_get_show_window_mode 15947->15949 15948->15949 15950 7ff7c6bb0890 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 15949->15950 15951 7ff7c6bb08de BuildCatchObjectHelperInternal 15950->15951 15951->15704 15953 7ff7c6bb1e22 15952->15953 15954 7ff7c6bb1e18 15952->15954 15953->15722 15958 7ff7c6bb1fe8 15954->15958 15959 7ff7c6bb1e1d 15958->15959 15960 7ff7c6bb1ff7 15958->15960 15962 7ff7c6bb5234 15959->15962 15966 7ff7c6bb5404 15960->15966 15963 7ff7c6bb525f 15962->15963 15964 7ff7c6bb5242 DeleteCriticalSection 15963->15964 15965 7ff7c6bb5263 15963->15965 15964->15963 15965->15953 15970 7ff7c6bb526c 15966->15970 15971 7ff7c6bb5356 TlsFree 15970->15971 15977 7ff7c6bb52b0 __vcrt_InitializeCriticalSectionEx 15970->15977 15972 7ff7c6bb52de LoadLibraryExW 15974 7ff7c6bb52ff GetLastError 15972->15974 15975 7ff7c6bb537d 15972->15975 15973 7ff7c6bb539d GetProcAddress 15973->15971 15974->15977 15975->15973 15976 7ff7c6bb5394 FreeLibrary 15975->15976 15976->15973 15977->15971 15977->15972 15977->15973 15978 7ff7c6bb5321 LoadLibraryExW 15977->15978 15978->15975 15978->15977 15980 7ff7c6bb0913 GetStartupInfoW 15979->15980 15980->15711 15982 7ff7c6ba5c2d 15981->15982 15982->15982 15983 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 15982->15983 15984 7ff7c6ba359d 15983->15984 15985 7ff7c6ba68c0 15984->15985 15986 7ff7c6ba68d3 15985->15986 15986->15986 15987 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 15986->15987 15988 7ff7c6ba35b3 15987->15988 15989 7ff7c6ba6204 15988->15989 15990 7ff7c6ba6253 15989->15990 15992 7ff7c6ba6229 ctype 15989->15992 16040 7ff7c6ba6ec8 15990->16040 15992->15737 15994 7ff7c6ba6cd8 15993->15994 15995 7ff7c6ba6c47 15993->15995 15996 7ff7c6ba1874 std::ios_base::failure::failure 41 API calls 15994->15996 15998 7ff7c6ba6c4d ctype 15995->15998 15999 7ff7c6ba6c70 15995->15999 16000 7ff7c6ba6ca8 15995->16000 15997 7ff7c6ba6cdd 15996->15997 15998->15739 16001 7ff7c6ba9350 std::ios_base::failure::failure 41 API calls 15999->16001 16002 7ff7c6bafae8 std::_Facet_Register 41 API calls 16000->16002 16001->15998 16002->15998 16004 7ff7c6ba48ac 16003->16004 16018 7ff7c6ba495e 16003->16018 16006 7ff7c6ba48bf 16004->16006 16007 7ff7c6ba4987 16004->16007 16005 7ff7c6bafac0 _Strcoll 8 API calls 16008 7ff7c6ba4972 16005->16008 16010 7ff7c6ba48df 16006->16010 16011 7ff7c6ba48d8 16006->16011 16015 7ff7c6ba48c8 16006->16015 16140 7ff7c6ba7778 16007->16140 16008->15859 16014 7ff7c6bafae8 std::_Facet_Register 41 API calls 16010->16014 16013 7ff7c6ba9350 std::ios_base::failure::failure 41 API calls 16011->16013 16013->16015 16014->16015 16016 7ff7c6ba494f 16015->16016 16121 7ff7c6ba6ce0 16015->16121 16131 7ff7c6ba7ff8 16016->16131 16018->16005 16021 7ff7c6ba5b3b 16020->16021 16022 7ff7c6ba5b5f messages 16020->16022 16021->16022 16023 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16021->16023 16022->15866 16024 7ff7c6ba5b82 16023->16024 16026 7ff7c6ba1864 16025->16026 16027 7ff7c6ba186c 16025->16027 16026->15867 16028 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16027->16028 16029 7ff7c6ba1871 16028->16029 16031 7ff7c6ba5f8b messages 16030->16031 16032 7ff7c6ba5f0a messages 16030->16032 16031->15932 16032->16031 16033 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16032->16033 16034 7ff7c6ba5fb6 16033->16034 16036 7ff7c6bb7348 _invalid_parameter_noinfo_noreturn 37 API calls 16035->16036 16037 7ff7c6bb74e9 16036->16037 16038 7ff7c6bb7500 _invalid_parameter_noinfo_noreturn 17 API calls 16037->16038 16039 7ff7c6bb74fe 16038->16039 16044 7ff7c6ba6f07 16040->16044 16051 7ff7c6ba700b 16040->16051 16041 7ff7c6ba6f2c 16052 7ff7c6ba9350 16041->16052 16044->16041 16046 7ff7c6ba6f63 16044->16046 16048 7ff7c6ba6f4f ctype 16044->16048 16064 7ff7c6bafae8 16046->16064 16049 7ff7c6ba6fc3 messages ctype 16048->16049 16050 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16048->16050 16049->15992 16050->16051 16073 7ff7c6ba1874 16051->16073 16053 7ff7c6ba9383 16052->16053 16054 7ff7c6ba935d 16052->16054 16076 7ff7c6ba17b0 16053->16076 16056 7ff7c6bafae8 std::_Facet_Register 41 API calls 16054->16056 16057 7ff7c6ba9365 16056->16057 16058 7ff7c6ba936d 16057->16058 16059 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16057->16059 16058->16048 16059->16053 16061 7ff7c6ba93f1 messages 16061->16048 16062 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16063 7ff7c6ba9412 16062->16063 16065 7ff7c6bafaf3 16064->16065 16066 7ff7c6bafb0c 16065->16066 16067 7ff7c6bb890c std::_Facet_Register 2 API calls 16065->16067 16068 7ff7c6bafb12 16065->16068 16066->16048 16067->16065 16071 7ff7c6bafb1d 16068->16071 16109 7ff7c6bae8b8 16068->16109 16070 7ff7c6ba17b0 Concurrency::cancel_current_task 41 API calls 16072 7ff7c6bafb23 16070->16072 16071->16070 16113 7ff7c6bae8d8 16073->16113 16077 7ff7c6ba17be std::bad_alloc::bad_alloc 16076->16077 16082 7ff7c6bb1b00 16077->16082 16079 7ff7c6ba17cf 16087 7ff7c6bb183c 16079->16087 16083 7ff7c6bb1b1f 16082->16083 16084 7ff7c6bb1b6a RaiseException 16083->16084 16085 7ff7c6bb1b48 RtlPcToFileHeader 16083->16085 16084->16079 16086 7ff7c6bb1b60 16085->16086 16086->16084 16088 7ff7c6bb185d 16087->16088 16092 7ff7c6ba17f9 16087->16092 16089 7ff7c6bb1892 16088->16089 16088->16092 16093 7ff7c6bbb5a0 16088->16093 16102 7ff7c6bb689c 16089->16102 16092->16061 16092->16062 16094 7ff7c6bbb5b7 16093->16094 16095 7ff7c6bbb5ad 16093->16095 16096 7ff7c6bb8408 _Strcoll 11 API calls 16094->16096 16095->16094 16098 7ff7c6bbb5d2 16095->16098 16101 7ff7c6bbb5be 16096->16101 16097 7ff7c6bb74b0 _invalid_parameter_noinfo 37 API calls 16099 7ff7c6bbb5ca 16097->16099 16098->16099 16100 7ff7c6bb8408 _Strcoll 11 API calls 16098->16100 16099->16089 16100->16101 16101->16097 16103 7ff7c6bbd8a8 16102->16103 16104 7ff7c6bbd8de 16103->16104 16105 7ff7c6bbd8ad HeapFree 16103->16105 16104->16092 16105->16104 16106 7ff7c6bbd8c8 GetLastError 16105->16106 16107 7ff7c6bbd8d5 Concurrency::details::SchedulerProxy::DeleteThis 16106->16107 16108 7ff7c6bb8408 _Strcoll 11 API calls 16107->16108 16108->16104 16110 7ff7c6bae8c6 std::bad_alloc::bad_alloc 16109->16110 16111 7ff7c6bb1b00 Concurrency::cancel_current_task 2 API calls 16110->16111 16112 7ff7c6bae8d7 16111->16112 16118 7ff7c6bae62c 16113->16118 16116 7ff7c6bb1b00 Concurrency::cancel_current_task 2 API calls 16117 7ff7c6bae8fa 16116->16117 16119 7ff7c6bb183c __std_exception_copy 39 API calls 16118->16119 16120 7ff7c6bae660 16119->16120 16120->16116 16122 7ff7c6ba6d91 16121->16122 16126 7ff7c6ba6d08 16121->16126 16123 7ff7c6ba1874 std::ios_base::failure::failure 41 API calls 16122->16123 16125 7ff7c6ba6d96 16123->16125 16124 7ff7c6ba6d0e ctype 16124->16015 16126->16124 16127 7ff7c6ba6d2f 16126->16127 16128 7ff7c6ba6d65 16126->16128 16129 7ff7c6ba9350 std::ios_base::failure::failure 41 API calls 16127->16129 16130 7ff7c6bafae8 std::_Facet_Register 41 API calls 16128->16130 16129->16124 16130->16124 16133 7ff7c6ba800b messages 16131->16133 16132 7ff7c6ba805a 16132->16018 16133->16132 16134 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16133->16134 16135 7ff7c6ba806a 16134->16135 16143 7ff7c6bae944 __uncaught_exceptions 16135->16143 16137 7ff7c6ba807a 16138 7ff7c6ba8086 16137->16138 16147 7ff7c6ba83e4 16137->16147 16138->16018 16141 7ff7c6bae8d8 std::ios_base::failure::failure 41 API calls 16140->16141 16142 7ff7c6ba7788 16141->16142 16143->16137 16144 7ff7c6bb1ba8 16143->16144 16154 7ff7c6bb1f50 16144->16154 16148 7ff7c6ba842d 16147->16148 16149 7ff7c6ba83fb 16147->16149 16148->16138 16149->16148 16163 7ff7c6ba2364 16149->16163 16152 7ff7c6bb1b00 Concurrency::cancel_current_task 2 API calls 16153 7ff7c6ba8484 16152->16153 16155 7ff7c6bb1bb1 16154->16155 16156 7ff7c6bb1f67 GetLastError 16154->16156 16155->16137 16159 7ff7c6bb544c 16156->16159 16160 7ff7c6bb526c __vcrt_InitializeCriticalSectionEx 5 API calls 16159->16160 16161 7ff7c6bb5473 TlsGetValue 16160->16161 16166 7ff7c6ba1bc8 16163->16166 16165 7ff7c6ba2384 16165->16152 16167 7ff7c6ba1bf5 16166->16167 16167->16167 16168 7ff7c6ba6c20 std::ios_base::failure::failure 41 API calls 16167->16168 16169 7ff7c6ba1c0c 16168->16169 16177 7ff7c6ba1ac0 16169->16177 16171 7ff7c6ba1c5d messages 16171->16165 16172 7ff7c6ba1c28 16172->16171 16173 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16172->16173 16174 7ff7c6ba1c7f 16173->16174 16175 7ff7c6bb183c __std_exception_copy 39 API calls 16174->16175 16176 7ff7c6ba1cad 16175->16176 16176->16165 16178 7ff7c6ba1af4 16177->16178 16179 7ff7c6ba6ce0 std::ios_base::failure::failure 41 API calls 16178->16179 16180 7ff7c6ba1b03 16179->16180 16190 7ff7c6ba19ac 16180->16190 16182 7ff7c6ba1b1c 16213 7ff7c6ba1888 16182->16213 16185 7ff7c6ba1b59 messages 16185->16172 16186 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16187 7ff7c6ba1b80 16186->16187 16219 7ff7c6bb18cc 16187->16219 16189 7ff7c6ba1ba6 messages 16189->16172 16191 7ff7c6ba19e6 16190->16191 16192 7ff7c6ba19fb 16190->16192 16193 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 16191->16193 16194 7ff7c6ba6204 std::ios_base::failure::failure 41 API calls 16192->16194 16193->16192 16195 7ff7c6ba1a30 16194->16195 16196 7ff7c6ba1a64 messages 16195->16196 16199 7ff7c6ba1ab7 16195->16199 16197 7ff7c6bafac0 _Strcoll 8 API calls 16196->16197 16198 7ff7c6ba1aaf 16197->16198 16198->16182 16200 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16199->16200 16201 7ff7c6ba1abc 16200->16201 16202 7ff7c6ba6ce0 std::ios_base::failure::failure 41 API calls 16201->16202 16203 7ff7c6ba1b03 16202->16203 16204 7ff7c6ba19ac std::ios_base::failure::failure 41 API calls 16203->16204 16205 7ff7c6ba1b1c 16204->16205 16206 7ff7c6ba1888 std::ios_base::failure::failure 39 API calls 16205->16206 16208 7ff7c6ba1b27 16206->16208 16207 7ff7c6ba1b59 messages 16207->16182 16208->16207 16209 7ff7c6bb74d0 _invalid_parameter_noinfo_noreturn 37 API calls 16208->16209 16210 7ff7c6ba1b80 16209->16210 16211 7ff7c6bb18cc __std_exception_destroy 13 API calls 16210->16211 16212 7ff7c6ba1ba6 messages 16211->16212 16212->16182 16214 7ff7c6ba18aa 16213->16214 16215 7ff7c6bb183c __std_exception_copy 39 API calls 16214->16215 16216 7ff7c6ba18d5 16215->16216 16217 7ff7c6bafac0 _Strcoll 8 API calls 16216->16217 16218 7ff7c6ba18ef 16217->16218 16218->16185 16218->16186 16220 7ff7c6bb18e3 16219->16220 16221 7ff7c6bb18db 16219->16221 16220->16189 16222 7ff7c6bb689c _Yarn 13 API calls 16221->16222 16222->16220

