Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
conhost.exe

Overview

General Information

Sample Name:conhost.exe
Analysis ID:599739
MD5:0d698af330fd17bee3bf90011d49251d
SHA1:52a7274a0b4f9493632060fe25993a2ef24fe827
SHA256:3c1c6d813d2b031d988204155fc198fe4f32ff56c05dabbcfcd5486131f4fb9d
Infos:

Detection

Score:5
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Sample file is different than original file name gathered from version info
PE file contains strange resources
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Uses code obfuscation techniques (call, push, ret)
PE file contains sections with non-standard names
Detected potential crypto function
Found potential string decryption / allocating functions
Contains functionality to call native functions
Contains functionality to communicate with device drivers
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Program does not show much activity (idle)

Classification

  • System is w10x64
  • conhost.exe (PID: 6744 cmdline: "C:\Users\user\Desktop\conhost.exe" -install MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • conhost.exe (PID: 6904 cmdline: "C:\Users\user\Desktop\conhost.exe" /install MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • conhost.exe (PID: 7008 cmdline: "C:\Users\user\Desktop\conhost.exe" /load MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: conhost.exeStatic PE information: GUARD_CF, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
Source: Binary string: conhost.pdbUGP source: conhost.exe
Source: Binary string: conhost.pdb source: conhost.exe
Source: conhost.exeBinary or memory string: OriginalFilename vs conhost.exe
Source: conhost.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: conhost.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: conhost.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D5C9D40_2_00007FF6A8D5C9D4
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CD8B000_2_00007FF6A8CD8B00
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CDAC100_2_00007FF6A8CDAC10
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D4ED000_2_00007FF6A8D4ED00
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CDA1900_2_00007FF6A8CDA190
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CD82B00_2_00007FF6A8CD82B0
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D627940_2_00007FF6A8D62794
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CE89300_2_00007FF6A8CE8930
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D2C8800_2_00007FF6A8D2C880
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D23C140_2_00007FF6A8D23C14
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D69B900_2_00007FF6A8D69B90
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CD9B700_2_00007FF6A8CD9B70
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D2DDF00_2_00007FF6A8D2DDF0
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CE7ED00_2_00007FF6A8CE7ED0
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D5DE7C0_2_00007FF6A8D5DE7C
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D53FF80_2_00007FF6A8D53FF8
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D6A0000_2_00007FF6A8D6A000
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D09FBC0_2_00007FF6A8D09FBC
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CDB1400_2_00007FF6A8CDB140
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D551400_2_00007FF6A8D55140
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CD73000_2_00007FF6A8CD7300
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D232900_2_00007FF6A8D23290
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D694180_2_00007FF6A8D69418
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D2D3A80_2_00007FF6A8D2D3A8
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D494E40_2_00007FF6A8D494E4
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CD56000_2_00007FF6A8CD5600
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CE75440_2_00007FF6A8CE7544
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CE76D80_2_00007FF6A8CE76D8
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D417F00_2_00007FF6A8D417F0
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D537640_2_00007FF6A8D53764
Source: C:\Users\user\Desktop\conhost.exeCode function: String function: 00007FF6A8D0C2DC appears 159 times
Source: C:\Users\user\Desktop\conhost.exeCode function: String function: 00007FF6A8D0C924 appears 130 times
Source: C:\Users\user\Desktop\conhost.exeCode function: String function: 00007FF6A8CE88EC appears 140 times
Source: C:\Users\user\Desktop\conhost.exeCode function: String function: 00007FF6A8D09F84 appears 177 times
Source: C:\Users\user\Desktop\conhost.exeCode function: String function: 00007FF6A8D089B0 appears 67 times
Source: C:\Users\user\Desktop\conhost.exeCode function: String function: 00007FF6A8CEE820 appears 53 times
Source: C:\Users\user\Desktop\conhost.exeCode function: String function: 00007FF6A8CDCD64 appears 386 times
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D56C78 NtAlpcSendWaitReceivePort,0_2_00007FF6A8D56C78
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CEC30C NtQueryVolumeInformationFile,0_2_00007FF6A8CEC30C
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D563D8 RtlCreateUnicodeString,AlpcInitializeMessageAttribute,NtAlpcConnectPort,AlpcGetMessageAttribute,AlpcGetMessageAttribute,NtAlpcQueryInformationMessage,memset,0_2_00007FF6A8D563D8
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CEAF14: DeviceIoControl,0_2_00007FF6A8CEAF14
Source: conhost.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\conhost.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\conhost.exe "C:\Users\user\Desktop\conhost.exe" -install
Source: unknownProcess created: C:\Users\user\Desktop\conhost.exe "C:\Users\user\Desktop\conhost.exe" /install
Source: unknownProcess created: C:\Users\user\Desktop\conhost.exe "C:\Users\user\Desktop\conhost.exe" /load
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D288B8 FindResourceExW,LoadResource,LockResource,memmove,0_2_00007FF6A8D288B8
Source: conhost.exeString found in binary or memory: <!--StartFragment -->
Source: conhost.exeString found in binary or memory: <!--StartFragment -->
Source: conhost.exeString found in binary or memory: onecore\windows\core\console\open\src\host\utils.cppStartEndUnknownTextUnit_CharacterTextUnit_FormatTextUnit_WordTextUnit_LineTextUnit_ParagraphTextUnit_PageTextUnit_DocumentUIA_AutomationFocusChangedEventIdNavigateDirection_FirstChildNavigateDirection_LastChildNavigateDirection_NextSiblingNavigateDirection_PreviousSiblingonecore\windows\core\console\open\src\host\registry.cpponecore\windows\core\console\open\src\host\ntprivapi.cppNtOpenProcessNtQueryInformationProcessNtCloseWriteCharsLegacy failed %xWriteCharsLegacy failed 0x%xonecore\windows\core\console\open\src\host\renderdata.cpponecore\windows\core\console\open\src\host\utf8towidecharparser.cpponecore\windows\core\console\open\src\host\conimeinfo.cpp"" invalid stoi argumentstoi argument out of rangeonecore\windows\core\console\open\src\host\commandnumberpopup.cpponecore\windows\core\console\open\src\host\commandlistpopup.cpp onecore\windows\core\console\open\src\host\exemain.cppConhostV1.dllConsoleCreateIoThreadonecore\windows\core\console\open\src\buffer\out\cursor.cpponecore\windows\core\console\open\src\buffer\out\textbuffer.cpp&lt;&gt;&amp;</TITLE></HEAD><BODY><!DOCTYPE><HTML><HEAD><TITLE><!--StartFragment --><DIV STYLE="display:inline-block;white-space:pre;background-color:;font-family:'',monospace;font-size:pt;padding:px;"><BR></SPAN><SPAN STYLE="color:</DIV><!--EndFragment --></BODY></HTML>Version:0.9
Source: conhost.exeBinary string: [25lonecore\windows\core\console\open\src\server\objectheader.cpponecore\windows\core\console\open\src\server\apimessage.cpponecore\windows\core\console\open\src\server\processhandle.cpponecore\windows\core\console\open\src\server\waitblock.cpponecore\windows\core\console\open\src\server\processpolicy.cpponecore\windows\core\console\open\src\server\iodispatchers.cpp\Device\ConDrv\Serveronecore\windows\core\console\open\src\server\winntcontrol.cpponecore\windows\core\console\open\src\interactivity\base\servicelocator.cpponecore\windows\core\console\open\src\interactivity\win32\uiatextrange.cpponecore\windows\core\console\open\src\interactivity\win32\accessibilitynotifier.cpponecore\windows\core\console\open\src\interactivity\win32\windowmetrics.cpponecore\windows\core\console\open\src\interactivity\win32\systemconfigurationprovider.cpponecore\windows\core\console\open\src\interactivity\win32\window.cpponecore\windows\core\console\open\src\interactivity\win32\windowio.cpponecore\windows\core\console\open\src\interactivity\win32\icon.cpponecore\windows\core\console\open\src\interactivity\win32\windowuiaprovider.cpponecore\windows\core\console\open\src\interactivity\win32\windowproc.cpponecore\windows\core\console\open\src\interactivity\win32\clipboard.cpponecore\windows\core\console\open\src\interactivity\win32\screeninfouiaprovider.cpponecore\windows\core\console\open\src\types\viewport.cpponecore\windows\core\console\open\src\types\convert.cpponecore\windows\core\console\open\src\types\utils.cpp
Source: classification engineClassification label: clean5.winEXE@3/0@0/0
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CD2C54 CoInitializeEx,CoCreateInstance,CoCreateInstance,0_2_00007FF6A8CD2C54
Source: conhost.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: conhost.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: conhost.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: conhost.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: conhost.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: conhost.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: conhost.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: conhost.exeStatic PE information: GUARD_CF, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
Source: conhost.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: conhost.pdbUGP source: conhost.exe
Source: Binary string: conhost.pdb source: conhost.exe
Source: conhost.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: conhost.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: conhost.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: conhost.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: conhost.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D9F330 push 00000009h; iretd 0_2_00007FF6A8D9F332
Source: conhost.exeStatic PE information: section name: .didat
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CDCEC8 GetCurrentThreadId,IsDebuggerPresent,OutputDebugStringW,0_2_00007FF6A8CDCEC8
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8D069FC GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,0_2_00007FF6A8D069FC
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CEE848 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF6A8CEE848
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CEF440 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6A8CEF440
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CEF638 SetUnhandledExceptionFilter,0_2_00007FF6A8CEF638
Source: C:\Users\user\Desktop\conhost.exeCode function: 0_2_00007FF6A8CEF2DC GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF6A8CEF2DC
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts2
Command and Scripting Interpreter
Path Interception1
Process Injection
1
Process Injection
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
Exfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Deobfuscate/Decode Files or Information
LSASS Memory2
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)2
Obfuscated Files or Information
Security Account Manager2
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 599739 Sample: conhost.exe Startdate: 30/03/2022 Architecture: WINDOWS Score: 5 4 conhost.exe 2->4         started        6 conhost.exe 2->6         started        8 conhost.exe 2->8         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
conhost.exe0%MetadefenderBrowse
conhost.exe0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:599739
Start date and time:2022-03-30 00:27:41 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 41s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:conhost.exe
Cookbook file name:default.jbs
Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
Run name:Cmdline fuzzy
Number of analysed new started processes analysed:27
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • HDC enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Detection:CLEAN
Classification:clean5.winEXE@3/0@0/0
EGA Information:Failed
HDC Information:
  • Successful, ratio: 97.3% (good quality ratio 64.5%)
  • Quality average: 45.5%
  • Quality standard deviation: 39.8%
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 243
Cookbook Comments:
  • Adjust boot time
  • Enable AMSI
  • Found application associated with file extension: .exe
  • Excluded IPs from analysis (whitelisted): 23.211.6.115
  • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, ctldl.windowsupdate.com, settings-win.data.microsoft.com, store-images.s-microsoft.com-c.edgekey.net, arc.msn.com, ris.api.iris.microsoft.com, e12564.dspb.akamaiedge.net, go.microsoft.com, store-images.s-microsoft.com, sls.update.microsoft.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net
  • Execution Graph export aborted for target conhost.exe, PID 6744 because there are no executed function
  • Not all processes where analyzed, report is missing behavior information
  • VT rate limit hit for: conhost.exe
No simulations
No context
No context
No context
No context
No context
No created / dropped files found
File type:PE32+ executable (GUI) x86-64, for MS Windows
Entropy (8bit):6.389554828127213
TrID:
  • Win64 Executable GUI (202006/5) 86.49%
  • Win 9x/ME Control Panel applet (15529/13) 6.65%
  • Win64 Executable (generic) (12005/4) 5.14%
  • Generic Win/DOS Executable (2004/3) 0.86%
  • DOS Executable Generic (2002/1) 0.86%
File name:conhost.exe
File size:862208
MD5:0d698af330fd17bee3bf90011d49251d
SHA1:52a7274a0b4f9493632060fe25993a2ef24fe827
SHA256:3c1c6d813d2b031d988204155fc198fe4f32ff56c05dabbcfcd5486131f4fb9d
SHA512:298ec9d63b9bfa84c07bd32827ab5d3985da8d955cf4f36018ce6994768e37715df3603edd4eca2c68a80089d4a4ed184550ec4936b7ddc55e100ff6e4d67c71
SSDEEP:12288:ac4SbTjKm3X608EWSEa9oTGdVgmq2h6vYpz6wJapK:8cpa08VS5/VVh8YpzbJeK
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PWg..6...6...6...N..p6...]...6...]...6...6...3...]...6...]...6...]..26...]...6...]...6...]...6..Rich.6..........PE..d....K.V...
Icon Hash:b0ef7ac32101a5a0
Entrypoint:0x14001e7f0
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x140000000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:GUARD_CF, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
Time Stamp:0x56B24BE3 [Wed Feb 3 18:50:11 2016 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:10
OS Version Minor:0
File Version Major:10
File Version Minor:0
Subsystem Version Major:10
Subsystem Version Minor:0
Import Hash:c21b297aeb85cef1bcce8d72106bbdd0
Instruction
dec eax
sub esp, 28h
call 00007FF7C4726B58h
dec eax
add esp, 28h
jmp 00007FF7C4725EE3h
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
nop word ptr [eax+eax+00000000h]
dec eax
cmp ecx, dword ptr [000A2A51h]
jne 00007FF7C4726085h
dec eax
rol ecx, 10h
test cx, FFFFh
jne 00007FF7C4726075h
ret
dec eax
ror ecx, 10h
jmp 00007FF7C47260E4h
int3
int3
int3
int3
int3
int3
int3
inc eax
push ebx
dec eax
sub esp, 20h
dec eax
mov ebx, ecx
call dword ptr [0007F6F9h]
mov ecx, 00000001h
mov dword ptr [000A311Eh], eax
call 00007FF7C4726C3Eh
xor ecx, ecx
call dword ptr [0007F721h]
dec eax
mov ecx, ebx
call dword ptr [0007F720h]
cmp dword ptr [000A3101h], 00000000h
jne 00007FF7C472607Ch
mov ecx, 00000001h
call 00007FF7C4726C1Ah
call dword ptr [0007F937h]
dec eax
mov ecx, eax
mov edx, C0000409h
dec eax
add esp, 20h
pop ebx
dec eax
jmp dword ptr [0007F943h]
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
int3
dec eax
mov dword ptr [esp+08h], ecx
dec eax
sub esp, 00000000h
Programming Language:
  • [IMP] VS2008 SP1 build 30729
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0xbc1c80x3e8.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0xd00000x86a0.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0xc50000x9678.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0xd90000xd9c.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0xa30d00x70.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x9d1800x28.rdata
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x9c8f00x118.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x9df100xa30.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0xba5800x6c0.rdata
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x993900x99400False0.515809798124data6.32206951087IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
.rdata0x9b0000x245620x24600False0.407854112973data5.69606443901IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0xc00000x48a80x1400False0.2412109375data3.23312444263IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
.pdata0xc50000x96780x9800False0.510665090461data5.99032109009IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.didat0xcf0000x6080x800False0.224609375Dyalog APL DFS component file 64-bit level 3 journaled checksummed version 2.642.45356820095IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
.rsrc0xd00000x86a00x8800False0.285874310662data4.38933989252IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0xd90000xd9c0xe00False0.364397321429data5.41339750422IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountry
MUI0xd85c80xd8dataEnglishUnited States
RT_ICON0xd09b00x668dataEnglishUnited States
RT_ICON0xd10180x2e8dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 356432, next used block 458800EnglishUnited States
RT_ICON0xd13000x128GLS_BINARY_LSB_FIRSTEnglishUnited States
RT_ICON0xd14280xea8dataEnglishUnited States
RT_ICON0xd22d00x8a8dBase IV DBT of @.DBF, block length 1024, next free block index 40, next free block 0, next used block 0EnglishUnited States
RT_ICON0xd2b780x568GLS_BINARY_LSB_FIRSTEnglishUnited States
RT_ICON0xd30e00x169ePNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States
RT_ICON0xd47800x25a8dataEnglishUnited States
RT_ICON0xd6d280x10a8dataEnglishUnited States
RT_ICON0xd7dd00x468GLS_BINARY_LSB_FIRSTEnglishUnited States
RT_GROUP_ICON0xd82380x92dataEnglishUnited States
RT_VERSION0xd06200x38cdataEnglishUnited States
RT_MANIFEST0xd03800x29dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States
RT_MANIFEST0xd82d00x2f4XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States
DLLImport
msvcp_win.dll?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ, ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z, ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ, ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ, ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ, ?width@ios_base@std@@QEBA_JXZ, ?width@ios_base@std@@QEAA_J_J@Z, ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z, ?good@ios_base@std@@QEBA_NXZ, ?uncaught_exception@std@@YA_NXZ, ?flags@ios_base@std@@QEBAHXZ, ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ, ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ, ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z, ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ, ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ, ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ, ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z, ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ, ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ, ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ?_Xlength_error@std@@YAXPEBD@Z, ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z, ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z, ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z, ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z, ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z, ?setf@ios_base@std@@QEAAHHH@Z, ?setf@ios_base@std@@QEAAHH@Z, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@F@Z, ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z, ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ, ?tellp@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z, ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAADD@Z, ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z, ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z, ?_Xout_of_range@std@@YAXPEBD@Z, ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z, ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ, ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ, ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ, ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z, ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ, ?_Xbad_function_call@std@@YAXXZ, ?_Xinvalid_argument@std@@YAXPEBD@Z, ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z, _Mtx_destroy_in_situ, _Mtx_unlock, ?_Throw_C_error@std@@YAXH@Z, _Mtx_lock, _Mtx_init_in_situ, ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
api-ms-win-crt-time-l1-1-0.dll_time64
api-ms-win-crt-runtime-l1-1-0.dll_initterm, _initterm_e, _register_thread_local_exe_atexit_callback, _c_exit
api-ms-win-crt-private-l1-1-0.dll_o__get_wide_winmain_command_line, _o__initialize_onexit_table, _o__initialize_wide_environment, _o__invalid_parameter_noinfo, _o__invalid_parameter_noinfo_noreturn, _o__itoa_s, _o__purecall, _o__register_onexit_function, _o__seh_filter_exe, _o__set_app_type, _o__set_fmode, _o__set_new_mode, memmove, _o__wcsicmp, _o__wcsnicmp, _o_calloc, _o_exit, _o_floor, _o_free, _o_iswdigit, _o_iswspace, _o_malloc, _o_roundf, _o_sqrt, _o_terminate, _o_towlower, _o_towupper, _o_wcscpy_s, _o_wcstol, _o_wcstoul, __C_specific_handler, __CxxFrameHandler3, _CxxThrowException, _o__cexit, _o__callnewh, _o__exit, _o__errno, _o___stdio_common_vswprintf_s, _o___stdio_common_vswprintf, _o___stdio_common_vsprintf_s, _o___stdio_common_vsprintf, _o___stdio_common_vsnwprintf_s, _o___stdio_common_vsnprintf_s, _o___std_exception_destroy, _o___std_exception_copy, _o__crt_atexit, _o___p__commode, _o__configure_wide_argv, __std_terminate, __CxxFrameHandler4, _o__configthreadlocale, memcmp, memcpy, wcschr
api-ms-win-crt-string-l1-1-0.dllwcsncmp, wcscmp, memset, wcsnlen
api-ms-win-core-libraryloader-l1-2-0.dllLoadResource, FreeLibrary, GetModuleFileNameW, LockResource, GetModuleHandleExW, LoadLibraryExW, FindResourceExW, GetModuleHandleW, GetProcAddress, GetModuleFileNameA, LoadStringW
api-ms-win-core-synch-l1-1-0.dllCreateEventW, InitializeCriticalSectionAndSpinCount, EnterCriticalSection, LeaveCriticalSection, TryEnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, CreateMutexExW, OpenSemaphoreW, WaitForSingleObjectEx, ResetEvent, ReleaseMutex, SetEvent, WaitForSingleObject, CreateSemaphoreExW, ReleaseSemaphore, CreateEventExW, ReleaseSRWLockShared, AcquireSRWLockShared, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, InitializeCriticalSectionEx
api-ms-win-core-heap-l1-1-0.dllGetProcessHeap, HeapFree, HeapAlloc
api-ms-win-core-errorhandling-l1-1-0.dllSetUnhandledExceptionFilter, UnhandledExceptionFilter, GetLastError, SetLastError
api-ms-win-core-processthreads-l1-1-0.dllGetCurrentProcessId, UpdateProcThreadAttribute, GetCurrentThread, DeleteProcThreadAttributeList, CreateProcessW, GetProcessTimes, GetStartupInfoW, GetCurrentThreadId, GetCurrentProcess, OpenProcessToken, SetProcessShutdownParameters, ExitThread, TerminateProcess, CreateThread, InitializeProcThreadAttributeList
api-ms-win-core-localization-l1-2-0.dllFormatMessageW, GetACP, GetOEMCP, GetCPInfo, IsValidCodePage, GetUserDefaultLocaleName
api-ms-win-core-debug-l1-1-0.dllDebugBreak, IsDebuggerPresent, OutputDebugStringW, OutputDebugStringA
api-ms-win-core-handle-l1-1-0.dllDuplicateHandle, CloseHandle
api-ms-win-core-threadpool-legacy-l1-1-0.dllDeleteTimerQueueTimer, CreateTimerQueueTimer, DeleteTimerQueueEx, CreateTimerQueue
api-ms-win-core-file-l1-1-0.dllWriteFile, ReadFile
api-ms-win-core-sidebyside-l1-1-0.dllCreateActCtxW
api-ms-win-core-processenvironment-l1-1-0.dllGetCommandLineW, GetEnvironmentVariableW, ExpandEnvironmentStringsW, SearchPathW, GetStdHandle, SetEnvironmentVariableW
api-ms-win-core-registry-l1-1-0.dllRegGetValueW, RegCloseKey, RegEnumValueW, RegOpenKeyExW, RegQueryValueExW, RegOpenCurrentUser
api-ms-win-core-string-l1-1-0.dllMultiByteToWideChar, WideCharToMultiByte, GetStringTypeW, CompareStringOrdinal
api-ms-win-core-sysinfo-l1-1-0.dllGetSystemTimeAsFileTime, GetWindowsDirectoryW, GetSystemDirectoryW
api-ms-win-core-threadpool-l1-2-0.dllCreateThreadpoolTimer, SetThreadpoolTimer, WaitForThreadpoolTimerCallbacks, CloseThreadpoolTimer
api-ms-win-eventing-provider-l1-1-0.dllEventWriteTransfer, EventActivityIdControl, EventSetInformation, EventRegister, EventUnregister
api-ms-win-core-psapi-l1-1-0.dllQueryFullProcessImageNameW
api-ms-win-core-shlwapi-legacy-l1-1-0.dllPathFileExistsW, PathFindFileNameW, PathIsSameRootW
api-ms-win-shcore-obsolete-l1-1-0.dllCommandLineToArgvW
api-ms-win-core-heap-l2-1-0.dllGlobalAlloc, GlobalFree, LocalFree
ntdll.dllRtlFreeHeap, RtlAllocateHeap, RtlQueryPackageClaims, NtQueryVolumeInformationFile, CsrClientCallServer, NtAlpcSendWaitReceivePort, NtAlpcQueryInformationMessage, AlpcGetMessageAttribute, AlpcInitializeMessageAttribute, RtlCreateUnicodeString, NtAlpcConnectPort
api-ms-win-core-rtlsupport-l1-1-0.dllRtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind
api-ms-win-core-processthreads-l1-1-1.dllIsProcessorFeaturePresent, OpenProcess
api-ms-win-core-profile-l1-1-0.dllQueryPerformanceCounter
api-ms-win-core-interlocked-l1-1-0.dllInitializeSListHead
api-ms-win-core-registry-l2-1-0.dllRegCreateKeyW, RegOpenKeyW
api-ms-win-core-synch-l1-2-0.dllSignalObjectAndWait, Sleep
api-ms-win-core-io-l1-1-0.dllDeviceIoControl
api-ms-win-core-libraryloader-l1-2-1.dllLoadLibraryW
api-ms-win-core-com-l1-1-0.dllCoTaskMemFree, CoCreateInstance, CoInitializeEx, CoUninitialize
api-ms-win-core-heap-obsolete-l1-1-0.dllGlobalSize, GlobalLock, GlobalUnlock
api-ms-win-core-io-l1-1-1.dllCancelSynchronousIo
api-ms-win-core-util-l1-1-0.dllBeep
api-ms-win-core-apiquery-l1-1-0.dllApiSetQueryApiSetPresence
api-ms-win-security-base-l1-1-0.dllGetSidSubAuthority, GetTokenInformation, GetSidSubAuthorityCount
api-ms-win-core-path-l1-1-0.dllPathCchRemoveExtension
api-ms-win-shell-shellcom-l1-1-0.dllSHCoCreateInstance
api-ms-win-core-sysinfo-l1-2-0.dllVerSetConditionMask
api-ms-win-core-kernel32-legacy-l1-1-1.dllVerifyVersionInfoW
api-ms-win-core-largeinteger-l1-1-0.dllMulDiv
api-ms-win-core-delayload-l1-1-1.dllResolveDelayLoadedAPI
api-ms-win-core-delayload-l1-1-0.dllDelayLoadFailureHook
api-ms-win-crt-math-l1-1-0.dllceilf
DescriptionData
LegalCopyright Microsoft Corporation. All rights reserved.
InternalNameConHost
FileVersion10.0.19041.1566 (WinBuild.160101.0800)
CompanyNameMicrosoft Corporation
ProductNameMicrosoft Windows Operating System
ProductVersion10.0.19041.1566
FileDescriptionConsole Window Host
OriginalFilenameCONHOST.EXE
Translation0x0409 0x04b0
Language of compilation systemCountry where language is spokenMap
EnglishUnited States
No network behavior found

Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:02:28:44
Start date:30/03/2022
Path:C:\Users\user\Desktop\conhost.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\conhost.exe" -install
Imagebase:0x7ff6a8cd0000
File size:862208 bytes
MD5 hash:0D698AF330FD17BEE3BF90011D49251D
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low

Target ID:3
Start time:02:28:47
Start date:30/03/2022
Path:C:\Users\user\Desktop\conhost.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\conhost.exe" /install
Imagebase:0x7ff6a8cd0000
File size:862208 bytes
MD5 hash:0D698AF330FD17BEE3BF90011D49251D
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low

Target ID:5
Start time:02:28:49
Start date:30/03/2022
Path:C:\Users\user\Desktop\conhost.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\conhost.exe" /load
Imagebase:0x7ff6a8cd0000
File size:862208 bytes
MD5 hash:0D698AF330FD17BEE3BF90011D49251D
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low