Executed Functions

Control-flow Graph

  • Executed
  • Not Executed
control_flow_graph 0 7ff7c6ba3518-7ff7c6ba3571 GetUserNameA 1 7ff7c6ba3573-7ff7c6ba3576 0->1 2 7ff7c6ba357b-7ff7c6ba3638 call 7ff7c6ba4850 call 7ff7c6ba5c10 call 7ff7c6ba68c0 call 7ff7c6ba6204 call 7ff7c6ba6c20 0->2 3 7ff7c6ba4819-7ff7c6ba4848 call 7ff7c6bafac0 1->3 16 7ff7c6ba363b-7ff7c6ba3642 2->16 16->16 17 7ff7c6ba3644-7ff7c6ba36fc call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 16->17 24 7ff7c6ba36ff-7ff7c6ba3706 17->24 24->24 25 7ff7c6ba3708-7ff7c6ba37ba call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 24->25 32 7ff7c6ba37bd-7ff7c6ba37c4 25->32 32->32 33 7ff7c6ba37c6-7ff7c6ba387b call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 32->33 40 7ff7c6ba387e-7ff7c6ba3885 33->40 40->40 41 7ff7c6ba3887-7ff7c6ba393c call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 40->41 48 7ff7c6ba393f-7ff7c6ba3946 41->48 48->48 49 7ff7c6ba3948-7ff7c6ba3a94 call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 * 4 48->49 62 7ff7c6ba3a97-7ff7c6ba3a9e 49->62 62->62 63 7ff7c6ba3aa0-7ff7c6ba3b64 call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 62->63 70 7ff7c6ba3b67-7ff7c6ba3b6e 63->70 70->70 71 7ff7c6ba3b70-7ff7c6ba3c31 call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 70->71 78 7ff7c6ba3c34-7ff7c6ba3c3b 71->78 78->78 79 7ff7c6ba3c3d-7ff7c6ba3cfe call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 78->79 86 7ff7c6ba3d01-7ff7c6ba3d08 79->86 86->86 87 7ff7c6ba3d0a-7ff7c6ba3dce call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 86->87 94 7ff7c6ba3dd1-7ff7c6ba3dd8 87->94 94->94 95 7ff7c6ba3dda-7ff7c6ba3e9e call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 94->95 102 7ff7c6ba3ea1-7ff7c6ba3ea8 95->102 102->102 103 7ff7c6ba3eaa-7ff7c6ba3ff6 call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 * 4 102->103 116 7ff7c6ba3ff9-7ff7c6ba4000 103->116 116->116 117 7ff7c6ba4002-7ff7c6ba40c6 call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 116->117 124 7ff7c6ba40c9-7ff7c6ba40d0 117->124 124->124 125 7ff7c6ba40d2-7ff7c6ba4184 call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 124->125 132 7ff7c6ba4187-7ff7c6ba418e 125->132 132->132 133 7ff7c6ba4190-7ff7c6ba4242 call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 132->133 140 7ff7c6ba4245-7ff7c6ba424c 133->140 140->140 141 7ff7c6ba424e-7ff7c6ba42fd call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 140->141 148 7ff7c6ba4300-7ff7c6ba4307 141->148 148->148 149 7ff7c6ba4309-7ff7c6ba43b1 call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 148->149 156 7ff7c6ba43b8-7ff7c6ba43bf 149->156 156->156 157 7ff7c6ba43c1-7ff7c6ba4535 call 7ff7c6ba6204 * 2 call 7ff7c6ba6c20 * 3 call 7ff7c6ba4860 call 7ff7c6bafb24 156->157 172 7ff7c6ba4565-7ff7c6ba457f 157->172 173 7ff7c6ba4537-7ff7c6ba4545 157->173 174 7ff7c6ba4581-7ff7c6ba458e 172->174 175 7ff7c6ba45b6-7ff7c6ba45c7 172->175 176 7ff7c6ba4560 call 7ff7c6bafae0 173->176 177 7ff7c6ba4547-7ff7c6ba455a 173->177 180 7ff7c6ba4590-7ff7c6ba45a3 174->180 181 7ff7c6ba45a9-7ff7c6ba45ae call 7ff7c6bafae0 174->181 182 7ff7c6ba45ff-7ff7c6ba4612 175->182 183 7ff7c6ba45c9-7ff7c6ba45d7 175->183 176->172 177->176 178 7ff7c6ba4849-7ff7c6ba484f call 7ff7c6bb74d0 177->178 180->178 180->181 181->175 188 7ff7c6ba4614-7ff7c6ba462d 182->188 189 7ff7c6ba465d-7ff7c6ba47e1 call 7ff7c6ba5b28 * 32 182->189 186 7ff7c6ba45f2-7ff7c6ba45f7 call 7ff7c6bafae0 183->186 187 7ff7c6ba45d9-7ff7c6ba45ec 183->187 186->182 187->178 187->186 190 7ff7c6ba4650-7ff7c6ba4655 call 7ff7c6bafae0 188->190 191 7ff7c6ba462f-7ff7c6ba4649 call 7ff7c6ba1848 188->191 264 7ff7c6ba4806-7ff7c6ba4809 189->264 190->189 191->190 265 7ff7c6ba47e3-7ff7c6ba47ea 264->265 266 7ff7c6ba480b-7ff7c6ba4817 call 7ff7c6ba5eec 264->266 267 7ff7c6ba47ef-7ff7c6ba47f8 GetFileAttributesA 265->267 268 7ff7c6ba47ec 265->268 266->3 271 7ff7c6ba4802 267->271 272 7ff7c6ba47fa-7ff7c6ba47fd call 7ff7c6ba31c4 267->272 268->267 271->264 272->271
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: NameUser
  • String ID: .php$C:\Users\$C:\inetpub$C:\wamp64$C:\xampp$D:\Users\$D:\inetpub$D:\wamp64$D:\xampp$E:\Users\$E:\inetpub$E:\wamp64$E:\xampp$\Desktop$\Documents$\Downloads$\Music$\Pictures$\Videos
  • API String ID: 2645101109-2252226799
  • Opcode ID: 28ff0a4ffb8e6d361176906c899271f9ba3979d0f3f6f7c5e929975fe70ae57a
  • Instruction ID: 9bb574cb26899dbbf1ba4d3eac946d9d8dd2e275140f0163abf9f317260f365e
  • Opcode Fuzzy Hash: 28ff0a4ffb8e6d361176906c899271f9ba3979d0f3f6f7c5e929975fe70ae57a
  • Instruction Fuzzy Hash: 2EC2A053D18BC594E722DF348C812E9A760FBA9798F959321EB8C16A57EF24E3D0C350

Control-flow Graph

APIs
  • FreeLibrary.KERNEL32(?,?,?,00007FF7C6BBE744,?,?,?,?,00007FF7C6BB7D01,?,?,?,?,00007FF7C6BAE538), ref: 00007FF7C6BBE1B8
  • GetProcAddress.KERNEL32(?,?,?,00007FF7C6BBE744,?,?,?,?,00007FF7C6BB7D01,?,?,?,?,00007FF7C6BAE538), ref: 00007FF7C6BBE1C4
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: AddressFreeLibraryProc
  • String ID: api-ms-$ext-ms-
  • API String ID: 3013587201-537541572
  • Opcode ID: 933019dcc0fbd5848821acf18b732c32933b14a96845b994dc779ebab6b2dcf8
  • Instruction ID: 0134b8bfeb816d799959500482ce8c3ae52675ea2bd8a84f5597ba85d426ca1c
  • Opcode Fuzzy Hash: 933019dcc0fbd5848821acf18b732c32933b14a96845b994dc779ebab6b2dcf8
  • Instruction Fuzzy Hash: CC41D031B19A1291EA17EF169C80267A395BF85BF0FE84535ED0D47794DE3CE4028324

Control-flow Graph

APIs
    • Part of subcall function 00007FF7C6BAFC30: __scrt_dllmain_crt_thread_attach.LIBCMT ref: 00007FF7C6BAFC44
  • __scrt_acquire_startup_lock.LIBCMT ref: 00007FF7C6BAFF70
  • __scrt_release_startup_lock.LIBCMT ref: 00007FF7C6BAFFDE
  • __scrt_get_show_window_mode.LIBCMT ref: 00007FF7C6BB0031
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_release_startup_lock
  • String ID:
  • API String ID: 3251591375-0
  • Opcode ID: 5324d965c8c309e2eddf3ebd36c367fcd01fae4ccd6c01d1cdfdc9b7472d90f4
  • Instruction ID: 62bfb87415aa1cf024f18a1d5ab6857389a9d1b81a8a787a93cb00b4c9d0453e
  • Opcode Fuzzy Hash: 5324d965c8c309e2eddf3ebd36c367fcd01fae4ccd6c01d1cdfdc9b7472d90f4
  • Instruction Fuzzy Hash: CF312911E0824742FA27BF259CE12BBE3919F853A4FE44035ED4D4B2D3DE2DE5448238

Control-flow Graph

APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Process$CurrentExitTerminate
  • String ID:
  • API String ID: 1703294689-0
  • Opcode ID: 64f5a314acf0d0577079106ac6116e740043fcc94654ce8b7ae2396de8d76da9
  • Instruction ID: e1a60400ba929e39e511f4f39752871e2bc82362a06642e9bbcc2495884c8025
  • Opcode Fuzzy Hash: 64f5a314acf0d0577079106ac6116e740043fcc94654ce8b7ae2396de8d76da9
  • Instruction Fuzzy Hash: 90D01710B0860A52EA463F30ACC817E82162FA8721BA0183EC81E06393CD3CA4084220

Control-flow Graph

APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: HandleModule$AddressFreeLibraryProc
  • String ID:
  • API String ID: 3947729631-0
  • Opcode ID: bec4e057efd22ef7971475711ccf8f05bef3624c47bc1f8d12fe4a0cda5783cd
  • Instruction ID: 54b13d3a56bb3b7e4f3ce77281613118fc4840daaece7e0e7354b281b7be05f9
  • Opcode Fuzzy Hash: bec4e057efd22ef7971475711ccf8f05bef3624c47bc1f8d12fe4a0cda5783cd
  • Instruction Fuzzy Hash: 1B21A172A15745CAEB26AF74C8802FD73A0FB84328FA4063ADB5D06AC9DF38D544C754

Non-executed Functions

Control-flow Graph

  • Executed
  • Not Executed
control_flow_graph 435 7ff7c6ba1000-7ff7c6ba1180 call 7ff7c6ba6c20 * 8 call 7ff7c6bafae8 454 7ff7c6ba1187-7ff7c6ba11ad call 7ff7c6ba8f50 435->454 457 7ff7c6ba1281-7ff7c6ba1290 454->457 458 7ff7c6ba11b3-7ff7c6ba11c4 454->458 457->454 461 7ff7c6ba1296-7ff7c6ba12d7 call 7ff7c6bafb24 457->461 459 7ff7c6ba11ca-7ff7c6ba120e call 7ff7c6bafae8 458->459 460 7ff7c6ba12dc-7ff7c6ba14f2 call 7ff7c6ba26d4 call 7ff7c6baeae8 call 7ff7c6ba7014 call 7ff7c6ba65d8 call 7ff7c6ba6a20 call 7ff7c6ba66d8 call 7ff7c6baeae8 call 7ff7c6ba7014 call 7ff7c6ba65d8 call 7ff7c6ba6a20 call 7ff7c6ba66d8 call 7ff7c6baeae8 call 7ff7c6ba7014 call 7ff7c6ba65d8 call 7ff7c6ba6a20 call 7ff7c6ba66d8 call 7ff7c6baeae8 call 7ff7c6ba7014 call 7ff7c6ba65d8 call 7ff7c6ba6a20 call 7ff7c6ba66d8 call 7ff7c6ba5834 call 7ff7c6bafb24 458->460 469 7ff7c6ba1210 459->469 470 7ff7c6ba1213-7ff7c6ba123f call 7ff7c6ba6ce0 459->470 524 7ff7c6ba1520-7ff7c6ba152d 460->524 525 7ff7c6ba14f4-7ff7c6ba14fd 460->525 468 7ff7c6bafe1c-7ff7c6bafe32 call 7ff7c6bafde0 461->468 469->470 479 7ff7c6ba1241 470->479 480 7ff7c6ba1244-7ff7c6ba127c call 7ff7c6ba6ce0 call 7ff7c6ba7488 470->480 479->480 480->457 527 7ff7c6ba152f-7ff7c6ba1538 524->527 528 7ff7c6ba154a-7ff7c6ba1552 524->528 525->524 526 7ff7c6ba14ff-7ff7c6ba1504 525->526 529 7ff7c6ba151b-7ff7c6ba151e 526->529 527->528 537 7ff7c6ba153a-7ff7c6ba1549 527->537 530 7ff7c6ba1580-7ff7c6ba158d 528->530 531 7ff7c6ba1554-7ff7c6ba155d 528->531 529->524 534 7ff7c6ba1506-7ff7c6ba1516 529->534 532 7ff7c6ba158f-7ff7c6ba1598 530->532 533 7ff7c6ba15aa-7ff7c6ba15b2 530->533 531->530 536 7ff7c6ba155f-7ff7c6ba1564 531->536 532->533 546 7ff7c6ba159a-7ff7c6ba15a9 532->546 538 7ff7c6ba15e0-7ff7c6ba15ec 533->538 539 7ff7c6ba15b4-7ff7c6ba15bd 533->539 534->529 540 7ff7c6ba157b-7ff7c6ba157e 536->540 537->528 541 7ff7c6ba1609-7ff7c6ba1610 538->541 542 7ff7c6ba15ee-7ff7c6ba15f7 538->542 539->538 545 7ff7c6ba15bf-7ff7c6ba15c4 539->545 540->530 543 7ff7c6ba1566-7ff7c6ba1576 540->543 547 7ff7c6ba1612-7ff7c6ba161b 541->547 548 7ff7c6ba163d-7ff7c6ba1648 541->548 542->541 556 7ff7c6ba15f9-7ff7c6ba1608 542->556 543->540 550 7ff7c6ba15db-7ff7c6ba15de 545->550 546->533 547->548 552 7ff7c6ba161d-7ff7c6ba1621 547->552 553 7ff7c6ba1661-7ff7c6ba167f 548->553 554 7ff7c6ba164a-7ff7c6ba1653 548->554 550->538 555 7ff7c6ba15c6-7ff7c6ba15d6 550->555 558 7ff7c6ba1638-7ff7c6ba163b 552->558 553->468 554->553 561 7ff7c6ba1655-7ff7c6ba165b 554->561 555->550 556->541 558->548 559 7ff7c6ba1623-7ff7c6ba1633 558->559 559->558 561->553
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Concurrency::cancel_current_task
  • String ID: 0x1a2f21755df3849f307e874cafabbe94c4026b90$1N75DmxTsCut3SV23Mp4QV6qt1kKbmNiwH$LPfod1Raka3rYAjG6tYsPRf1UGjfe3yXUz$TXddtHfr8STtmDEDxcrzanC8htLQZtbTgX$\b(?:[13][a-km-zA-HJ-NP-Z1-9]{25,34}|bc1[a-zA-HJ-NP-Z0-9]{39,59})\b$\b(?:[LM3][a-km-zA-HJ-NP-Z1-9]{26,33})\b$\b0x[a-fA-F0-9]{40}\b$\bT[a-zA-Z0-9]{33}\b|\bT[a-zA-Z0-9]{34}\b$btc$eth$ltc$trx
  • API String ID: 118556049-2374793347
  • Opcode ID: f92cce702970a9531a72e72ed2e898de2691a48bbf204ab308b3a587b26451bf
  • Instruction ID: aa43b8f7712b2b6c78ccf77d226ba5f4c77cfe7e82aba0ca6196908984c72629
  • Opcode Fuzzy Hash: f92cce702970a9531a72e72ed2e898de2691a48bbf204ab308b3a587b26451bf
  • Instruction Fuzzy Hash: 7A12B332A15B4695EB12EF24D8802EEB3B0FB84764FA44236EB4D17666EF3CD545C350