Reset < >
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CloseHandle
    • String ID: %WINDIR%\system32\cmd.exe$\Device\ConDrv\Server$\Input$\Output$\Reference$onecore\windows\core\console\open\src\server\entrypoints.cpp
    • API String ID: 2962429428-1317094634
    • Opcode ID: c501041c74b32eee37d382e84e7065e6698aea19266817f6b9233676b42c50b1
    • Instruction ID: 5349c40485335226247028be01ff72d55f0598c84b1a749d34f1feebb9e76e09
    • Opcode Fuzzy Hash: c501041c74b32eee37d382e84e7065e6698aea19266817f6b9233676b42c50b1
    • Instruction Fuzzy Hash: ED22853161AA8296E710AB35E8406FDB760FB857A8F509331DA6DC7AE9DF3CD108C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate$Xout_of_range@std@@
    • String ID: $ $CONSRV: Ignoring backspace to previous line$invalid deque<T> subscript$invalid string_view position$onecore\windows\core\console\open\src\host\_stream.cpp$onecore\windows\core\console\open\src\types\codepointwidthdetector.cpp
    • API String ID: 4238520144-3798436871
    • Opcode ID: 0950437b91d533fd9bbc9c55d0f2176b41683372f4e4386d209609acd6daff0b
    • Instruction ID: 70361784c2e94fb531902d7820a4729798ff79bdcc98a4eb1914d4a431a5d9d5
    • Opcode Fuzzy Hash: 0950437b91d533fd9bbc9c55d0f2176b41683372f4e4386d209609acd6daff0b
    • Instruction Fuzzy Hash: CE036C2691DBC581E6719B28E0403FAB7B0FF95784F049125EA8E83B69EF3DD585CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@_o_terminate
    • String ID: VUUUUUUU$invalid deque<T> subscript$invalid unordered_map<K, T> key$invalid vector<T> subscript$onecore\windows\core\console\open\src\buffer\out\textbuffercelliterator.cpp$onecore\windows\core\console\open\src\server\apimessage.cpp$onecore\windows\core\console\open\src\server\devicecomm.cpp
    • API String ID: 1206583107-2403402179
    • Opcode ID: d32bed2b4e656c31f9280c3f712e0eb8f3a632f79e9116dff5effd5680a1a04a
    • Instruction ID: 2ba6743065ed48b07c4779b3a83a8e467b8421c765cda2ab836c39cbaa07acb4
    • Opcode Fuzzy Hash: d32bed2b4e656c31f9280c3f712e0eb8f3a632f79e9116dff5effd5680a1a04a
    • Instruction Fuzzy Hash: 6D12AE22A1AB8582EB14EB79E0401BC73B1FF54B88B548636DE4E87B55EF3CE554C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: VUUUUUUU$invalid deque<T> subscript$invalid unordered_map<K, T> key$invalid vector<T> subscript$onecore\windows\core\console\open\src\buffer\out\textbuffercelliterator.cpp$onecore\windows\core\console\open\src\host\screeninfo.cpp$onecore\windows\core\console\open\src\types\convert.cpp
    • API String ID: 1960685668-1255646998
    • Opcode ID: 5fdc4394d7d241bc792635dae1afe1c32e8852194a1abdbdcb220716ab368993
    • Instruction ID: 429af8a270ef6e66737d47f36b28cf8bb96236c34fd4d55aa0f6a0a42e6c2715
    • Opcode Fuzzy Hash: 5fdc4394d7d241bc792635dae1afe1c32e8852194a1abdbdcb220716ab368993
    • Instruction Fuzzy Hash: F132C426A1AB8681FE24EB25D0503B963B1FF94B80F548136DA4F87B95EF3CE544C708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: VUUUUUUU$VUUUUUUU$VUUUUUUU$invalid string_view position$invalid vector<T> subscript$onecore\windows\core\console\open\src\buffer\out\charrow.cpp$onecore\windows\core\console\open\src\buffer\out\charrowcellreference.cpp$onecore\windows\core\console\open\src\buffer\out\outputcelliterator.cpp$onecore\windows\core\console\open\src\buffer\out\row.cpp$onecore\windows\core\console\open\src\types\codepointwidthdetector.cpp
    • API String ID: 1960685668-845067340
    • Opcode ID: 3f640ed0b66f960cb40a73f37c9994cac538498bb11d00aaf311aca8a3195bdb
    • Instruction ID: d2a044779bf0313920ff151fd7ce3ebb1f8c5bfbc90e3c8b32f057df751e2231
    • Opcode Fuzzy Hash: 3f640ed0b66f960cb40a73f37c9994cac538498bb11d00aaf311aca8a3195bdb
    • Instruction Fuzzy Hash: 2452F362E1AB8596F715AF34C1042FC23B1FF55788F008232DE5E97A96DF28E599C708
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: VUUUUUUU$invalid deque<T> subscript$invalid unordered_map<K, T> key$invalid vector<T> subscript$onecore\windows\core\console\open\src\buffer\out\textbuffercelliterator.cpp$onecore\windows\core\console\open\src\renderer\base\renderer.cpp
    • API String ID: 0-1200157833
    • Opcode ID: 329cc6d53f6938404d283299daf77ff199d51be0a844fb151f9a7f0972b5883d
    • Instruction ID: aafc51d2820eff0a01354e53bf7fc7dfaad9c79479bd051eb36d5780940e8816
    • Opcode Fuzzy Hash: 329cc6d53f6938404d283299daf77ff199d51be0a844fb151f9a7f0972b5883d
    • Instruction Fuzzy Hash: D462CA26A1AB9589EB209F35D8402FD37B0FF95B88F545122EE8E87B58DF38D544CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: invalid deque<T> subscript$onecore\windows\core\console\open\src\host\_stream.cpp
    • API String ID: 1960685668-3945297005
    • Opcode ID: d0b6acff23520263dd0f28429f46088fb322b13c779c6a4e90939fc263570e0a
    • Instruction ID: 364c977b516e5ff602c94169fbcdeabd2e459bf365f8049ff1fca927a0bce409
    • Opcode Fuzzy Hash: d0b6acff23520263dd0f28429f46088fb322b13c779c6a4e90939fc263570e0a
    • Instruction Fuzzy Hash: 97726F26A1E78585EA209B31E0403BAB7B0FF95B44F505136EB8E83B59EF3CD554CB09
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_delete
    • String ID: onecore\windows\core\console\open\src\host\readdatacooked.cpp$onecore\windows\core\console\open\src\server\objecthandle.cpp
    • API String ID: 3712186324-2221960914
    • Opcode ID: 159edfe88807fa8c34d8266bf0ee4b9a86081ca9baeb7c4ceb8ae74958856593
    • Instruction ID: 9269732d2c2cc1a0f3c30b135cf98fa6229a63b5ef45a3d62c317931551bcc32
    • Opcode Fuzzy Hash: 159edfe88807fa8c34d8266bf0ee4b9a86081ca9baeb7c4ceb8ae74958856593
    • Instruction Fuzzy Hash: 17D1A372A0AB8582DB20FB75E04127EA770FB45B94F045235DBAE83B96DF6DE444C708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Library$Loadmemset$AddressCriticalDirectoryEnterFreeProcSectionSystem
    • String ID: .\console.dll$CPlApplet$\console.dll$onecore\windows\core\console\open\src\interactivity\win32\menu.cpp
    • API String ID: 3929820730-1215343536
    • Opcode ID: 1cae74b71a0057d1e2d219ba1b77a798f0040a11e84e36d459c6130a28f41f6b
    • Instruction ID: 1f49bdf12ecdd978fe1d6c92d2d5fb7bd1977b5ece5190b2fea808fa860115cd
    • Opcode Fuzzy Hash: 1cae74b71a0057d1e2d219ba1b77a798f0040a11e84e36d459c6130a28f41f6b
    • Instruction Fuzzy Hash: D371D262B5A75286FB58AB75D810AB92BA1FF85B44F444232DD2E87784DF3CE50CC708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ByteCharMultiWide$_o_terminate$memset
    • String ID: onecore\windows\core\console\open\src\renderer\gdi\math.cpp$onecore\windows\core\console\open\src\renderer\gdi\paint.cpp
    • API String ID: 2157953957-3378245266
    • Opcode ID: 5559cb429cc5a9a7470da23f3813218801cf963b186b8411021a95eb2df578fd
    • Instruction ID: 852180f26582f5d391843afe83eb602dd4dd9def18f8678d2a7af7bd0404e425
    • Opcode Fuzzy Hash: 5559cb429cc5a9a7470da23f3813218801cf963b186b8411021a95eb2df578fd
    • Instruction Fuzzy Hash: 4DD1C632A0A78682E724EB21E44077A77B4FB85B84F108235EA5ED3795DF3DD549CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\interactivity\win32\systemconfigurationprovider.cpp, xrefs: 00007FF6A8CE81DD
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memset$Path$CodeExistsFileInitializePageSearchUninitializeValid
    • String ID: onecore\windows\core\console\open\src\interactivity\win32\systemconfigurationprovider.cpp
    • API String ID: 1996372929-2568609167
    • Opcode ID: 8af6ace75dc8d4f51f39af88f2d43aa20b2d85a31ed6939893a983097ea072d8
    • Instruction ID: 47781c222159d2cc02379351bdc14f691975fe0a0191ba9fa03cd67c1a95779f
    • Opcode Fuzzy Hash: 8af6ace75dc8d4f51f39af88f2d43aa20b2d85a31ed6939893a983097ea072d8
    • Instruction Fuzzy Hash: E091A47261AB8286E720DF31E8412AA77B1FF86B94F404235DA5E87B94DF3CD644CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Alpc$Message$Attribute$ConnectCreateInformationInitializePortQueryStringUnicodememset
    • String ID: \ConsoleInputServerPort
    • API String ID: 1000960221-2084386880
    • Opcode ID: d99be3fc26456ed4dbf885b09ed5abafdccd1e486e95201518d41fc6ce491c29
    • Instruction ID: efe8a864bf312be2305c27e43313a60152a8f6587b317274babc85a3a0c93219
    • Opcode Fuzzy Hash: d99be3fc26456ed4dbf885b09ed5abafdccd1e486e95201518d41fc6ce491c29
    • Instruction Fuzzy Hash: C5514732A15B51CAE710DF60E8807AE77B4FB49748F900226EF9997B08DF38D558CB44
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
    • String ID:
    • API String ID: 313767242-0
    • Opcode ID: 505be5050e45fac1d2bd8b48167c0143024233ccc3450512102eb2f5365156cd
    • Instruction ID: debed19b4e8d9a440461d4740e5f680455f3fcbac7e53397e3beb2eadaca6b52
    • Opcode Fuzzy Hash: 505be5050e45fac1d2bd8b48167c0143024233ccc3450512102eb2f5365156cd
    • Instruction Fuzzy Hash: 27317E7261AB858AEB609F70E8403ED3370FB95748F44453ADA4E87B98DF38C648CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CEEE2C: _o_malloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8CDE93E,?,?,?,?,00007FF6A8D0931C,?,?,?,?,?,?,?), ref: 00007FF6A8CEEE46
      • Part of subcall function 00007FF6A8CE8604: memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8CE868B
      • Part of subcall function 00007FF6A8CE7AB8: LoadLibraryExW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CE7AE2
      • Part of subcall function 00007FF6A8CE79E8: GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CE7A18
    • FreeLibrary.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CE7993
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Library$AddressFreeLoadProc_o_mallocmemset
    • String ID: ($ConsoleWindowClass$CreateWindow failed with gle = 0x%x$onecore\windows\core\console\open\src\interactivity\win32\window.cpp$onecore\windows\core\console\open\src\renderer\dx\dxrenderer.cpp
    • API String ID: 1844532708-1952155981
    • Opcode ID: 6506f003f8fa4317ebf09d0979ed1918bd008f8104ac67c757e8157110f647c4
    • Instruction ID: e0800b7db372eb4ea8c237c5d7b63c9301a4a41fdbd15c5f82f5c3dbdf6463d3
    • Opcode Fuzzy Hash: 6506f003f8fa4317ebf09d0979ed1918bd008f8104ac67c757e8157110f647c4
    • Instruction Fuzzy Hash: BAC19132A0A78286E760EB75E4517BA77A4FB86744F408235DA9E83B55DF3CE448CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\host\inputreadhandledata.cpp, xrefs: 00007FF6A8D2330D
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_deletememmove
    • String ID: onecore\windows\core\console\open\src\host\inputreadhandledata.cpp
    • API String ID: 36335320-3387545977
    • Opcode ID: 9bb7836af647ab1899944e9f98417e1b11198e6cfc3874a8e0800f29a043d07f
    • Instruction ID: 57705181e1e38c818fca28961a5a3c828d3d9f38bf2a84a94e17361fd2e45124
    • Opcode Fuzzy Hash: 9bb7836af647ab1899944e9f98417e1b11198e6cfc3874a8e0800f29a043d07f
    • Instruction Fuzzy Hash: D5910072B1E78182EB64EF31A0416BA67A0FB55B80F484175EF9E83B55EE3CE059C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Create$Event$ErrorLastThread
    • String ID:
    • API String ID: 933546937-0
    • Opcode ID: 424e89d14e6528be1de5798a1b171673b5db04e644939060b024e64d6a84af77
    • Instruction ID: bf20a96d85b1e253c39a3cdaf9b73db7fe0536ae5c8ba44a05f78e6d02951742
    • Opcode Fuzzy Hash: 424e89d14e6528be1de5798a1b171673b5db04e644939060b024e64d6a84af77
    • Instruction Fuzzy Hash: 31319236A0AB6387F714AF75B44527A7AB0FB49705F448634DA4E82740EF7CE0188B48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Heap$Free$AllocateSleepmemset
    • String ID: Courier New$en-us
    • API String ID: 1592316401-2224409271
    • Opcode ID: b62daf3406f1742635d60fdf494bc696493cbefaf21b269a49961dbb62b2f299
    • Instruction ID: 17faf734070e2008df3bc4a1163d39b373701d54f3f74f8ccb0f48515bd80da9
    • Opcode Fuzzy Hash: b62daf3406f1742635d60fdf494bc696493cbefaf21b269a49961dbb62b2f299
    • Instruction Fuzzy Hash: 2F91AD32B26B0A96EB00EF36D4402A877A1FB89B98F555332DE0D87324DF39E449C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalEnterSection
    • String ID: onecore\windows\core\console\open\src\interactivity\win32\windowproc.cpp$~
    • API String ID: 1904992153-736058143
    • Opcode ID: e38223a1ff6fffaefafb6de79afa826a019c5f750b6887194eafad338808efe4
    • Instruction ID: e2425ee7772dc91a679e391ace56650d5bb1ca11d9eb5e469ca26a3aabdefc28
    • Opcode Fuzzy Hash: e38223a1ff6fffaefafb6de79afa826a019c5f750b6887194eafad338808efe4
    • Instruction Fuzzy Hash: 11729D21A4E64287E724AB35E4402BEAAF1FF95740F504136EA5EC7B96DF3CE4458F08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D29BC4: memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8D29C06
      • Part of subcall function 00007FF6A8D29BC4: _vswprintf_c.LEGACY_STDIO_DEFINITIONS ref: 00007FF6A8D29C1B
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,00000000,?,00000000,?,onecore\windows\core\console\open\src\server\objecthandle.cpp,?,00007FF6A8D2E430), ref: 00007FF6A8D2D7C3
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,00000000,?,00000000,?,onecore\windows\core\console\open\src\server\objecthandle.cpp,?,00007FF6A8D2E430), ref: 00007FF6A8D2D8C4
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove$_vswprintf_cmemset
    • String ID: WriteCharsLegacy failed %x$WriteCharsLegacy failed 0x%x$onecore\windows\core\console\open\src\host\readdatacooked.cpp$onecore\windows\core\console\open\src\server\objecthandle.cpp
    • API String ID: 1118619546-1833037669
    • Opcode ID: d1b46c24b7e73d40d7927902b5a3a50ed45ff9264eee8ae2bffc4366f978fad5
    • Instruction ID: 801b3d8ffd74ec8a47bfc3d0a06ac21ef164bea8fc57627293f71a799927831a
    • Opcode Fuzzy Hash: d1b46c24b7e73d40d7927902b5a3a50ed45ff9264eee8ae2bffc4366f978fad5
    • Instruction Fuzzy Hash: D822DD72A1A79586EB50AF31C0402AD3BB4FB04B9CF105236EE5D97399EF38D895C358
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\buffer\out\attrrow.cpp, xrefs: 00007FF6A8CFF8D0
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove
    • String ID: onecore\windows\core\console\open\src\buffer\out\attrrow.cpp
    • API String ID: 2162964266-2351056112
    • Opcode ID: 8ab6519550dbf1876f9b3e4a456354b6466b6947ae094de412daa71261f477c2
    • Instruction ID: 98a4d65cba7abd99da2e63c44f9ac39380da714ea37a73f993bc611f9108a880
    • Opcode Fuzzy Hash: 8ab6519550dbf1876f9b3e4a456354b6466b6947ae094de412daa71261f477c2
    • Instruction Fuzzy Hash: 24C103A3E1AB9185FB10DFB6D4000BD37F1EB1AB847948032DE9E97686DF28D542D714
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CE82A8: _Init_thread_footer.LIBCMT ref: 00007FF6A8CE82F0
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,00000001,00007FF6A8D54050), ref: 00007FF6A8D53913
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?,?,?,00000001,00007FF6A8D54050), ref: 00007FF6A8D539F7
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?,?,?,00000001,00007FF6A8D54050), ref: 00007FF6A8D5395D
      • Part of subcall function 00007FF6A8D51D48: memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8D53A30,?,?,?,?,?,?,?,?,00000001,00007FF6A8D54050), ref: 00007FF6A8D51D70
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memset$Init_thread_footermemcpymemmove
    • String ID: onecore\windows\core\console\open\src\interactivity\win32\menu.cpp
    • API String ID: 119229397-2952571135
    • Opcode ID: 1ff5c6e79c14b3ba78e9d642f09bea4edd0e528ce4c136137aa241beb58ca3bf
    • Instruction ID: bf26fc6369d67cfb6b753663cb86fdd92d86432f273dcfc54eaf7b80a4bcc99f
    • Opcode Fuzzy Hash: 1ff5c6e79c14b3ba78e9d642f09bea4edd0e528ce4c136137aa241beb58ca3bf
    • Instruction Fuzzy Hash: 1BA19076A0A7829BE748EF35D9506A877A0FB48740F044236DA6DC7B91DF3CE469CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • FindResourceExW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,00000001,00007FF6A8D28686), ref: 00007FF6A8D28901
    • LoadResource.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,00000001,00007FF6A8D28686), ref: 00007FF6A8D28918
    • LockResource.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,00000001,00007FF6A8D28686), ref: 00007FF6A8D2892C
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000001,00007FF6A8D28686), ref: 00007FF6A8D2896F
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Resource$FindLoadLockmemmove
    • String ID:
    • API String ID: 3479116980-0
    • Opcode ID: 03a70a9fcac64f895ad44122824d301a3da115f73c48bfdbc1d39a8e41d8be62
    • Instruction ID: 9d3d072660281f46b6b01c1829fbf2aa3b68730b6a98efbd207b9f8d0ba4b5fb
    • Opcode Fuzzy Hash: 03a70a9fcac64f895ad44122824d301a3da115f73c48bfdbc1d39a8e41d8be62
    • Instruction Fuzzy Hash: E62108B1F06B8186EF506F259040139A6A0FF89FD0B588274DE5D93791EF3CE414C304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • IsDebuggerPresent.API-MS-WIN-CORE-DEBUG-L1-1-0(?,?,?,00007FF6A8CEE97D), ref: 00007FF6A8CEE851
    • SetUnhandledExceptionFilter.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,00007FF6A8CEE97D), ref: 00007FF6A8CEE869
    • UnhandledExceptionFilter.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,00007FF6A8CEE97D), ref: 00007FF6A8CEE872
    • GetCurrentProcess.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,?,00007FF6A8CEE97D), ref: 00007FF6A8CEE88B
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ExceptionFilterUnhandled$CurrentDebuggerPresentProcess
    • String ID:
    • API String ID: 2506494423-0
    • Opcode ID: 6c073b8aca7d0d20754044302a4e09bc63205a32a496e7eddbb327b1db8189ba
    • Instruction ID: f8c320485c9b6a1602b3d858742354e31314879ce6901c4e16e45afa9a61bc54
    • Opcode Fuzzy Hash: 6c073b8aca7d0d20754044302a4e09bc63205a32a496e7eddbb327b1db8189ba
    • Instruction Fuzzy Hash: 17F06530D2B60686F7543B71B8152343220AF55748F040634D92FC5691DF7D648D8708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetProcessHeap.API-MS-WIN-CORE-HEAP-L1-1-0(?,?,00000078,00007FF6A8D06807,?,?,?,00007FF6A8D072EB,?,?,?,?,?,00007FF6A8CEE489), ref: 00007FF6A8D06A3A
    • HeapFree.API-MS-WIN-CORE-HEAP-L1-1-0(?,?,00000078,00007FF6A8D06807,?,?,?,00007FF6A8D072EB,?,?,?,?,?,00007FF6A8CEE489), ref: 00007FF6A8D06A4E
    • GetProcessHeap.API-MS-WIN-CORE-HEAP-L1-1-0(?,?,00000078,00007FF6A8D06807,?,?,?,00007FF6A8D072EB,?,?,?,?,?,00007FF6A8CEE489), ref: 00007FF6A8D06A72
    • HeapFree.API-MS-WIN-CORE-HEAP-L1-1-0(?,?,00000078,00007FF6A8D06807,?,?,?,00007FF6A8D072EB,?,?,?,?,?,00007FF6A8CEE489), ref: 00007FF6A8D06A86
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Heap$FreeProcess
    • String ID:
    • API String ID: 3859560861-0
    • Opcode ID: b42e981b0e7b51b8a0e17a10e3714aa8aa24fe6f0553feab6a5dde9cc80c1822
    • Instruction ID: 3c13e84ca98c51a366f3686707cc7fd013d8165ddc2d55a3afac3b4402f57432
    • Opcode Fuzzy Hash: b42e981b0e7b51b8a0e17a10e3714aa8aa24fe6f0553feab6a5dde9cc80c1822
    • Instruction Fuzzy Hash: 01113732605B81CADB10AF22F4400A9BBB0F789F84B498131DB8E53B24CF38E596C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CreateInstance$Initialize
    • String ID:
    • API String ID: 1108742289-0
    • Opcode ID: 74dfc0f7f8fb169d923dfd916464f4625c218de07aee76a6485b8d0a3b0faba9
    • Instruction ID: 207c59dec90acbc134e5e97540fdec621824fd78eaf35eb72e8a52a17b53a0f5
    • Opcode Fuzzy Hash: 74dfc0f7f8fb169d923dfd916464f4625c218de07aee76a6485b8d0a3b0faba9
    • Instruction Fuzzy Hash: F3C11636A1AB0AC6EB10EF75D4401AD7375FB88B98B554232EE1E87364DF38E849C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CurrentDebuggerPresentThread
    • String ID:
    • API String ID: 1979983199-0
    • Opcode ID: 0a83a38080d530bd9d9e4dad04b16e365d2496b3dd5ab8aca7cbdcdd4394800b
    • Instruction ID: dcc08b334d7309fade914d3f0990277e760cceec68966b4c1fb6b227875bc010
    • Opcode Fuzzy Hash: 0a83a38080d530bd9d9e4dad04b16e365d2496b3dd5ab8aca7cbdcdd4394800b
    • Instruction Fuzzy Hash: C081AF21E4E78282FB60AF76A44027977B4FF89B84F184235DA5E83751DF3CE8498748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • DeviceIoControl.API-MS-WIN-CORE-IO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D49393), ref: 00007FF6A8CEAF41
    Strings
    • onecore\windows\core\console\open\src\server\devicecomm.cpp, xrefs: 00007FF6A8D05815
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ControlDevice
    • String ID: onecore\windows\core\console\open\src\server\devicecomm.cpp
    • API String ID: 2352790924-3100342381
    • Opcode ID: f6d7907ce8c99aef724ffa5f14de688d00255979112a0bd07f2f968c56075386
    • Instruction ID: bbcadf948a7f2d882c246e3a057650c9514cf82a69f69ffdc8175da662dd0877
    • Opcode Fuzzy Hash: f6d7907ce8c99aef724ffa5f14de688d00255979112a0bd07f2f968c56075386
    • Instruction Fuzzy Hash: 24F04432A29B46C6E700DB64E44436D73B4F789790F604231DA6D83714CF79C44A8B04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: FileInformationQueryVolume
    • String ID: onecore\windows\core\console\open\src\host\exemain.cpp
    • API String ID: 634242254-3772832676
    • Opcode ID: 84e16f5188d2248a0b4c218bfe61edc1703b08c4967a2eb84e3f7c3ad67b0d01
    • Instruction ID: 96f3f326a48c82fe0f1a4dc0f4a9e53416cfdfa129b209d08066c0c1afac77a4
    • Opcode Fuzzy Hash: 84e16f5188d2248a0b4c218bfe61edc1703b08c4967a2eb84e3f7c3ad67b0d01
    • Instruction Fuzzy Hash: EDF0A0A2B29643C1E700AB75E8016A9ABB0FB82B94F804231E65DD3764DF3CC14D8B04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CEF0A0: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE769,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF0B0
    • _Init_thread_footer.LIBCMT ref: 00007FF6A8D551B5
      • Part of subcall function 00007FF6A8CEF038: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF048
      • Part of subcall function 00007FF6A8CEF038: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF088
      • Part of subcall function 00007FF6A8CE0604: memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8CE0A81,?,?,?,00007FF6A8CD11C7), ref: 00007FF6A8CE0634
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8D552DD
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$Enter$Init_thread_footerLeave_onexitmemmove
    • String ID:
    • API String ID: 971411246-0
    • Opcode ID: 105d9a853b963783f2d8080bee0a2ad07caafcdbdf8df099ecef13e1b8435331
    • Instruction ID: 4966475567b8b2a811a203eae0e1ba71df8cab6cd493189bfaf2d724b76f9f82
    • Opcode Fuzzy Hash: 105d9a853b963783f2d8080bee0a2ad07caafcdbdf8df099ecef13e1b8435331
    • Instruction Fuzzy Hash: 2FA1D632A0AB4186EB00EB36E8511B977B1FF99B80F449332D95E97B65DF3CE4498704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,00000000,00007FF6A8CE8029), ref: 00007FF6A8D2C8A6
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8CE8029), ref: 00007FF6A8D2C96D
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmovememset
    • String ID:
    • API String ID: 1288253900-0
    • Opcode ID: 038466205d6b0e98e0916513c029e1c8bba3dc12b7e7c62d560b37f7fa28e4c9
    • Instruction ID: 023ff159005a47a7c65376ef12b2e1c0596d0032a1106b782f7808b9f618ca70
    • Opcode Fuzzy Hash: 038466205d6b0e98e0916513c029e1c8bba3dc12b7e7c62d560b37f7fa28e4c9
    • Instruction Fuzzy Hash: 3F5191776146919BD369CF39E68169ABBE0F708340F04812ADBAAC3A40E738F560CB10
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\tsf\tfeditses.cpp
    • API String ID: 0-2059936226
    • Opcode ID: b00585028618dd18f39f55cbf83ca8a016017b4dd698fa97394d1fa57542a1ff
    • Instruction ID: 17a8194256fcee2ffd29fd5ae8e70ad61eea6297266d08d71574018b5ef18120
    • Opcode Fuzzy Hash: b00585028618dd18f39f55cbf83ca8a016017b4dd698fa97394d1fa57542a1ff
    • Instruction Fuzzy Hash: 0E221D36609B85C2E770EB65E4407AAB7A4FB88B94F504132DE8D83B68DF3CD549CB04
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\tsf\tfeditses.cpp
    • API String ID: 0-2059936226
    • Opcode ID: 8e1f1d0c0b055c98e149aa588d99a3d8856f6ef586c8d98fa24807be9bfd4bfd
    • Instruction ID: 6ec6c329c90dd8bf419a9e7d8d7bbf6b27415a21d6c6bc55f5dac1ca0c326a67
    • Opcode Fuzzy Hash: 8e1f1d0c0b055c98e149aa588d99a3d8856f6ef586c8d98fa24807be9bfd4bfd
    • Instruction Fuzzy Hash: 89F17232A0A7C582EA74AB75E4407AA7361FBC4790F504336DA9D87B99DF3CD449CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AlpcPortReceiveSendWait
    • String ID:
    • API String ID: 1544246631-0
    • Opcode ID: 97c68c61486a1b6be6facedcfebe76708b76e4666f06451908df1a73e45d92a5
    • Instruction ID: 0ff025a43e1c82604774e2499da68519cb61fcdfb34141b63fe3a2d1dc468d83
    • Opcode Fuzzy Hash: 97c68c61486a1b6be6facedcfebe76708b76e4666f06451908df1a73e45d92a5
    • Instruction Fuzzy Hash: 7DF0A5B7A14B98C6D344DF11E488A5C37B8F769B91FA19128CBAC07710CF768AB5C784
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memset
    • String ID:
    • API String ID: 2221118986-0
    • Opcode ID: 9891075c6d0eefcf83e109a18726b5040a6e3772b69644b865663e25a03d542a
    • Instruction ID: 36c84052f1bd88491028bd0ea6407e2f154085e312eba5321623bef0259db456
    • Opcode Fuzzy Hash: 9891075c6d0eefcf83e109a18726b5040a6e3772b69644b865663e25a03d542a
    • Instruction Fuzzy Hash: 81B15736A11B4ADAE710DF7AD4402AD37B5FB88B98B048236DE5C97728DF38D15AC344
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    • onecore\windows\core\console\open\src\renderer\dx\dxrenderer.cpp, xrefs: 00007FF6A8D627D2
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\renderer\dx\dxrenderer.cpp
    • API String ID: 0-3506895815
    • Opcode ID: 8e8f95f0b0242844094a964368b7cdc2a0a4c255882e09fed56f4bcbc7341487
    • Instruction ID: 4a33205dc25689f110e35ddca474c950f46f967eaba288ba4de03e7bbf59a46f
    • Opcode Fuzzy Hash: 8e8f95f0b0242844094a964368b7cdc2a0a4c255882e09fed56f4bcbc7341487
    • Instruction Fuzzy Hash: B2212761D2679D5AE356D73B4C40E24B6119FAE78175CD722F818B2E92CF2CF0A1DB10
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Init_thread_footer
    • String ID:
    • API String ID: 1385522511-0
    • Opcode ID: ccde7c701325708c4d13affc0f7eee0fa7d2d59de34dc23908eec1d69d2262b7
    • Instruction ID: 1d9e14a6a0d70af4830d216df2029f60013955815abadc245ac0c81ceeecf611
    • Opcode Fuzzy Hash: ccde7c701325708c4d13affc0f7eee0fa7d2d59de34dc23908eec1d69d2262b7
    • Instruction Fuzzy Hash: 8A52A13AA4A74786EF68BB35C48417C3761EBD5B55F11423ADA6E837A0DE2DE44CC308
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 216ca0b8e3a3fadf86a84e756231e4a77c150758c01ecde000c19a748099031b
    • Instruction ID: c7cf2b24575d61fc187cba459fbef4f49d2adea846f400206e047ee589b5b963
    • Opcode Fuzzy Hash: 216ca0b8e3a3fadf86a84e756231e4a77c150758c01ecde000c19a748099031b
    • Instruction Fuzzy Hash: 26E1CF2761DAC181E7609B25E4412EEB7B0FB85B40F449236EADE87B99DF3CD485CB04
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 7e42740a49184a4a81fc1e60140f10a6e0eb908fd0205cb19ccea0d6df0a050e
    • Instruction ID: ce13292f0c82a6eab54fb06cec13d9dfd69965a2a9066bc2143f126e86998515
    • Opcode Fuzzy Hash: 7e42740a49184a4a81fc1e60140f10a6e0eb908fd0205cb19ccea0d6df0a050e
    • Instruction Fuzzy Hash: 2CB1C032A25A898AEB01DF76C0401BD7771FF88B88B159332DE5DA7364DF39E4899344
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 120f67cd3132ac0e6854baad49d49a0c45b809b135dc40afcb8e74427a80663f
    • Instruction ID: bcb12b8a88578514516ea28999b40ddd9da8e0f958a42d1e9cffa37a7ac7587b
    • Opcode Fuzzy Hash: 120f67cd3132ac0e6854baad49d49a0c45b809b135dc40afcb8e74427a80663f
    • Instruction Fuzzy Hash: C4619032A0964186DB54FB35E48176EB7A1FB88B90F005236EE5E97B56DF3CD805CB08
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 3d1a25f0590fa40f40b0842fa08438b049b271b2121658c298dae262b7359619
    • Instruction ID: 3b0b761d0a944e22e18d0e0dbdd9cb2a9da29249b59ec4a9d000434d2488ba97
    • Opcode Fuzzy Hash: 3d1a25f0590fa40f40b0842fa08438b049b271b2121658c298dae262b7359619
    • Instruction Fuzzy Hash: 1B51F82271569186EB08EFB1E5100E93762FF28BA87415532EE5C83B69FF3DD889C344
    Uniqueness