Control-flow Graph

  • Executed
  • Not Executed
control_flow_graph 584 7ff7c6bc75b8-7ff7c6bc762b call 7ff7c6bc719c 587 7ff7c6bc7645-7ff7c6bc764f call 7ff7c6bc39cc 584->587 588 7ff7c6bc762d-7ff7c6bc7636 call 7ff7c6bb83e8 584->588 594 7ff7c6bc7651-7ff7c6bc7668 call 7ff7c6bb83e8 call 7ff7c6bb8408 587->594 595 7ff7c6bc766a-7ff7c6bc76d3 CreateFileW 587->595 593 7ff7c6bc7639-7ff7c6bc7640 call 7ff7c6bb8408 588->593 611 7ff7c6bc7986-7ff7c6bc79a6 593->611 594->593 596 7ff7c6bc7750-7ff7c6bc775b GetFileType 595->596 597 7ff7c6bc76d5-7ff7c6bc76db 595->597 603 7ff7c6bc77ae-7ff7c6bc77b5 596->603 604 7ff7c6bc775d-7ff7c6bc7798 GetLastError call 7ff7c6bb837c CloseHandle 596->604 600 7ff7c6bc771d-7ff7c6bc774b GetLastError call 7ff7c6bb837c 597->600 601 7ff7c6bc76dd-7ff7c6bc76e1 597->601 600->593 601->600 609 7ff7c6bc76e3-7ff7c6bc771b CreateFileW 601->609 607 7ff7c6bc77b7-7ff7c6bc77bb 603->607 608 7ff7c6bc77bd-7ff7c6bc77c0 603->608 604->593 619 7ff7c6bc779e-7ff7c6bc77a9 call 7ff7c6bb8408 604->619 614 7ff7c6bc77c6-7ff7c6bc781b call 7ff7c6bc38e4 607->614 608->614 615 7ff7c6bc77c2 608->615 609->596 609->600 622 7ff7c6bc783a-7ff7c6bc786b call 7ff7c6bc6f1c 614->622 623 7ff7c6bc781d-7ff7c6bc7829 call 7ff7c6bc73a4 614->623 615->614 619->593 629 7ff7c6bc7871-7ff7c6bc78b3 622->629 630 7ff7c6bc786d-7ff7c6bc786f 622->630 623->622 631 7ff7c6bc782b 623->631 633 7ff7c6bc78d5-7ff7c6bc78e0 629->633 634 7ff7c6bc78b5-7ff7c6bc78b9 629->634 632 7ff7c6bc782d-7ff7c6bc7835 call 7ff7c6bbda20 630->632 631->632 632->611 636 7ff7c6bc78e6-7ff7c6bc78ea 633->636 637 7ff7c6bc7984 633->637 634->633 635 7ff7c6bc78bb-7ff7c6bc78d0 634->635 635->633 636->637 639 7ff7c6bc78f0-7ff7c6bc7935 CloseHandle CreateFileW 636->639 637->611 641 7ff7c6bc796a-7ff7c6bc797f 639->641 642 7ff7c6bc7937-7ff7c6bc7965 GetLastError call 7ff7c6bb837c call 7ff7c6bc3b0c 639->642 641->637 642->641
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
  • String ID:
  • API String ID: 1617910340-0
  • Opcode ID: 98dbda4ce531ff64c2c3eb78b33b6cc2ef0d19486f2d80594ea85e9c8d2e1f12
  • Instruction ID: 15a592ac43e7108e44da0ac950fb2affdd189f8253c23df32519b4da0f7bdcc1
  • Opcode Fuzzy Hash: 98dbda4ce531ff64c2c3eb78b33b6cc2ef0d19486f2d80594ea85e9c8d2e1f12
  • Instruction Fuzzy Hash: 22C1E536B24A4196EB11DF69C8D06AE7761FB48BA8BA00235DF1E573D5DF38D112C310
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorLastNameTranslate$CodeInfoLocalePageValidValue
  • String ID: utf8
  • API String ID: 3069159798-905460609
  • Opcode ID: 2a17088055c9c1c9c2355bdc920a44067c63e7d7da4458fbaba91a42e976d9e2
  • Instruction ID: 87a4cb1a684fdad36f94e1bf75a179fc25fa9ce1be920d0157c399742d753d2c
  • Opcode Fuzzy Hash: 2a17088055c9c1c9c2355bdc920a44067c63e7d7da4458fbaba91a42e976d9e2
  • Instruction Fuzzy Hash: 67917332A0874295EB26BF11DD816BAA794EB84BA0FA44131DA4D47796DF3CE661C320
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Value$Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
  • String ID:
  • API String ID: 2591520935-0
  • Opcode ID: 2a0b70611619fbe5e4cb92711768d18b31f9a17638e2f1b651d57f2b08e46b06
  • Instruction ID: 0ed457bcf740a200ea64b44fdb3b3eb27486a4a230befa79503803fb76c86167
  • Opcode Fuzzy Hash: 2a0b70611619fbe5e4cb92711768d18b31f9a17638e2f1b651d57f2b08e46b06
  • Instruction Fuzzy Hash: DC718322B04613A5FB22AF64DC90ABEB7A4BF84764FA44035CE0D47695EF3CE645C360
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
  • String ID:
  • API String ID: 3140674995-0
  • Opcode ID: 808b0641316214cb5e09ba379ea4ac13f852f3c4882ef47f01b1c8580cfb5d14
  • Instruction ID: 0e796150df8374b05d5ade3c7dc152e8ebc940fd16cd3de8848961a0d0c3929d
  • Opcode Fuzzy Hash: 808b0641316214cb5e09ba379ea4ac13f852f3c4882ef47f01b1c8580cfb5d14
  • Instruction Fuzzy Hash: 40311072709B8195EB61AF60EC803EEB364FB84754F94403ADA4E47B94DF38D648C714
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: _invalid_parameter_noinfo_noreturn
  • String ID:
  • API String ID: 3668304517-0
  • Opcode ID: 8a902b7be431d02df3ba500bd66ce96bf1eeeab9e6532306908a5ac2762c6ab3
  • Instruction ID: 125436d61830962d49fdb766ae0e984d0a0aba54c3c6d3381bdd848f9d1a385d
  • Opcode Fuzzy Hash: 8a902b7be431d02df3ba500bd66ce96bf1eeeab9e6532306908a5ac2762c6ab3
  • Instruction Fuzzy Hash: 07B19362F04B4689EB02EFB5C8802EE7376AB45BA8F605631DE5D177DADE38D142C350
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
  • String ID:
  • API String ID: 1239891234-0
  • Opcode ID: f9dc588e434046a8e6ad214f4f0423ac09d416a39b87351110955c191f75c733
  • Instruction ID: 8a06056586d55bfbf70db1633e4a3a2fffb1a8c9fd31bac8cbdcde28167ae26e
  • Opcode Fuzzy Hash: f9dc588e434046a8e6ad214f4f0423ac09d416a39b87351110955c191f75c733
  • Instruction Fuzzy Hash: 8F316136618B8196D761DF25EC802AEB3A4FB84764FA40135EE9D43B55DF38D145CB10
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: FileFindFirst_invalid_parameter_noinfo
  • String ID:
  • API String ID: 2227656907-0
  • Opcode ID: d8a9710a4b4f931bd6ce2afdc65b7a4ee70d8132e401df3b10f6fe435f2bd8f4
  • Instruction ID: 9c338175c42af6cce4ce25f094ea3f785b49dec671f86e3553e91ea71de67ef1
  • Opcode Fuzzy Hash: d8a9710a4b4f931bd6ce2afdc65b7a4ee70d8132e401df3b10f6fe435f2bd8f4
  • Instruction Fuzzy Hash: 21B1A522B1CA9251EA66FF21AC901BFA360EB84BF4FA45131DE5D07B85DE7CE541C320
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
  • String ID:
  • API String ID: 2933794660-0
  • Opcode ID: b8bf11e0edaa7af157fb36c591e00a94452557a9715cf19873dd124ae2f7a1b8
  • Instruction ID: 5d33b11682ea8537957075eeb113307e98bac251d574b29ab94bb252ca7c635e
  • Opcode Fuzzy Hash: b8bf11e0edaa7af157fb36c591e00a94452557a9715cf19873dd124ae2f7a1b8
  • Instruction Fuzzy Hash: 2C117026B14F0689EB00DF60EC852B973B4FB18768F840E31DA6D877A4DF38E1548350
APIs
    • Part of subcall function 00007FF7C6BBC4EC: GetLastError.KERNEL32 ref: 00007FF7C6BBC4FB
    • Part of subcall function 00007FF7C6BBC4EC: FlsGetValue.KERNEL32 ref: 00007FF7C6BBC510
    • Part of subcall function 00007FF7C6BBC4EC: SetLastError.KERNEL32 ref: 00007FF7C6BBC59B
    • Part of subcall function 00007FF7C6BBC4EC: FlsSetValue.KERNEL32 ref: 00007FF7C6BBC531
  • GetLocaleInfoW.KERNEL32 ref: 00007FF7C6BC5D38
    • Part of subcall function 00007FF7C6BC2050: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7C6BC206D
  • GetLocaleInfoW.KERNEL32 ref: 00007FF7C6BC5D81
    • Part of subcall function 00007FF7C6BC2050: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7C6BC20C6
  • GetLocaleInfoW.KERNEL32 ref: 00007FF7C6BC5E49
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: InfoLocale$ErrorLastValue_invalid_parameter_noinfo
  • String ID:
  • API String ID: 1791019856-0
  • Opcode ID: 92d6418423355d8314ef6e3732ed53f47abfbc63526a58c66444b589371c7a5e
  • Instruction ID: 683bbf3130b63f6f1dc2f12aa2676c54d78dfc7433f4be837d3030d697201e58
  • Opcode Fuzzy Hash: 92d6418423355d8314ef6e3732ed53f47abfbc63526a58c66444b589371c7a5e
  • Instruction Fuzzy Hash: EB618073A1864396E735AF11DA802BAB7A1FB44760FA08135C75D83691DF3CE661C720
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: InfoLocale
  • String ID: GetLocaleInfoEx
  • API String ID: 2299586839-2904428671
  • Opcode ID: f15e76d6e855b28a7bafbdc5ca666a80898fff7fb5e5d42698dac467ec48329f
  • Instruction ID: 15af9b3e19ac5db90d44cd9b10450c50946123c1480a84812b4844d1f6d597b7
  • Opcode Fuzzy Hash: f15e76d6e855b28a7bafbdc5ca666a80898fff7fb5e5d42698dac467ec48329f
  • Instruction Fuzzy Hash: 0901AC20B0868195E701AF57BC804ABE764FF88BE0FE48035EE4D47765CE3CD5428354
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ExceptionRaise_clrfp
  • String ID:
  • API String ID: 15204871-0
  • Opcode ID: c708c24bb35013bb7bdb1e2621b49e645dd4763db2aed20d5418e663672de887
  • Instruction ID: 44a9a1f0b6556e58db40399542cac9acbc9c218e08f778d3c491bb78c233853a
  • Opcode Fuzzy Hash: c708c24bb35013bb7bdb1e2621b49e645dd4763db2aed20d5418e663672de887
  • Instruction Fuzzy Hash: 78B19F73604B848BE716DF2AC88636D7BE0F744B58F688822DB5D937A4CB39D451C710
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: _invalid_parameter_noinfo_noreturn
  • String ID:
  • API String ID: 3668304517-0
  • Opcode ID: 238ee77b4b42b418bce7edc90a1a7eabbcaf1b3457ba01408fd08da84169fb79
  • Instruction ID: 8032957bc9733fc3bc11994394880749d861a39b7f84eb122d8b727cbce73e2e
  • Opcode Fuzzy Hash: 238ee77b4b42b418bce7edc90a1a7eabbcaf1b3457ba01408fd08da84169fb79
  • Instruction Fuzzy Hash: 0D22C672B0864286FA6BAE25C9907BEB7A1FB45BA0FA44131DB5D47796CF38F450C310
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Info
  • String ID:
  • API String ID: 1807457897-0
  • Opcode ID: eb912bc076c4651410f1f807135b2de7a5736efec1f6849bd158a2a389d2cc83
  • Instruction ID: 105bf0393f6d2a6c877128bc18ae5b446a7585960a40a1dba379c9429de3122a
  • Opcode Fuzzy Hash: eb912bc076c4651410f1f807135b2de7a5736efec1f6849bd158a2a389d2cc83
  • Instruction Fuzzy Hash: 7512C322A08BC586E752DF3898952FEB3A4FB99758F559235EF8C43252DF38E181C710
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID:
  • String ID:
  • API String ID:
  • Opcode ID: 1e954d66a7babcac885fdb59602c755f6187e6d08d64ffabe0be64fba41a2f2f
  • Instruction ID: 67a094d14c7e32f2c2a2fd0852bf61561dd18b36c2a818ae48a1499f3308a994
  • Opcode Fuzzy Hash: 1e954d66a7babcac885fdb59602c755f6187e6d08d64ffabe0be64fba41a2f2f
  • Instruction Fuzzy Hash: A7E17E22A04B8186E721EF61E8912EEB7A4FB95798F904631DF8D53B56EF3CD245C310
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorLastValue$InfoLocale
  • String ID:
  • API String ID: 673564084-0
  • Opcode ID: 4588f150d22ce24f224f6be4c08b9b4783216d4540ea3b4a57068b8ff2d23c7f
  • Instruction ID: c2a4f8e32aff082afe14c967eddc9556675541e1b67bf687ee6b6912edf44358
  • Opcode Fuzzy Hash: 4588f150d22ce24f224f6be4c08b9b4783216d4540ea3b4a57068b8ff2d23c7f
  • Instruction Fuzzy Hash: 7231D632B0868296EB29AF21D9817BFB7A1FB48754F908035DA4DC7685DF3CE650C710
APIs
    • Part of subcall function 00007FF7C6BBC4EC: GetLastError.KERNEL32 ref: 00007FF7C6BBC4FB
    • Part of subcall function 00007FF7C6BBC4EC: FlsGetValue.KERNEL32 ref: 00007FF7C6BBC510
    • Part of subcall function 00007FF7C6BBC4EC: SetLastError.KERNEL32 ref: 00007FF7C6BBC59B
  • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF7C6BC6353,?,00000000,00000092,?,?,00000000,?,00007FF7C6BBA501), ref: 00007FF7C6BC5C02
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorLast$EnumLocalesSystemValue
  • String ID:
  • API String ID: 3029459697-0
  • Opcode ID: c887938fb4a37e1bc8cd3e13e4edcd669c0b7bc5127d781b011fd1bfa64565a2
  • Instruction ID: 521319fed2f6b06bf2d55ded9eac5bdda66d42c39337661010394ab53b2470be
  • Opcode Fuzzy Hash: c887938fb4a37e1bc8cd3e13e4edcd669c0b7bc5127d781b011fd1bfa64565a2
  • Instruction Fuzzy Hash: 4C112B63A0864599EB15AF15D9802BEBFA0FB40BB0F944131C65D433C0CF78D6E1C750
APIs
    • Part of subcall function 00007FF7C6BBC4EC: GetLastError.KERNEL32 ref: 00007FF7C6BBC4FB
    • Part of subcall function 00007FF7C6BBC4EC: FlsGetValue.KERNEL32 ref: 00007FF7C6BBC510
    • Part of subcall function 00007FF7C6BBC4EC: SetLastError.KERNEL32 ref: 00007FF7C6BBC59B
  • GetLocaleInfoW.KERNEL32(?,?,?,00007FF7C6BC5EC6), ref: 00007FF7C6BC6153
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorLast$InfoLocaleValue
  • String ID:
  • API String ID: 3796814847-0
  • Opcode ID: 2201f97147862c275546d1a65b0f63e2fc243d5b3d43f8eef933fad15bf94eab
  • Instruction ID: 1a74202e8be620d0e5400194d26be472f0f59f3b0eaa41aa10147c1e7f75a2e2
  • Opcode Fuzzy Hash: 2201f97147862c275546d1a65b0f63e2fc243d5b3d43f8eef933fad15bf94eab
  • Instruction Fuzzy Hash: 9B115B31B1812353E735AE19A880E7FA261EB80B71FA45231D66D476C6FF29E6408310
APIs
    • Part of subcall function 00007FF7C6BBC4EC: GetLastError.KERNEL32 ref: 00007FF7C6BBC4FB
    • Part of subcall function 00007FF7C6BBC4EC: FlsGetValue.KERNEL32 ref: 00007FF7C6BBC510
    • Part of subcall function 00007FF7C6BBC4EC: SetLastError.KERNEL32 ref: 00007FF7C6BBC59B
  • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF7C6BC630F,?,00000000,00000092,?,?,00000000,?,00007FF7C6BBA501), ref: 00007FF7C6BC5CB2
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorLast$EnumLocalesSystemValue
  • String ID:
  • API String ID: 3029459697-0
  • Opcode ID: fb9e70061f9454bdf4dfd69dda33c59ded4b3e02d44b7d369b15ad2070437982
  • Instruction ID: d9f84637827c9a9a3500b613d543a6dae143f29004a41e6516e0acfc6084e489
  • Opcode Fuzzy Hash: fb9e70061f9454bdf4dfd69dda33c59ded4b3e02d44b7d369b15ad2070437982
  • Instruction Fuzzy Hash: E301F573F0824156E7166F15EA807BBBA91EB407B0FA58231D67D472C4CF6896908710
APIs
  • EnumSystemLocalesW.KERNEL32(?,?,00000000,00007FF7C6BBE323,?,?,?,?,?,?,?,?,00000000,00007FF7C6BC51B4), ref: 00007FF7C6BBE00F
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: EnumLocalesSystem
  • String ID:
  • API String ID: 2099609381-0
  • Opcode ID: 8d9dd42306da5125309a9bc46ecfd08a448bbfacd4485c87034d631c15510ceb
  • Instruction ID: da72cd80b7be12d7bd5b5845850698d663dc75c1b67f9723343fac5649216021
  • Opcode Fuzzy Hash: 8d9dd42306da5125309a9bc46ecfd08a448bbfacd4485c87034d631c15510ceb
  • Instruction Fuzzy Hash: C3F06D72708B4182E605EF15ECD01AAA365EB88790FA49035EA0D873A9CE3CE4528314
APIs
  • GetLastError.KERNEL32 ref: 00007FF7C6BC0021
    • Part of subcall function 00007FF7C6BBDF10: HeapAlloc.KERNEL32(?,?,00000000,00007FF7C6BBC6C6,?,?,8000000000000000,00007FF7C6BB8411,?,?,?,?,00007FF7C6BBD8DC), ref: 00007FF7C6BBDF65
    • Part of subcall function 00007FF7C6BBD8A8: HeapFree.KERNEL32 ref: 00007FF7C6BBD8BE
    • Part of subcall function 00007FF7C6BBD8A8: GetLastError.KERNEL32 ref: 00007FF7C6BBD8C8
    • Part of subcall function 00007FF7C6BC68E0: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7C6BC6913
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorHeapLast$AllocFree_invalid_parameter_noinfo
  • String ID:
  • API String ID: 916656526-0
  • Opcode ID: eeca50d074c0a531bd5a1a244eef28eacd6f7651627bfea427eade9577dc6069
  • Instruction ID: 35f4505c365d3ad688dbbfb0381716debe92587171a9c0e53988b07db81f82d2
  • Opcode Fuzzy Hash: eeca50d074c0a531bd5a1a244eef28eacd6f7651627bfea427eade9577dc6069
  • Instruction Fuzzy Hash: 1A41E521B0964311FA627F266C9277BE2D0BF857E4FE44135EE8D47786DE3DE5018620
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: HeapProcess
  • String ID:
  • API String ID: 54951025-0
  • Opcode ID: 029dfcd14a4f579f43b3cbeaac2bc55aea181f50d690abcdde2cc191421cc009
  • Instruction ID: bf98be8943988706b4cb79767cc6d7e49c313fdfc1a42c753579b0f65b5da1de
  • Opcode Fuzzy Hash: 029dfcd14a4f579f43b3cbeaac2bc55aea181f50d690abcdde2cc191421cc009
  • Instruction Fuzzy Hash: FDB09224F07A06C2EA0A3F116CC221967A4BF48721FEC0138C10C48320DF2C21B65720
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID:
  • String ID:
  • API String ID:
  • Opcode ID: cae3adf7fbac91320012ab16532260f0aa30efb7dd90cca7ff8292f0ba493c03
  • Instruction ID: e47d99fa0bbcf60e56cff7441edfa6d274507c73b6681a8e3ccaa1e02a16ee0a
  • Opcode Fuzzy Hash: cae3adf7fbac91320012ab16532260f0aa30efb7dd90cca7ff8292f0ba493c03
  • Instruction Fuzzy Hash: 94E1A121E2814247EA77BE2598D12BFE391AF45770FB04235D76E47AD3CE2CF442A621
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID:
  • String ID:
  • API String ID:
  • Opcode ID: 08c9dd133e6468ba80f0366311fa496fb00e70f8319ea936cf9032a9658e574b
  • Instruction ID: f07c9be28e96eb9f47bd4acfb4cfd33cafa55159d90a8524be8dd047daef77a0
  • Opcode Fuzzy Hash: 08c9dd133e6468ba80f0366311fa496fb00e70f8319ea936cf9032a9658e574b
  • Instruction Fuzzy Hash: E5B13373B2858587DB17DF29D99417AB7E1B754BE8B558231EE5E43B80DA3CE808C700
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorLastNameTranslate$CodePageValidValue_invalid_parameter_noinfo
  • String ID:
  • API String ID: 4023145424-0
  • Opcode ID: aeb893f807a164511336be8fb668a02362ef3396e49cfcee77405b01a9b323c0
  • Instruction ID: 096c02b3cb71abc4bad6a5afa8852545269331a1b76b069f64896a086408dc0b
  • Opcode Fuzzy Hash: aeb893f807a164511336be8fb668a02362ef3396e49cfcee77405b01a9b323c0
  • Instruction Fuzzy Hash: EAC1E665E0868245EB61AF669C903BFA7A0FBD47A8FE04032DE4E47794EE3CD505C314
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorLast$Value_invalid_parameter_noinfo
  • String ID:
  • API String ID: 1500699246-0
  • Opcode ID: eab00eb692c8d8a89824e34906ddcee93f3974e9b307a53620d81c849ffb5913
  • Instruction ID: 9902b3b89733caaf2976f4a0b6061c59e087fbfd584618f48109dd2bafc7f8d9
  • Opcode Fuzzy Hash: eab00eb692c8d8a89824e34906ddcee93f3974e9b307a53620d81c849ffb5913
  • Instruction Fuzzy Hash: 53B10C33A0864692E765AF21DD916BB7791FB80B64FA04131DB4D836C9DF3CE661C360
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID:
  • String ID:
  • API String ID:
  • Opcode ID: 1c460685fd67758052ea2b7dce6c978d9c479210279eca324e6e8b4d07f8538b
  • Instruction ID: a8fa44c5971484eabc96260c9a0531a2bf07eb60cbad8d03d8fd9da2ed0d94cb
  • Opcode Fuzzy Hash: 1c460685fd67758052ea2b7dce6c978d9c479210279eca324e6e8b4d07f8538b
  • Instruction Fuzzy Hash: 6E91D563B18A8542EB16DF19D8911BAE350FB547E4FA48235DF9E47B92EE3CE150C320
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: _invalid_parameter_noinfo
  • String ID:
  • API String ID: 3215553584-0
  • Opcode ID: a8b64890f8a5c68d8385ce03da0778d4774394f66062af822aaa3bba0e4bfb5c
  • Instruction ID: 9ee177c9732ca890af528f29dfdd717d5d3dae0570397e90265504581883813d
  • Opcode Fuzzy Hash: a8b64890f8a5c68d8385ce03da0778d4774394f66062af822aaa3bba0e4bfb5c
  • Instruction Fuzzy Hash: C781E332A04A4186EB25EF25D8C137E63A0FB84BA8FA45636EE1D87794DF38D441C318
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: _invalid_parameter_noinfo
  • String ID:
  • API String ID: 3215553584-0
  • Opcode ID: f5c9fa3cca629cf5d8793f39275e1d762ffb1edc1acd4677815cd10845c10586
  • Instruction ID: d9eff51f00d9bb4b622a9feb7da99d7677111560051a829aedabb0f130e73ce7
  • Opcode Fuzzy Hash: f5c9fa3cca629cf5d8793f39275e1d762ffb1edc1acd4677815cd10845c10586
  • Instruction Fuzzy Hash: D461F922E0825256F766AD388CD067FE690EF41770FB40235DA2D867D5EF7DEA008720
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorFreeHeapLast
  • String ID:
  • API String ID: 485612231-0
  • Opcode ID: c69eabad792825c5f6511685fc167655e0992adfed19b0812a01b8ee0a2a676b
  • Instruction ID: ebcd66ab4a5db786f121f9f3bd381926538a1bfc8e10b2c872ba98ae4e0433d1
  • Opcode Fuzzy Hash: c69eabad792825c5f6511685fc167655e0992adfed19b0812a01b8ee0a2a676b
  • Instruction Fuzzy Hash: C741D462714A5582EF08EF2ADD5416AB3A1BB88FE4B999037DE0D87B58DF3CD4428304
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID:
  • String ID:
  • API String ID:
  • Opcode ID: 8d33683f98f197dc21d68b29f391e5934b2ff1920e6effd4f5691da30b931023
  • Instruction ID: 4fdda48174ec0c65362700a726aa82abc8e43a4c5176b218cbddfc204f9d7c40
  • Opcode Fuzzy Hash: 8d33683f98f197dc21d68b29f391e5934b2ff1920e6effd4f5691da30b931023
  • Instruction Fuzzy Hash: 50F068717192558AEBA5DF2CA84266A7BD0F748390F948039F68D87B08DA3C90628F14
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID:
  • String ID:
  • API String ID:
  • Opcode ID: 9fe86df744f2ff4f81e95c621db372488a3b0e6b943bb028424438111a8b8076
  • Instruction ID: 15d9f33dfe9c012100ed1024ce0a432467a0d6fe86cb5ee17b583fef6e925363
  • Opcode Fuzzy Hash: 9fe86df744f2ff4f81e95c621db372488a3b0e6b943bb028424438111a8b8076
  • Instruction Fuzzy Hash: 01A00221A0DC46E4F606AF04EED0136A336FFD0321BE10031C49D45061EF3CA600D32E