    Uniqueness Score: -1.00%

    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 12c553a6231258a7953ebe64ca3c821901f306539d3da55e855b6bd9cf610428
    • Instruction ID: fd8b7699dc2b13fff9d9d1f05216dcc7420dfbf541b1c817ad42a767a4b86d4f
    • Opcode Fuzzy Hash: 12c553a6231258a7953ebe64ca3c821901f306539d3da55e855b6bd9cf610428
    • Instruction Fuzzy Hash: D1A0012192A846E5EA459F21A8550246734BBA1304B401571D01ED50A49E6DA4048708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetEnvironmentVariableW.API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0 ref: 00007FF6A8CD3427
    • RegGetValueW.API-MS-WIN-CORE-REGISTRY-L1-1-0 ref: 00007FF6A8CFA62D
    • SetEnvironmentVariableW.API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0 ref: 00007FF6A8CFA662
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: EnvironmentVariable$Value
    • String ID: CommonFilesDir$CommonFilesDir (x86)$CommonProgramFiles$CommonProgramFiles(x86)$CommonProgramW6432$CommonW6432Dir$GetModuleFileNameW failed %d.$ProgramFiles$ProgramFiles(x86)$ProgramFilesDir$ProgramFilesDir (x86)$ProgramW6432$ProgramW6432Dir$Software\Microsoft\Windows\CurrentVersion
    • API String ID: 2902449149-4252908956
    • Opcode ID: 57c77a7a60e7e5c896dc0987980d7bcefc72bb88e2c23f1d86b9a6b12376136a
    • Instruction ID: 469a91076d75b4c2d11c358b532df30e187d36a56e69fef07ba6cba3260b2de7
    • Opcode Fuzzy Hash: 57c77a7a60e7e5c896dc0987980d7bcefc72bb88e2c23f1d86b9a6b12376136a
    • Instruction Fuzzy Hash: 89514F32A1AF42D9EB00AB70E4442A977B8FB49754F940336DA6D877A4EF3CD548C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o_malloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8CDE93E,?,?,?,?,00007FF6A8D0931C,?,?,?,?,?,?,?), ref: 00007FF6A8CEEE46
    • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6A8CEEE5C
      • Part of subcall function 00007FF6A8CEFA04: std::bad_alloc::bad_alloc.LIBCMT ref: 00007FF6A8CEFA0D
      • Part of subcall function 00007FF6A8CEFA04: _CxxThrowException.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,00007FF6A8CEEE61,?,?,00000000,00007FF6A8CDE93E), ref: 00007FF6A8CEFA1E
    • InitializeCriticalSectionAndSpinCount.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CEEE95
    • GetModuleHandleW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEA3
    • GetModuleHandleW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEB9
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEED6
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEEA
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEFE
    • CreateEventW.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CEEF97
    • DeleteCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CEEFDB
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0 ref: 00007FF6A8CEEFED
      • Part of subcall function 00007FF6A8CEF440: IsProcessorFeaturePresent.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-1 ref: 00007FF6A8CEF45C
      • Part of subcall function 00007FF6A8CEF440: memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8CEF480
      • Part of subcall function 00007FF6A8CEF440: RtlCaptureContext.API-MS-WIN-CORE-RTLSUPPORT-L1-1-0 ref: 00007FF6A8CEF489
      • Part of subcall function 00007FF6A8CEF440: RtlLookupFunctionEntry.API-MS-WIN-CORE-RTLSUPPORT-L1-1-0 ref: 00007FF6A8CEF4A3
      • Part of subcall function 00007FF6A8CEF440: RtlVirtualUnwind.API-MS-WIN-CORE-RTLSUPPORT-L1-1-0 ref: 00007FF6A8CEF4E4
      • Part of subcall function 00007FF6A8CEF440: memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8CEF517
      • Part of subcall function 00007FF6A8CEF440: IsDebuggerPresent.API-MS-WIN-CORE-DEBUG-L1-1-0 ref: 00007FF6A8CEF538
      • Part of subcall function 00007FF6A8CEF440: SetUnhandledExceptionFilter.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0 ref: 00007FF6A8CEF559
      • Part of subcall function 00007FF6A8CEF440: UnhandledExceptionFilter.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0 ref: 00007FF6A8CEF564
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressExceptionHandleProc$CriticalFilterModulePresentSectionUnhandledmemset$CaptureCloseConcurrency::cancel_current_taskContextCountCreateDebuggerDeleteEntryEventFeatureFunctionInitializeLookupProcessorSpinThrowUnwindVirtual_o_mallocstd::bad_alloc::bad_alloc
    • String ID: InitializeConditionVariable$SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
    • API String ID: 683641506-1714406822
    • Opcode ID: 926aa7a2d835a7c1c136655371e710575e3c69263077944b1b7fa9d9a48129e4
    • Instruction ID: d34df07794961db4e164f307e7c1bcfa0daa2e4727e65e3ad882cb2978dd3a34
    • Opcode Fuzzy Hash: 926aa7a2d835a7c1c136655371e710575e3c69263077944b1b7fa9d9a48129e4
    • Instruction Fuzzy Hash: C3414E20E1B64792FF14BB34A85227522A1AF467A0F581734D96EC77D5EF2CE8498B0C
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CurrentFormatMessageThread
    • String ID: $%hs!%p: $%hs(%d) tid(%x) %08X %ws$%hs(%u)\%hs!%p: $(caller: %p) $CallContext:[%hs] $Exception$FailFast$LogHr$Msg:[%ws] $ReturnHr$[%hs(%hs)]$[%hs]
    • API String ID: 2411632146-3173542853
    • Opcode ID: f43a2caa12b02a6b0de14e976f96f5f193551454712b8849ba57de93f300097f
    • Instruction ID: 1a94c7eaf90267ca0630f9cf658de14fb7b7bf3f21752d9a8be6d4ee2ab0c3ea
    • Opcode Fuzzy Hash: f43a2caa12b02a6b0de14e976f96f5f193551454712b8849ba57de93f300097f
    • Instruction Fuzzy Hash: 9B617271A0AB4691EA64FB71A8005B967B0FF45784F44433ADA6E87B94EF3CE558830C
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5AF54
    • CoTaskMemFree.API-MS-WIN-CORE-COM-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5AF66
    • SetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5AF75
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5AFBA
    • CoTaskMemFree.API-MS-WIN-CORE-COM-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5AFCC
    • SetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5AFDB
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5B00A
    • CoTaskMemFree.API-MS-WIN-CORE-COM-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5B01C
    • SetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5B02B
    • CoTaskMemFree.API-MS-WIN-CORE-COM-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5B0B5
    • CoTaskMemFree.API-MS-WIN-CORE-COM-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5B0CB
    • CoTaskMemFree.API-MS-WIN-CORE-COM-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D54AA1), ref: 00007FF6A8D5B0E1
    Strings
    • onecore\windows\core\console\conint\edpconsolepolicy.cpp, xrefs: 00007FF6A8D5B090
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ErrorFreeLastTask
    • String ID: onecore\windows\core\console\conint\edpconsolepolicy.cpp
    • API String ID: 3486484475-1700090441
    • Opcode ID: 8fab6a86e59291517ebadc1e6f7659cf2340d3ac4b7e4f017ec1d86b28ac4b30
    • Instruction ID: 51ae5436b98f93bc09b8bed12bfc02b47ed747164f16a119622fa493ded96737
    • Opcode Fuzzy Hash: 8fab6a86e59291517ebadc1e6f7659cf2340d3ac4b7e4f017ec1d86b28ac4b30
    • Instruction Fuzzy Hash: F4512C32A16B51CAE700AB71E8505BD7BB4FB8AB85B456235DA5EE3B58CF38D40C8704
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: A rendering engine required too many retries.$input handle$onecore\windows\core\console\open\src\renderer\base\renderer.cpp$onecore\windows\core\console\open\src\server\apidispatchers.cpp$onecore\windows\core\console\open\src\server\objecthandle.cpp$output handle$own
    • API String ID: 0-2733136493
    • Opcode ID: 00f1368b16f22fa5b75ce1ac8f4ab2bf53e97da97eb2b696a67dd5f2bbe25401
    • Instruction ID: 5191796b3274e9ea77cee3e7f360397357ca8dd2f8730c61824b3966b434fc10
    • Opcode Fuzzy Hash: 00f1368b16f22fa5b75ce1ac8f4ab2bf53e97da97eb2b696a67dd5f2bbe25401
    • Instruction Fuzzy Hash: 66028F22F0AB4685EB10AB75D5403BC23B5AB49BA8F404331DA2E977D9DF3CE549C748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D34AAB
    • ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D34AC6
    • ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D34AE1
    • ?flags@ios_base@std@@QEBAHXZ.MSVCP_WIN ref: 00007FF6A8D34B20
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D34B4D
    • ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ.MSVCP_WIN ref: 00007FF6A8D34B66
    • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP_WIN ref: 00007FF6A8D34B77
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D34B9E
    • ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ.MSVCP_WIN ref: 00007FF6A8D34BB7
    • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP_WIN ref: 00007FF6A8D34BC8
    • ?width@ios_base@std@@QEAA_J_J@Z.MSVCP_WIN ref: 00007FF6A8D34BEC
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D34C0D
    • ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP_WIN ref: 00007FF6A8D34C22
    • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP_WIN ref: 00007FF6A8D34C5E
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: U?$char_traits@$D@std@@@std@@$?width@ios_base@std@@$?rdbuf@?$basic_ios@D@std@@@2@V?$basic_streambuf@$?fill@?$basic_ios@?sputc@?$basic_streambuf@$?flags@ios_base@std@@?setstate@?$basic_ios@?sputn@?$basic_streambuf@
    • String ID:
    • API String ID: 4125389999-0
    • Opcode ID: 36d29ad8e06e404558534be1a93ca429ee0870889679ef9e7dc33a2ec4dcde91
    • Instruction ID: 00f9f27efecf23d40ca42e672f0f89c92669e65f619182d9ffc412323a88e6b6
    • Opcode Fuzzy Hash: 36d29ad8e06e404558534be1a93ca429ee0870889679ef9e7dc33a2ec4dcde91
    • Instruction Fuzzy Hash: 94513132A19A4586EB10AF25E450278FFA1FF8AF55B59D631DA1E83364CF3CD4498704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D340C9
    • ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D340E4
    • ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D340FF
    • ?flags@ios_base@std@@QEBAHXZ.MSVCP_WIN ref: 00007FF6A8D3413E
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D34163
    • ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ.MSVCP_WIN ref: 00007FF6A8D3417C
    • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP_WIN ref: 00007FF6A8D3418D
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D341AD
    • ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP_WIN ref: 00007FF6A8D341C2
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D341E2
    • ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ.MSVCP_WIN ref: 00007FF6A8D341FB
    • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP_WIN ref: 00007FF6A8D3420C
    • ?width@ios_base@std@@QEAA_J_J@Z.MSVCP_WIN ref: 00007FF6A8D34232
    • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP_WIN ref: 00007FF6A8D3425E
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: U?$char_traits@$D@std@@@std@@$?width@ios_base@std@@$?rdbuf@?$basic_ios@D@std@@@2@V?$basic_streambuf@$?fill@?$basic_ios@?sputc@?$basic_streambuf@$?flags@ios_base@std@@?setstate@?$basic_ios@?sputn@?$basic_streambuf@
    • String ID:
    • API String ID: 4125389999-0
    • Opcode ID: e712a1638d37fb830bd72cc4455f9dc37970ff8623a382ad9ba4058091dfb03c
    • Instruction ID: f43302b71234a690418e7ae4108942813255d99157b885ae79443b6eb0409473
    • Opcode Fuzzy Hash: e712a1638d37fb830bd72cc4455f9dc37970ff8623a382ad9ba4058091dfb03c
    • Instruction Fuzzy Hash: E3519B31A1A945C7EB10AB25D69023CBFA1FF96BA1B55C631DA2E83751CF3CD419C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Open$CurrentUser
    • String ID: Console
    • API String ID: 688027284-4190041642
    • Opcode ID: 78ff861a040b04bfbf41c6af765c4c2fa2b3aecd47cc967da2eead6ae96eee59
    • Instruction ID: 788d7405ef409b6755ddf5229e92d914d997c5f9c3ee6664eb3bb1044d3e714d
    • Opcode Fuzzy Hash: 78ff861a040b04bfbf41c6af765c4c2fa2b3aecd47cc967da2eead6ae96eee59
    • Instruction Fuzzy Hash: 02413F31A0AF42CAE7149F75E8442787AA0FB4EBA9F455331EA5E83794DF3CD4488744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D3553C: ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D3555E
      • Part of subcall function 00007FF6A8D3553C: ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D3557C
      • Part of subcall function 00007FF6A8D3553C: ?good@ios_base@std@@QEBA_NXZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D355A6
      • Part of subcall function 00007FF6A8D3553C: ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D355C0
      • Part of subcall function 00007FF6A8D3553C: ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D355DB
      • Part of subcall function 00007FF6A8D3553C: ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D355F6
      • Part of subcall function 00007FF6A8D3553C: ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D35605
      • Part of subcall function 00007FF6A8D3553C: ?good@ios_base@std@@QEBA_NXZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D3561B
    • ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33E9D
    • ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33EBD
    • ?flags@ios_base@std@@QEBAHXZ.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33ED7
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33F04
    • ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33F1D
    • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33F2E
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33F59
    • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33F6B
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33F99
    • ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33FB2
    • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33FC3
    • ?width@ios_base@std@@QEAA_J_J@Z.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D33FF7
    • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP_WIN(?,?,?,?,?,00007FF6A8D35AFD), ref: 00007FF6A8D34012
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: U?$char_traits@$D@std@@@std@@$D@std@@@2@$?rdbuf@?$basic_ios@V?$basic_streambuf@$?sputc@?$basic_streambuf@?tie@?$basic_ios@?width@ios_base@std@@V?$basic_ostream@$?fill@?$basic_ios@?good@ios_base@std@@$?flags@ios_base@std@@?flush@?$basic_ostream@?setstate@?$basic_ios@V12@
    • String ID:
    • API String ID: 4018470129-0
    • Opcode ID: 3ad4787b89151a6a2179a84b9b147fee9394a63977d8c64df809d13f73024422
    • Instruction ID: 646c59d42c213995e3c01b9ecd8f534182aea6d33d790418296e31fb13e149ca
    • Opcode Fuzzy Hash: 3ad4787b89151a6a2179a84b9b147fee9394a63977d8c64df809d13f73024422
    • Instruction Fuzzy Hash: CB517232A09E4587EB14AF25E55027CBBA1FFC6F96B599631DA2E83364CF3CD4098704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate$ErrorLastmemset$_o_wcscpy_s
    • String ID: __DefaultTTFont__$onecore\windows\core\console\open\src\types\utils.cpp
    • API String ID: 2841634189-622446547
    • Opcode ID: 363ef17cba4ffdf3d8adea84111637182a3f2c6e3e15e6734f4f6705bd8a7c39
    • Instruction ID: a14ed1644dc9cf8245f4f3db2a8402e1a7ab368ad3c525d05f1f6cfade361e62
    • Opcode Fuzzy Hash: 363ef17cba4ffdf3d8adea84111637182a3f2c6e3e15e6734f4f6705bd8a7c39
    • Instruction Fuzzy Hash: 7D518E32605B86D7D718DF20E5446A9BBB0FB49754F148225DBAE83B94CF38E138CB48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: Invalid screen buffer size (0x%x, 0x%x)$VUUUUUUU$VUUUUUUU$invalid unordered_map<K, T> key$invalid vector<T> subscript$onecore\windows\core\console\open\src\host\screeninfo.cpp
    • API String ID: 1960685668-3002075300
    • Opcode ID: 03558975bc1aa84b6ce5e4e6b1c64022e9f9254bcb6a3f349bd36923111f5760
    • Instruction ID: 7094ed45d09c29885cd5a3a5e2dd3a7dd1cc2543d6b632635e43419c6a792554
    • Opcode Fuzzy Hash: 03558975bc1aa84b6ce5e4e6b1c64022e9f9254bcb6a3f349bd36923111f5760
    • Instruction Fuzzy Hash: E112F536A0E6C185DAA0AF35A0406BE7BB0FB85B84F401671EE9E87755EF3CD849C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Init_thread_footer
    • String ID: onecore\windows\core\console\open\src\host\input.cpp$onecore\windows\core\console\open\src\server\apidispatchers.cpp
    • API String ID: 1385522511-2142256027
    • Opcode ID: 9679941410f3769a96707f0d3427b659b44c654fbcb82f5143cc7790e8abc684
    • Instruction ID: c56f592969e8e757026c39d18ee85ea757805591bcb892085ec72a3fc5586965
    • Opcode Fuzzy Hash: 9679941410f3769a96707f0d3427b659b44c654fbcb82f5143cc7790e8abc684
    • Instruction Fuzzy Hash: 2ED18D32A0AA4686EB10AF35D4516B83B71FF45788F504231DA6FC7AA5DF3CE849C708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D46868: ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ.MSVCP_WIN ref: 00007FF6A8D4689F
      • Part of subcall function 00007FF6A8D46868: ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z.MSVCP_WIN ref: 00007FF6A8D468BE
      • Part of subcall function 00007FF6A8D34090: ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D340C9
      • Part of subcall function 00007FF6A8D34090: ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D340E4
      • Part of subcall function 00007FF6A8D34090: ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D340FF
      • Part of subcall function 00007FF6A8D34090: ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP_WIN ref: 00007FF6A8D3425E
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@F@Z.MSVCP_WIN ref: 00007FF6A8D46F8E
      • Part of subcall function 00007FF6A8D34090: ?flags@ios_base@std@@QEBAHXZ.MSVCP_WIN ref: 00007FF6A8D3413E
      • Part of subcall function 00007FF6A8D34090: ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D34163
      • Part of subcall function 00007FF6A8D34090: ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ.MSVCP_WIN ref: 00007FF6A8D3417C
      • Part of subcall function 00007FF6A8D34090: ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP_WIN ref: 00007FF6A8D3418D
      • Part of subcall function 00007FF6A8D34090: ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D341AD
      • Part of subcall function 00007FF6A8D34090: ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP_WIN ref: 00007FF6A8D341C2
      • Part of subcall function 00007FF6A8D34090: ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D341E2
      • Part of subcall function 00007FF6A8D34090: ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ.MSVCP_WIN ref: 00007FF6A8D341FB
      • Part of subcall function 00007FF6A8D34090: ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z.MSVCP_WIN ref: 00007FF6A8D3420C
      • Part of subcall function 00007FF6A8D34090: ?width@ios_base@std@@QEAA_J_J@Z.MSVCP_WIN ref: 00007FF6A8D34232
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@F@Z.MSVCP_WIN ref: 00007FF6A8D46FB4
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@F@Z.MSVCP_WIN ref: 00007FF6A8D46FDA
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@F@Z.MSVCP_WIN ref: 00007FF6A8D47000
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@F@Z.MSVCP_WIN ref: 00007FF6A8D47031
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@F@Z.MSVCP_WIN ref: 00007FF6A8D4705E
      • Part of subcall function 00007FF6A8D38DCC: ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E06
      • Part of subcall function 00007FF6A8D38DCC: ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E1A
      • Part of subcall function 00007FF6A8D38DCC: ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E2C
      • Part of subcall function 00007FF6A8D38508: memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,00007FF6A8D343AC), ref: 00007FF6A8D38549
    • ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ.MSVCP_WIN ref: 00007FF6A8D470F3
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: U?$char_traits@$D@std@@@std@@$??6?$basic_ostream@V01@$?width@ios_base@std@@V?$basic_streambuf@$?rdbuf@?$basic_ios@D@std@@@2@$?fill@?$basic_ios@?pptr@?$basic_streambuf@?sputc@?$basic_streambuf@$??0?$basic_ios@??0?$basic_iostream@??1?$basic_ios@?flags@ios_base@std@@?pbase@?$basic_streambuf@?setstate@?$basic_ios@?sputn@?$basic_streambuf@D@std@@@1@@memmove
    • String ID: ) RB:($) [${LT:(
    • API String ID: 3851257767-2145079954
    • Opcode ID: 8299830ad2369e1a400a937566b400e841a7a185adc4ff1ea94a096dec4e5011
    • Instruction ID: 9e53c38959531429f977b0d4769e98bdbf0dfad86a6f7759df414d90f0700cd5
    • Opcode Fuzzy Hash: 8299830ad2369e1a400a937566b400e841a7a185adc4ff1ea94a096dec4e5011
    • Instruction Fuzzy Hash: 8A51AE22619997D6EB00AF30E8401FDB771FB95B48F809231E65E836A9EF3CD948C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D67CBC: ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,00007FF6A8D66D9E,?,?,?,00007FF6A8D66E3D), ref: 00007FF6A8D67CF4
    • ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN ref: 00007FF6A8D67173
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: invalid string position$onecore\windows\core\console\open\src\renderer\dx\customtextlayout.cpp
    • API String ID: 1960685668-2152613991
    • Opcode ID: 0a1671ad543f5168c41422ceb83610ecdf3c5acd4a4651098320c7dd43592a89
    • Instruction ID: ab8448702361bc0401e259bd37f578acb61e19ca9f377dd1b8b3f89af92a4c0c
    • Opcode Fuzzy Hash: 0a1671ad543f5168c41422ceb83610ecdf3c5acd4a4651098320c7dd43592a89
    • Instruction Fuzzy Hash: 5E129E3261ABC986D760EB65E4847EEB7A5FB88780F514236DA9D83754DF3CE048CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSectiondefault_delete$ByteCharEnterInit_thread_footerLeaveMultiWidememset
    • String ID: invalid string position$onecore\windows\core\console\open\src\host\_stream.cpp
    • API String ID: 183490158-599477270
    • Opcode ID: 9fc54d52075468982d4d808f0f11727d18c45dd4d13e4649c68ec022d8cdd14e
    • Instruction ID: 4689da8f5277d10c6ee5d0a5baa7754a67f1d3fb059c3e6cef767984b25c091c
    • Opcode Fuzzy Hash: 9fc54d52075468982d4d808f0f11727d18c45dd4d13e4649c68ec022d8cdd14e
    • Instruction Fuzzy Hash: 28F18572A4E78286E760EB35E45027A77B1FB95780F105635EA9E83B96DF3CD404CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Global$AllocLockUnlock
    • String ID: HTML Format$Windows Console Host$onecore\windows\core\console\open\src\interactivity\win32\clipboard.cpp
    • API String ID: 3972497268-1260932009
    • Opcode ID: 467f1c210ade1f1d67a45c88a8cebd004336b66ffae137e8f5bfb47abf117d2d
    • Instruction ID: 2d16b5e0c36a23e74640ce63a7c6ddd5830beddf044bbe4f37bdc454c72dbb17
    • Opcode Fuzzy Hash: 467f1c210ade1f1d67a45c88a8cebd004336b66ffae137e8f5bfb47abf117d2d
    • Instruction Fuzzy Hash: 6DB14F65A0AB4286FB04AF71D4542F96B72FF98B88F444232DA2E83B59DF3CD409C304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Heap$Process$AllocCloseEnumFreeOpenValue
    • String ID: *$Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
    • API String ID: 1259498659-1414037276
    • Opcode ID: ff0ff7adef7cf78664ca5bc3adf3959e93f41d7236033aed7f13e865aded9daa
    • Instruction ID: 337df51ee45c6c686d213186a2215d07bdb5f0c09c5fbd4233d42c9059f7fef5
    • Opcode Fuzzy Hash: ff0ff7adef7cf78664ca5bc3adf3959e93f41d7236033aed7f13e865aded9daa
    • Instruction Fuzzy Hash: F261B332A19F818AEB109F31E4402B9B7B4FB4AB54F944631DA9E83794DF3CD149CB44
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8D35009,?,?,?,?,?,?,?,00007FF6A8D3776C), ref: 00007FF6A8CE09A9
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8D35009,?,?,?,?,?,?,?,00007FF6A8D3776C), ref: 00007FF6A8CE09C4
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,00000000,00007FF6A8D35009,?,?,?,?,?,?,?,00007FF6A8D3776C), ref: 00007FF6A8CE09D9
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,00000000,00007FF6A8D35009,?,?,?,?,?,?,?,00007FF6A8D3776C), ref: 00007FF6A8CE09E6
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmovememset
    • String ID: deque<T> too long$onecore\windows\core\console\open\src\host\consolearguments.cpp
    • API String ID: 1288253900-3798327426
    • Opcode ID: 1f96ee3daf2149a4f1c450344c6a6e779cec27ae11fbbc4b57f5949d29f05ff1
    • Instruction ID: edf9fcd21c662098c1dcd4dcd90b3255fc720a99ae59e0cbf7953016ed901934
    • Opcode Fuzzy Hash: 1f96ee3daf2149a4f1c450344c6a6e779cec27ae11fbbc4b57f5949d29f05ff1
    • Instruction Fuzzy Hash: 5341D572B15B8592EE14DFA2E5410B9A3A1EB85FE0B548235DE7E57B96CF3CE001C308
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • WaitForSingleObject.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000000,00007FF6A8D02E21), ref: 00007FF6A8D06F52
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ObjectSingleWait
    • String ID: wil
    • API String ID: 24740636-1589926490
    • Opcode ID: ad935d75d79f2680a1dca7d1f7b30669862039ccd549ee188a20447763dff730
    • Instruction ID: d1f31368e6324faa958e275c8952c5328825ae0afb704946b6f9016960908f66
    • Opcode Fuzzy Hash: ad935d75d79f2680a1dca7d1f7b30669862039ccd549ee188a20447763dff730
    • Instruction Fuzzy Hash: 62415331A1964287F7206B31E40067D7A71EF85782F608331E56EC6AD4DF3ED44D8B05
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetModuleFileNameW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CD34C3
    • CreateActCtxW.API-MS-WIN-CORE-SIDEBYSIDE-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000001,00007FF6A8CD344F), ref: 00007FF6A8CD3517
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0 ref: 00007FF6A8CFA682
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CreateErrorFileLastModuleName
    • String ID: 8$GetModuleFileNameW failed %d.$GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.$InitSideBySide failed create an activation context. Error: %d$d
    • API String ID: 1775755052-3069648676
    • Opcode ID: 4f5f3032353e696e2719e309aebc212e3c128a70b1be28a4f2fbc4108c39b3df
    • Instruction ID: 8623c2c222f9ba5b1473fdb751f36426f34d6977c864a29893428bd9b6c207ac
    • Opcode Fuzzy Hash: 4f5f3032353e696e2719e309aebc212e3c128a70b1be28a4f2fbc4108c39b3df
    • Instruction Fuzzy Hash: 2B31A422E1A782C6E760AB31A444179B7F0FB58B58F54C235D72E83391EF7CA495CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D46868: ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ.MSVCP_WIN ref: 00007FF6A8D4689F
      • Part of subcall function 00007FF6A8D46868: ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z.MSVCP_WIN ref: 00007FF6A8D468BE
      • Part of subcall function 00007FF6A8D34090: ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D340C9
      • Part of subcall function 00007FF6A8D34090: ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D340E4
      • Part of subcall function 00007FF6A8D34090: ?width@ios_base@std@@QEBA_JXZ.MSVCP_WIN ref: 00007FF6A8D340FF
      • Part of subcall function 00007FF6A8D34090: ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP_WIN ref: 00007FF6A8D3425E
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z.MSVCP_WIN ref: 00007FF6A8D58F4E
    • ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAADD@Z.MSVCP_WIN ref: 00007FF6A8D58F69
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z.MSVCP_WIN ref: 00007FF6A8D58F7F
    • ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z.MSVCP_WIN ref: 00007FF6A8D58F97
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z.MSVCP_WIN ref: 00007FF6A8D58FCA
    • ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z.MSVCP_WIN ref: 00007FF6A8D58FDD
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z.MSVCP_WIN ref: 00007FF6A8D59012
    • ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z.MSVCP_WIN ref: 00007FF6A8D59025
    • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z.MSVCP_WIN ref: 00007FF6A8D5905B
      • Part of subcall function 00007FF6A8D38DCC: ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E06
      • Part of subcall function 00007FF6A8D38DCC: ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E1A
      • Part of subcall function 00007FF6A8D38DCC: ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E2C
    • ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ.MSVCP_WIN ref: 00007FF6A8D59082
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: U?$char_traits@$D@std@@@std@@$??6?$basic_ostream@V01@$?setw@std@@?width@ios_base@std@@J@1@_Smanip@_U?$_$?pptr@?$basic_streambuf@V21@@Vios_base@1@$??0?$basic_ios@??0?$basic_iostream@??1?$basic_ios@?fill@?$basic_ios@?pbase@?$basic_streambuf@?setstate@?$basic_ios@D@std@@@1@@V?$basic_streambuf@
    • String ID:
    • API String ID: 1081597296-0
    • Opcode ID: 9444b24c98cc12ef68961d586367c45fdaa660b3771907d4cc6382763c6e1c3e
    • Instruction ID: a96dcff3bf508f351049fb55162f9fb3945d616b63a8ea6e22ca0467fac09f81
    • Opcode Fuzzy Hash: 9444b24c98cc12ef68961d586367c45fdaa660b3771907d4cc6382763c6e1c3e
    • Instruction Fuzzy Hash: 5D417F32615A85D6DB00EF25E4901B9BB70FBC9B81B958232EA5E83724DF3CD90DC740
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ControlDeviceInit_thread_footermemset
    • String ID: onecore\windows\core\console\open\src\server\apidispatchers.cpp$onecore\windows\core\console\open\src\server\apimessage.cpp$onecore\windows\core\console\open\src\server\devicecomm.cpp$onecore\windows\core\console\open\src\server\objecthandle.cpp
    • API String ID: 1779181428-3195736410
    • Opcode ID: 9f233df8214833f99c9d0123012b3cddb6adc7ab9fa494ba4ad645126d82de74
    • Instruction ID: 94b3277383a2426514245556f92b27869efb1291e0a8e06db57ea5563f0e41d0
    • Opcode Fuzzy Hash: 9f233df8214833f99c9d0123012b3cddb6adc7ab9fa494ba4ad645126d82de74
    • Instruction Fuzzy Hash: 13E15036A0AB4685E710EF75D4406A833B5FB48B98F405236DE5E97B99DF3CE408C748
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: VUUUUUUU$invalid unordered_map<K, T> key$invalid vector<T> subscript$onecore\windows\core\console\open\src\types\viewport.cpp$vector<T> too long
    • API String ID: 0-2488907146
    • Opcode ID: 3a2f7204bc0ae7333aaddfbf04df58a7d96a0182fadd7d001de59034bb0b722f
    • Instruction ID: 6307954e13130cff1d56d1e80ca0c1c9e59c407c54ebfe76474be0b835ae1e26
    • Opcode Fuzzy Hash: 3a2f7204bc0ae7333aaddfbf04df58a7d96a0182fadd7d001de59034bb0b722f
    • Instruction Fuzzy Hash: 0BB1C126A09B6286EB14DF35D0801BC77B0FB59B98B504136EF4E83B85DF38E4A5CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CE4ED0: RegOpenCurrentUser.API-MS-WIN-CORE-REGISTRY-L1-1-0 ref: 00007FF6A8CE4F08
      • Part of subcall function 00007FF6A8CE4ED0: RegOpenKeyW.API-MS-WIN-CORE-REGISTRY-L2-1-0 ref: 00007FF6A8CE4F42
      • Part of subcall function 00007FF6A8CE5508: GetWindowsDirectoryW.API-MS-WIN-CORE-SYSINFO-L1-1-0 ref: 00007FF6A8CE5557
      • Part of subcall function 00007FF6A8CE5508: CompareStringOrdinal.API-MS-WIN-CORE-STRING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CDA8FC), ref: 00007FF6A8CE55D0
    • RegOpenKeyW.API-MS-WIN-CORE-REGISTRY-L2-1-0(?,?,?,?,?,?,?,?,?,?,?,000008A9,?,?,00000041,00000595), ref: 00007FF6A8CE5058
    • RegCloseKey.API-MS-WIN-CORE-REGISTRY-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,000008A9,?,?,00000041,00000595), ref: 00007FF6A8CE517E
    • RegCloseKey.API-MS-WIN-CORE-REGISTRY-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,000008A9,?,?,00000041,00000595), ref: 00007FF6A8CE5195
    • RegOpenKeyW.API-MS-WIN-CORE-REGISTRY-L2-1-0(?,?,?,?,?,?,?,?,?,?,?,000008A9,?,?,00000041,00000595), ref: 00007FF6A8CE51E7
    • RegCloseKey.API-MS-WIN-CORE-REGISTRY-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,000008A9,?,?,00000041,00000595), ref: 00007FF6A8CE520C
      • Part of subcall function 00007FF6A8CE5394: RegQueryValueExW.API-MS-WIN-CORE-REGISTRY-L1-1-0 ref: 00007FF6A8CE53C0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Open$Close$CompareCurrentDirectoryOrdinalQueryStringUserValueWindows
    • String ID: CodePage$ColorTable%02u$WindowPosition
    • API String ID: 2278421442-3581126301
    • Opcode ID: ec04b8387e95130574dac8e98e119084406a2c9ab660584bc09266f4bbdb49b9
    • Instruction ID: 576e1c3ebf6ac137f6ecc76aefb68684920162391a803ea07fba4a9e5dd66992
    • Opcode Fuzzy Hash: ec04b8387e95130574dac8e98e119084406a2c9ab660584bc09266f4bbdb49b9
    • Instruction Fuzzy Hash: D3618332B1AA4285FB10AB32E4416BE6772FB8AB84F445131EE5F97794DE3CE445CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$EnterLeave
    • String ID: onecore\windows\core\console\open\src\host\_stream.cpp$onecore\windows\core\console\open\src\host\input.cpp
    • API String ID: 3168844106-1286246513
    • Opcode ID: da14826e42f02988b03f842f1a2c4cc8e1bb5d6ae12bbed43d28479d162baa1f
    • Instruction ID: bd05c90c0e55f2f57337971345bc00eddc9d81ce4d92960ced79e685ef7df2e2
    • Opcode Fuzzy Hash: da14826e42f02988b03f842f1a2c4cc8e1bb5d6ae12bbed43d28479d162baa1f
    • Instruction Fuzzy Hash: CE518031B0E74286FA10AB35E4506B977B0FF95B80F145231DA5EC3AA5DE3CE949CB48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(00000000,00000000,00000000,00007FF6A8D491E8,?,?,00000000,00007FF6A8D58821,?,?,?,?,?,?,00000000,00000000), ref: 00007FF6A8D0C85B
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(00000000,00000000,00000000,00007FF6A8D491E8,?,?,00000000,00007FF6A8D58821,?,?,?,?,?,?,00000000,00000000), ref: 00007FF6A8D0C872
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(00000000,00000000,00000000,00007FF6A8D491E8,?,?,00000000,00007FF6A8D58821,?,?,?,?,?,?,00000000,00000000), ref: 00007FF6A8D0C887
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(00000000,00000000,00000000,00007FF6A8D491E8,?,?,00000000,00007FF6A8D58821,?,?,?,?,?,?,00000000,00000000), ref: 00007FF6A8D0C89E
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(00000000,00000000,00000000,00007FF6A8D491E8,?,?,00000000,00007FF6A8D58821,?,?,?,?,?,?,00000000,00000000), ref: 00007FF6A8D0C8B7
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(00000000,00000000,00000000,00007FF6A8D491E8,?,?,00000000,00007FF6A8D58821,?,?,?,?,?,?,00000000,00000000), ref: 00007FF6A8D0C8C5
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove$memset
    • String ID: deque<T> too long
    • API String ID: 3790616698-309773918
    • Opcode ID: bc786877fc7d260f55611f00be12d0546dc747a1c2ac2820dca731e2b83df3cf
    • Instruction ID: fba12d680559026b0e57f00be5f0699f352b21a7458394c32136333525b452d2
    • Opcode Fuzzy Hash: bc786877fc7d260f55611f00be12d0546dc747a1c2ac2820dca731e2b83df3cf
    • Instruction Fuzzy Hash: 5231B4A2B15B8586DE14EB62A5410A9A761EB85FF0B188335DE7E5BBD2CE3CD045C308
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8D0FD86), ref: 00007FF6A8D12FE4
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8D0FD86), ref: 00007FF6A8D12FFB
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,00000000,00007FF6A8D0FD86), ref: 00007FF6A8D13010
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8D0FD86), ref: 00007FF6A8D13027
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8D0FD86), ref: 00007FF6A8D13040
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,00000000,00007FF6A8D0FD86), ref: 00007FF6A8D1304E
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove$memset
    • String ID: deque<T> too long
    • API String ID: 3790616698-309773918
    • Opcode ID: bdb79f53aab3b9fa90a30fbd8f0a190016f26e6961cd84673523f3e5589781a9
    • Instruction ID: a45f2068191703411edea42b185991e1f6d8dfd66104fcf6efe638f74ec31467
    • Opcode Fuzzy Hash: bdb79f53aab3b9fa90a30fbd8f0a190016f26e6961cd84673523f3e5589781a9
    • Instruction Fuzzy Hash: 0F31A4A1715B8182DE18EFA6E5410A9A761EB45FE0B488335DF7E5BBD5CE3CD045C308
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Current$Process$CriticalDuplicateEnterErrorFileHandleLastReadSectionThread
    • String ID: onecore\windows\core\console\open\src\interactivity\onecore\coniosrvcomm.cpp
    • API String ID: 3595956420-2051704093
    • Opcode ID: f5becd69f15ac0bb690a8311c97d52ca97d75b5a317458d465362d138c117e09
    • Instruction ID: 96b0bbc7ec5e38c569ebadb1b6c00d2e810e9ec30e4fa928a5ec413ffdf3f5fa
    • Opcode Fuzzy Hash: f5becd69f15ac0bb690a8311c97d52ca97d75b5a317458d465362d138c117e09
    • Instruction Fuzzy Hash: 7B414F3291D78287E724AB71F4403BABBA0FB99781F545236DA9D83A58DF7CD148CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00007FF6A8CE1E0E), ref: 00007FF6A8CE1FA7
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00007FF6A8CE1E0E), ref: 00007FF6A8D02593
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00007FF6A8CE1E0E), ref: 00007FF6A8D025A0
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,00007FF6A8CE1E0E), ref: 00007FF6A8D025AE
    • SetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,00007FF6A8CE1E0E), ref: 00007FF6A8D025CD
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate$ErrorLast
    • String ID: onecore\windows\core\console\open\src\types\utils.cpp$vvv$HV
    • API String ID: 3541018266-4251474025
    • Opcode ID: ea539d1948043ed860e7f5c59b7e817d7f6244be8fad9de7168a4eb231c5ece8
    • Instruction ID: 5d12c1492d02a627239b87f2de81184a075ee8a04ed54959ef89aa50a30477e4
    • Opcode Fuzzy Hash: ea539d1948043ed860e7f5c59b7e817d7f6244be8fad9de7168a4eb231c5ece8
    • Instruction Fuzzy Hash: 9B413872C06A42C6E7616F28D804A3C7BF0FB86B09F258236C25AC7340DF7E9459CB49
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D387C8
    • ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D387DA
    • ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ.MSVCP_WIN ref: 00007FF6A8D387F8
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: D@std@@@std@@U?$char_traits@$?epptr@?$basic_streambuf@?pptr@?$basic_streambuf@Pninc@?$basic_streambuf@
    • String ID:
    • API String ID: 4060314879-0
    • Opcode ID: 8ce4cadc5d2bdd30ff5109754d63fe70107003bea4d7e938a2ae4a577c858c39
    • Instruction ID: c09ac6b8cb97fabf9697d32d745873a1cafd0b235d645fafbf98e79d862b1ebe
    • Opcode Fuzzy Hash: 8ce4cadc5d2bdd30ff5109754d63fe70107003bea4d7e938a2ae4a577c858c39
    • Instruction Fuzzy Hash: 0D41A435A1AB9586EA10AF76A504178BBE0FB49FE0B548731DE2D93790DF3CE819C304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: __scrt_acquire_startup_lock__scrt_get_show_window_mode__scrt_initialize_crt__scrt_is_managed_app__scrt_release_startup_lock_o__cexit_o__exit_o__get_wide_winmain_command_line_register_thread_local_exe_atexit_callback
    • String ID:
    • API String ID: 105026157-0
    • Opcode ID: 373c1e3d959a289a0859a5006aa4aa7d659e965486686b4d9a266f4acda0f4cd
    • Instruction ID: a8afd70c2af9564d234cc764b463c9c85a1e7dd30504362a071d3b3649f0e93b
    • Opcode Fuzzy Hash: 373c1e3d959a289a0859a5006aa4aa7d659e965486686b4d9a266f4acda0f4cd
    • Instruction Fuzzy Hash: 8E315E21E1F24781FB24BB7594633B922B19F87384F544174E95FCB6D7DE6CA8088B48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_wcscpy_smemsetwcsnlen
    • String ID: Terminal$onecore\windows\core\console\open\src\renderer\gdi\state.cpp
    • API String ID: 2585542015-367812907
    • Opcode ID: c81ce58fb0a7eac440a729ce454c481af7880623ebe3f3f2668de8c7c396ac09
    • Instruction ID: 16e9de3852c06227d292313c21fef6d6fa1a1e0d401dc61d023a509b012a2920
    • Opcode Fuzzy Hash: c81ce58fb0a7eac440a729ce454c481af7880623ebe3f3f2668de8c7c396ac09
    • Instruction Fuzzy Hash: 8EA1922260A6818AE7109B31E8106BE7B70FB8BB95F54A136DE5E97B54DF3CD409CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_delete$CriticalEnterSection
    • String ID: onecore\windows\core\console\open\src\host\directio.cpp
    • API String ID: 739439809-2458865805
    • Opcode ID: f657a72c47d512cebf83ace46d7da8a903c7b252305197ed4b335dbf1bd9a689
    • Instruction ID: 7e64b099994037ad31fbbb2cada1080eed6f67b2098ed8795b2de3348f44e62d
    • Opcode Fuzzy Hash: f657a72c47d512cebf83ace46d7da8a903c7b252305197ed4b335dbf1bd9a689
    • Instruction Fuzzy Hash: 05914332A4FB8182EA20FB35E4412BE67B5FB86780F545135DA8EC3A5ADE3CD445CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memcpy
    • String ID: onecore\windows\core\console\open\src\server\apidispatchers.cpp$onecore\windows\core\console\open\src\server\objecthandle.cpp
    • API String ID: 3510742995-1968334596
    • Opcode ID: bc1ba511ef39bfb40384cc7a468ac745e4de5380c81dbb88d4129812fea58121
    • Instruction ID: 6b3ab59e72a4b3f0f8e1b0e1bc0b9ae00b11aea0403f363ad164f41ad31d0640
    • Opcode Fuzzy Hash: bc1ba511ef39bfb40384cc7a468ac745e4de5380c81dbb88d4129812fea58121
    • Instruction Fuzzy Hash: AC81AF62B0AA0692EE10EB36E4512B92371FB49BE0F544236DA6F877D5CF3CE445C748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CloseCriticalHandleLeaveSectionXout_of_range@std@@
    • String ID: invalid string_view position$onecore\windows\core\console\open\src\buffer\out\textcolor.cpp$onecore\windows\core\console\open\src\host\input.cpp
    • API String ID: 3449835143-4230967921
    • Opcode ID: 411bfcc234b14af91bfcebd3d0918440583c7c9552b477f29b42018c14b5dd2b
    • Instruction ID: 32cb9970226748661251c3a9121a633ab93aa363870afc8e6da8042a61debc2a
    • Opcode Fuzzy Hash: 411bfcc234b14af91bfcebd3d0918440583c7c9552b477f29b42018c14b5dd2b
    • Instruction Fuzzy Hash: 3D71DF22B0F64282EA50AB35D450A796B72FB86784F544731D96FC3BA1DE2CE94DC708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ControlDevice$memset
    • String ID: DeviceIoControl failed with Result 0x%x$onecore\windows\core\console\open\src\server\apimessage.cpp$onecore\windows\core\console\open\src\server\devicecomm.cpp
    • API String ID: 3112380785-4252510830
    • Opcode ID: 787c8d8be26f4c7a755e2287d03781ec937ab2250cff14a14d97306bd705d75e
    • Instruction ID: d52b00c1441bd2bff20baa564e03bfdd722498b78c93c9e39ab819b7236a8f34
    • Opcode Fuzzy Hash: 787c8d8be26f4c7a755e2287d03781ec937ab2250cff14a14d97306bd705d75e
    • Instruction Fuzzy Hash: D3716032A1AB8286E710DF75E4402AE77B4FB89B84F504536EA4E97B59DF3CE444CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Name$FileFindFullImagePathProcessQuery
    • String ID: d
    • API String ID: 2220688768-2564639436
    • Opcode ID: c28339e45d940fb66dab24b98da191ffb03e41c3ed2a32a37b3939fae9a40673
    • Instruction ID: ea12194279e36c8372077ace0dbabee992525be06a49a9350dac871b3b35e053
    • Opcode Fuzzy Hash: c28339e45d940fb66dab24b98da191ffb03e41c3ed2a32a37b3939fae9a40673
    • Instruction Fuzzy Hash: B751A132A19A8581EB10AF35E4503B977B1FB89B98F484635DA9E87788EF3CD448C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CE087E), ref: 00007FF6A8D0AAFE
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CE087E), ref: 00007FF6A8D0AB43
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CE087E), ref: 00007FF6A8D0AB7F
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CE087E), ref: 00007FF6A8D0AC01
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CE087E), ref: 00007FF6A8D0AC18
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CE087E), ref: 00007FF6A8D0AC30
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove$Xout_of_range@std@@memcpy
    • String ID: invalid string position
    • API String ID: 4206165965-1799206989
    • Opcode ID: 7ced0bd7981491a45fd76aa9d4dd7a4b499f8e809f598190a9e6e2a87112e682
    • Instruction ID: fc6e8b5382a0b2f11e8498a9ec2b52d1b316b8126b2b76fb13448019514110f5
    • Opcode Fuzzy Hash: 7ced0bd7981491a45fd76aa9d4dd7a4b499f8e809f598190a9e6e2a87112e682
    • Instruction Fuzzy Hash: 5341F17271AB9695DA10EF22E4440E97372FB44BC4B940236DE5E9BB50CF3CE14AC308
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CE4314: GetOEMCP.API-MS-WIN-CORE-LOCALIZATION-L1-2-0 ref: 00007FF6A8CE435B
      • Part of subcall function 00007FF6A8CE4314: GetACP.API-MS-WIN-CORE-LOCALIZATION-L1-2-0 ref: 00007FF6A8CE436D
    • CreateEventExW.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CE4679
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0 ref: 00007FF6A8CE4691
    • CreateEventExW.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CE46C4
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0 ref: 00007FF6A8CE46DC
      • Part of subcall function 00007FF6A8CEAF14: DeviceIoControl.API-MS-WIN-CORE-IO-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8D49393), ref: 00007FF6A8CEAF41
    • CreateThread.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0 ref: 00007FF6A8CE4757
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0 ref: 00007FF6A8CE476F
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Create$ErrorEventLast$CloseControlDeviceHandleThread
    • String ID: onecore\windows\core\console\open\src\host\srvinit.cpp
    • API String ID: 2164167334-2090781281
    • Opcode ID: fa6c6db053bca38a8369b6625860772f932979406d6a3cf3f734a9529d32d6dc
    • Instruction ID: 010a9d336be7e286c82304dfbc2b469bb269f57be6fccb1fb1403a8356f082c0
    • Opcode Fuzzy Hash: fa6c6db053bca38a8369b6625860772f932979406d6a3cf3f734a9529d32d6dc
    • Instruction Fuzzy Hash: D441BD25B0FB4386FB15AB71E4513BA6AA1AF89754F408231DA1FC6795DE3CE4089708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,00000000,?,00007FF6A8CE137C,?,?,?,00007FF6A8D1F417), ref: 00007FF6A8CE14CA
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,00000000,?,00007FF6A8CE137C,?,?,?,00007FF6A8D1F417), ref: 00007FF6A8CE14DF
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,00000000,?,00007FF6A8CE137C,?,?,?,00007FF6A8D1F417), ref: 00007FF6A8CE14EC
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,00000000,?,00007FF6A8CE137C,?,?,?,00007FF6A8D1F417), ref: 00007FF6A8D0235C
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memset$Xlength_error@std@@memmove
    • String ID: deque<T> too long
    • API String ID: 4008601576-309773918
    • Opcode ID: 9fba5ebbcc1a089a27578ff48af67d98813d0afa3da1cccbbe2271fefd5a60c3
    • Instruction ID: f5d713e411dc8e61d9c231c05cf405c26ad4677446383afcc1ed653adf8d0ca9
    • Opcode Fuzzy Hash: 9fba5ebbcc1a089a27578ff48af67d98813d0afa3da1cccbbe2271fefd5a60c3
    • Instruction Fuzzy Hash: D931C2A2B16B8182DE14DF62E5410A9A361EB45FE0B588635DF7E5BBD6CE3CE051C308
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: QueryValue$CloseOpen
    • String ID: DisplayInitDelay$FontSize$SYSTEM\CurrentControlSet\Control\ConKbd
    • API String ID: 1586453840-3302960082
    • Opcode ID: 92f522511b410d275b33565efa5e9dd6597bed42a4c4554be2ff3eb6887cfda5
    • Instruction ID: b011d8ec71dfbc5b06e0d9a8070623eb6cf341ee1cf75fe77507b822dfa21b31
    • Opcode Fuzzy Hash: 92f522511b410d275b33565efa5e9dd6597bed42a4c4554be2ff3eb6887cfda5
    • Instruction Fuzzy Hash: 0A315132A25656DFEB60AF30D4406B977A0FB4876CB445336FA5E82A54DF3CD448CB48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D67851
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D678B9
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D6791A
    • memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8D679E2
    • memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8D67A40
      • Part of subcall function 00007FF6A8D64A24: ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D64A58
      • Part of subcall function 00007FF6A8D64A24: memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D64AD2
      • Part of subcall function 00007FF6A8D64A24: memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D64AE4
    • memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8D67AA1
    Strings
    • onecore\windows\core\console\open\src\renderer\dx\customtextlayout.cpp, xrefs: 00007FF6A8D67977
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memset$Xlength_error@std@@memmove
    • String ID: onecore\windows\core\console\open\src\renderer\dx\customtextlayout.cpp
    • API String ID: 4008601576-174823080
    • Opcode ID: 30ba88031fcf8e667f91a7b610c581243580d2fe17ebc8ec3aa7aa3ba1a57bb5
    • Instruction ID: 2c0fb0b689bfe0a9b859b0843d46b8a2ede32e72b2d804f5f725217f1224f04f
    • Opcode Fuzzy Hash: 30ba88031fcf8e667f91a7b610c581243580d2fe17ebc8ec3aa7aa3ba1a57bb5
    • Instruction Fuzzy Hash: A2A1C326B2BA8E81DE14EA76D5444BE7357EB48BD0B559632CA6E83741DE3CE148C304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D3555E
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D3557C
    • ?good@ios_base@std@@QEBA_NXZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D355A6
    • ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D355C0
    • ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D355DB
    • ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D355F6
    • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D35605
    • ?good@ios_base@std@@QEBA_NXZ.MSVCP_WIN(?,?,00000000,00007FF6A8D34B04), ref: 00007FF6A8D3561B
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: U?$char_traits@$D@std@@@std@@$D@std@@@2@$?tie@?$basic_ios@V?$basic_ostream@$?good@ios_base@std@@?rdbuf@?$basic_ios@V?$basic_streambuf@$?flush@?$basic_ostream@V12@
    • String ID:
    • API String ID: 2615938766-0
    • Opcode ID: 032b58e1e1fc7a8bac2eededd9a2a2a66c7ba88c990e68d37655290dfce7a694
    • Instruction ID: 939397e05b944d013852cb3769978155dd1a4f208a4a5aa757938f14d2751663
    • Opcode Fuzzy Hash: 032b58e1e1fc7a8bac2eededd9a2a2a66c7ba88c990e68d37655290dfce7a694
    • Instruction Fuzzy Hash: 02319832615E89C6EB14AF25E594238BBA0FF8AF96759D931DA1E83321DF3CD0588704
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: UUUUUUUU$vector<T> too long
    • API String ID: 0-1961640351
    • Opcode ID: 71fe72eecde0641b9d7757be0279f8e3b598ae0fff16df11db615935e03f09c6
    • Instruction ID: b20f56740b9ac71fc4437d3ac0d35d4430af91db7968a1ecab18482127d08f2c
    • Opcode Fuzzy Hash: 71fe72eecde0641b9d7757be0279f8e3b598ae0fff16df11db615935e03f09c6
    • Instruction Fuzzy Hash: 2691E03361AB8085D720DF25E84466E77F8FB99790F468225EBAE83790EF38D591C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$EnterLeavememmove
    • String ID: invalid deque<T> subscript
    • API String ID: 572680541-2228476695
    • Opcode ID: 53cefdf846a752a5982d1de22903b77f3d0166d5d4c7d25a994cfd6a0fc982a0
    • Instruction ID: 5a0e643e54623c36b9430cf40cc8b2ef681a335308cb4b17ed4e5049f39449e8
    • Opcode Fuzzy Hash: 53cefdf846a752a5982d1de22903b77f3d0166d5d4c7d25a994cfd6a0fc982a0
    • Instruction Fuzzy Hash: 1F91622661A6C1C6EA60DF25E0506BDB7B0FB99B40F449136DA8EC3B55DF3CD445CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\renderer\dx\customtextlayout.cpp, xrefs: 00007FF6A8D6528F
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate
    • String ID: onecore\windows\core\console\open\src\renderer\dx\customtextlayout.cpp
    • API String ID: 882196631-174823080
    • Opcode ID: d714449d7efe7df7a22c0c797813e6e5a645ecd97442e868335dd366e9e44f45
    • Instruction ID: 97cf52d07e53aa58868a25191ff70ecf77517a2e88f480819643f0fcd4ec3d62
    • Opcode Fuzzy Hash: d714449d7efe7df7a22c0c797813e6e5a645ecd97442e868335dd366e9e44f45
    • Instruction Fuzzy Hash: 8A913D72615F49C1DB10EF21E844AA833B8FB49B98F558235DEAD83720DF38D4A9C344
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetCurrentProcess.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000,?,00007FF6A8D00C4A), ref: 00007FF6A8D48F80
    • GetCurrentProcess.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000,?,00007FF6A8D00C4A), ref: 00007FF6A8D48F93
    • DuplicateHandle.API-MS-WIN-CORE-HANDLE-L1-1-0 ref: 00007FF6A8D48FBD
    • ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000,?,00007FF6A8D00C4A), ref: 00007FF6A8D4906F
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CurrentProcess$DuplicateHandleXout_of_range@std@@
    • String ID: invalid deque<T> subscript$onecore\windows\core\console\open\src\server\processlist.cpp
    • API String ID: 4104642312-902665438
    • Opcode ID: 9ed595a072ce553778611dced97afd19a1d1c89f452a1499fb489d34d163cac6
    • Instruction ID: 29fc230ad6eb01d8588ed7af66aa418ecb08105ac2fd06d591fc95fec0c1e545
    • Opcode Fuzzy Hash: 9ed595a072ce553778611dced97afd19a1d1c89f452a1499fb489d34d163cac6
    • Instruction Fuzzy Hash: E261AF32A0AB8586EA10AF22E4406ADB7A0FBC9B90F558236DF5D937A5DF3CD445C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CE1C60: memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8CE1D3B
      • Part of subcall function 00007FF6A8CE1C60: _o_wcscpy_s.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8CE1D4F
      • Part of subcall function 00007FF6A8CE1C60: memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8CE1D68
    • _Mtx_init_in_situ.MSVCP_WIN ref: 00007FF6A8CE12A2
    • CreateTimerQueue.API-MS-WIN-CORE-THREADPOOL-LEGACY-L1-1-0 ref: 00007FF6A8CE12CA
    • InitializeCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CE1313
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,00000000,?,00007FF6A8CE137C,?,?,?,00007FF6A8D1F417), ref: 00007FF6A8D02318
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,00000000,?,00007FF6A8CE137C,?,?,?,00007FF6A8D1F417), ref: 00007FF6A8D02331
    Strings
    • onecore\windows\core\console\open\src\host\cursorblinker.cpp, xrefs: 00007FF6A8D022FC
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmovememset$CreateCriticalInitializeMtx_init_in_situQueueSectionTimer_o_wcscpy_s
    • String ID: onecore\windows\core\console\open\src\host\cursorblinker.cpp
    • API String ID: 2788725267-1313982512
    • Opcode ID: f28b91d695cdba21fdef27a45ad2185306c15cc78d740734dbfa6ffca3e74e8b
    • Instruction ID: 504250d68eb9e55c54172145a7905d5580aeb121f9d6c35be27752fb2559d13f
    • Opcode Fuzzy Hash: f28b91d695cdba21fdef27a45ad2185306c15cc78d740734dbfa6ffca3e74e8b
    • Instruction Fuzzy Hash: 2B71E832A09F81EAD34C9F30EA90299B7A5F744750F585229D7AD83350DF38B1B4CB49
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00000000,?,?,00007FF6A8D02C29), ref: 00007FF6A8D01F6A
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,00000000,?,?,00007FF6A8D02C29), ref: 00007FF6A8D01F7E
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,00007FF6A8D33D23,?,?,?,00007FF6A8D0A96B), ref: 00007FF6A8D01FA0
      • Part of subcall function 00007FF6A8CEEE2C: _o_malloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8CDE93E,?,?,?,?,00007FF6A8D0931C,?,?,?,?,?,?,?), ref: 00007FF6A8CEEE46
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate$Xlength_error@std@@_o_malloc
    • String ID: list<T> too long$onecore\windows\core\console\open\src\host\screeninfo.cpp$onecore\windows\core\console\open\src\server\apidispatchers.cpp
    • API String ID: 1587979356-1453441454
    • Opcode ID: e9c6caf4a20561dfef44d2f169fd6de7ff4898cf2c80cb75a588ac0d81687d7d
    • Instruction ID: f2d1a989ed97cd3dbf0da79f9ee2a404686240dfaad1dd53b6d5c040429858d9
    • Opcode Fuzzy Hash: e9c6caf4a20561dfef44d2f169fd6de7ff4898cf2c80cb75a588ac0d81687d7d
    • Instruction Fuzzy Hash: 9A41AF32909B4682E720AF21E440279B7B0FB88B94F548235EBDE97765DF3CE495C748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8CE1E91
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00007FF6A8CE1E0E), ref: 00007FF6A8D02593
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00007FF6A8CE1E0E), ref: 00007FF6A8D025A0
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,00007FF6A8CE1E0E), ref: 00007FF6A8D025AE
    • SetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,00007FF6A8CE1E0E), ref: 00007FF6A8D025CD
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate$ErrorLast
    • String ID: onecore\windows\core\console\open\src\types\utils.cpp
    • API String ID: 3541018266-2938961315
    • Opcode ID: bc668e80d84e03032da5e37e2e1e258f2d6943aa9b863624f11f8cd5f1543d10
    • Instruction ID: bf3d7d7444840b6a6bb75847af95fbc1bd62906a355c3245dbdf531d61949075
    • Opcode Fuzzy Hash: bc668e80d84e03032da5e37e2e1e258f2d6943aa9b863624f11f8cd5f1543d10
    • Instruction Fuzzy Hash: 4D41D2B1E05686CAE314AB60E0444B87BB0FB89B15F145633DA9E83B40DF3DD4A4CF04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • LoadLibraryExW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6A8D05F4A), ref: 00007FF6A8D33AB3
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6A8D05F4A), ref: 00007FF6A8D33AD6
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6A8D05F4A), ref: 00007FF6A8D33AF8
      • Part of subcall function 00007FF6A8CE97A0: EventWriteTransfer.API-MS-WIN-EVENTING-PROVIDER-L1-1-0 ref: 00007FF6A8CE9823
    • FreeLibrary.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6A8D05F4A), ref: 00007FF6A8D33B21
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Library$AddressErrorEventFreeLastLoadProcTransferWrite
    • String ID: ConhostV1.dll$ConsoleCreateIoThread
    • API String ID: 331234469-2092506167
    • Opcode ID: 478e00b8d43400c205c645caf0b0e7b58c71f14c9e032ff31fb6f5d3ebfe6d8a
    • Instruction ID: 5ebf80c3e8d02c7e4a68edaf5b923259bf8a5be9d8f610cef2358de853eaf182
    • Opcode Fuzzy Hash: 478e00b8d43400c205c645caf0b0e7b58c71f14c9e032ff31fb6f5d3ebfe6d8a
    • Instruction Fuzzy Hash: 5B318B32A1AB4285FB50AB21F944778B3A4FB88B80F555234D92D83750EF3CE809C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38EE2
    • ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38EFD
    • ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38F16
    • ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38F44
    • ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38F56
    • ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z.MSVCP_WIN ref: 00007FF6A8D38F6E
    • ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38F7D
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: D@std@@@std@@U?$char_traits@$?gptr@?$basic_streambuf@$?eback@?$basic_streambuf@?egptr@?$basic_streambuf@?pptr@?$basic_streambuf@?setg@?$basic_streambuf@D00@
    • String ID:
    • API String ID: 1210260451-0
    • Opcode ID: 9698536e5543edc20f1fbd59e770de1db72d3f4fa393cb7878400daeceb2bd1e
    • Instruction ID: 7ec685440468be3cab3dcbcf4f2cba64ac09fd5b9249f3e12829036eb500ed94
    • Opcode Fuzzy Hash: 9698536e5543edc20f1fbd59e770de1db72d3f4fa393cb7878400daeceb2bd1e
    • Instruction Fuzzy Hash: E111A521A0AA9582FB107B31A504178FBE1FB4AFD1B489630EE2E53744CF3CD4598704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN(?,?,?,00007FF6A8D356EC,?,?,?,00007FF6A8D469A6,?,?,00000002,00007FF6A8D5907E), ref: 00007FF6A8D3845B
    • ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN(?,?,?,00007FF6A8D356EC,?,?,?,00007FF6A8D469A6,?,?,00000002,00007FF6A8D5907E), ref: 00007FF6A8D38470
    • ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN(?,?,?,00007FF6A8D356EC,?,?,?,00007FF6A8D469A6,?,?,00000002,00007FF6A8D5907E), ref: 00007FF6A8D3847F
    • ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN(?,?,?,00007FF6A8D356EC,?,?,?,00007FF6A8D469A6,?,?,00000002,00007FF6A8D5907E), ref: 00007FF6A8D38492
    • ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN(?,?,?,00007FF6A8D356EC,?,?,?,00007FF6A8D469A6,?,?,00000002,00007FF6A8D5907E), ref: 00007FF6A8D384A5
    • ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z.MSVCP_WIN(?,?,?,00007FF6A8D356EC,?,?,?,00007FF6A8D469A6,?,?,00000002,00007FF6A8D5907E), ref: 00007FF6A8D384C9
    • ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z.MSVCP_WIN(?,?,?,00007FF6A8D356EC,?,?,?,00007FF6A8D469A6,?,?,00000002,00007FF6A8D5907E), ref: 00007FF6A8D384DE
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: D@std@@@std@@U?$char_traits@$?eback@?$basic_streambuf@$?egptr@?$basic_streambuf@?epptr@?$basic_streambuf@?pptr@?$basic_streambuf@?setg@?$basic_streambuf@?setp@?$basic_streambuf@D00@
    • String ID:
    • API String ID: 2626452370-0
    • Opcode ID: 8fc7cd35d9df268a50c79aa50dff00d68e15ae2ab654d587b5844d874c0975b2
    • Instruction ID: 0f1d26162d34990c7179ac417fa6b9767319bdf738cbc2b47809545ceead1ff7
    • Opcode Fuzzy Hash: 8fc7cd35d9df268a50c79aa50dff00d68e15ae2ab654d587b5844d874c0975b2
    • Instruction Fuzzy Hash: BB118221A15B468BE6147B35A414238BBA1FB8FB62F58A230DA1E42754DF3C844C8608
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\renderer\base\thread.cpp, xrefs: 00007FF6A8D05295
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: EventObjectSingleWait$ResetSleep
    • String ID: onecore\windows\core\console\open\src\renderer\base\thread.cpp
    • API String ID: 1999667587-1671638080
    • Opcode ID: 060eb9c7abadf1573f866dac22e3bb619aaab6933dc54f74b328813f189fdaab
    • Instruction ID: 1c727da12847f4b3735f71b37d2eff228fc3e244a82a5e3db468656303eb837f
    • Opcode Fuzzy Hash: 060eb9c7abadf1573f866dac22e3bb619aaab6933dc54f74b328813f189fdaab
    • Instruction Fuzzy Hash: 3E115C26A1AA4686FB60AB71A80117C3BB0FF8AF55F585230DD6E837A4CF2CD4498744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o__errno.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00000000,00000000,?,00007FF6A8D021F3), ref: 00007FF6A8D31ED9
    • _o_wcstol.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00000000,00000000,?,00007FF6A8D021F3), ref: 00007FF6A8D31F03
    • ?_Xinvalid_argument@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,00000000,00000000,?,00007FF6A8D021F3), ref: 00007FF6A8D31F20
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xinvalid_argument@std@@_o__errno_o_wcstol
    • String ID: invalid stoi argument$stoi argument out of range
    • API String ID: 503588107-1606216832
    • Opcode ID: fc30ed6c13a5f84a7e89a698331b1b88d1bab552335b316ffc5616c4c3fea35b
    • Instruction ID: d7da75f77f7e69228aed75777cf760bf96c7122a25a84dc101835a83500fc002
    • Opcode Fuzzy Hash: fc30ed6c13a5f84a7e89a698331b1b88d1bab552335b316ffc5616c4c3fea35b
    • Instruction Fuzzy Hash: A511A532619A42C2EB04AF21F940078FB70FB99B91F889234EA5E83754DF3CD498C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • CancelSynchronousIo.API-MS-WIN-CORE-IO-L1-1-1(?,?,00000000,00007FF6A8D4D9A4), ref: 00007FF6A8D5629C
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,00000000,00007FF6A8D4D9A4), ref: 00007FF6A8D562C4
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,00000000,00007FF6A8D4D9A4), ref: 00007FF6A8D562E2
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,00000000,00007FF6A8D4D9A4), ref: 00007FF6A8D562FB
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,00000000,00007FF6A8D4D9A4), ref: 00007FF6A8D56314
    Strings
    • onecore\windows\core\console\open\src\interactivity\onecore\coniosrvcomm.cpp, xrefs: 00007FF6A8D562B1
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CloseHandle$CancelSynchronous
    • String ID: onecore\windows\core\console\open\src\interactivity\onecore\coniosrvcomm.cpp
    • API String ID: 2419186852-2051704093
    • Opcode ID: 5122a756d0b2cfb834670bf352ffe02bd31e776ba7c576efe7403dd518ae31a5
    • Instruction ID: 46b924eef5ff37698983535c7a384a89e493ec2ea2ccf54e856628812ab4aa29
    • Opcode Fuzzy Hash: 5122a756d0b2cfb834670bf352ffe02bd31e776ba7c576efe7403dd518ae31a5
    • Instruction Fuzzy Hash: BA115C3261AB46C6EB14AF31F4402787BB4FB89F68B555331CA3E82694CF39D458C344
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_delete
    • String ID:
    • API String ID: 3712186324-0
    • Opcode ID: ab0a72f54758f0031add3fd889993b7b147e8b745e6485766e15a140c1a6de20
    • Instruction ID: a5621509e36e2c1d3e62bf3dcbfd2e518f8551f135be325377fabdb35e8bee21
    • Opcode Fuzzy Hash: ab0a72f54758f0031add3fd889993b7b147e8b745e6485766e15a140c1a6de20
    • Instruction Fuzzy Hash: 1671E832A0E68181EB60EF71E1417BEA3A0FF85790F444275EA9D87686EF3DD048C708
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\server\apidispatchers.cpp
    • API String ID: 0-3284698556
    • Opcode ID: 93fbe8aeeccf5441b3cf188328939435f8224b8c64599d999f7002164c7239da
    • Instruction ID: e0b652742df3cdd3515b8cad722e4df061548da73eb314241cedaba2ae94862c
    • Opcode Fuzzy Hash: 93fbe8aeeccf5441b3cf188328939435f8224b8c64599d999f7002164c7239da
    • Instruction Fuzzy Hash: 6FF1A372B05B4689FB10AB74D8402FD27B1FB84B88F148636DE5D9B799DF38D5898304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38B38
    • ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38B4A
    • ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38B6B
    • ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z.MSVCP_WIN ref: 00007FF6A8D38C24
    • ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38C3E
    • ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z.MSVCP_WIN ref: 00007FF6A8D38C56
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: D@std@@@std@@U?$char_traits@$D00@$?eback@?$basic_streambuf@?epptr@?$basic_streambuf@?gptr@?$basic_streambuf@?pptr@?$basic_streambuf@?setg@?$basic_streambuf@?setp@?$basic_streambuf@
    • String ID:
    • API String ID: 2849800682-0
    • Opcode ID: 641fabe91b91b1978779cd095bce43cdcc9c56a17aedd7549abd142ef7668995
    • Instruction ID: bc1ec048699c36076a542cb50cf28aeb4c58b68edc15989ee513421732dae7b3
    • Opcode Fuzzy Hash: 641fabe91b91b1978779cd095bce43cdcc9c56a17aedd7549abd142ef7668995
    • Instruction Fuzzy Hash: 5B41B829A0BB4689E6557B319504236E7D0EF45FD4F584330DD2E97784DF3CE859C208
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CEC35C: EventRegister.API-MS-WIN-EVENTING-PROVIDER-L1-1-0(?,?,?,?,?,?,?,00007FF6A8CE4052), ref: 00007FF6A8CEC3A8
      • Part of subcall function 00007FF6A8CEC35C: EventSetInformation.API-MS-WIN-EVENTING-PROVIDER-L1-1-0(?,?,?,?,?,?,?,00007FF6A8CE4052), ref: 00007FF6A8CEC3CD
    • GetStdHandle.API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0 ref: 00007FF6A8CEC20D
    • GetStdHandle.API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0 ref: 00007FF6A8CEC221
    • GetCommandLineW.API-MS-WIN-CORE-PROCESSENVIRONMENT-L1-1-0 ref: 00007FF6A8CEC230
      • Part of subcall function 00007FF6A8CE0AC4: CommandLineToArgvW.API-MS-WIN-SHCORE-OBSOLETE-L1-1-0 ref: 00007FF6A8CE0B42
    • EventUnregister.API-MS-WIN-EVENTING-PROVIDER-L1-1-0 ref: 00007FF6A8CEC2D3
    • SetProcessShutdownParameters.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0 ref: 00007FF6A8CEC2EB
    • ExitThread.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0 ref: 00007FF6A8CEC2F9
      • Part of subcall function 00007FF6A8CE44B8: RegOpenKeyExW.API-MS-WIN-CORE-REGISTRY-L1-1-0 ref: 00007FF6A8CE44E7
      • Part of subcall function 00007FF6A8CE44B8: RegQueryValueExW.API-MS-WIN-CORE-REGISTRY-L1-1-0 ref: 00007FF6A8CE4529
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Event$CommandHandleLine$ArgvExitInformationOpenParametersProcessQueryRegisterShutdownThreadUnregisterValue
    • String ID:
    • API String ID: 3181419396-0
    • Opcode ID: e7d41ba07157651c59372171ef00f3341990f83a09fa3859baa44af066e69f04
    • Instruction ID: 2ff746d2c0f0553c916627f9698827a3cc21334cc7d11c536ead50933e4257af
    • Opcode Fuzzy Hash: e7d41ba07157651c59372171ef00f3341990f83a09fa3859baa44af066e69f04
    • Instruction Fuzzy Hash: 4C415022F0AA429AFB20EBB0D4510FC3774EF59744B814675EA1ED7696DE2CE448C748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38CCC
    • ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38CDE
    • ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38CFF
    • ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z.MSVCP_WIN ref: 00007FF6A8D38D50
    • ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38D6A
    • ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z.MSVCP_WIN ref: 00007FF6A8D38D82
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: D@std@@@std@@U?$char_traits@$D00@$?eback@?$basic_streambuf@?epptr@?$basic_streambuf@?gptr@?$basic_streambuf@?pptr@?$basic_streambuf@?setg@?$basic_streambuf@?setp@?$basic_streambuf@
    • String ID:
    • API String ID: 2849800682-0
    • Opcode ID: 429131a2e2207ffa7eb825d695100224249643dab29ce70be871a6ae7b20d31d
    • Instruction ID: ff447812f82805622788b6cd37c244f093e9bbfcac75d7bf7cdf2c354bade34f
    • Opcode Fuzzy Hash: 429131a2e2207ffa7eb825d695100224249643dab29ce70be871a6ae7b20d31d
    • Instruction Fuzzy Hash: A3318225606B418AE6556F22A904379B7A0FB49FE4F484734DE2D93B94DF3CD8998308
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D63770: GetUserDefaultLocaleName.API-MS-WIN-CORE-LOCALIZATION-L1-2-0 ref: 00007FF6A8D637A4
    • _o_roundf.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D639E8
    • ceilf.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FF6A8D63A3D
    • ceilf.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FF6A8D63A4A
      • Part of subcall function 00007FF6A8CE1A54: _o_wcscpy_s.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8CE19BC), ref: 00007FF6A8CE1A74
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ceilf$DefaultLocaleNameUser_o_roundf_o_wcscpy_s
    • String ID: $onecore\windows\core\console\open\src\renderer\dx\dxrenderer.cpp
    • API String ID: 1877041966-2592510457
    • Opcode ID: deb38df96e466a38da3de6402ff6179ea484fbe6db73723d83056e501f1f6874
    • Instruction ID: 684b80726271424a2dc013a4a240b737aadc093443b63b387a8d590d8b73c8f0
    • Opcode Fuzzy Hash: deb38df96e466a38da3de6402ff6179ea484fbe6db73723d83056e501f1f6874
    • Instruction Fuzzy Hash: F2E18322619BC591E721AB75E4406EAB3A0FF99784F005333EA8DA3769DF3CD449CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • AcquireSRWLockShared.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,?,?,00007FF6A8CF364A,?,?,?,?,00007FF6A8CF242C), ref: 00007FF6A8CF3531
    • ReleaseSRWLockShared.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,?,?,00007FF6A8CF364A,?,?,?,?,00007FF6A8CF242C), ref: 00007FF6A8CF3551
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,?,?,00007FF6A8CF364A,?,?,?,?,00007FF6A8CF242C), ref: 00007FF6A8CF3571
    • AcquireSRWLockExclusive.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,?,?,00007FF6A8CF364A,?,?,?,?,00007FF6A8CF242C), ref: 00007FF6A8CF3580
    • ReleaseSRWLockExclusive.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,?,?,00007FF6A8CF364A,?,?,?,?,00007FF6A8CF242C), ref: 00007FF6A8CF35D8
    • LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,?,?,00007FF6A8CF364A,?,?,?,?,00007FF6A8CF242C), ref: 00007FF6A8CF35FD
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Lock$AcquireCriticalExclusiveReleaseSectionShared$EnterLeave
    • String ID:
    • API String ID: 3221859647-0
    • Opcode ID: f3baf2eb562313c3a31125de947098063528a7a9156a5ae7727c7dc9a42d9cc4
    • Instruction ID: 95e4bd30a4681eb2e6beb9b688e209ee4de0d53ce5c68a71af3b546a7f9e2133
    • Opcode Fuzzy Hash: f3baf2eb562313c3a31125de947098063528a7a9156a5ae7727c7dc9a42d9cc4
    • Instruction Fuzzy Hash: 25316F22B0AB42D6FA159F31A50017DBB60FF99F91F499530EE4E47714DF3CE4858A04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E06
    • ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E1A
    • ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E2C
    • ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E4C
    • ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E60
    • ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38E72
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: D@std@@@std@@U?$char_traits@$?pptr@?$basic_streambuf@$?eback@?$basic_streambuf@?egptr@?$basic_streambuf@?gptr@?$basic_streambuf@?pbase@?$basic_streambuf@
    • String ID:
    • API String ID: 2812601886-0
    • Opcode ID: b6f32f2ad70b12da2e36fe06b89bf332eb25904ebcef1ba64f6193410b40940d
    • Instruction ID: bf1426e4e0ab11cce61c8edd50d6d095bc79ec545ddcc337acf2b7d79ec9836c
    • Opcode Fuzzy Hash: b6f32f2ad70b12da2e36fe06b89bf332eb25904ebcef1ba64f6193410b40940d
    • Instruction Fuzzy Hash: 31213B32A1978186EA046F25A54433CBBA1FB8AF90F988274DB1D93750CF7CD499C344
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\host\stream.cpp, xrefs: 00007FF6A8D226CE
    • onecore\windows\core\console\open\src\server\objecthandle.cpp, xrefs: 00007FF6A8D22630
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_delete
    • String ID: onecore\windows\core\console\open\src\host\stream.cpp$onecore\windows\core\console\open\src\server\objecthandle.cpp
    • API String ID: 3712186324-1446427362
    • Opcode ID: 1fcea8844a4132750f7121d3063d3c2171974deda0e613e036a1c7ce79ec79cb
    • Instruction ID: de8363f25ba2056c70e9770eb4a411caeb9220bc6438e882f49a35b496543468
    • Opcode Fuzzy Hash: 1fcea8844a4132750f7121d3063d3c2171974deda0e613e036a1c7ce79ec79cb
    • Instruction Fuzzy Hash: EDB1E53260E68281EB65AF31D04067AA7A0FF85F90F148171EE9D977A5EF3CD849C718
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: Access attempted beyond valid size.$invalid array<T, N> subscript
    • API String ID: 0-3498661005
    • Opcode ID: ed55feb6a2bf09e9331b5667a1934da63c46666082347720cf453630b9274995
    • Instruction ID: 6171a72f1b345ac2a35da8e5728cfc39a060106b52a43178d4ea8f682762ad21
    • Opcode Fuzzy Hash: ed55feb6a2bf09e9331b5667a1934da63c46666082347720cf453630b9274995
    • Instruction Fuzzy Hash: 1AD19022918AC695EB11EF34E4411FDB770FB95348F405222EB8D5396AEF3CE689CB44
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CF4DB4), ref: 00007FF6A8CF5292
      • Part of subcall function 00007FF6A8CF4E08: GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,?,?,?,?,00007FF6A8CF397B), ref: 00007FF6A8CF4E33
    • GetProcessHeap.API-MS-WIN-CORE-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CF4DB4), ref: 00007FF6A8CF5331
    • HeapFree.API-MS-WIN-CORE-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CF4DB4), ref: 00007FF6A8CF5345
    • GetProcessHeap.API-MS-WIN-CORE-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CF4DB4), ref: 00007FF6A8CF5351
    • HeapAlloc.API-MS-WIN-CORE-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CF4DB4), ref: 00007FF6A8CF5365
    • GetProcessHeap.API-MS-WIN-CORE-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CF4DB4), ref: 00007FF6A8CF5519
    • HeapFree.API-MS-WIN-CORE-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CF4DB4), ref: 00007FF6A8CF552D
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Heap$Process$Free$AddressAllocProcmemset
    • String ID:
    • API String ID: 2515388404-0
    • Opcode ID: 03df552c036efd102eeba95cdf94358c3b6e42abdfa1f26a311696fa93278af3
    • Instruction ID: 512e144f742dcf36d7f5b118e212ebf9ef76f3c17f2bbcdb5c20c272aada95fb
    • Opcode Fuzzy Hash: 03df552c036efd102eeba95cdf94358c3b6e42abdfa1f26a311696fa93278af3
    • Instruction Fuzzy Hash: F9916B32A15B918AEB20DF76E4005ADBBB0FB59B48B448235DF8E83B54EF38D544CB14
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_delete$memmove
    • String ID: onecore\windows\core\console\open\src\host\readdataraw.cpp
    • API String ID: 1454313208-2856902044
    • Opcode ID: 8b9876f997857eecdfb85955554a420a2cc10ebabd19a547140f715ef6fef4aa
    • Instruction ID: 6ec4b0b282c5bd1b088bff5b7583d1ef92bcf1e827fa6d8427c37a312cef103d
    • Opcode Fuzzy Hash: 8b9876f997857eecdfb85955554a420a2cc10ebabd19a547140f715ef6fef4aa
    • Instruction Fuzzy Hash: AB81E332A0D68185EB60FB31D0453BE67A4FB85B94F044271EAAE8769BDF3DD048C709
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ErrorLastOpenSemaphore
    • String ID: _p0$wil
    • API String ID: 1909229842-1814513734
    • Opcode ID: bb716a445eb5f807d2fd9c29a65b22a5955492dd0fc231d08743a8f7c7c46de0
    • Instruction ID: c09a01dc9a76a08f6332130334264b9135d92d99e29c14c047b37dabf19f998c
    • Opcode Fuzzy Hash: bb716a445eb5f807d2fd9c29a65b22a5955492dd0fc231d08743a8f7c7c46de0
    • Instruction Fuzzy Hash: EB71B172B2B78281EF22EB3594115B962B5EF89B80F444636DA1F87785EE3CE408C704
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: QueryValue
    • String ID: AllowAltF4Close$WordDelimiters
    • API String ID: 3660427363-1684327172
    • Opcode ID: e5523c97cafc533abfaefd3beb414606d8c3a5eab9d4fef52ab1874036f01a01
    • Instruction ID: c55e348bf6a7d167fd3f0f584874e934664964e37c8db0b8bc45a20f3ec58961
    • Opcode Fuzzy Hash: e5523c97cafc533abfaefd3beb414606d8c3a5eab9d4fef52ab1874036f01a01
    • Instruction Fuzzy Hash: 43619A76B1AB4289EB10AB71E4405AC33B1FB49788F402235DE5E93B58DF3CE449CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,00000101,?,00007FF6A8D39FFB,?,?,?,?,?,?,?,?,00007FF6A8D39E52,?,?,00000001), ref: 00007FF6A8D3A06A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xlength_error@std@@
    • String ID: UUUUUUUU$VUUUUUUU$VUUUUUUU$vector<T> too long
    • API String ID: 1004598685-446613321
    • Opcode ID: feeeb2caef8de16dfa1feaff76b776b44ef47d06d513b48e7a07226d7b0002a9
    • Instruction ID: d370dd287499753e5484d3f40cece0f568c5d7ec03cc8cfdcd5f59dfee1a7047
    • Opcode Fuzzy Hash: feeeb2caef8de16dfa1feaff76b776b44ef47d06d513b48e7a07226d7b0002a9
    • Instruction Fuzzy Hash: A341BFA2B06A9482CE14CF26E544269F775FB58FD0B148232DEAD8BB98EF3CD455C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetCurrentProcessId.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0 ref: 00007FF6A8CE6B36
    • CreateMutexExW.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CE6B7E
      • Part of subcall function 00007FF6A8CE6C4C: WaitForSingleObjectEx.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CE6C65
      • Part of subcall function 00007FF6A8CE6434: memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8CE64E5
      • Part of subcall function 00007FF6A8CE6434: memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8CE6500
      • Part of subcall function 00007FF6A8CED1A4: ReleaseMutex.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CED1A8
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Mutexmemset$CreateCurrentObjectProcessReleaseSingleWait
    • String ID: Local\SM0:%d:%d:%hs$wil$x
    • API String ID: 588896006-630742106
    • Opcode ID: 62074cf9a2ee31fbdf3198cc566985a4febff992dbd5441c89d469a5ff807d09
    • Instruction ID: fa9e26d1c591236ca6602827e07b67bd24b8a15d8c7b6f92c0e06ff9fb482b8d
    • Opcode Fuzzy Hash: 62074cf9a2ee31fbdf3198cc566985a4febff992dbd5441c89d469a5ff807d09
    • Instruction Fuzzy Hash: 7541823261AA8286EB60AB31E8417FA6770EB89784F845135EA4FC7795DE3CD509CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetCurrentThreadId.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,00000000,00007FF6A8CD3593), ref: 00007FF6A8CD3976
      • Part of subcall function 00007FF6A8CD36F4: GetCurrentProcessId.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,?,?,00000000,00007FF6A8CD39C0,?,?,00000000,00007FF6A8CD3593), ref: 00007FF6A8CD373A
      • Part of subcall function 00007FF6A8CD36F4: GetCurrentThreadId.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,?,?,00000000,00007FF6A8CD39C0,?,?,00000000,00007FF6A8CD3593), ref: 00007FF6A8CD3748
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,00000000,00007FF6A8CD3593), ref: 00007FF6A8CFA83A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Current$Thread$ErrorLastProcess
    • String ID: CreateWindowsWindow failed with status 0x%x, gle = 0x%x$onecore\windows\core\console\open\src\interactivity\win32\windowio.cpp$onecore\windows\core\console\open\src\interactivity\win32\windowproc.cpp
    • API String ID: 1620930315-1732931737
    • Opcode ID: 56ace35cebfc3a5fc6a5a66dcab77babb794268237222d07e61c8716418aecae
    • Instruction ID: 4088d98f8e3f901ba4fb07652f00e6351b0bd48f964bc22e5f8d29f4cc0ccaeb
    • Opcode Fuzzy Hash: 56ace35cebfc3a5fc6a5a66dcab77babb794268237222d07e61c8716418aecae
    • Instruction Fuzzy Hash: 7E418425B1AA4382E710BB36E8505B57BA1FF98B84F149131DA1EC7B95DE3CD409C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_delete
    • String ID: invalid deque<T> subscript$onecore\windows\core\console\open\src\host\_stream.cpp
    • API String ID: 3712186324-3945297005
    • Opcode ID: f41d419615db58492d4e43b281603835d7b29edf9071934be31ec606a1a746b9
    • Instruction ID: 23dd2c748cd8066b67079a07bac45183e26b95cc9a64044a3615e5436bcc6a30
    • Opcode Fuzzy Hash: f41d419615db58492d4e43b281603835d7b29edf9071934be31ec606a1a746b9
    • Instruction Fuzzy Hash: D6318372A0EB4682E650EB65E44016973B0FF98BC0F544131EA9E83759DF3CE455CB48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ErrorLastLibrary$FreeLoadmemset
    • String ID: PseudoConsoleWindow
    • API String ID: 1700184377-840225159
    • Opcode ID: a3a8ee61fbd72d31616a1aa1c784c642f45b0e58bc202d714f1f77be1aef2e63
    • Instruction ID: c75bcb1a35b47d134842c45d77ec7577107e7bc01fbbba99c28af01ea1849f12
    • Opcode Fuzzy Hash: a3a8ee61fbd72d31616a1aa1c784c642f45b0e58bc202d714f1f77be1aef2e63
    • Instruction Fuzzy Hash: FA317332A09B81C6E7506F25F44026DBAA1FBC9784F558235DA9DC3B58DF3DD449CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8CE3FD8
    • memset.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FF6A8CE3FFF
    • _time64.API-MS-WIN-CRT-TIME-L1-1-0 ref: 00007FF6A8CE403A
      • Part of subcall function 00007FF6A8CEC35C: EventRegister.API-MS-WIN-EVENTING-PROVIDER-L1-1-0(?,?,?,?,?,?,?,00007FF6A8CE4052), ref: 00007FF6A8CEC3A8
      • Part of subcall function 00007FF6A8CEC35C: EventSetInformation.API-MS-WIN-EVENTING-PROVIDER-L1-1-0(?,?,?,?,?,?,?,00007FF6A8CE4052), ref: 00007FF6A8CEC3CD
      • Part of subcall function 00007FF6A8CE40E0: EventActivityIdControl.API-MS-WIN-EVENTING-PROVIDER-L1-1-0(?,?,?,?,00007FF6A8CE4057), ref: 00007FF6A8CE40F9
      • Part of subcall function 00007FF6A8CE97A0: EventWriteTransfer.API-MS-WIN-EVENTING-PROVIDER-L1-1-0 ref: 00007FF6A8CE9823
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Event$memset$ActivityControlInformationRegisterTransferWrite_time64
    • String ID: bash.exe
    • API String ID: 1899261239-706137074
    • Opcode ID: 832fbc8bc11e08a7cbe9c60d3c6c0ca5074abca75c90f06ac178adb658487ee4
    • Instruction ID: e97d3ec98744d4306b6580dddbe00ebdf9abc0e271739fbf5afcf33787565c28
    • Opcode Fuzzy Hash: 832fbc8bc11e08a7cbe9c60d3c6c0ca5074abca75c90f06ac178adb658487ee4
    • Instruction Fuzzy Hash: 8D410C31D1FA4685EB10AF35F8A12B976B0BF49350F904339D5ADC2AA5DF3CA518CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressExceptionHandleModuleProcThrow
    • String ID: RaiseFailFastException$kernelbase.dll
    • API String ID: 1273124314-919018592
    • Opcode ID: 340b8bf8a41fe92ec4f005a0ce6e5e8395b607c5bece4314819f3e0e167b03f8
    • Instruction ID: 71341f50a52d7bc315337fad73f03b0ee3b08d8d5bbe97d04bd646df7549f43b
    • Opcode Fuzzy Hash: 340b8bf8a41fe92ec4f005a0ce6e5e8395b607c5bece4314819f3e0e167b03f8
    • Instruction Fuzzy Hash: C1117321E19B8581E660AB21F440279B760FF9DB80F64D331E99E43B18EF2CD198C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: OpenQueryValue
    • String ID: Console$ForceV2
    • API String ID: 4153817207-204486278
    • Opcode ID: 1921fd15eda439bd854e55fa8165d1e07ea0593432aeba538e2b7661c0700cd7
    • Instruction ID: a0dad97be9c7ebe458acdcc1e77c1e1cf1605348ed37798cb14f9c7240f37db1
    • Opcode Fuzzy Hash: 1921fd15eda439bd854e55fa8165d1e07ea0593432aeba538e2b7661c0700cd7
    • Instruction Fuzzy Hash: 74118732A1AA95CBEB209B60E40037AB7B0FB86754F504231FA5E83A64DF7CD448DF04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ErrorLastLibrary$FreeLoad
    • String ID: uxtheme.dll
    • API String ID: 1452865118-291804724
    • Opcode ID: c7f5c8dac863e08da36685b2759f2a40199b4dd1380d2e66154f07ed3042d2ff
    • Instruction ID: a89418b545cd4fb3953ec1703be657f40abf86f93ee174c56cafd5e8121f93ae
    • Opcode Fuzzy Hash: c7f5c8dac863e08da36685b2759f2a40199b4dd1380d2e66154f07ed3042d2ff
    • Instruction Fuzzy Hash: 1F015A32A19B85CAE700AF22F840279BA64FB8DF81F589230DA5E83755DF3CD018CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • LoadLibraryExW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,00007FF6A8D4D3E3), ref: 00007FF6A8D4D309
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,00007FF6A8D4D3E3), ref: 00007FF6A8D4D340
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressLibraryLoadProc
    • String ID: NtOpenFile$ntdll.dll$onecore\windows\core\console\open\src\server\winntcontrol.cpp
    • API String ID: 2574300362-2293150788
    • Opcode ID: 3f7caa3ff715c06d388e26ba02a65faf05c3adfdf4bde93906755b50b37056c2
    • Instruction ID: c76cf04bfc5e94d49e3df4ab6a9a3ab7bca177012e45e444322b38ae17377f0d
    • Opcode Fuzzy Hash: 3f7caa3ff715c06d388e26ba02a65faf05c3adfdf4bde93906755b50b37056c2
    • Instruction Fuzzy Hash: 11015E31A1AB4682EA10EB21F8405B47BA1FF98748F588736D96D83B64EF3CE15CC744
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: Escape$Ground$OscTermination$Print
    • API String ID: 0-1586554955
    • Opcode ID: 81e1042cd255a04c22fa24d498576ab43d2dafdc67691663d470adbac0a80d6b
    • Instruction ID: bf70bf0d25f31879f33e6ac238d14b79a1bea045440bf0eeb65e3e719f070d31
    • Opcode Fuzzy Hash: 81e1042cd255a04c22fa24d498576ab43d2dafdc67691663d470adbac0a80d6b
    • Instruction Fuzzy Hash: CA716221D5E712C2FA68B735A1901BC22B5FF96380F504231E65FC7AA6DF2DF8058B49
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$EnterLeave
    • String ID: onecore\windows\core\console\open\src\host\input.cpp
    • API String ID: 3168844106-1659879473
    • Opcode ID: a3aa942beff152bd249eb2e091127b16c148c3fbbb55a04d96d2e5af357f18af
    • Instruction ID: aeb9a48ca9b89dabd2c072abeaf0294e819c02ce8ca9450aa12019b98af9cb12
    • Opcode Fuzzy Hash: a3aa942beff152bd249eb2e091127b16c148c3fbbb55a04d96d2e5af357f18af
    • Instruction Fuzzy Hash: 8F41D132A0A68286E620AB31E450A797BB1FF46B94F144635DD2EC37A5DF3CE50CC748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: LoadString$memset
    • String ID:
    • API String ID: 2160227474-0
    • Opcode ID: 2cb8e3ffb6c2a8227b393da31a3283314f20a9eba047cdd78a75ba8818e3417f
    • Instruction ID: 1bf3da9483f38a2ce7193fad4b7391dc48081b25146a0749d3b114c047daea5a
    • Opcode Fuzzy Hash: 2cb8e3ffb6c2a8227b393da31a3283314f20a9eba047cdd78a75ba8818e3417f
    • Instruction Fuzzy Hash: D0514835B06A4296F710AF62E8247B97BA0FB8AB94F449231DD0EA3B54CF3CD509C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$Leave$CloseEnterHandle
    • String ID: onecore\windows\core\console\open\src\host\input.cpp
    • API String ID: 409575328-1659879473
    • Opcode ID: 7b5fd56e974f1191e1aa145b6960964012f50e1d5fd837460aeb5b6423f25cf7
    • Instruction ID: a04cd85c2ac2c1c5cdd8ed5129f6afec1359ed0b0170cb14310caf788487d0ce
    • Opcode Fuzzy Hash: 7b5fd56e974f1191e1aa145b6960964012f50e1d5fd837460aeb5b6423f25cf7
    • Instruction Fuzzy Hash: 7641B332A0A64286EA14EB31E4519797BB1BF46794F544331DD2EC3AA5DF3CE40DC748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D221B0: memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,00007FF6A8D2F55F,?,?,?,?,00000000,?,00000000,00007FF6A8D2F46C), ref: 00007FF6A8D221DD
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00000000,?,00000000,00007FF6A8D2F46C), ref: 00007FF6A8D2F56C
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00000000,?,00000000,00007FF6A8D2F46C), ref: 00007FF6A8D2F57F
    • MultiByteToWideChar.API-MS-WIN-CORE-STRING-L1-1-0(?,?,?,?,00000000,?,00000000,00007FF6A8D2F46C), ref: 00007FF6A8D2F5D9
    • MultiByteToWideChar.API-MS-WIN-CORE-STRING-L1-1-0(?,?,?,?,00000000,?,00000000,00007FF6A8D2F46C), ref: 00007FF6A8D2F635
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ByteCharMultiWidememmove$memset
    • String ID: onecore\windows\core\console\open\src\host\utf8towidecharparser.cpp
    • API String ID: 2437670355-2572910317
    • Opcode ID: 2b6796955da8970cfb97e89a1722d0f607505696a352dcd9b3936e10f4f3e128
    • Instruction ID: b1011a4f21ff6052cf33da92523ecb6efa7fa766da666a13828acb600af44bf5
    • Opcode Fuzzy Hash: 2b6796955da8970cfb97e89a1722d0f607505696a352dcd9b3936e10f4f3e128
    • Instruction Fuzzy Hash: AB41E472A0968187E620EF26E54046EB761FB847C0F104631EA5E83B55EF3CE555CF48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CE87AF), ref: 00007FF6A8D03AAC
      • Part of subcall function 00007FF6A8CE82A8: _Init_thread_footer.LIBCMT ref: 00007FF6A8CE82F0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ErrorInit_thread_footerLast
    • String ID: +$ConsoleWindowClass$P$onecore\windows\core\console\open\src\interactivity\win32\window.cpp
    • API String ID: 375221603-2508929681
    • Opcode ID: 65d1d02c9be5cbf2c83cf03b75cdccea5677bd7f8de363e3fcf64647ec02b270
    • Instruction ID: aa91bdc5b0b7e67643f8339fb2d9a6425b6b5d79f3aec45289e6c4537b6eb318