Control-flow Graph

  • Executed
  • Not Executed
control_flow_graph 647 7ff7c6bb2940-7ff7c6bb29a8 call 7ff7c6bb4d00 650 7ff7c6bb2e09-7ff7c6bb2e0f call 7ff7c6bb8558 647->650 651 7ff7c6bb29ae-7ff7c6bb29b1 647->651 651->650 652 7ff7c6bb29b7-7ff7c6bb29bd 651->652 654 7ff7c6bb29c3-7ff7c6bb29c7 652->654 655 7ff7c6bb2a8c-7ff7c6bb2a9e 652->655 654->655 659 7ff7c6bb29cd-7ff7c6bb29d8 654->659 657 7ff7c6bb2aa4-7ff7c6bb2aa8 655->657 658 7ff7c6bb2d59-7ff7c6bb2d5d 655->658 657->658 660 7ff7c6bb2aae-7ff7c6bb2ab9 657->660 662 7ff7c6bb2d5f-7ff7c6bb2d66 658->662 663 7ff7c6bb2d96-7ff7c6bb2da0 call 7ff7c6bb1e74 658->663 659->655 661 7ff7c6bb29de-7ff7c6bb29e3 659->661 660->658 665 7ff7c6bb2abf-7ff7c6bb2ac3 660->665 661->655 666 7ff7c6bb29e9-7ff7c6bb29f3 call 7ff7c6bb1e74 661->666 662->650 667 7ff7c6bb2d6c-7ff7c6bb2d91 call 7ff7c6bb3314 662->667 663->650 673 7ff7c6bb2da2-7ff7c6bb2dc1 call 7ff7c6bafac0 663->673 670 7ff7c6bb2c89-7ff7c6bb2c95 665->670 671 7ff7c6bb2ac9-7ff7c6bb2b04 call 7ff7c6bb0f84 665->671 666->673 681 7ff7c6bb29f9-7ff7c6bb2a24 call 7ff7c6bb1e74 * 2 call 7ff7c6bb16dc 666->681 667->663 670->663 674 7ff7c6bb2c9b-7ff7c6bb2c9f 670->674 671->670 685 7ff7c6bb2b0a-7ff7c6bb2b13 671->685 678 7ff7c6bb2ca1-7ff7c6bb2cad call 7ff7c6bb169c 674->678 679 7ff7c6bb2caf-7ff7c6bb2cb7 674->679 678->679 692 7ff7c6bb2cd0-7ff7c6bb2cd8 678->692 679->663 684 7ff7c6bb2cbd-7ff7c6bb2cca call 7ff7c6bb0dc4 679->684 714 7ff7c6bb2a26-7ff7c6bb2a2a 681->714 715 7ff7c6bb2a44-7ff7c6bb2a4e call 7ff7c6bb1e74 681->715 684->663 684->692 689 7ff7c6bb2b17-7ff7c6bb2b49 685->689 694 7ff7c6bb2b4f-7ff7c6bb2b5b 689->694 695 7ff7c6bb2c7c-7ff7c6bb2c83 689->695 696 7ff7c6bb2cde-7ff7c6bb2ce2 692->696 697 7ff7c6bb2dec-7ff7c6bb2e08 call 7ff7c6bb1e74 * 2 call 7ff7c6bb8984 692->697 694->695 698 7ff7c6bb2b61-7ff7c6bb2b80 694->698 695->670 695->689 700 7ff7c6bb2cf5 696->700 701 7ff7c6bb2ce4-7ff7c6bb2cf3 call 7ff7c6bb169c 696->701 697->650 702 7ff7c6bb2b86-7ff7c6bb2bc3 call 7ff7c6bb16b0 * 2 698->702 703 7ff7c6bb2c6c-7ff7c6bb2c71 698->703 710 7ff7c6bb2cf7-7ff7c6bb2d01 call 7ff7c6bb4d98 700->710 701->710 727 7ff7c6bb2bf6-7ff7c6bb2bf9 702->727 703->695 710->663 725 7ff7c6bb2d07-7ff7c6bb2d57 call 7ff7c6bb0e90 call 7ff7c6bb1224 710->725 714->715 719 7ff7c6bb2a2c-7ff7c6bb2a37 714->719 715->655 730 7ff7c6bb2a50-7ff7c6bb2a70 call 7ff7c6bb1e74 * 2 call 7ff7c6bb4d98 715->730 719->715 724 7ff7c6bb2a39-7ff7c6bb2a3e 719->724 724->650 724->715 725->663 733 7ff7c6bb2bc5-7ff7c6bb2beb call 7ff7c6bb16b0 call 7ff7c6bb3878 727->733 734 7ff7c6bb2bfb-7ff7c6bb2c02 727->734 752 7ff7c6bb2a72-7ff7c6bb2a7c call 7ff7c6bb4e88 730->752 753 7ff7c6bb2a87 730->753 749 7ff7c6bb2c0d-7ff7c6bb2c6a call 7ff7c6bb2798 733->749 750 7ff7c6bb2bed-7ff7c6bb2bf0 733->750 738 7ff7c6bb2c73 734->738 739 7ff7c6bb2c04-7ff7c6bb2c08 734->739 740 7ff7c6bb2c78 738->740 739->702 740->695 749->740 750->727 757 7ff7c6bb2a82-7ff7c6bb2de5 call 7ff7c6bb191c call 7ff7c6bb41c8 call 7ff7c6bb1b00 752->757 758 7ff7c6bb2de6-7ff7c6bb2deb call 7ff7c6bb8984 752->758 753->655 757->758 758->697
APIs
  • __FrameHandler3::GetHandlerSearchState.LIBVCRUNTIME ref: 00007FF7C6BB299D
    • Part of subcall function 00007FF7C6BB4D00: __GetUnwindTryBlock.LIBCMT ref: 00007FF7C6BB4D43
    • Part of subcall function 00007FF7C6BB4D00: __SetUnwindTryBlock.LIBVCRUNTIME ref: 00007FF7C6BB4D68
  • Is_bad_exception_allowed.LIBVCRUNTIME ref: 00007FF7C6BB2A75
  • __FrameHandler3::ExecutionInCatch.LIBVCRUNTIME ref: 00007FF7C6BB2CC3
  • std::bad_alloc::bad_alloc.LIBCMT ref: 00007FF7C6BB2DD0
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
  • String ID: csm$csm$csm
  • API String ID: 849930591-393685449
  • Opcode ID: d27a991ab0389ce6a1b21555a8b89e6d26dc1bc5bf5d7869a115a3ad2456b0fa
  • Instruction ID: 54cf092391439db030edc1e28d05a9eae84bf0b7d94560c1fb2bd7f06ab70285
  • Opcode Fuzzy Hash: d27a991ab0389ce6a1b21555a8b89e6d26dc1bc5bf5d7869a115a3ad2456b0fa
  • Instruction Fuzzy Hash: 1BD1A532A08B4186EB21EF65D8813BEB7A0FB857A8F600235EE4D57B55DF38E441C754