    • Opcode Fuzzy Hash: 65d1d02c9be5cbf2c83cf03b75cdccea5677bd7f8de363e3fcf64647ec02b270
    • Instruction Fuzzy Hash: 5E316B32A05B529AE700EFB1E8401AD37B8FB49784F908236EA5D93B54DF38D549CB44
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memset$AlpcPortReceiveSendWait_o__errno_o__invalid_parameter_noinfomemcpy
    • String ID:
    • API String ID: 1376145858-0
    • Opcode ID: 02463cfab35b8edaaa22ba997779b0fa5854f9a355f5b7c05837a7215f85ca0e
    • Instruction ID: c10050156d2bbb16c0c356c639189d11bbbb7749280878a94fdbfc257920fd82
    • Opcode Fuzzy Hash: 02463cfab35b8edaaa22ba997779b0fa5854f9a355f5b7c05837a7215f85ca0e
    • Instruction Fuzzy Hash: 5421F732B0A74687EA64AB35E44166A73A1FF45B80F245135DB4D83B46CF3DE504CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • default_delete.LIBCPMT ref: 00007FF6A8D16CC6
    • _Mtx_destroy_in_situ.MSVCP_WIN(?,?,?,00007FF6A8D180CD,?,?,?,00007FF6A8CEE42C), ref: 00007FF6A8D16CD0
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,?,00007FF6A8D180CD,?,?,?,00007FF6A8CEE42C), ref: 00007FF6A8D16CEB
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,?,00007FF6A8D180CD,?,?,?,00007FF6A8CEE42C), ref: 00007FF6A8D16D06
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,?,00007FF6A8D180CD,?,?,?,00007FF6A8CEE42C), ref: 00007FF6A8D16D21
      • Part of subcall function 00007FF6A8D16D48: CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,00000000,00007FF6A8D06479), ref: 00007FF6A8D16D73
      • Part of subcall function 00007FF6A8D16D48: CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,00000000,00007FF6A8D06479), ref: 00007FF6A8D16D8D
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CloseHandle$Mtx_destroy_in_situdefault_delete
    • String ID:
    • API String ID: 1176461943-0
    • Opcode ID: d1d79924ff1785f0be8aa4a082f247c9722438fee7d2a29b7267dd30addd81fc
    • Instruction ID: ccb7718ee65cc715664707b8e9da73f3b44e1df8692b438d74c49370ffcac573
    • Opcode Fuzzy Hash: d1d79924ff1785f0be8aa4a082f247c9722438fee7d2a29b7267dd30addd81fc
    • Instruction Fuzzy Hash: 4811FB3160AA4695EA10BF74E4441787B60FF86F79B556331CA3D822D4DF29D44CC368
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o__errno.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D06F1D), ref: 00007FF6A8CF577A
    • _o__invalid_parameter_noinfo.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D06F1D), ref: 00007FF6A8CF578D
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o__errno_o__invalid_parameter_noinfo
    • String ID:
    • API String ID: 2671245207-0
    • Opcode ID: 515cfafbca91b1e4f7fec3eba1c6b59c68381ce37d97585809eaa0391ef60ed3
    • Instruction ID: 991684829b74337a5fe55e066780c14b00667da89566b7dbae77082d32c58d13
    • Opcode Fuzzy Hash: 515cfafbca91b1e4f7fec3eba1c6b59c68381ce37d97585809eaa0391ef60ed3
    • Instruction Fuzzy Hash: 43019264E2E742C7FA146B71A64427A55709F69B90F148031EF0FD7B86DE2CAC418E08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ConditionMask$InfoVerifyVersionmemset
    • String ID:
    • API String ID: 375572348-0
    • Opcode ID: 5dac4023c5125fb4e3d26aaed136ffb815ee6bc27deb214d78040365ab784f4c
    • Instruction ID: 2cfaaa9713a16373d8b8c78156e534df35148b6afdec2a38636760efb2529941
    • Opcode Fuzzy Hash: 5dac4023c5125fb4e3d26aaed136ffb815ee6bc27deb214d78040365ab784f4c
    • Instruction Fuzzy Hash: 61112B3251978586E724EF31E4513EAB7A1FB8DB05F419234DA5D87754EF3CD1088B44
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • SignalObjectAndWait.API-MS-WIN-CORE-SYNCH-L1-2-0 ref: 00007FF6A8D44913
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0 ref: 00007FF6A8D44923
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,00000001,00007FF6A8D21044,?,?,?,00007FF6A8D2101A), ref: 00007FF6A8D4493D
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,00000001,00007FF6A8D21044,?,?,?,00007FF6A8D2101A), ref: 00007FF6A8D44957
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,00000001,00007FF6A8D21044,?,?,?,00007FF6A8D2101A), ref: 00007FF6A8D44971
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CloseHandle$ObjectSignalWait
    • String ID:
    • API String ID: 1085041809-0
    • Opcode ID: aaf8bad1a5927950247fbd1d898fabd3d44ed995ad5999141c105d7a519e0bb2
    • Instruction ID: 37b1bb63821387290435cbd440c380c3d52c9114c06649f6d2dd8cfac78712a3
    • Opcode Fuzzy Hash: aaf8bad1a5927950247fbd1d898fabd3d44ed995ad5999141c105d7a519e0bb2
    • Instruction Fuzzy Hash: D3112832617A86C6EB059F70E4553387BB0FB89F19F189334CA2E8A290CF39C099C344
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\host\inputbuffer.cpp, xrefs: 00007FF6A8D1F124
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_delete
    • String ID: onecore\windows\core\console\open\src\host\inputbuffer.cpp
    • API String ID: 3712186324-425006629
    • Opcode ID: 52685382f09faabc763cc5ffdc57e93325a96629c8264a405f95b3a6694fa126
    • Instruction ID: 10759fc77f686906e686b4c665c661fffc24d57f69b18fc884cb109f6b27841e
    • Opcode Fuzzy Hash: 52685382f09faabc763cc5ffdc57e93325a96629c8264a405f95b3a6694fa126
    • Instruction Fuzzy Hash: A5D16E22A1AB4581EB10EB31E4411AD73B5FF85B88F404132EE8E97BA9DF3CD509C748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\buffer\out\outputcellrect.cpp, xrefs: 00007FF6A8D2519B
    • onecore\windows\core\console\open\src\host\screeninfo.cpp, xrefs: 00007FF6A8D25127
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate
    • String ID: onecore\windows\core\console\open\src\buffer\out\outputcellrect.cpp$onecore\windows\core\console\open\src\host\screeninfo.cpp
    • API String ID: 882196631-1126056439
    • Opcode ID: 2d5879e4ee89b0b63942a5a69e3af457705df7694d9424595863ecb6eff99f89
    • Instruction ID: 64fb33e87725c0cab5a9342fbbf04eb84b0e9e5aa947ae19f0abee1393d803a8
    • Opcode Fuzzy Hash: 2d5879e4ee89b0b63942a5a69e3af457705df7694d9424595863ecb6eff99f89
    • Instruction Fuzzy Hash: 23B19E32A09B818AEB50EF31E8402EDB7B1FB95354F404231EA9D87A96EF7CD149C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8D11A8F
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D11E0A
      • Part of subcall function 00007FF6A8CDD6A0: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,?,00000000,00007FF6A8D550E6,?,?,?,?,00000000,00007FF6A8CFA2D9), ref: 00007FF6A8CDD6D0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$EnterLeave_o_terminate
    • String ID: onecore\windows\core\console\open\src\host\alias.cpp
    • API String ID: 1404396024-1127424212
    • Opcode ID: aba18af1fd77b13f2f958ad503ea4ec7814e631fed3fe6419733dc427d13f248
    • Instruction ID: 3c877a7c45e5a004e87d212f27bb323b86db792e265d43d22f7fb190dff197a3
    • Opcode Fuzzy Hash: aba18af1fd77b13f2f958ad503ea4ec7814e631fed3fe6419733dc427d13f248
    • Instruction Fuzzy Hash: 3CB1A822A4EA8586EB30BB74E4413AAA370FFC9744F409635EADD9365ADF3CD544CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8D1545F
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D15733
      • Part of subcall function 00007FF6A8CDD6A0: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,?,00000000,00007FF6A8D550E6,?,?,?,?,00000000,00007FF6A8CFA2D9), ref: 00007FF6A8CDD6D0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$EnterLeave_o_terminate
    • String ID: onecore\windows\core\console\open\src\host\history.cpp
    • API String ID: 1404396024-3034099481
    • Opcode ID: 93ed7f719ecb20b44f067a1ea9854dfe108b5304c3c93aca2fed8f64f6f3b3ca
    • Instruction ID: 913250f6965b9771f3d8d93528ed68acff15e697db6597df61901ad9cf4634d5
    • Opcode Fuzzy Hash: 93ed7f719ecb20b44f067a1ea9854dfe108b5304c3c93aca2fed8f64f6f3b3ca
    • Instruction Fuzzy Hash: 58A17622A5EB8283E610BB74E4516BAA370FF85740F505631EADED3A59EF6CD448CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8D10FAB
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D11222
      • Part of subcall function 00007FF6A8CDD6A0: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,?,00000000,00007FF6A8D550E6,?,?,?,?,00000000,00007FF6A8CFA2D9), ref: 00007FF6A8CDD6D0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$EnterLeave_o_terminate
    • String ID: onecore\windows\core\console\open\src\host\alias.cpp
    • API String ID: 1404396024-1127424212
    • Opcode ID: 5cd82a6db7594ba71964fd177fef5d012f9e6df74958ac9f88e50a926934a6fe
    • Instruction ID: 22a6015a004a945b4db997fa2f9add668f12b0718d21ef3e4c8df8ce74828474
    • Opcode Fuzzy Hash: 5cd82a6db7594ba71964fd177fef5d012f9e6df74958ac9f88e50a926934a6fe
    • Instruction Fuzzy Hash: 7281A621A5F68282EB60BB74E4517BAA360FF89740F006635EADDD3655DF7CE448CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CEEE2C: _o_malloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8CDE93E,?,?,?,?,00007FF6A8D0931C,?,?,?,?,?,?,?), ref: 00007FF6A8CEEE46
      • Part of subcall function 00007FF6A8CEEE2C: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6A8CEEE5C
      • Part of subcall function 00007FF6A8CEEE2C: InitializeCriticalSectionAndSpinCount.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CEEE95
      • Part of subcall function 00007FF6A8CEEE2C: GetModuleHandleW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEA3
      • Part of subcall function 00007FF6A8CEEE2C: GetModuleHandleW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEB9
      • Part of subcall function 00007FF6A8CEEE2C: GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEED6
      • Part of subcall function 00007FF6A8CEEE2C: GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEEA
      • Part of subcall function 00007FF6A8CEEE2C: GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEFE
      • Part of subcall function 00007FF6A8CE7544: CreateEventW.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CE7566
      • Part of subcall function 00007FF6A8CE7544: CreateEventW.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CE7598
      • Part of subcall function 00007FF6A8CE7544: CreateEventW.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CE75C1
      • Part of subcall function 00007FF6A8CE7544: CreateThread.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CDA8FC), ref: 00007FF6A8CE75F7
      • Part of subcall function 00007FF6A8CE7400: ~_Func_class.LIBCONCRT ref: 00007FF6A8CE743A
      • Part of subcall function 00007FF6A8CDD6A0: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,?,00000000,00007FF6A8D550E6,?,?,?,?,00000000,00007FF6A8CFA2D9), ref: 00007FF6A8CDD6D0
    • WaitForSingleObjectEx.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CE7317
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CE7339
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0 ref: 00007FF6A8CE7348
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Create$AddressCriticalEventHandleProcSection$Module$CloseConcurrency::cancel_current_taskCountEnterFunc_classInitializeLeaveObjectSingleSpinThreadWait_o_malloc
    • String ID: onecore\windows\core\console\open\src\host\srvinit.cpp
    • API String ID: 2027669528-2090781281
    • Opcode ID: 802f6e2f42939c32cb5bc331f3ba4fe2b7e66be8a5cd43b5c9f1f310d04da371
    • Instruction ID: 6fcd9ba77960af58e537c3389e81b98f760ed58d1f99d42b7b9dc4678bbcbaa9
    • Opcode Fuzzy Hash: 802f6e2f42939c32cb5bc331f3ba4fe2b7e66be8a5cd43b5c9f1f310d04da371
    • Instruction Fuzzy Hash: 6091AC31A0AB9285E760AB31E8512B977B5FF86744F104235DA9EC3B95DF3CE449CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CreateSemaphore
    • String ID: _p0$wil
    • API String ID: 1078844751-1814513734
    • Opcode ID: 8b16ef8102d262773ab81b2d95850f650c17885c2b074fe93987077f690a795d
    • Instruction ID: bc862c349f94708e802e2daf0e60a082c1b0fcd6d46f0d6262fb2e4a650eb42a
    • Opcode Fuzzy Hash: 8b16ef8102d262773ab81b2d95850f650c17885c2b074fe93987077f690a795d
    • Instruction Fuzzy Hash: 4D510822B1BB828AEE21DF3494553B962B4FF85B80F544535DA4F97B85DF3CE4048B48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,00000000,00007FF6A8D4A3CF,?,?,00000000,?,00000000,00007FF6A8D0072F), ref: 00007FF6A8D49E05
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memset
    • String ID: list<T> too long$onecore\windows\core\console\open\src\server\waitblock.cpp
    • API String ID: 2221118986-3756024062
    • Opcode ID: 40712be97c9d585647ddb55641e925b529283b93909504c4e122e3300a52a699
    • Instruction ID: e4f0abe80a30642842005837cf6cc39f74cad29b6fea886f086eb5e23ae67eab
    • Opcode Fuzzy Hash: 40712be97c9d585647ddb55641e925b529283b93909504c4e122e3300a52a699
    • Instruction Fuzzy Hash: 3C612632919B8486E710DF25E9403A877B4F7A8B88F16D225DB9D53B56DF38E2D8C340
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove$Xlength_error@std@@
    • String ID: vector<T> too long
    • API String ID: 1743304318-3788999226
    • Opcode ID: 075a65bc8ee0494369c5ce074ed58635f7942b4d0192f6126b50c1c612d0513f
    • Instruction ID: f144cd9427b6c6eca4c4a47c608f2c591df4d2c20578d89b6bb76d3047a6a581
    • Opcode Fuzzy Hash: 075a65bc8ee0494369c5ce074ed58635f7942b4d0192f6126b50c1c612d0513f
    • Instruction Fuzzy Hash: F23126A2B15B8992CE24DFAAE9044A9A760F758BD0B408233DFAD47791EF7CE145C304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CE027C: memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8CE035D
    • ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN ref: 00007FF6A8D3A303
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@memcpy
    • String ID: VUUUUUUU$VUUUUUUU$invalid vector<T> subscript
    • API String ID: 3575991107-1373641553
    • Opcode ID: 93ac9e62a939d41f5fc00236523b509d442cc19d6689710d9b38992980f7b759
    • Instruction ID: 2bfbd904add5bb7a947061c99be0b8ff7752b477711e9ec10e765a89481b57d0
    • Opcode Fuzzy Hash: 93ac9e62a939d41f5fc00236523b509d442cc19d6689710d9b38992980f7b759
    • Instruction Fuzzy Hash: EB31F466B05A4586CA14FF26E5042AEB760F788FC4F185136DE6E4B310EF3CE48AC304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove$Xlength_error@std@@
    • String ID: vector<T> too long
    • API String ID: 1743304318-3788999226
    • Opcode ID: 5c5327e46ecceda5942e5832114983a24a62a439581446d187de79db99920d8f
    • Instruction ID: fedcab9634c12551ff522ba997230cd4f8f0458060f0f0c1ce0661499d044ab6
    • Opcode Fuzzy Hash: 5c5327e46ecceda5942e5832114983a24a62a439581446d187de79db99920d8f
    • Instruction Fuzzy Hash: A4318D62706A8581EA14DF7AE90447967A1BB45FF8B208335DE7E437D9DE3CE085C304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CreateCurrentMutexProcess
    • String ID: Local\SM0:%d:%d:%hs$wil
    • API String ID: 3937467467-2303653343
    • Opcode ID: 0e9eed410c7c6de1d0a86c1b13e65036f699f52f7cd017972544330f8bd7c99d
    • Instruction ID: 873a03f64dc747b6bc82f8be021bef068cf87512515e47e6d92db0d37ec79a27
    • Opcode Fuzzy Hash: 0e9eed410c7c6de1d0a86c1b13e65036f699f52f7cd017972544330f8bd7c99d
    • Instruction Fuzzy Hash: 0A415332629B8186FB10DB30E4417AA67B0FB98784F405135EA4EC7B95EF7CD504CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove$Xlength_error@std@@
    • String ID: vector<T> too long
    • API String ID: 1743304318-3788999226
    • Opcode ID: 2c68accc4461f723a0a67e99f711c193face358e7b08148a3b0a653838dda964
    • Instruction ID: a285fb684dca3d79f6f2c350998ffef436d453055898d08424c42faf1ed53089
    • Opcode Fuzzy Hash: 2c68accc4461f723a0a67e99f711c193face358e7b08148a3b0a653838dda964
    • Instruction Fuzzy Hash: F231BC62B19AC581CE10DFA6E8444A9AB60F789FE4B548236DF7D97BD0CF38D055C308
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,00000000,?,00007FF6A8D5F7CA), ref: 00007FF6A8D5F57B
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,00000000,?,00007FF6A8D5F7CA), ref: 00007FF6A8D5F5EA
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,00000000,?,00007FF6A8D5F7CA), ref: 00007FF6A8D5F5FE
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove$Xlength_error@std@@
    • String ID: vector<T> too long
    • API String ID: 1743304318-3788999226
    • Opcode ID: 265e80f5e6d93505e7d547e8d284a07080aa049b79ed1845713361e80c0414c5
    • Instruction ID: d5fd1202147b245da72279e0f52cf93c3ade4f415f69cf8a6cc3b8f015f3ff77
    • Opcode Fuzzy Hash: 265e80f5e6d93505e7d547e8d284a07080aa049b79ed1845713361e80c0414c5
    • Instruction Fuzzy Hash: 6E21F12260ABC481DA14EFB6E44447EA7A0FB45FE8B208236DE6D47B94CE3CD046C304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\renderer\vt\state.cpp, xrefs: 00007FF6A8D4515C
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _scwprintf_vsnwprintf_smemset
    • String ID: onecore\windows\core\console\open\src\renderer\vt\state.cpp
    • API String ID: 2187233866-1242362329
    • Opcode ID: 3136805dd261ab6cdf40a346369e45861b9dd799a47d787206fb75b0373e824a
    • Instruction ID: 70c99a36dd1249571cad2f9ebed6e7d5444785b82362d0e5db8b2d041d6228bb
    • Opcode Fuzzy Hash: 3136805dd261ab6cdf40a346369e45861b9dd799a47d787206fb75b0373e824a
    • Instruction Fuzzy Hash: 4F210622B1A74681FA14EB35A8414B96361AFC5BD0F100635EE6F87795DF3CE4458748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetTokenInformation.API-MS-WIN-SECURITY-BASE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CDA8FC), ref: 00007FF6A8CF6056
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CDA8FC), ref: 00007FF6A8CF606A
    • GetTokenInformation.API-MS-WIN-SECURITY-BASE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CDA8FC), ref: 00007FF6A8CF60D1
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: InformationToken$ErrorLast
    • String ID: onecore\internal\sdk\inc\wil\opensource\wil\token_helpers.h
    • API String ID: 2567405617-2881811202
    • Opcode ID: 149a34fbe7df9a021629190144de0734047cbf593aff251d6b1f6c0412a363da
    • Instruction ID: 9f02541b436c2544106fada4e5103bdc7828e833a41cbf9ac5cf4a79b57a0e53
    • Opcode Fuzzy Hash: 149a34fbe7df9a021629190144de0734047cbf593aff251d6b1f6c0412a363da
    • Instruction Fuzzy Hash: 5431C83270A74282FB109761E4416796771EFD67D4F648234E95F87BAADF3CD8058B04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6A8D5C60F), ref: 00007FF6A8D5ED83
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6A8D5C60F), ref: 00007FF6A8D5EDEB
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FF6A8D5C60F), ref: 00007FF6A8D5EE01
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove$Xlength_error@std@@
    • String ID: vector<T> too long
    • API String ID: 1743304318-3788999226
    • Opcode ID: 2670d143d9f76fbd17e99910f80f5deb9e10e68815c3f4e7e4c43fdc48f1ad8c
    • Instruction ID: 2bda0c141d00fff4307c7be28922ec31247d9ff5bdd1c673e41d845881874f81
    • Opcode Fuzzy Hash: 2670d143d9f76fbd17e99910f80f5deb9e10e68815c3f4e7e4c43fdc48f1ad8c
    • Instruction Fuzzy Hash: 0F21E062A15B8481EE04EF76E8040A9A7A0FB49BF8B108732EE7D637D5DF3CE1558304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove$Xlength_error@std@@
    • String ID: vector<T> too long
    • API String ID: 1743304318-3788999226
    • Opcode ID: 2603397ffb43da3af39cc61aa926b3d05f45087dbbf57f0ee62b862a7b97a162
    • Instruction ID: 2933bfda7ef27857edc0c6dc406fff1dfe58c909a3dc8738fd956b0b5929147e
    • Opcode Fuzzy Hash: 2603397ffb43da3af39cc61aa926b3d05f45087dbbf57f0ee62b862a7b97a162
    • Instruction Fuzzy Hash: D521DE22715A8591DE10EF72E8044A9A7A0FB49FE8B108336EE7E53BD9CF38D456C304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D64A58
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D64AD2
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D64AE4
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xlength_error@std@@memmovememset
    • String ID: vector<T> too long
    • API String ID: 1954582803-3788999226
    • Opcode ID: ec617feea6dc0c885b06871e174a483c0735b72463e6be89300867d4e88f09ee
    • Instruction ID: 40228ca1be745342ee17aad396a11b3427b210d01987439eddc377fa2e2a8887
    • Opcode Fuzzy Hash: ec617feea6dc0c885b06871e174a483c0735b72463e6be89300867d4e88f09ee
    • Instruction Fuzzy Hash: 37210462B1AA8481DA20DB66A9040B9BB61F744FF0B144336DFBD53BD4DF7CC0458308
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,00007FF6A8D6633D,?,?,?,?,?,?,?,00000000,?,00007FF6A8D655F1), ref: 00007FF6A8D64B70
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,00007FF6A8D6633D,?,?,?,?,?,?,?,00000000,?,00007FF6A8D655F1), ref: 00007FF6A8D64BCC
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D6633D,?,?,?,?,?,?,?,00000000,?,00007FF6A8D655F1), ref: 00007FF6A8D64BDE
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xlength_error@std@@memmovememset
    • String ID: vector<T> too long
    • API String ID: 1954582803-3788999226
    • Opcode ID: 6e88c4c6a2f2529a1ddcb16807dcb2b029a5a86c94764582b46bb5b3e03836e9
    • Instruction ID: e0a56bd3309763447891a5e0b0fecf4898faecc08fff86eb66c3d1f2c47d1cb9
    • Opcode Fuzzy Hash: 6e88c4c6a2f2529a1ddcb16807dcb2b029a5a86c94764582b46bb5b3e03836e9
    • Instruction Fuzzy Hash: 1B21AC32616A8481DB10DF79E54406DB7A5FB88FE4B248236DA6D97B98DF38C056C304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xlength_error@std@@memmovememset
    • String ID: vector<T> too long
    • API String ID: 1954582803-3788999226
    • Opcode ID: 795b2fbf75ea4f009c3746e826dade859282b226e1861e847c17e170e7ec445d
    • Instruction ID: 88cc9d72c5123ba30d2c7160ffa6b9d6534047b9b162d69f6331fc1e5ea70e29
    • Opcode Fuzzy Hash: 795b2fbf75ea4f009c3746e826dade859282b226e1861e847c17e170e7ec445d
    • Instruction Fuzzy Hash: 7A21B062B16A8481DA20EF66E5100B9BB61FB45FE0B144336DFBD57BD4EE3CC0458304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D64940
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D649B8
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,00007FF6A8D6561F), ref: 00007FF6A8D649CA
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xlength_error@std@@memmovememset
    • String ID: vector<T> too long
    • API String ID: 1954582803-3788999226
    • Opcode ID: 2381032421b63c84f0f85173d2c53aeda107773747b74a19716f14cb23deb04a
    • Instruction ID: fed25bc0075c26394b3bcbf8a8568a04a582e4cc33ff21c7faf961648e64ed01
    • Opcode Fuzzy Hash: 2381032421b63c84f0f85173d2c53aeda107773747b74a19716f14cb23deb04a
    • Instruction Fuzzy Hash: 10219F62716AC481DA20DBA6A9140BABB61FB45FF0B148336DFBD57BD4DE3CD0458304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate_o_wcscpy_s
    • String ID: __DefaultTTFont__$onecore\windows\core\console\open\src\host\screeninfo.cpp
    • API String ID: 1762320008-2396263476
    • Opcode ID: 82436d976a2f1785bb7ca170c0834c2d9b7d44c67a53a270cf21db9b5573e5f3
    • Instruction ID: c101d0121d2cb8de2b7210613e21064e611ca8337314b6ef56443162fa640bc0
    • Opcode Fuzzy Hash: 82436d976a2f1785bb7ca170c0834c2d9b7d44c67a53a270cf21db9b5573e5f3
    • Instruction Fuzzy Hash: 952139725097818AE700AF24E4043A87BB4FB48B4CF54463ADB9C8726ADFBDE159CB54
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CEEE2C: _o_malloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8CDE93E,?,?,?,?,00007FF6A8D0931C,?,?,?,?,?,?,?), ref: 00007FF6A8CEEE46
    • GetOEMCP.API-MS-WIN-CORE-LOCALIZATION-L1-2-0 ref: 00007FF6A8CE435B
    • GetACP.API-MS-WIN-CORE-LOCALIZATION-L1-2-0 ref: 00007FF6A8CE436D
      • Part of subcall function 00007FF6A8CEEE2C: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF6A8CEEE5C
      • Part of subcall function 00007FF6A8CEEE2C: InitializeCriticalSectionAndSpinCount.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8CEEE95
      • Part of subcall function 00007FF6A8CEEE2C: GetModuleHandleW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEA3
      • Part of subcall function 00007FF6A8CEEE2C: GetModuleHandleW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEB9
      • Part of subcall function 00007FF6A8CEEE2C: GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEED6
      • Part of subcall function 00007FF6A8CEEE2C: GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEEA
      • Part of subcall function 00007FF6A8CEEE2C: GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8CEEEFE
      • Part of subcall function 00007FF6A8CE4BE0: RegOpenKeyW.API-MS-WIN-CORE-REGISTRY-L2-1-0 ref: 00007FF6A8CE4C40
      • Part of subcall function 00007FF6A8CE4BE0: RegEnumValueW.API-MS-WIN-CORE-REGISTRY-L1-1-0 ref: 00007FF6A8CE4C9E
      • Part of subcall function 00007FF6A8CE4BE0: GetProcessHeap.API-MS-WIN-CORE-HEAP-L1-1-0 ref: 00007FF6A8CE4CC3
      • Part of subcall function 00007FF6A8CE4BE0: HeapAlloc.API-MS-WIN-CORE-HEAP-L1-1-0 ref: 00007FF6A8CE4CDD
    Strings
    • onecore\windows\core\console\open\src\server\devicecomm.cpp, xrefs: 00007FF6A8D027B6
    • onecore\windows\core\console\open\src\host\renderfontdefaults.cpp, xrefs: 00007FF6A8D027CB
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressProc$HandleHeapModule$AllocConcurrency::cancel_current_taskCountCriticalEnumInitializeOpenProcessSectionSpinValue_o_malloc
    • String ID: onecore\windows\core\console\open\src\host\renderfontdefaults.cpp$onecore\windows\core\console\open\src\server\devicecomm.cpp
    • API String ID: 4221633738-3638091250
    • Opcode ID: fd12480195ba354fe0205ff2a21ca6f7d642545913bbbf194506a56ee6b7350f
    • Instruction ID: 7ab51f2c415ba4ac6bd6ffbd1961c7298d38b6f3cfeec537b4ef4093a33c0629
    • Opcode Fuzzy Hash: fd12480195ba354fe0205ff2a21ca6f7d642545913bbbf194506a56ee6b7350f
    • Instruction Fuzzy Hash: E5117F31A0AA0286E710AB71F8112B977B5BF89BA0F445335D56EC3B91DF3CE418C708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,00000000,00007FF6A8CD4722,?,?,00000000,00007FF6A8CE772D), ref: 00007FF6A8CD47EF
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,00000000,00007FF6A8CD4722,?,?,00000000,00007FF6A8CE772D), ref: 00007FF6A8CD4812
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressProc
    • String ID: GetDpiMetrics$GetSystemMetricsForDpi
    • API String ID: 190572456-1926441701
    • Opcode ID: e5473cafcee883c27343b43098423b35a5c89e8e4d42a35b958c986d1c34aac7
    • Instruction ID: 29c8b151345135095b329e624ceef4b3946b4661130b82fcf58d1ead2a11242f
    • Opcode Fuzzy Hash: e5473cafcee883c27343b43098423b35a5c89e8e4d42a35b958c986d1c34aac7
    • Instruction Fuzzy Hash: A3114221A1AB82C1FB146B75F85017877A4FF89780F185235D55E86BA4CF7CE488C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,00007FF6A8CDC701), ref: 00007FF6A8CFEFFE
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,00007FF6A8CDC701), ref: 00007FF6A8CFF01F
    Strings
    • onecore\windows\core\console\open\src\server\apimessage.cpp, xrefs: 00007FF6A8CFF04D
    • onecore\windows\core\console\open\src\server\devicecomm.cpp, xrefs: 00007FF6A8CFF030
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate
    • String ID: onecore\windows\core\console\open\src\server\apimessage.cpp$onecore\windows\core\console\open\src\server\devicecomm.cpp
    • API String ID: 882196631-2344770978
    • Opcode ID: 7b070bdc5667bbf5cac90748fc74cde1c0d995f614337f7ee13705c076c6d2f1
    • Instruction ID: 229aeca394ac86f9a66de8b995e6e93797416becb160440bcd36fadb030f3d62
    • Opcode Fuzzy Hash: 7b070bdc5667bbf5cac90748fc74cde1c0d995f614337f7ee13705c076c6d2f1
    • Instruction Fuzzy Hash: 2B11C221D1AF4681E710FB30A8400B937B4FF99758F508235DD4EC2A56EF3CE1858708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memmove
    • String ID:
    • API String ID: 2162964266-0
    • Opcode ID: 52881c43f627d45d0b7dc1172b65d19caa51d7f7f965c06911b78e4c3ead517d
    • Instruction ID: be0f461c19843ebe0b065f2558298d9d009900d96258e37b937d9823bcd7a7d6
    • Opcode Fuzzy Hash: 52881c43f627d45d0b7dc1172b65d19caa51d7f7f965c06911b78e4c3ead517d
    • Instruction Fuzzy Hash: 0E51C362B0A7C582DE28FE76D5041BAAB90FB44BE4F144636CFAE87B94DE3CD0058704
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\renderer\gdi\paint.cpp$onecore\windows\core\console\open\src\renderer\gdi\state.cpp
    • API String ID: 0-357235055
    • Opcode ID: 14e46df0dc258a89ec90310c282dc1f70479946cf3c542e482d3ec40e713ae89
    • Instruction ID: 66d8b769ab2632005cfd013e191a6648a077d4f1b733dc628c88a6b1b1ba690d
    • Opcode Fuzzy Hash: 14e46df0dc258a89ec90310c282dc1f70479946cf3c542e482d3ec40e713ae89
    • Instruction Fuzzy Hash: CC617231A0AA4681EB50AB71E4407B97BB0FB86B84F145132DE1FD7794CF3CD4498718
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o_towupper.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00000000,00000001,?,?,00007FF6A8D13EAD), ref: 00007FF6A8D141E0
    • _o_towupper.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00000000,00000001,?,?,00007FF6A8D13EAD), ref: 00007FF6A8D141FE
    • _o_towupper.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00000000,00000001,?,?,00007FF6A8D13EAD), ref: 00007FF6A8D1421C
    • _o_towupper.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00000000,00000001,?,?,00007FF6A8D13EAD), ref: 00007FF6A8D1423A
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_towupper
    • String ID:
    • API String ID: 3866689482-0
    • Opcode ID: 5cbdab9b002a646d330e8e37ee542fdc7c9a8dfd8974efd7113b080bffe617b6
    • Instruction ID: 9b0dba16459e8239928bddf87f1aabc5780dfae609a0737e1d854539df3d6ccb
    • Opcode Fuzzy Hash: 5cbdab9b002a646d330e8e37ee542fdc7c9a8dfd8974efd7113b080bffe617b6
    • Instruction Fuzzy Hash: 8D51BF22F09A62C5FB10AB71D8402BC6772FF54B88F408231DF6D56299EF3CA598C358
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalEnterSection
    • String ID: Ground$onecore\windows\core\console\open\src\host\getset.cpp
    • API String ID: 1904992153-3105179758
    • Opcode ID: 8a0aedf749ba3026fbae2cb59e01699f6eb80560e52a41f747c5edcb8128f089
    • Instruction ID: a0c66e68aea177bc117d8838d72f4c878617985c1956b2cf11f0a9158fdc7684
    • Opcode Fuzzy Hash: 8a0aedf749ba3026fbae2cb59e01699f6eb80560e52a41f747c5edcb8128f089
    • Instruction Fuzzy Hash: 8151CE71D5E64681FF64AB70E8007B96AF0BF15794F146231D91FC72A6CE2CE848DB88
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,?,00000000,00007FF6A8D550E6,?,?,?,?,00000000,00007FF6A8CFA2D9), ref: 00007FF6A8CDD6D0
    • LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,?,00000000,00007FF6A8D550E6,?,?,?,?,00000000,00007FF6A8CFA2D9), ref: 00007FF6A8D00C9D
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,00000001,?,00000000,00007FF6A8D550E6,?,?,?,?,00000000,00007FF6A8CFA2D9), ref: 00007FF6A8D00D2F
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalLeaveSection$CloseHandle
    • String ID: onecore\windows\core\console\open\src\host\input.cpp
    • API String ID: 3647471834-1659879473
    • Opcode ID: 8e5f32e443d27e6e2a51a1fc28fe3880b5ab3efab165417e16990dd5c36faee6
    • Instruction ID: eeef3455a4e5875da83f85ec930a2d9c2cbe9822512275db5888eb6496769995
    • Opcode Fuzzy Hash: 8e5f32e443d27e6e2a51a1fc28fe3880b5ab3efab165417e16990dd5c36faee6
    • Instruction Fuzzy Hash: B8419D32E1E64796E620BF35E45027A7BA0BF55790F000231DA6FC3AA5DE2CE94D8748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D69B90: RtlAllocateHeap.NTDLL ref: 00007FF6A8D69BF0
    • _o_calloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D56719), ref: 00007FF6A8D6900B
    • _o_calloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D56719), ref: 00007FF6A8D69039
    • _o_calloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D56719), ref: 00007FF6A8D6906D
    • _o_calloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D56719), ref: 00007FF6A8D6908E
      • Part of subcall function 00007FF6A8D69E9C: RtlFreeHeap.NTDLL(?,?,00000000,00007FF6A8D69E64), ref: 00007FF6A8D69F16
      • Part of subcall function 00007FF6A8D69E9C: RtlFreeHeap.NTDLL(?,?,00000000,00007FF6A8D69E64), ref: 00007FF6A8D69F34
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_calloc$Heap$Free$Allocate
    • String ID:
    • API String ID: 500635130-0
    • Opcode ID: dd1ef7bda5d80b0519b007587ba2b0b16992592565546365a4b96c7ead6762e7
    • Instruction ID: c83b7b140abbda5e0bb32c7a654942b72106a5daffc6d42509444d9c15b7f5bb
    • Opcode Fuzzy Hash: dd1ef7bda5d80b0519b007587ba2b0b16992592565546365a4b96c7ead6762e7
    • Instruction Fuzzy Hash: F941C032A1AA46CAEB14AF31D44057977A0FB89F94B249231DF2D97784CF3DD859C348
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,?,00000000,00007FF6A8CD56D2), ref: 00007FF6A8CD62C7
    • LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,?,00000000,00007FF6A8CD56D2), ref: 00007FF6A8CFC413
    • CloseHandle.API-MS-WIN-CORE-HANDLE-L1-1-0(?,?,?,?,00000000,00007FF6A8CD56D2), ref: 00007FF6A8CFC4A5
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalLeaveSection$CloseHandle
    • String ID: onecore\windows\core\console\open\src\host\input.cpp
    • API String ID: 3647471834-1659879473
    • Opcode ID: 73bddc9e77b503a5bf2eb5f173a164dcc15d5bdbddba1b7ca72a0c00f438309e
    • Instruction ID: 2f4d0a51b0775a23dff3dc628ee56e4887c2923a6c78aedfc19ec53a7a275c24
    • Opcode Fuzzy Hash: 73bddc9e77b503a5bf2eb5f173a164dcc15d5bdbddba1b7ca72a0c00f438309e
    • Instruction Fuzzy Hash: 4B418032B0E75286F610DF35E4506797B70FF95790F540231DA6EC3696CE2CE9498B48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_delete$CriticalEnterSection
    • String ID:
    • API String ID: 739439809-0
    • Opcode ID: 5a09bb44ef19cd86aab93222f83cac3ea7ed4b5e662e99fe9f1d4724bc7f8892
    • Instruction ID: a7a81611851c9e6e751bb279f7dde99dc9a386da79dc59a697c16b7a602f1be5
    • Opcode Fuzzy Hash: 5a09bb44ef19cd86aab93222f83cac3ea7ed4b5e662e99fe9f1d4724bc7f8892
    • Instruction Fuzzy Hash: 5731CB62A0EB8143EB21BB35D0413AEA361FF96780F449231EB9D97646DF3CD505C718
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • MultiByteToWideChar.API-MS-WIN-CORE-STRING-L1-1-0(?,?,?,00000000,00000000,00007FF6A8D2F4A1), ref: 00007FF6A8D2F81A
    • GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,00000000,00000000,00007FF6A8D2F4A1), ref: 00007FF6A8D2F82D
    • MultiByteToWideChar.API-MS-WIN-CORE-STRING-L1-1-0(?,?,?,00000000,00000000,00007FF6A8D2F4A1), ref: 00007FF6A8D2F896
    Strings
    • onecore\windows\core\console\open\src\host\utf8towidecharparser.cpp, xrefs: 00007FF6A8D2F8AD
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ByteCharMultiWide$ErrorLast
    • String ID: onecore\windows\core\console\open\src\host\utf8towidecharparser.cpp
    • API String ID: 1717984340-2572910317
    • Opcode ID: 9dc23a76fa0b50f9c5334ca6194d0ebc23699ffdf1a9e0b4daf8e49233d3de5a
    • Instruction ID: 26665d2bdc0cbb690dbf3026ca25abc5937940b1a58964c56cdf07dd33358e86
    • Opcode Fuzzy Hash: 9dc23a76fa0b50f9c5334ca6194d0ebc23699ffdf1a9e0b4daf8e49233d3de5a
    • Instruction Fuzzy Hash: 2F21A276A05B8186E710EF22E80056DFB61FB88BD4B104636EE5D83765DF38E40ACB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GlobalLock.API-MS-WIN-CORE-HEAP-OBSOLETE-L1-1-0(?,?,?,?,?,00007FF6A8CFA202), ref: 00007FF6A8D549E1
    • GlobalSize.API-MS-WIN-CORE-HEAP-OBSOLETE-L1-1-0(?,?,?,?,?,00007FF6A8CFA202), ref: 00007FF6A8D549F3
    • GlobalUnlock.API-MS-WIN-CORE-HEAP-OBSOLETE-L1-1-0(?,?,?,?,?,00007FF6A8CFA202), ref: 00007FF6A8D54AA4
      • Part of subcall function 00007FF6A8CEF0A0: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE769,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF0B0
      • Part of subcall function 00007FF6A8D2862C: LoadStringW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8D286A1
    • _Init_thread_footer.LIBCMT ref: 00007FF6A8D54A66
      • Part of subcall function 00007FF6A8CEF038: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF048
      • Part of subcall function 00007FF6A8CEF038: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF088
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalGlobalSection$Enter$Init_thread_footerLeaveLoadLockSizeStringUnlock_onexit
    • String ID:
    • API String ID: 2108246701-0
    • Opcode ID: bcc166b96e6cecf86c460346c6cafedecc88d5e318756f39ec0fd11905d366e0
    • Instruction ID: a9fb05aeb9b1f8422978cf9eb2943e341f1f83999b1bdc683cc0aabc4e6f55d8
    • Opcode Fuzzy Hash: bcc166b96e6cecf86c460346c6cafedecc88d5e318756f39ec0fd11905d366e0
    • Instruction Fuzzy Hash: E3313E21A1AB4286EA10BB35F8501787BA1FF89B95F444335D96E827A2DF3CE548C748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o_free.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D690DB,?,?,?,00007FF6A8D56719), ref: 00007FF6A8D68E87
    • _o_free.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D690DB,?,?,?,00007FF6A8D56719), ref: 00007FF6A8D68EA6
    • _o_free.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D690DB,?,?,?,00007FF6A8D56719), ref: 00007FF6A8D68EBA
    • _o_free.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D690DB,?,?,?,00007FF6A8D56719), ref: 00007FF6A8D68ED4
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_free
    • String ID:
    • API String ID: 1736097121-0
    • Opcode ID: e81e91b737be6263841cf472c3b7c49c53c33adf209855ad5b46dc4bef150c32
    • Instruction ID: 74ce50b4e2ccd2896e78c89a5892aa88e32b0604686761976622b1ed7576e7ea
    • Opcode Fuzzy Hash: e81e91b737be6263841cf472c3b7c49c53c33adf209855ad5b46dc4bef150c32
    • Instruction Fuzzy Hash: F5210B32A15A45C2EB54AB25D4442387B60FB88F64F144331DE3E933D5DF39D458C204
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38959
    • ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D38970
    • ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z.MSVCP_WIN ref: 00007FF6A8D3899A
    • ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ.MSVCP_WIN ref: 00007FF6A8D389AE
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: D@std@@@std@@U?$char_traits@$?gptr@?$basic_streambuf@$?eback@?$basic_streambuf@?gbump@?$basic_streambuf@
    • String ID:
    • API String ID: 3536508186-0
    • Opcode ID: 1c65b7b266a5f0832414f1a825994a5aea22d367ef0d6bc22512e22e54351364
    • Instruction ID: 7c3aec2fb7d8b7d434bf1ae6717b26d31ff728d1bda7a7333793b9fc9d132c4e
    • Opcode Fuzzy Hash: 1c65b7b266a5f0832414f1a825994a5aea22d367ef0d6bc22512e22e54351364
    • Instruction Fuzzy Hash: A7117325A0EA8186F6607B35A44003CBBA0FF8AB60F585370EA7D527D0CF7CD8598719
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_floor$_o_terminate
    • String ID:
    • API String ID: 1703617362-0
    • Opcode ID: 1dff807ed10203ae981e139152731be224b5bdeb45af1774741340f5d46d88e9
    • Instruction ID: f6a056c61fc8229c332d8bb2ba33130d0263ece361ed033864d10f534cb1ac87
    • Opcode Fuzzy Hash: 1dff807ed10203ae981e139152731be224b5bdeb45af1774741340f5d46d88e9
    • Instruction Fuzzy Hash: 320182229351C5CED310AF75D10179DB370EF09B88F14C231EA08AB54AFF34B4A18765
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: C_error@std@@Throw_$Mtx_lockMtx_unlock
    • String ID:
    • API String ID: 973703179-0
    • Opcode ID: 0ad2df4ea2f5d8d65433150ef1f0cae2bf4f65fff6fcfc7fb25db7a77f4657f0
    • Instruction ID: 8abd6fa47b4ea36b4c565f774c1876ee9a3a218b85e4ba0af1e42266574c6d28
    • Opcode Fuzzy Hash: 0ad2df4ea2f5d8d65433150ef1f0cae2bf4f65fff6fcfc7fb25db7a77f4657f0
    • Instruction Fuzzy Hash: F4010031A15A46C6EA04BB31F854279B7A0FF8AB95F589230EA2E83751DF3CD44D8748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,00007FF6A8CF4808,?,?,?,?,?,?,?,?,00007FF6A8CEE4CD), ref: 00007FF6A8CF4765
    • AcquireSRWLockExclusive.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,00007FF6A8CF4808,?,?,?,?,?,?,?,?,00007FF6A8CEE4CD), ref: 00007FF6A8CF4774
    • ReleaseSRWLockExclusive.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,00007FF6A8CF4808,?,?,?,?,?,?,?,?,00007FF6A8CEE4CD), ref: 00007FF6A8CF47AB
    • LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,?,00007FF6A8CF4808,?,?,?,?,?,?,?,?,00007FF6A8CEE4CD), ref: 00007FF6A8CF47BF
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalExclusiveLockSection$AcquireEnterLeaveRelease
    • String ID:
    • API String ID: 1115728412-0
    • Opcode ID: 9abf083363c304a2b98f4fbeb07bab957f754108b788e33b801ef26f58aed5d1
    • Instruction ID: c005a1542b0108d742d3bcc600251bc31f3050714882788572e4ea2f3f2120d7
    • Opcode Fuzzy Hash: 9abf083363c304a2b98f4fbeb07bab957f754108b788e33b801ef26f58aed5d1
    • Instruction Fuzzy Hash: 20018022A19B8686EA049F21A54407CB760FF9AF81758D231EE4F43714DF3CD484C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?uncaught_exception@std@@YA_NXZ.MSVCP_WIN ref: 00007FF6A8D3587D
    • ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP_WIN ref: 00007FF6A8D35891
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D358AB
    • ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ.MSVCP_WIN ref: 00007FF6A8D358CA
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: U?$char_traits@$D@std@@@std@@$?rdbuf@?$basic_ios@D@std@@@2@V?$basic_streambuf@$?uncaught_exception@std@@Osfx@?$basic_ostream@
    • String ID:
    • API String ID: 1787288787-0
    • Opcode ID: 0239d206f73ea04be3f0cd2018dfd3e7ed90836f2c3ea7a1a55b47288cb3c434
    • Instruction ID: 50137f9d355aeaa1fd97b433ea8a0b86e026b50091c879af047a0c30f3ce6194
    • Opcode Fuzzy Hash: 0239d206f73ea04be3f0cd2018dfd3e7ed90836f2c3ea7a1a55b47288cb3c434
    • Instruction Fuzzy Hash: 1D01EC62602F49C6EF14AB25E4942387BA0FF8BF92755E531CA1E43320CF3CD4598304
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: C_error@std@@Throw_$Mtx_lockMtx_unlock
    • String ID:
    • API String ID: 973703179-0
    • Opcode ID: 59ce70c62e8ac519cdb2100c223609393bff3886c015a256684f0493b26b5068
    • Instruction ID: 4aa2d60e3e3a8b52a3703f3edb99912ac5b49d71c5fa18aa5d69db96bf70ad83
    • Opcode Fuzzy Hash: 59ce70c62e8ac519cdb2100c223609393bff3886c015a256684f0493b26b5068
    • Instruction Fuzzy Hash: E0014F31A1564286EA447B71B504379BBA0FF8AB91F489230DA2E83281DF3CD45C8708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o__errno.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8CF3EE5,?,?,?,?,?,?,?,?,?), ref: 00007FF6A8CF5803
    • _o__invalid_parameter_noinfo.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8CF3EE5,?,?,?,?,?,?,?,?,?), ref: 00007FF6A8CF5816
    • _o__errno.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8CF3EE5,?,?,?,?,?,?,?,?,?), ref: 00007FF6A8CF5829
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8CF3EE5,?,?,?,?,?,?,?,?,?), ref: 00007FF6A8CF5842
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o__errno$_o__invalid_parameter_noinfomemmove
    • String ID:
    • API String ID: 2571840558-0
    • Opcode ID: be486194915683632673ed37dac5cf3ae0eea899fd02ac3274c835527c2a5e5e
    • Instruction ID: 4bd5781a04956b0264bbabf59486a608a4df6fea64db635d2400b3522584c054
    • Opcode Fuzzy Hash: be486194915683632673ed37dac5cf3ae0eea899fd02ac3274c835527c2a5e5e
    • Instruction Fuzzy Hash: E9F082A0E5B34682FE142BB0560457869B09F79741F444030DE2FC7782DE2C6844CA19
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\server\apidispatchers.cpp
    • API String ID: 0-3284698556
    • Opcode ID: 7b05fe9f2eb0da08f827a37733c2df2e8183140c3383395911a1998c488368bd
    • Instruction ID: 456e073ec5b034052699e0d50a7be7820062f8e98445275aa748dc3937cf73bd
    • Opcode Fuzzy Hash: 7b05fe9f2eb0da08f827a37733c2df2e8183140c3383395911a1998c488368bd
    • Instruction Fuzzy Hash: 5512AF72B09A46C6EB10AFB5C4402BD37A1FB94B88F148232EE5E97799DF39D449C344
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate
    • String ID: onecore\windows\core\console\open\src\renderer\dx\customtextrenderer.cpp
    • API String ID: 882196631-1094745302
    • Opcode ID: 24ad0fd14f18b7c4dc36d65e5e8ec2ccbe7648c28cfc33c948706354dc4ea7eb
    • Instruction ID: 7de118e414cf0f3351347c810c4af25647b1b677c79f64e61f587cd7deec39f3
    • Opcode Fuzzy Hash: 24ad0fd14f18b7c4dc36d65e5e8ec2ccbe7648c28cfc33c948706354dc4ea7eb
    • Instruction Fuzzy Hash: 51026F36B19B8AC6EB10EB75E4401AD7371FB88B98B104232EE5D93B64DF38E459C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ArgvCommandFreeLineLocal
    • String ID: onecore\windows\core\console\open\src\host\consolearguments.cpp
    • API String ID: 1203019955-3802082478
    • Opcode ID: d626b4acf327974589c02b88e852fc3bd03353590e7e59394bb1806e5d9cb9ee
    • Instruction ID: 2028e5778306b86458b85afac5fc3b1454550c11f607db0dd53e09f710207b91
    • Opcode Fuzzy Hash: d626b4acf327974589c02b88e852fc3bd03353590e7e59394bb1806e5d9cb9ee
    • Instruction Fuzzy Hash: F4E18422F0AA42A6EB20EB70E4521FD2371FF45388F804131EA5F97A99DF38E509C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8D109F8
      • Part of subcall function 00007FF6A8CDD6A0: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,?,00000000,00007FF6A8D550E6,?,?,?,?,00000000,00007FF6A8CFA2D9), ref: 00007FF6A8CDD6D0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$EnterLeave
    • String ID: onecore\windows\core\console\open\src\host\alias.cpp
    • API String ID: 3168844106-1127424212
    • Opcode ID: 339ebed7bb795ad6163647fa44795a36c097bdab381132b9dfe6ac3097c13487
    • Instruction ID: 4e7b6da33399ecf31b9530bb26d23fda04790b74148b5d71d4694239a4969e5c
    • Opcode Fuzzy Hash: 339ebed7bb795ad6163647fa44795a36c097bdab381132b9dfe6ac3097c13487
    • Instruction Fuzzy Hash: 55D15122A4EBC586E630BB75E4517EAA360FBC9744F409231EACD93A5ADF3CD544CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • default_delete.LIBCPMT ref: 00007FF6A8D4BC6D
      • Part of subcall function 00007FF6A8D221B0: memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,00007FF6A8D2F55F,?,?,?,?,00000000,?,00000000,00007FF6A8D2F46C), ref: 00007FF6A8D221DD
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D4BC93
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminatedefault_deletememset
    • String ID: onecore\windows\core\console\open\src\server\apidispatchers.cpp
    • API String ID: 1132286936-3284698556
    • Opcode ID: 66aece760ef958224f6601192a7f088e18abf51517416b0bf2ea9b3b945a6037
    • Instruction ID: 49cde80ffb520a25ddefed2faf80e26a248945b953e1682c377c72e8fd17032d
    • Opcode Fuzzy Hash: 66aece760ef958224f6601192a7f088e18abf51517416b0bf2ea9b3b945a6037
    • Instruction Fuzzy Hash: F8C18172A0E78282EB75AB71A0413AAA3A0FFD5780F108631DADD87B55DF7CE449C744
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: invalid string position$onecore\windows\core\console\open\src\renderer\vt\paint.cpp
    • API String ID: 0-2687595187
    • Opcode ID: d1b88116d110934a071ae8d0814433cf4757cb8c83414df2b745efc46083bd7d
    • Instruction ID: 9d6db1d7c33568b860023682f65f3a5e1fe572de56f28144d15d58c1d630017a
    • Opcode Fuzzy Hash: d1b88116d110934a071ae8d0814433cf4757cb8c83414df2b745efc46083bd7d
    • Instruction Fuzzy Hash: 87B1E512A1E68293E720BB71D4017FAA7A0FBC4794F405232EAADD3695DF3CE559C708
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\server\apidispatchers.cpp
    • API String ID: 0-3284698556
    • Opcode ID: 69b1395beaa8edf41c94988c1037acb4b94da1c3a803ee7bc086063945451b83
    • Instruction ID: a8ab9f9fabe53ff5c8f3409c5622e6c67688421bd42f142f9ece3d01c2c57cdd
    • Opcode Fuzzy Hash: 69b1395beaa8edf41c94988c1037acb4b94da1c3a803ee7bc086063945451b83
    • Instruction Fuzzy Hash: 5DA17372B05B468AEB10AB74D8401FD23B1FB94B88F148632EE6D9B799DF38D4498744
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\server\apidispatchers.cpp
    • API String ID: 0-3284698556
    • Opcode ID: c09851dd085333fb767e740ef8665de864de54929d5d0d63b6d11b3c09c3a5df
    • Instruction ID: 08315b45fcb28715f29e5e9da6760e220658481bdcd7e7e3becd5e7af6f59c2a
    • Opcode Fuzzy Hash: c09851dd085333fb767e740ef8665de864de54929d5d0d63b6d11b3c09c3a5df
    • Instruction Fuzzy Hash: 7E917072B06B4A8AEB109BB5C8401FC23B1FB94788F148632EE6D97B58DF38D559C344
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_delete
    • String ID: onecore\windows\core\console\open\src\host\readdatadirect.cpp
    • API String ID: 3712186324-866399598
    • Opcode ID: 8e7038385e4e7abc8d5e415338f7774f781a5ced1f40f0d816cbc50e86aba467
    • Instruction ID: 80d40de8e20637e082fb5bf2f4a9b9dfa6716fa56a49b2f3a322b40bfef4218e
    • Opcode Fuzzy Hash: 8e7038385e4e7abc8d5e415338f7774f781a5ced1f40f0d816cbc50e86aba467
    • Instruction Fuzzy Hash: 3391437650AB4181EA20FB35E4412AEB774FF95780F504632DB9E83AA6EF3DE445CB04
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\host\directio.cpp
    • API String ID: 0-2458865805
    • Opcode ID: 9e7c1374358d71fdefef2b12a913fedb5b990084adaf10bcaa1f5809e5cb8e05
    • Instruction ID: 2eced88921bfcb38a9541810fccc5c420fec9354d53636c3b6272c9de7d4db31
    • Opcode Fuzzy Hash: 9e7c1374358d71fdefef2b12a913fedb5b990084adaf10bcaa1f5809e5cb8e05
    • Instruction Fuzzy Hash: 6091722261E696C1D730EB20E0405BEA3B0FF98B84F405235EA9E87A59DF3CD645CB18
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: invalid deque<T> subscript$onecore\windows\core\console\open\src\interactivity\win32\window.cpp
    • API String ID: 0-908316100
    • Opcode ID: df22d15d63ba2ed1d4b628c8953d2e63524621fdc82018348276f7b5904e68a3
    • Instruction ID: 1a5fadc62bacb9c30f3ad0e4908b0f79f5d065d2db211835fb9801ac183ec2f5
    • Opcode Fuzzy Hash: df22d15d63ba2ed1d4b628c8953d2e63524621fdc82018348276f7b5904e68a3
    • Instruction Fuzzy Hash: 26817B26A0AA9685EF04EF75C4505BC33B2FF54B98B408536EA0E87B95EF3CE445C748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN ref: 00007FF6A8CFD021
    • _o__invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8CFD07A
      • Part of subcall function 00007FF6A8CEEE2C: _o_malloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8CDE93E,?,?,?,?,00007FF6A8D0931C,?,?,?,?,?,?,?), ref: 00007FF6A8CEEE46
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xlength_error@std@@_o__invalid_parameter_noinfo_noreturn_o_malloc
    • String ID: vector<T> too long
    • API String ID: 3132977491-3788999226
    • Opcode ID: f39f7ab04ac6802c9ed33644b7a0eccb040fba9d0a111bec8e041f2528b00038
    • Instruction ID: 3ad8073b717274b153ae501e8f1eea5bb7b27a2333ddbd68047ec51b68f76d82
    • Opcode Fuzzy Hash: f39f7ab04ac6802c9ed33644b7a0eccb040fba9d0a111bec8e041f2528b00038
    • Instruction Fuzzy Hash: 2361CE72A06B4982EE14CB29E500279A7F1FB68BD4F408232DE6E47795EF7CE491C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,00000000,?,00007FF6A8D39D5F,?,?,?,?,?,?,00000000,00000001,?,00007FF6A8D35085), ref: 00007FF6A8CFF129
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xlength_error@std@@
    • String ID: vector<T> too long
    • API String ID: 1004598685-3788999226
    • Opcode ID: 5e6d067f68e1cab0e2262cbc6cd023cca7754c2eb0b5139f3ebf96977e154f2d
    • Instruction ID: 42ac19b7c80d4e8eb6c2b674d750f741d4e55f610c1a3ec0e3e12ef521f8f29b
    • Opcode Fuzzy Hash: 5e6d067f68e1cab0e2262cbc6cd023cca7754c2eb0b5139f3ebf96977e154f2d
    • Instruction Fuzzy Hash: F451BBB2B16B4A82EE14CF29D55017963F1FB68BD4B009322DE6E4B790EF78E591C700
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CDDC24: GetCurrentThreadId.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,00000000,00007FF6A8CD3715,?,?,?,?,00000000,00007FF6A8CD39C0,?,?,00000000,00007FF6A8CD3593), ref: 00007FF6A8CDDC2D
      • Part of subcall function 00007FF6A8CEEE2C: _o_malloc.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000000,00007FF6A8CDE93E,?,?,?,?,00007FF6A8D0931C,?,?,?,?,?,?,?), ref: 00007FF6A8CEEE46
      • Part of subcall function 00007FF6A8CDEAF0: OpenProcess.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-1 ref: 00007FF6A8CDEB6E
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN ref: 00007FF6A8D01A3B
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CurrentOpenProcessThreadXlength_error@std@@_o_malloc
    • String ID: list<T> too long$onecore\windows\core\console\open\src\server\processlist.cpp
    • API String ID: 584409634-208596408
    • Opcode ID: e73b535be9f8393cf8cc111f4633867a476dc62d7dfbdd2531513eb3c00ac7bc
    • Instruction ID: d07fcad06a0981888ed8aa47076f0c86891277bbc8d17c1dd9d39a766385b1d4
    • Opcode Fuzzy Hash: e73b535be9f8393cf8cc111f4633867a476dc62d7dfbdd2531513eb3c00ac7bc
    • Instruction Fuzzy Hash: F2516132A0A68286EB54EF25E04037977F0FB84B84F548535DA9E87B95DF3CE846CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN ref: 00007FF6A8D269B4
      • Part of subcall function 00007FF6A8D393D0: ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,00007FF6A8D268F5), ref: 00007FF6A8D39424
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: invalid vector<T> subscript$onecore\windows\core\console\open\src\host\screeninfo.cpp
    • API String ID: 1960685668-2524403630
    • Opcode ID: d7044f07a3cd514b7324133609b21f4bc9c5b005a45997c569989b00a542ddf2
    • Instruction ID: 84e3054d877849e57c19ad407312a2a241387053793aeef4bf74e898be52c288
    • Opcode Fuzzy Hash: d7044f07a3cd514b7324133609b21f4bc9c5b005a45997c569989b00a542ddf2
    • Instruction Fuzzy Hash: D451E532A04AD495E721DF39E8411E9A3B0FF98798F045222FF8D57A14EF38D596C340
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ExceptionThrowXlength_error@std@@
    • String ID: vector<T> too long
    • API String ID: 2465630161-3788999226
    • Opcode ID: c19a9f81be7dc59e4fb3110e6a99d28d511340c68f24d5dc85752da0ea7ce0b8
    • Instruction ID: 1fcbe252ede1b15a0d4631ff0999dcd34ebb3e9f951a52964c42e41a79c4894a
    • Opcode Fuzzy Hash: c19a9f81be7dc59e4fb3110e6a99d28d511340c68f24d5dc85752da0ea7ce0b8
    • Instruction Fuzzy Hash: 104194B2716F4982DE14DF2AE8540A9A7E5FB48BD4B148136DEAD877A4EF3CD046C300
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetWindowsDirectoryW.API-MS-WIN-CORE-SYSINFO-L1-1-0 ref: 00007FF6A8CE5557
    • CompareStringOrdinal.API-MS-WIN-CORE-STRING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CDA8FC), ref: 00007FF6A8CE55D0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CompareDirectoryOrdinalStringWindows
    • String ID: %SystemRoot%
    • API String ID: 2837938056-4275961626
    • Opcode ID: 38fbd9cbe6d6418650c1b5dbd779d37c42d07556d546e8757831a8eb28c7d26e
    • Instruction ID: 6d591cb68f6bd1834e5f939bbf80378f5ae05c4702b888e2c5f2802de05e96bc
    • Opcode Fuzzy Hash: 38fbd9cbe6d6418650c1b5dbd779d37c42d07556d546e8757831a8eb28c7d26e
    • Instruction Fuzzy Hash: AA410866B1A74282EB209F2595021BA63BAFF45B90F984536DF0E87784EF3CD545CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ByteCharMultiWide
    • String ID: onecore\windows\core\console\open\src\types\convert.cpp
    • API String ID: 626452242-4041387901
    • Opcode ID: e7de951adf3559d61e640213feeba7194e5188ec6cd6d8f9e5307a7c61120304
    • Instruction ID: fc7bf63988d9b8fda07981192c8fc97f71370c37fbc25ca12f9c82f27d2c2d54
    • Opcode Fuzzy Hash: e7de951adf3559d61e640213feeba7194e5188ec6cd6d8f9e5307a7c61120304
    • Instruction Fuzzy Hash: 5C41D432A09B8185F7149F71E8402AE3BA1FB487A8F145336EE6E93B59DF3CD1958344
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\host\settings.cpp
    • API String ID: 0-2613322999
    • Opcode ID: 3f6fcc13f082b65a357f316b7577eb5fa9982b6cfd61926f78e4efd5e22f344c
    • Instruction ID: f763c4e97f2603489de15dddfc24046d6e8e2010a26fa6c49336f57a7fab6b21
    • Opcode Fuzzy Hash: 3f6fcc13f082b65a357f316b7577eb5fa9982b6cfd61926f78e4efd5e22f344c
    • Instruction Fuzzy Hash: 0051F72190F292C1EB18AB78E4412BD36B1EF61709F744235C65EC66E0CF3EE6578B58
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: FileWrite
    • String ID: onecore\windows\core\console\open\src\interactivity\onecore\coniosrvcomm.cpp$onecore\windows\core\console\open\src\renderer\wddmcon\wddmconrenderer.cpp
    • API String ID: 3934441357-3505446033
    • Opcode ID: 6567b095aada44fa265a130c26f692d5c4ba332c386afbfc4b970b049784d087
    • Instruction ID: 982659871924a6ff40ef68bb0924766b5357d9756ed2adbfa0dfa903e570aedc
    • Opcode Fuzzy Hash: 6567b095aada44fa265a130c26f692d5c4ba332c386afbfc4b970b049784d087
    • Instruction Fuzzy Hash: 85516332A1974282EB54AB35E4502797760EB91BB4F105332EA7D83BE4DF2CE449C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\server\objecthandle.cpp, xrefs: 00007FF6A8D236A0
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ByteCharMultiWidedefault_deletememcpy
    • String ID: onecore\windows\core\console\open\src\server\objecthandle.cpp
    • API String ID: 3457730176-459684902
    • Opcode ID: 661b5a6c5bc580e1b8fae619fa52b21119997ed4f1281d0843e7df60d7bbb928
    • Instruction ID: 7e5a0af45471ffb35b1b76e542626f31d6d1479f580b489cb8a3ef0dfe02c81c
    • Opcode Fuzzy Hash: 661b5a6c5bc580e1b8fae619fa52b21119997ed4f1281d0843e7df60d7bbb928
    • Instruction Fuzzy Hash: AB410672A0D78182E714EB34A44037ABBA1FB44794F144375EAAD837A6DF3CD409CB44
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8D1A95F
      • Part of subcall function 00007FF6A8D19264: _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,00007FF6A8D18EB9), ref: 00007FF6A8D19287
    • _o_terminate.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D1AA56
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminate$CriticalEnterSection
    • String ID: onecore\windows\core\console\open\src\host\directio.cpp
    • API String ID: 1354191923-2458865805
    • Opcode ID: 20e3c2a6af560e2a48426a5bdd753e6a648b836dfdd16eed2ec7240eab106d37
    • Instruction ID: 4ff4b25c0b3e4fd576349b48eca6da5845eda66bbfa6f521e07089d408c5dfe6
    • Opcode Fuzzy Hash: 20e3c2a6af560e2a48426a5bdd753e6a648b836dfdd16eed2ec7240eab106d37
    • Instruction Fuzzy Hash: 6441D921B5E78282E710BB35E0406BAA7A0EF95B80F145235EF9DD375ADF2CE408C718
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\host\writedata.cpp, xrefs: 00007FF6A8D2EDE4
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: default_delete
    • String ID: onecore\windows\core\console\open\src\host\writedata.cpp
    • API String ID: 3712186324-3632423436
    • Opcode ID: 4338fcd892c886e92812478ad7913a92a20ecef39a3d79b848ace9ea15297bef
    • Instruction ID: 43b0c0ebbf28eca6f3fb6a907f6857fed6061b2c3fc3a0496d00ac160093ee77
    • Opcode Fuzzy Hash: 4338fcd892c886e92812478ad7913a92a20ecef39a3d79b848ace9ea15297bef
    • Instruction Fuzzy Hash: B041927250DB8592EA60AB25E0413AEB3B4FB84794F109235DB9D47B56EF3CD099CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressProc
    • String ID: DarkMode_Explorer$onecore\windows\core\console\open\src\interactivity\win32\windowtheme.cpp
    • API String ID: 190572456-2049200211
    • Opcode ID: 9f7ead23967ba0327d55fe9e940d047a9ae006d3513f134122dcfab5b2bf62fa
    • Instruction ID: 058bc26f68abd575af2809116c1930165609a8b0e1fe74ed27cd12e3d896ac27
    • Opcode Fuzzy Hash: 9f7ead23967ba0327d55fe9e940d047a9ae006d3513f134122dcfab5b2bf62fa
    • Instruction Fuzzy Hash: FC31B221A0E74386FB60AB71E85167926A0EF4A781F10A235D95FC3A50DF3CE54C8708
    Uniqueness