Control-flow Graph

APIs
  • LoadLibraryExW.KERNEL32(?,?,7FFFFFFFFFFFFFFF,00007FF7C6BB5473,?,?,00000000,00007FF7C6BB1F7A,?,?,7FFFFFFFFFFFFFFF,00007FF7C6BB1BB1), ref: 00007FF7C6BB52F1
  • GetLastError.KERNEL32(?,?,7FFFFFFFFFFFFFFF,00007FF7C6BB5473,?,?,00000000,00007FF7C6BB1F7A,?,?,7FFFFFFFFFFFFFFF,00007FF7C6BB1BB1), ref: 00007FF7C6BB52FF
  • LoadLibraryExW.KERNEL32(?,?,7FFFFFFFFFFFFFFF,00007FF7C6BB5473,?,?,00000000,00007FF7C6BB1F7A,?,?,7FFFFFFFFFFFFFFF,00007FF7C6BB1BB1), ref: 00007FF7C6BB5329
  • FreeLibrary.KERNEL32(?,?,7FFFFFFFFFFFFFFF,00007FF7C6BB5473,?,?,00000000,00007FF7C6BB1F7A,?,?,7FFFFFFFFFFFFFFF,00007FF7C6BB1BB1), ref: 00007FF7C6BB5397
  • GetProcAddress.KERNEL32(?,?,7FFFFFFFFFFFFFFF,00007FF7C6BB5473,?,?,00000000,00007FF7C6BB1F7A,?,?,7FFFFFFFFFFFFFFF,00007FF7C6BB1BB1), ref: 00007FF7C6BB53A3
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Library$Load$AddressErrorFreeLastProc
  • String ID: api-ms-$btc
  • API String ID: 2559590344-994717500
  • Opcode ID: 7752c46d701261b92908a059a399f55efe9df7d0bad221ac0cb651ebb6a12407
  • Instruction ID: 7f30a0d84c9bcae27ef446c94b1f9f8a737a1ac07844f9ab52b12cfbff04fe88
  • Opcode Fuzzy Hash: 7752c46d701261b92908a059a399f55efe9df7d0bad221ac0cb651ebb6a12407
  • Instruction Fuzzy Hash: 7F31A332B1A78191EE27AF16AD8057AA398BF84B70FA90535DD1E07390EE7CE4448725
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: _invalid_parameter_noinfo
  • String ID: f$p$p
  • API String ID: 3215553584-1995029353
  • Opcode ID: 62848ba5f44f271a4da2666373930817cbbe369541c32e4d2495745b2fc7bc00
  • Instruction ID: 3d269acd085592efc4244ee1fb4bc75b4bbcf7ab9623527b44e57c5a6e80bada
  • Opcode Fuzzy Hash: 62848ba5f44f271a4da2666373930817cbbe369541c32e4d2495745b2fc7bc00
  • Instruction Fuzzy Hash: 8B127261E0854386FB26BE14D8D4A7BF691FBD0B60FE44135DA9D466C4DF3CE9808B28

Control-flow Graph

  • Executed
  • Not Executed
control_flow_graph 959 7ff7c6bbf69c-7ff7c6bbf6c2 960 7ff7c6bbf6c4-7ff7c6bbf6d8 call 7ff7c6bb83e8 call 7ff7c6bb8408 959->960 961 7ff7c6bbf6dd-7ff7c6bbf6e1 959->961 975 7ff7c6bbface 960->975 962 7ff7c6bbfab7-7ff7c6bbfac3 call 7ff7c6bb83e8 call 7ff7c6bb8408 961->962 963 7ff7c6bbf6e7-7ff7c6bbf6ee 961->963 982 7ff7c6bbfac9 call 7ff7c6bb74b0 962->982 963->962 966 7ff7c6bbf6f4-7ff7c6bbf722 963->966 966->962 969 7ff7c6bbf728-7ff7c6bbf72f 966->969 972 7ff7c6bbf731-7ff7c6bbf743 call 7ff7c6bb83e8 call 7ff7c6bb8408 969->972 973 7ff7c6bbf748-7ff7c6bbf74b 969->973 972->982 978 7ff7c6bbf751-7ff7c6bbf757 973->978 979 7ff7c6bbfab3-7ff7c6bbfab5 973->979 980 7ff7c6bbfad1-7ff7c6bbfae8 975->980 978->979 983 7ff7c6bbf75d-7ff7c6bbf760 978->983 979->980 982->975 983->972 986 7ff7c6bbf762-7ff7c6bbf787 983->986 987 7ff7c6bbf7ba-7ff7c6bbf7c1 986->987 988 7ff7c6bbf789-7ff7c6bbf78b 986->988 992 7ff7c6bbf796-7ff7c6bbf7ad call 7ff7c6bb83e8 call 7ff7c6bb8408 call 7ff7c6bb74b0 987->992 993 7ff7c6bbf7c3-7ff7c6bbf7eb call 7ff7c6bc0778 call 7ff7c6bbd8a8 * 2 987->993 990 7ff7c6bbf7b2-7ff7c6bbf7b8 988->990 991 7ff7c6bbf78d-7ff7c6bbf794 988->991 995 7ff7c6bbf838-7ff7c6bbf84f 990->995 991->990 991->992 1024 7ff7c6bbf940 992->1024 1020 7ff7c6bbf808-7ff7c6bbf833 call 7ff7c6bbfd5c 993->1020 1021 7ff7c6bbf7ed-7ff7c6bbf803 call 7ff7c6bb8408 call 7ff7c6bb83e8 993->1021 998 7ff7c6bbf851-7ff7c6bbf859 995->998 999 7ff7c6bbf8ca-7ff7c6bbf8d4 call 7ff7c6bc64d0 995->999 998->999 1003 7ff7c6bbf85b-7ff7c6bbf85d 998->1003 1011 7ff7c6bbf8da-7ff7c6bbf8ef 999->1011 1012 7ff7c6bbf95e 999->1012 1003->999 1007 7ff7c6bbf85f-7ff7c6bbf875 1003->1007 1007->999 1013 7ff7c6bbf877-7ff7c6bbf883 1007->1013 1011->1012 1017 7ff7c6bbf8f1-7ff7c6bbf903 GetConsoleMode 1011->1017 1015 7ff7c6bbf963-7ff7c6bbf983 ReadFile 1012->1015 1013->999 1018 7ff7c6bbf885-7ff7c6bbf887 1013->1018 1022 7ff7c6bbf989-7ff7c6bbf991 1015->1022 1023 7ff7c6bbfa7d-7ff7c6bbfa86 GetLastError 1015->1023 1017->1012 1025 7ff7c6bbf905-7ff7c6bbf90d 1017->1025 1018->999 1019 7ff7c6bbf889-7ff7c6bbf8a1 1018->1019 1019->999 1026 7ff7c6bbf8a3-7ff7c6bbf8af 1019->1026 1020->995 1021->1024 1022->1023 1028 7ff7c6bbf997 1022->1028 1031 7ff7c6bbfaa3-7ff7c6bbfaa6 1023->1031 1032 7ff7c6bbfa88-7ff7c6bbfa9e call 7ff7c6bb8408 call 7ff7c6bb83e8 1023->1032 1033 7ff7c6bbf943-7ff7c6bbf94d call 7ff7c6bbd8a8 1024->1033 1025->1015 1030 7ff7c6bbf90f-7ff7c6bbf931 ReadConsoleW 1025->1030 1026->999 1035 7ff7c6bbf8b1-7ff7c6bbf8b3 1026->1035 1039 7ff7c6bbf99e-7ff7c6bbf9b3 1028->1039 1041 7ff7c6bbf952-7ff7c6bbf95c 1030->1041 1042 7ff7c6bbf933 GetLastError 1030->1042 1036 7ff7c6bbf939-7ff7c6bbf93b call 7ff7c6bb837c 1031->1036 1037 7ff7c6bbfaac-7ff7c6bbfaae 1031->1037 1032->1024 1033->980 1035->999 1045 7ff7c6bbf8b5-7ff7c6bbf8c5 1035->1045 1036->1024 1037->1033 1039->1033 1047 7ff7c6bbf9b5-7ff7c6bbf9c0 1039->1047 1041->1039 1042->1036 1045->999 1052 7ff7c6bbf9c2-7ff7c6bbf9db call 7ff7c6bbf2b4 1047->1052 1053 7ff7c6bbf9e7-7ff7c6bbf9ef 1047->1053 1059 7ff7c6bbf9e0-7ff7c6bbf9e2 1052->1059 1056 7ff7c6bbf9f1-7ff7c6bbfa03 1053->1056 1057 7ff7c6bbfa6b-7ff7c6bbfa78 call 7ff7c6bbf0f4 1053->1057 1060 7ff7c6bbfa05 1056->1060 1061 7ff7c6bbfa5e-7ff7c6bbfa66 1056->1061 1057->1059 1059->1033 1063 7ff7c6bbfa0a-7ff7c6bbfa11 1060->1063 1061->1033 1064 7ff7c6bbfa13-7ff7c6bbfa17 1063->1064 1065 7ff7c6bbfa4d-7ff7c6bbfa58 1063->1065 1066 7ff7c6bbfa33 1064->1066 1067 7ff7c6bbfa19-7ff7c6bbfa20 1064->1067 1065->1061 1069 7ff7c6bbfa39-7ff7c6bbfa49 1066->1069 1067->1066 1068 7ff7c6bbfa22-7ff7c6bbfa26 1067->1068 1068->1066 1070 7ff7c6bbfa28-7ff7c6bbfa31 1068->1070 1069->1063 1071 7ff7c6bbfa4b 1069->1071 1070->1069 1071->1061
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: _invalid_parameter_noinfo
  • String ID:
  • API String ID: 3215553584-0
  • Opcode ID: e15b5cf98dc30e3f65ce3e3bb69fb3c5160b80e48adda0960393153b55cb3a6f
  • Instruction ID: 919b8650b165475aa06b03f2ce402b57ce8d6b66d089eda38968aaba103a8840
  • Opcode Fuzzy Hash: e15b5cf98dc30e3f65ce3e3bb69fb3c5160b80e48adda0960393153b55cb3a6f
  • Instruction Fuzzy Hash: 42C1D52290C78691E6667F159CC02BFBB68EBC1BA0FE54131EE4D07392DE7CE8458724
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Value$ErrorLast
  • String ID:
  • API String ID: 2506987500-0
  • Opcode ID: 2551cdd154a5609d4ca11e3405d1723823922fbe6af19826a7bd5426ca246490
  • Instruction ID: 1bd721057e6c7c5a90bb751e14096b01ea1aad50f60543e00aff00d38b649995
  • Opcode Fuzzy Hash: 2551cdd154a5609d4ca11e3405d1723823922fbe6af19826a7bd5426ca246490
  • Instruction Fuzzy Hash: B321FA20B0864241F56BBF616DD617B92955F847B0FA84634EE3E066D6DE2CF4024668
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
  • String ID: CONOUT$
  • API String ID: 3230265001-3130406586
  • Opcode ID: 6fdf5d222f80571ce6e4eabdb7f13ae867475ea6ef0378db38161a61cb0ba77b
  • Instruction ID: a0baec703d2dc649399e150296a2af9545794693db9df9f82bdc70c9d3f01289
  • Opcode Fuzzy Hash: 6fdf5d222f80571ce6e4eabdb7f13ae867475ea6ef0378db38161a61cb0ba77b
  • Instruction Fuzzy Hash: 81119321B18B5186E351AF06EC9432AA6A4FB88FF4FA40234EB1D8B7A4CF3CD5448750
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ByteCharMultiWide$CompareInfoString
  • String ID:
  • API String ID: 2984826149-0
  • Opcode ID: 44659eeeb4a105ce3f31a6b8163e69338e01b869477deb4ba4134cbc3fa3635c
  • Instruction ID: 53cbaa8629b74cbf40047fe816a102b48049e85815da0b13d8bb9424515c0246
  • Opcode Fuzzy Hash: 44659eeeb4a105ce3f31a6b8163e69338e01b869477deb4ba4134cbc3fa3635c
  • Instruction Fuzzy Hash: 1FA18422A0868286EB23AF11D8903FBA6AAAF417B4FA44631D95D476C6DF3CD5448330
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ByteCharMultiStringWide
  • String ID:
  • API String ID: 2829165498-0
  • Opcode ID: 651ad62222eed2a762eac88c53dfcd039c255ea8ebba40e0f5c98765f1e48ed2
  • Instruction ID: 3e1c703bfc1c23a672abc75739159cec88e8cce3e573da41cb752792be9b2ef0
  • Opcode Fuzzy Hash: 651ad62222eed2a762eac88c53dfcd039c255ea8ebba40e0f5c98765f1e48ed2
  • Instruction Fuzzy Hash: 56819572A0874186EB169F25E9803BAB3A9FB447F8FA44235DA5D47BD5DF3CD4048720
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Is_bad_exception_allowedstd::bad_alloc::bad_alloc
  • String ID: csm$csm$csm
  • API String ID: 3523768491-393685449
  • Opcode ID: 9a37e15862fbcc270d420a3857259dbb884f865d5a94a355de2b5c4d6b98c3e1
  • Instruction ID: 2a7137c0146892375ec6fc59dbb69771d9016760997e08c0b89d764fb8e48827
  • Opcode Fuzzy Hash: 9a37e15862fbcc270d420a3857259dbb884f865d5a94a355de2b5c4d6b98c3e1
  • Instruction Fuzzy Hash: A6E1A4729086818AE712EF24D8C02BEB7A0FF85768F644235DF4D57656CF38E481C764
APIs
  • GetLastError.KERNEL32(?,?,8000000000000000,00007FF7C6BB8411,?,?,?,?,00007FF7C6BBD8DC), ref: 00007FF7C6BBC673
  • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF7C6BB8411,?,?,?,?,00007FF7C6BBD8DC), ref: 00007FF7C6BBC6A9
  • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF7C6BB8411,?,?,?,?,00007FF7C6BBD8DC), ref: 00007FF7C6BBC6D6
  • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF7C6BB8411,?,?,?,?,00007FF7C6BBD8DC), ref: 00007FF7C6BBC6E7
  • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF7C6BB8411,?,?,?,?,00007FF7C6BBD8DC), ref: 00007FF7C6BBC6F8
  • SetLastError.KERNEL32(?,?,8000000000000000,00007FF7C6BB8411,?,?,?,?,00007FF7C6BBD8DC), ref: 00007FF7C6BBC713
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Value$ErrorLast
  • String ID:
  • API String ID: 2506987500-0
  • Opcode ID: 1966e868160955348dfaf9e96579d318b020fc441c334623bbc965988e85fce8
  • Instruction ID: 4e5f025c34adebff430667ba0e47ea5d777575e472831b4d4d5c9b3918a3de68
  • Opcode Fuzzy Hash: 1966e868160955348dfaf9e96579d318b020fc441c334623bbc965988e85fce8
  • Instruction Fuzzy Hash: 21114C20A0824242F567BF215DD113B91955F847F0FB81634ED3E0B6D6DF2CB4424274
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: AddressFreeHandleLibraryModuleProc
  • String ID: CorExitProcess$mscoree.dll
  • API String ID: 4061214504-1276376045
  • Opcode ID: a73d66c831001cd2bd554d640b161791c14e3f3ccc047ace81b544153c50086f
  • Instruction ID: 6385bd23f569c72e892c3d0336e6e01209ab69be2fa648841747be14ae555387
  • Opcode Fuzzy Hash: a73d66c831001cd2bd554d640b161791c14e3f3ccc047ace81b544153c50086f
  • Instruction Fuzzy Hash: C4F04F61B18A0691EA15AF24AC8437FA360EF84771FE4063ADA6D462F4CF2CD545C720
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: AdjustPointer
  • String ID:
  • API String ID: 1740715915-0
  • Opcode ID: 930144ff9b6462ddd6b08f97fed0d33d3da2547ceac4f915cc8ca7b0d9c71ac9
  • Instruction ID: 49325bfb511bf75399b5516741b271082ebd0fdfa98c9ee07e4dbe13c1034e48
  • Opcode Fuzzy Hash: 930144ff9b6462ddd6b08f97fed0d33d3da2547ceac4f915cc8ca7b0d9c71ac9
  • Instruction Fuzzy Hash: 1DB1B421A0DE8685EA67BF1598C057FE290EF84BE0FA98435DF4D07795DE3CE4428328
APIs
  • std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7C6BA703F
    • Part of subcall function 00007FF7C6BA1F6C: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7C6BA1F91
    • Part of subcall function 00007FF7C6BA1F6C: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7C6BA1FB5
  • std::_Facet_Register.LIBCPMT ref: 00007FF7C6BA70CB
  • std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7C6BA70E5
  • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7C6BA710D
    • Part of subcall function 00007FF7C6BA72C4: _Getcoll.LIBCPMT ref: 00007FF7C6BA7346
    • Part of subcall function 00007FF7C6BA72C4: std::_Locinfo::~_Locinfo.LIBCPMT ref: 00007FF7C6BA735B
  • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF7C6BA716C
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_GetcollLocinfoLocinfo::~_Register_invalid_parameter_noinfo_noreturn
  • String ID:
  • API String ID: 1991753141-0
  • Opcode ID: 8053cd6f63d67df124821716cdc35e9e19d1cfa386d9708e2718e4fcf9a69aea
  • Instruction ID: 631ab7b0a2762bc2505da97496aa7f658a2997024a7cfa47f7e9b4a902c0ff68
  • Opcode Fuzzy Hash: 8053cd6f63d67df124821716cdc35e9e19d1cfa386d9708e2718e4fcf9a69aea
  • Instruction Fuzzy Hash: 2941C866A18A4141EA27AF25D8943BBA361FB48BF4FA84631EE5D077D7DE3CD4818310
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: _set_statfp
  • String ID:
  • API String ID: 1156100317-0
  • Opcode ID: c02262ee2f2cd66e1d364d80464a93679a21a5a4cb8fd55b2b430f47eb87c8f0
  • Instruction ID: e836b95914c3277edbed105c0872ea6062507bf504b10d2fe66d88b66b66181f
  • Opcode Fuzzy Hash: c02262ee2f2cd66e1d364d80464a93679a21a5a4cb8fd55b2b430f47eb87c8f0
  • Instruction Fuzzy Hash: E5119832E6CA0371F7563E18DCD537798406F54370EF90634EA6E166D78E5C56424130
APIs
  • FlsGetValue.KERNEL32(?,?,?,00007FF7C6BB7173,?,?,00000000,00007FF7C6BB740E,?,?,?,?,8000000000000000,00007FF7C6BB739A), ref: 00007FF7C6BBC74B
  • FlsSetValue.KERNEL32(?,?,?,00007FF7C6BB7173,?,?,00000000,00007FF7C6BB740E,?,?,?,?,8000000000000000,00007FF7C6BB739A), ref: 00007FF7C6BBC76A
  • FlsSetValue.KERNEL32(?,?,?,00007FF7C6BB7173,?,?,00000000,00007FF7C6BB740E,?,?,?,?,8000000000000000,00007FF7C6BB739A), ref: 00007FF7C6BBC792
  • FlsSetValue.KERNEL32(?,?,?,00007FF7C6BB7173,?,?,00000000,00007FF7C6BB740E,?,?,?,?,8000000000000000,00007FF7C6BB739A), ref: 00007FF7C6BBC7A3
  • FlsSetValue.KERNEL32(?,?,?,00007FF7C6BB7173,?,?,00000000,00007FF7C6BB740E,?,?,?,?,8000000000000000,00007FF7C6BB739A), ref: 00007FF7C6BBC7B4
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Value
  • String ID:
  • API String ID: 3702945584-0
  • Opcode ID: 43ffeae2f24be8874fe5f45e5d28772aac1fa256c10feaa884fce4b7426b0804
  • Instruction ID: 63ede425f634e3b5102673a8ceb8845c0febd2a8e888c32f4671bd408e7dc9fc
  • Opcode Fuzzy Hash: 43ffeae2f24be8874fe5f45e5d28772aac1fa256c10feaa884fce4b7426b0804
  • Instruction Fuzzy Hash: 80112C60A0924241FA6ABF226DD117BA2555FC47F0FA85734ED3D066EADF6CB4028268
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Value
  • String ID:
  • API String ID: 3702945584-0
  • Opcode ID: f0c04397fb2190e6262e7a22f5cb64624b9fd9b60a89e5496fb87994e89112fa
  • Instruction ID: 968a155e10333c045294fc2601f70c974886b8a968cf54f899bcfadd6ea9cda9
  • Opcode Fuzzy Hash: f0c04397fb2190e6262e7a22f5cb64624b9fd9b60a89e5496fb87994e89112fa
  • Instruction Fuzzy Hash: 6F11EC50A0820705F96BBF255CD257BA1555FC43B0FB86B34ED3E4A2E6DE2CB84242B9
APIs
  • _invalid_parameter_noinfo.LIBCMT ref: 00007FF7C6BC1351
    • Part of subcall function 00007FF7C6BC6D58: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7C6BC6D75
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: _invalid_parameter_noinfo
  • String ID: UTF-16LEUNICODE$UTF-8$ccs
  • API String ID: 3215553584-1196891531
  • Opcode ID: 291d99f5026aec6b325bd30b7ab0a94a29543aa2c69d817a2efaa0f165dc7c44
  • Instruction ID: 03852d07d1afe7c4ad98248b7851c24e63185ed1f2c0d2a537527e4b2798cca0
  • Opcode Fuzzy Hash: 291d99f5026aec6b325bd30b7ab0a94a29543aa2c69d817a2efaa0f165dc7c44
  • Instruction Fuzzy Hash: 4981E535D0C252B5F7776E288DE033BAA909F52778FF44035C90EBA595CA1DAA029321
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: std::ios_base::failure::failure
  • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
  • API String ID: 2264918676-1866435925
  • Opcode ID: bbe6685c03cd52e133eb001cfd541e6abb3c283f8bea2f52295279ae2328b473
  • Instruction ID: 970a9b9c3216bff8edb05c5487ddbf54759ed9a13bc226b071c381c48e35d2d8
  • Opcode Fuzzy Hash: bbe6685c03cd52e133eb001cfd541e6abb3c283f8bea2f52295279ae2328b473
  • Instruction Fuzzy Hash: 3D81A03660DA8196DB62DF1AD9D017EB7A1FB84FA4BA58132CE0E43762CF39D442C350
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: CallEncodePointerTranslator
  • String ID: MOC$RCC
  • API String ID: 3544855599-2084237596
  • Opcode ID: 1d96fa7181670c94bd040ebf8979f6b8c91e5a9c606a6400767baf8e487eeb8a
  • Instruction ID: 58cc4a14ca2592cc1aa8254966bdf65e946d5023a67082f63e39ba21dee3e4b7
  • Opcode Fuzzy Hash: 1d96fa7181670c94bd040ebf8979f6b8c91e5a9c606a6400767baf8e487eeb8a
  • Instruction Fuzzy Hash: F291CF73A08B818AE712EF65D8802AEBBA0FB84798F60413AEF4D07755DF38D195C710
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
  • String ID: csm
  • API String ID: 2395640692-1018135373
  • Opcode ID: 87fecb4c19d7f374f51151fe647fe6a86feb1b6c3de8f60f5671d23c5a85ad02
  • Instruction ID: d930177a545637ad13832701c14066945f2e6ddccccc62ca0e70e022f68c58eb
  • Opcode Fuzzy Hash: 87fecb4c19d7f374f51151fe647fe6a86feb1b6c3de8f60f5671d23c5a85ad02
  • Instruction Fuzzy Hash: D351F932B196028ADB16EF15E88467EB395EB84BA4FB08131DE4E47788DF7DE441C714
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
  • String ID: csm$csm
  • API String ID: 3896166516-3733052814
  • Opcode ID: c42f88c54810ca32b05cdcb2320a4cf90955414e565f5cc8c7af55a5267144bd
  • Instruction ID: 602dfd176b3555ff34f707d96df172ca962bfe928452f7373123d1820259567f
  • Opcode Fuzzy Hash: c42f88c54810ca32b05cdcb2320a4cf90955414e565f5cc8c7af55a5267144bd
  • Instruction Fuzzy Hash: 5B51B132A087828AEB75AF1598C436AB7A1EF84BA4FA44135DF5C47789CF3CE450C718
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: CallEncodePointerTranslator
  • String ID: MOC$RCC
  • API String ID: 3544855599-2084237596
  • Opcode ID: a4f8b8c4ebd98fe0db67afa99fdf79c3740f6ba1bcc14b98c0367ead3b37ad59
  • Instruction ID: a9bac710cfc3ddb2de05b6c73aa25889e7065b8902f72f56c4db09e5a1d41d13
  • Opcode Fuzzy Hash: a4f8b8c4ebd98fe0db67afa99fdf79c3740f6ba1bcc14b98c0367ead3b37ad59
  • Instruction Fuzzy Hash: BA617F32908BC581E762AF15E8803AAB7A0FBC5BA4F544225EF9D03B95DF7CD194CB14
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: std::ios_base::failure::failure
  • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
  • API String ID: 2264918676-1866435925
  • Opcode ID: cd4cf638fca9e482345ec9218e7c3d066dd3142fa364015271f2780b454cd82e
  • Instruction ID: 3339ab44b33d321075523cff27b781c12f0b701e0cddaf69bfeeb05feee407ab
  • Opcode Fuzzy Hash: cd4cf638fca9e482345ec9218e7c3d066dd3142fa364015271f2780b454cd82e
  • Instruction Fuzzy Hash: 8D31E632608A4585EB62EF15D9D03BEB3A1FB84B94FA48131EA4D47A66CF3CD446C710
APIs
    • Part of subcall function 00007FF7C6BAEAE8: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7C6BAEB05
    • Part of subcall function 00007FF7C6BAEAE8: std::locale::_Setgloballocale.LIBCPMT ref: 00007FF7C6BAEB28
    • Part of subcall function 00007FF7C6BAEAE8: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7C6BAEBBD
    • Part of subcall function 00007FF7C6BA65D8: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7C6BA6603
    • Part of subcall function 00007FF7C6BA65D8: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7C6BA66A9
  • std::ios_base::failure::failure.LIBCPMT ref: 00007FF7C6BA65C0
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: Lockitstd::_$Lockit::_Lockit::~_$Setgloballocalestd::ios_base::failure::failurestd::locale::_
  • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
  • API String ID: 3020186397-1866435925
  • Opcode ID: b213a7e8670e4a75538bf82afb7f021029c94d6e790a4811917c0cc032a61614
  • Instruction ID: 9a944a7740597d62e5e0acc80bde7258ffad58e7b084541419ff1d04b146e823
  • Opcode Fuzzy Hash: b213a7e8670e4a75538bf82afb7f021029c94d6e790a4811917c0cc032a61614
  • Instruction Fuzzy Hash: 53418C72A14B4586EB21DF14E4843AEA3A0FB54B98FA48135D78D4B666DF3DD486C310
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: std::ios_base::failure::failure
  • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
  • API String ID: 2264918676-1866435925
  • Opcode ID: c1b67620a7b75c3aa4e20ac1e83c0262429a4c599721bceff29da8b160b365f3
  • Instruction ID: c1c524cc28c4dab0b5cef5c80127b4fd35ccdedea9abd2614bf2c922e59818d1
  • Opcode Fuzzy Hash: c1b67620a7b75c3aa4e20ac1e83c0262429a4c599721bceff29da8b160b365f3
  • Instruction Fuzzy Hash: D111CB62908E0985EB56EF14D8C12B9A760EB40BA8FF44535CB1D4B6A6DF3CD446C310
APIs
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: FileWrite$ConsoleErrorLastOutput
  • String ID:
  • API String ID: 2718003287-0
  • Opcode ID: ff04ec1ff6a6d2d4b6b83e9d1173d5f1996effd45d4a05bdea7f186a3231215c
  • Instruction ID: 80304d481ae26e91fb410fa91ed45e38f17b216fcccdab2c1cab6e64469ae016
  • Opcode Fuzzy Hash: ff04ec1ff6a6d2d4b6b83e9d1173d5f1996effd45d4a05bdea7f186a3231215c
  • Instruction Fuzzy Hash: BFD16932B18A8089E712DF74D8802ED77B5FB547A8BA04235DE5D97B89DF38E006C350
APIs
  • GetConsoleMode.KERNEL32(?,?,?,?,?,?,00000000,?,00000000,?,00000000,00000000,00000000,?,00007FF7C6BBD58B), ref: 00007FF7C6BBD6BC
  • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,?,00000000,?,00000000,00000000,00000000,?,00007FF7C6BBD58B), ref: 00007FF7C6BBD747
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ConsoleErrorLastMode
  • String ID:
  • API String ID: 953036326-0
  • Opcode ID: eef6b73cf427e12514af9276e4dc85e88e3c5314759b2a2d9083a048f42eb0d9
  • Instruction ID: 39e417376e05978d2b55f63f34362498f91706050d47fd521a34ba1d318b14af
  • Opcode Fuzzy Hash: eef6b73cf427e12514af9276e4dc85e88e3c5314759b2a2d9083a048f42eb0d9
  • Instruction Fuzzy Hash: 6191D622F1865285F752AF658CC02BEABE0BB847A8FA45179DE0E57684DE3CD442C724
APIs
  • std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7C6BA6603
    • Part of subcall function 00007FF7C6BA1F6C: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7C6BA1F91
    • Part of subcall function 00007FF7C6BA1F6C: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7C6BA1FB5
  • std::_Facet_Register.LIBCPMT ref: 00007FF7C6BA668F
  • std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7C6BA66A9
  • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7C6BA66D1
    • Part of subcall function 00007FF7C6BA2154: _Getctype.LIBCPMT ref: 00007FF7C6BA21C8
    • Part of subcall function 00007FF7C6BA2154: std::_Locinfo::~_Locinfo.LIBCPMT ref: 00007FF7C6BA21E4
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_GetctypeLocinfoLocinfo::~_Register
  • String ID:
  • API String ID: 2057624243-0
  • Opcode ID: a92b4c26d587f5f1fc2496f27d7dceb480a43d144b282e3090050a36e41427ba
  • Instruction ID: e4cec953087d30d194ae339dfc43a6104402ee87ddf9224801882729b5c6e593
  • Opcode Fuzzy Hash: a92b4c26d587f5f1fc2496f27d7dceb480a43d144b282e3090050a36e41427ba
  • Instruction Fuzzy Hash: B4519462A08B4281EA17EF15E8803AAB760FB54BB0FA94631DB5D07796EF3CD452C310
APIs
  • std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7C6BA694B
    • Part of subcall function 00007FF7C6BA1F6C: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7C6BA1F91
    • Part of subcall function 00007FF7C6BA1F6C: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7C6BA1FB5
  • std::_Facet_Register.LIBCPMT ref: 00007FF7C6BA69D7
  • std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF7C6BA69F1
  • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7C6BA6A19
    • Part of subcall function 00007FF7C6BA73F0: std::_Locinfo::~_Locinfo.LIBCPMT ref: 00007FF7C6BA7467
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_LocinfoLocinfo::~_Register
  • String ID:
  • API String ID: 3980266963-0
  • Opcode ID: d762a71aa88d400ef3c37ebf0151fe8d117812f20a0dd84f47510d80cc9adabc
  • Instruction ID: 9479450b0e507dee61f58925b568fa901fa1b394e7810e64d56be3a95af5b02b
  • Opcode Fuzzy Hash: d762a71aa88d400ef3c37ebf0151fe8d117812f20a0dd84f47510d80cc9adabc
  • Instruction Fuzzy Hash: AB317761608A4281EA17AF11E98017BF760FB98BB4FA84531EA9D07797DE3CD442C710
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: __except_validate_context_record
  • String ID: csm$csm
  • API String ID: 1467352782-3733052814
  • Opcode ID: 0560e5e2236336c234ea0b8be6ab1ce4c611589e81adc0c5d99d9f39cdf77d21
  • Instruction ID: c8ffb6a553977c99b1b98dee2590e0b7e7f7b43084ffb21a15d00ecfc3970398
  • Opcode Fuzzy Hash: 0560e5e2236336c234ea0b8be6ab1ce4c611589e81adc0c5d99d9f39cdf77d21
  • Instruction Fuzzy Hash: 9271A47290868186DB62AF25D89077EBBA0EF84BA4FA48135DF4C47A85CF3CE491C714
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: CreateFrameInfo__except_validate_context_record
  • String ID: csm
  • API String ID: 2558813199-1018135373
  • Opcode ID: 46a2ad83245cf6d7efc6605c8c4f88d4733f73d99b0de2d17a04f9ff24c83f0f
  • Instruction ID: 0b7932585db0c9523a735cd5836aab4d00e9f3f08146ed98a076ac55e9401e4e
  • Opcode Fuzzy Hash: 46a2ad83245cf6d7efc6605c8c4f88d4733f73d99b0de2d17a04f9ff24c83f0f
  • Instruction Fuzzy Hash: AA51503661874186E621EF15E88026EB7A4FBC9BA0F640135EF8D07B55CF38E461CB24
APIs
  • _invalid_parameter_noinfo.LIBCMT ref: 00007FF7C6BB907E
    • Part of subcall function 00007FF7C6BBD8A8: HeapFree.KERNEL32 ref: 00007FF7C6BBD8BE
    • Part of subcall function 00007FF7C6BBD8A8: GetLastError.KERNEL32 ref: 00007FF7C6BBD8C8
  • GetModuleFileNameW.KERNEL32(?,?,?,?,?,00007FF7C6BAFEBD), ref: 00007FF7C6BB909C
Strings
  • C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe, xrefs: 00007FF7C6BB908A
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorFileFreeHeapLastModuleName_invalid_parameter_noinfo
  • String ID: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.23321.28745.exe
  • API String ID: 3580290477-1472430217
  • Opcode ID: fb8983b3b5e5e9466b57d2ff6916d1b567982bc8b04b940e20eb30b24ef4965e
  • Instruction ID: 959de4d9ac80641dc693098736d7ce65044fb47402d681fa8d4c37024b27857f
  • Opcode Fuzzy Hash: fb8983b3b5e5e9466b57d2ff6916d1b567982bc8b04b940e20eb30b24ef4965e
  • Instruction Fuzzy Hash: 94416436A08B1295E716FF259CC10BEB7A5EF857A4BE84035EE0D47B55DE3CE4428324
APIs
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ErrorFileLastWrite
  • String ID: U
  • API String ID: 442123175-4171548499
  • Opcode ID: 32d3e78c01c43b2022bf2c965f2efe0706ff7ea1594ede922ccf26d9a22f7477
  • Instruction ID: 731008f54a84302206fa406fefef9ae86248ddfa31a742dbf7d4407d3c36e497
  • Opcode Fuzzy Hash: 32d3e78c01c43b2022bf2c965f2efe0706ff7ea1594ede922ccf26d9a22f7477
  • Instruction Fuzzy Hash: 7C41C522B28A4185DB21AF25E8843AEB7A4FB987A4FD04131EE4D87758DF3CD401C714
APIs
  • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,00007FF7C6BAE8FA), ref: 00007FF7C6BB1B50
  • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,7FFFFFFFFFFFFFFF,00007FF7C6BAE8FA), ref: 00007FF7C6BB1B91
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: ExceptionFileHeaderRaise
  • String ID: csm
  • API String ID: 2573137834-1018135373
  • Opcode ID: 685cf7f9216dc1c2b58ed291b228233822ec471b9a8c7a5f3f6fe7b455151c05
  • Instruction ID: aec02df848fbca9e3757bf21c638a789c5ee84db968b483fe48b79a7f0f31385
  • Opcode Fuzzy Hash: 685cf7f9216dc1c2b58ed291b228233822ec471b9a8c7a5f3f6fe7b455151c05
  • Instruction Fuzzy Hash: D5113032618B8582EB619F15F84026AB7E5FB88B94FA84235DECC07758EF3CD5518B04
APIs
  • std::_Lockit::_Lockit.LIBCPMT ref: 00007FF7C6BA1E7B
  • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 00007FF7C6BA1EBA
    • Part of subcall function 00007FF7C6BAEC58: _Yarn.LIBCPMT ref: 00007FF7C6BAEC86
Strings
Memory Dump Source
  • Source File: 00000000.00000002.1338185903.00007FF7C6BA1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7C6BA0000, based on PE: true
  • Associated: 00000000.00000002.1338170251.00007FF7C6BA0000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338210267.00007FF7C6BCB000.00000002.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338228780.00007FF7C6BDC000.00000004.00000001.01000000.00000003.sdmpDownload File
  • Associated: 00000000.00000002.1338243463.00007FF7C6BDF000.00000002.00000001.01000000.00000003.sdmpDownload File
Joe Sandbox IDA Plugin
  • Snapshot File: hcaresult_0_2_7ff7c6ba0000_SecuriteInfo.jbxd
Similarity
  • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_Yarn
  • String ID: bad locale name
  • API String ID: 1838369231-1405518554
  • Opcode ID: 9f2d4bba6482e44fbefb97c14935f5bc60200801a4d1a4bc911441947d06e13b
  • Instruction ID: 5aa2ea71c9b87da1723305f9b7c63afb7c5f80e3ad8df9650ca76b86f1555fd9
  • Opcode Fuzzy Hash: 9f2d4bba6482e44fbefb97c14935f5bc60200801a4d1a4bc911441947d06e13b
  • Instruction Fuzzy Hash: 6401A223105BC089C796EF74AD80159B7A5FB18B94B685138DB8C8370FEF38D491C350