    Uniqueness Score: -1.00%

    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID:
    • String ID: onecore\windows\core\console\open\src\host\_stream.cpp$onecore\windows\core\console\open\src\types\viewport.cpp
    • API String ID: 0-2014340473
    • Opcode ID: 05ebbd79bb0b0ce6f457e93bf48cd06ffb29930357654cae73a950500901303c
    • Instruction ID: a0c0c78b39b1756d40a92ef6433b6d4aef0e23b3fa9ed31fe2dc05af7672cdd9
    • Opcode Fuzzy Hash: 05ebbd79bb0b0ce6f457e93bf48cd06ffb29930357654cae73a950500901303c
    • Instruction Fuzzy Hash: 3231E632A4A607C2E615AB65E0807BD6774FF80B84F648131D64DC3E95DE3CD655CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: invalid string position$onecore\windows\core\console\open\src\host\_output.cpp
    • API String ID: 1960685668-258750115
    • Opcode ID: 38ecf8c2aed18670bfd4eaaa7e135c6f0500506731528955a4573e38c539ebd6
    • Instruction ID: 24a22868efd621eaea8faa082276bf3a78798cda53eded06390a6e541b549e2c
    • Opcode Fuzzy Hash: 38ecf8c2aed18670bfd4eaaa7e135c6f0500506731528955a4573e38c539ebd6
    • Instruction Fuzzy Hash: 2F219C32B16A459AE710ABB1E8416ED73B0FB49B88F448232DE4CA3B54DF38D509C744
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ClaimsCloseHandleOpenPackageProcessQueryToken
    • String ID: onecore\windows\core\console\open\src\server\processpolicy.cpp
    • API String ID: 1288261071-2159332910
    • Opcode ID: e8b788527686388de81541cd609e11689f492d9fca7d74c7161835a3fe5714c3
    • Instruction ID: c2213d674074ca75f1c17bf248b7a4900e7f2f6b71df195ccc9361fba5cbeac2
    • Opcode Fuzzy Hash: e8b788527686388de81541cd609e11689f492d9fca7d74c7161835a3fe5714c3
    • Instruction Fuzzy Hash: 0631AB2265D68781E710AB21A4401BA6B71FBC9794F445235EA6FC3B95CF3CD505C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _o__invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,00007FF6A8CEAB1F,?,?,?,?,00007FF6A8CDE3BA,?,?,00000000,00007FF6A8D1F521), ref: 00007FF6A8D05694
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o__invalid_parameter_noinfo_noreturn
    • String ID: onecore\internal\minwin\priv_sdk\inc\appmodelpolicy.h$onecore\windows\core\console\conint\processpolicy.cpp
    • API String ID: 38229942-1181345395
    • Opcode ID: b75abd4abcd6c4bc5c4beec981f59a95ecf4815447e6ffce5376b86eb343eb9b
    • Instruction ID: 3d6602d51e79ffb19802076d778adf6682a1ac8832a370c62eda802a1c1db1f1
    • Opcode Fuzzy Hash: b75abd4abcd6c4bc5c4beec981f59a95ecf4815447e6ffce5376b86eb343eb9b
    • Instruction Fuzzy Hash: EB212462E5BA438AFF186734904667C17B0AF63B64F404B35CA6FC2AD1CD2EE4558B0C
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CDDC24: GetCurrentThreadId.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,00000000,00007FF6A8CD3715,?,?,?,?,00000000,00007FF6A8CD39C0,?,?,00000000,00007FF6A8CD3593), ref: 00007FF6A8CDDC2D
    • GetCurrentProcessId.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,?,?,00000000,00007FF6A8CD39C0,?,?,00000000,00007FF6A8CD3593), ref: 00007FF6A8CD373A
    • GetCurrentThreadId.API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0(?,?,?,?,00000000,00007FF6A8CD39C0,?,?,00000000,00007FF6A8CD3593), ref: 00007FF6A8CD3748
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Current$Thread$Process
    • String ID: onecore\windows\core\console\open\src\interactivity\win32\windowio.cpp
    • API String ID: 3664162594-1145931909
    • Opcode ID: 188741aa74318de18b6eb8b9da41da8d0fbd70e8c2ce79ccf0596a3a3973f94e
    • Instruction ID: 1b86d55bec372280829e60e6555d8eac6d078a1ea2c4620e76f9ff3b8b320dde
    • Opcode Fuzzy Hash: 188741aa74318de18b6eb8b9da41da8d0fbd70e8c2ce79ccf0596a3a3973f94e
    • Instruction Fuzzy Hash: 59219475A0E64286EB10AB31E4405B9B7B0FF98B88F144532DE5E87B55DF3CE506CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_terminatememset
    • String ID: onecore\windows\core\console\open\src\host\dbcs.cpp
    • API String ID: 1963963490-3591230717
    • Opcode ID: 8a443f67c16865ce9948281305e1ae385d586deb8690b461eed9fdac37b7411b
    • Instruction ID: 49587e84f960897a40d0c795acf10bb5ba4e821d6b79b71fa58c08e1fc6a3d26
    • Opcode Fuzzy Hash: 8a443f67c16865ce9948281305e1ae385d586deb8690b461eed9fdac37b7411b
    • Instruction Fuzzy Hash: 7421F236B09A8282EB14EF35D08503DA361FB89B90F148236EA6EC3795EF3CD406C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memsetswprintf
    • String ID: `
    • API String ID: 3661171589-2679148245
    • Opcode ID: ea61f93e804bd4e92a1a444e7971b8ac5b2bf464773e6695c52460a3793db0ca
    • Instruction ID: fc0e2a66aaba362b5ab70bf7c11bd8db5875dd24300c9249b1244ea877b3678c
    • Opcode Fuzzy Hash: ea61f93e804bd4e92a1a444e7971b8ac5b2bf464773e6695c52460a3793db0ca
    • Instruction Fuzzy Hash: B321A332A19A8581EB60AB31E0513FE7360FB88B54F404231EAAD83B95DF7CE559CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: EventResetdefault_delete
    • String ID: onecore\windows\core\console\open\src\host\inputbuffer.cpp
    • API String ID: 1662629009-425006629
    • Opcode ID: 05e5960824894152e6df2af9721ad209b7c9c218524b927c01f014a8131a4dce
    • Instruction ID: 036128cf167c3b3bc53413c828b85ad04150faa1d1fa3b8064606eaf9f288222
    • Opcode Fuzzy Hash: 05e5960824894152e6df2af9721ad209b7c9c218524b927c01f014a8131a4dce
    • Instruction Fuzzy Hash: E9115111D0D68681FA10BF7194013B96770AF96B80F184132DE5E87B97CE2CE445CB18
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,00007FF6A8D30834), ref: 00007FF6A8D3042B
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D30834), ref: 00007FF6A8D30481
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xlength_error@std@@memcpy
    • String ID: string too long
    • API String ID: 237780522-2556327735
    • Opcode ID: f23fae20fa06fa54c7022bf4a1936f140ed9770427383d0554aefbc5fafd2193
    • Instruction ID: 027bae481e982d765356a9e683e11fc6792fa9de962800128893872e114c7375
    • Opcode Fuzzy Hash: f23fae20fa06fa54c7022bf4a1936f140ed9770427383d0554aefbc5fafd2193
    • Instruction Fuzzy Hash: AE11B122B09B8585EA04EF22EA40069B761FB44FE0F544231EE6D47B99DF7CD955C708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,00007FF6A8CDC6F8), ref: 00007FF6A8CF9013
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: invalid deque<T> subscript$onecore\windows\core\console\open\src\interactivity\win32\screeninfouiaprovider.cpp
    • API String ID: 1960685668-2975521098
    • Opcode ID: 93c1cccfe12fa8d1a52eeaa7079a5647e4b33e8dc40073549af0439a20713412
    • Instruction ID: f10bf0ad0436a0e0fbc4eb83228b60bfb75a152eb71c9f19ae949cb1619e5dc8
    • Opcode Fuzzy Hash: 93c1cccfe12fa8d1a52eeaa7079a5647e4b33e8dc40073549af0439a20713412
    • Instruction Fuzzy Hash: E8114766A06A4681EF14AFA9D0505B877F0FF94B84BA44536CA1F87751CE3DD8468B08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressProc
    • String ID: AdjustWindowRectExForDpi
    • API String ID: 190572456-2659676865
    • Opcode ID: 480e76d312b34245be1db12d2d977f824e44176cd9e9e7126fced6dfe973fd66
    • Instruction ID: f93fce5e5de1bf8a6450d215c95fdc6c8b60ffe7cdc27d29bdf1d13792174771
    • Opcode Fuzzy Hash: 480e76d312b34245be1db12d2d977f824e44176cd9e9e7126fced6dfe973fd66
    • Instruction Fuzzy Hash: FD216F35A0A79586FB509B25B810539B7A0FF89B80F584235EE9E87B64CF3CE445CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: invalid vector<T> subscript
    • API String ID: 1960685668-3016609489
    • Opcode ID: 8fd2c56356cd6798708bdba0ef57db57dbc992af49f0477f4b59e563c6b1b5ab
    • Instruction ID: 6931fe7258bf24821afac65871821d61be243ab298d99c28be46fa7ae3e105b1
    • Opcode Fuzzy Hash: 8fd2c56356cd6798708bdba0ef57db57dbc992af49f0477f4b59e563c6b1b5ab
    • Instruction Fuzzy Hash: D8019671B15A8A92DE48BB26E5402B8E3A0EF55BC4F58C231DE1D87754EF3CD854C204
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    • onecore\windows\core\console\open\src\host\vtinputthread.cpp, xrefs: 00007FF6A8D17974
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ErrorFileLastRead
    • String ID: onecore\windows\core\console\open\src\host\vtinputthread.cpp
    • API String ID: 1948546556-3316410220
    • Opcode ID: ceb6f511ea74cdae134aa25d898ae9173d9a5ee03308d43b2e841492f6c4df59
    • Instruction ID: 38b9d0582307b623cd9de63cd60e3abce7041b3328987217c82d46f9c6560779
    • Opcode Fuzzy Hash: ceb6f511ea74cdae134aa25d898ae9173d9a5ee03308d43b2e841492f6c4df59
    • Instruction Fuzzy Hash: 4E215E32A1968286E720AB31F4017BA77A0FB89B48F405235DA9DCB759DF3DD108CB64
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN(?,?,00000001,00007FF6A8D13D73), ref: 00007FF6A8D13697
    • memmove.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,00000001,00007FF6A8D13D73), ref: 00007FF6A8D136DE
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@memmove
    • String ID: invalid string position
    • API String ID: 1894236298-1799206989
    • Opcode ID: 1ed9ed0a16880018a04765611c2a41ca3e55cacf9ce9572e33293a0b47b578c5
    • Instruction ID: e4f015a78d07e5d4087c42b4a3669b44f236bca9c05c1ac49ad4a896188cbcb5
    • Opcode Fuzzy Hash: 1ed9ed0a16880018a04765611c2a41ca3e55cacf9ce9572e33293a0b47b578c5
    • Instruction Fuzzy Hash: 59118F71715B8990DE049F79E988098A362FB18FC4B648235DB1D47768DF3CD159C344
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D2CCDC: LoadLibraryExW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8D2CD20
      • Part of subcall function 00007FF6A8D2CCDC: _Init_thread_footer.LIBCMT ref: 00007FF6A8D2CD46
      • Part of subcall function 00007FF6A8CEF0A0: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE769,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF0B0
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,?,?,00007FF6A8D2CDB3), ref: 00007FF6A8D2CF35
    • _Init_thread_footer.LIBCMT ref: 00007FF6A8D2CF4F
      • Part of subcall function 00007FF6A8CEF038: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF048
      • Part of subcall function 00007FF6A8CEF038: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF088
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$EnterInit_thread_footer$AddressLeaveLibraryLoadProc
    • String ID: NtOpenProcess
    • API String ID: 3281356286-3690168757
    • Opcode ID: ff8f2d8a2f7362a75a002e012d4643e4eab9fc9e81fb725bb44d274f4bfe88db
    • Instruction ID: 2eb1e88d1940a665fcd414774ae0de9b78e1089131da3e5a9cc8fcbabc92cd9e
    • Opcode Fuzzy Hash: ff8f2d8a2f7362a75a002e012d4643e4eab9fc9e81fb725bb44d274f4bfe88db
    • Instruction Fuzzy Hash: 51116331A0AB8281EA00AB21F4501657760FF46BE0F554375EA2D877A5DF3CE84D8748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN(?,?,00000001,00007FF6A8D25943), ref: 00007FF6A8D3A7FD
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: invalid vector<T> subscript$onecore\windows\core\console\open\src\buffer\out\attrrow.cpp
    • API String ID: 1960685668-1249968659
    • Opcode ID: 03a7ea3692c647a9e7e7e01e4e3bc2d4693bfbef5eaf9239e9e554cc4479c7de
    • Instruction ID: 8e744d9a6451c36cc8a752c02a213b7c6e4d765be9d18b5f725eef79874e7d36
    • Opcode Fuzzy Hash: 03a7ea3692c647a9e7e7e01e4e3bc2d4693bfbef5eaf9239e9e554cc4479c7de
    • Instruction Fuzzy Hash: F011E572B15A8582DF04EF62E5544B8B7A0EB98BD4B54C132DE5D8B718DE2CC558C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: invalid string position$onecore\windows\core\console\open\src\renderer\dx\customtextlayout.cpp
    • API String ID: 1960685668-2152613991
    • Opcode ID: 1ac0f873dd5ae8ab636509b1610903246252af11c8f845ab7bbf4db0397aecc4
    • Instruction ID: 1a1c248dccf26f8842fdc956ef951026d27294575ec5ae7b7f71d70fa03290a8
    • Opcode Fuzzy Hash: 1ac0f873dd5ae8ab636509b1610903246252af11c8f845ab7bbf4db0397aecc4
    • Instruction Fuzzy Hash: D011E032A29A46C6EB10EF38E44036873B0EB98B54F514631C62D87B61EF3CC989C748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,00007FF6A8CD377D,?,?,?,?,00000000,00007FF6A8CD39C0,?,?,00000000,00007FF6A8CD3593), ref: 00007FF6A8CD38F3
    • _Init_thread_footer.LIBCMT ref: 00007FF6A8CD390D
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressInit_thread_footerProc
    • String ID: ConsoleControl
    • API String ID: 904429856-3740886617
    • Opcode ID: 3198f52e1553ac999460ea594d3c48a4415c4a5e0244b0df7a61095f563b9894
    • Instruction ID: 107d606a618417fceef297dd356aa7edd06e409417769dec1f2b4bf0e24e66f3
    • Opcode Fuzzy Hash: 3198f52e1553ac999460ea594d3c48a4415c4a5e0244b0df7a61095f563b9894
    • Instruction Fuzzy Hash: D3117221E1AA4681EB10AB35F84027573B1FB44B94F184236DA6E83BA5DF7CD449CB44
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D2CCDC: LoadLibraryExW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8D2CD20
      • Part of subcall function 00007FF6A8D2CCDC: _Init_thread_footer.LIBCMT ref: 00007FF6A8D2CD46
      • Part of subcall function 00007FF6A8CEF0A0: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE769,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF0B0
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,?,?,00007FF6A8D2CDD5), ref: 00007FF6A8D2CFF9
    • _Init_thread_footer.LIBCMT ref: 00007FF6A8D2D013
      • Part of subcall function 00007FF6A8CEF038: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF048
      • Part of subcall function 00007FF6A8CEF038: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF088
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$EnterInit_thread_footer$AddressLeaveLibraryLoadProc
    • String ID: NtQueryInformationProcess
    • API String ID: 3281356286-2781105232
    • Opcode ID: 0d970c17b07394b05731c22ebbf6571f6dda6fcb44bfd30ff292a20428907313
    • Instruction ID: 0277c8a0ce7261276c30da8289ec088d5b7805ee6533d70eb8b36b874737114e
    • Opcode Fuzzy Hash: 0d970c17b07394b05731c22ebbf6571f6dda6fcb44bfd30ff292a20428907313
    • Instruction Fuzzy Hash: E611B231A0AB8681FA00EB21F4506393BA0FF85BA4F544275DA2DC37A5DF3DE54A8748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _CxxThrowException.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D07658
      • Part of subcall function 00007FF6A8CECBF4: GetModuleHandleW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,?,00007FF6A8CECBA8), ref: 00007FF6A8CECC0B
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8D07693
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressExceptionHandleModuleProcThrow
    • String ID: RtlDllShutdownInProgress
    • API String ID: 1273124314-2005622848
    • Opcode ID: fab12884c421b694b9ce38a84147cd809622321d2e55d385d9d461c3159b3b47
    • Instruction ID: f53355715682ce184ff9df8eec7ccb721c1b3702c5f4168300879ca13795c630
    • Opcode Fuzzy Hash: fab12884c421b694b9ce38a84147cd809622321d2e55d385d9d461c3159b3b47
    • Instruction Fuzzy Hash: 30F0E520E17742C6FB58BBB5A8510B23271AF19701F545234DC2E86351EF2CA08D8B18
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,00007FF6A8D39CF4,?,?,?,?,?,?,00000000,00000001,?,00007FF6A8D35085), ref: 00007FF6A8D39F19
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xlength_error@std@@
    • String ID: UUUUUUUU$vector<T> too long
    • API String ID: 1004598685-1961640351
    • Opcode ID: 2c0b171d6e4021f1aa40519f0769b52febbade45dbb41d7277d8f4ce93d80f76
    • Instruction ID: 7c401288c06a7b49b3a3f8da4637fe0201d7ae5c4ff827fc5d57acc311f091a9
    • Opcode Fuzzy Hash: 2c0b171d6e4021f1aa40519f0769b52febbade45dbb41d7277d8f4ce93d80f76
    • Instruction Fuzzy Hash: A1018E76606B8181DB14DF22E54422AF7B5FB49BC0B088231EBAD83B54EF3CD4948700
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • wcsncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CE1BA0), ref: 00007FF6A8CE1BEE
    • _o_wcscpy_s.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CE1BA0), ref: 00007FF6A8CE1C47
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: _o_wcscpy_swcsncmp
    • String ID: __DefaultTTFont__
    • API String ID: 2955157898-894678944
    • Opcode ID: e50b77d1b2550543782a700d45af5ad65f9c6fe698ed5c4ec9455b5ec1baf5b4
    • Instruction ID: d73b053500aa9dc5bd94037daba940a6c6a8e0068323b817fdaeb76bfea2d27e
    • Opcode Fuzzy Hash: e50b77d1b2550543782a700d45af5ad65f9c6fe698ed5c4ec9455b5ec1baf5b4
    • Instruction Fuzzy Hash: 82117C61B1A64682FB50AB35E8123793760FB8AB45F444132D98EC3765EF3CE04A8B48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CF6010: GetTokenInformation.API-MS-WIN-SECURITY-BASE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CDA8FC), ref: 00007FF6A8CF6056
      • Part of subcall function 00007FF6A8CF6010: GetLastError.API-MS-WIN-CORE-ERRORHANDLING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CDA8FC), ref: 00007FF6A8CF606A
    • GetSidSubAuthorityCount.API-MS-WIN-SECURITY-BASE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CDA8FC), ref: 00007FF6A8CF6250
    • GetSidSubAuthority.API-MS-WIN-SECURITY-BASE-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00007FF6A8CDA8FC), ref: 00007FF6A8CF6266
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Authority$CountErrorInformationLastToken
    • String ID: onecore\windows\core\console\conint\processpolicy.cpp
    • API String ID: 184111022-3682059561
    • Opcode ID: 6679d8963210f8f2a08bb7035e9800e96efaa0fcab50d289e82243036acc575b
    • Instruction ID: ce54e3d4dc5425df9919eec216531a681da002e403811fdfa1df5c6566fca51c
    • Opcode Fuzzy Hash: 6679d8963210f8f2a08bb7035e9800e96efaa0fcab50d289e82243036acc575b
    • Instruction Fuzzy Hash: 5E012D7261868186E700AF65E4907BABBA1EB98B84F549135E64F87765CE3CD8488B04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xlength_error@std@@memset
    • String ID: vector<T> too long
    • API String ID: 1527646195-3788999226
    • Opcode ID: 097fbfab64ab46df1f134cce5395d1e43cef553f97ec5a712a157e2972b7e78b
    • Instruction ID: 7f56a8fde4e89ebca0506d0bba51f2237fb3cb75f6ddcc2830354c688c02fae4
    • Opcode Fuzzy Hash: 097fbfab64ab46df1f134cce5395d1e43cef553f97ec5a712a157e2972b7e78b
    • Instruction Fuzzy Hash: 31019232A16B8582EB14AB25E5403A9B7B0FB48BA4F588734DA7D877D4EF3CD455C300
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressInit_thread_footerProc
    • String ID: ConsoleControl
    • API String ID: 904429856-3740886617
    • Opcode ID: 42e50567071f8e24fc4418d1af3707f00d541188d1943d72713e7e020ba73433
    • Instruction ID: 5d7203e5c4746698b3ad85f7c4b99b43b43533e51d6b26f637ead6b90e158138
    • Opcode Fuzzy Hash: 42e50567071f8e24fc4418d1af3707f00d541188d1943d72713e7e020ba73433
    • Instruction Fuzzy Hash: 3D119E31A1AA07C5EB20EB34E4512793371FF45B88F444235C66E867A0CF3CE589CB08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8D1DB1F
    • IsValidCodePage.API-MS-WIN-CORE-LOCALIZATION-L1-2-0 ref: 00007FF6A8D1DB33
      • Part of subcall function 00007FF6A8CDD6A0: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,?,00000000,00007FF6A8D550E6,?,?,?,?,00000000,00007FF6A8CFA2D9), ref: 00007FF6A8CDD6D0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$CodeEnterLeavePageValid
    • String ID: onecore\windows\core\console\open\src\host\getset.cpp
    • API String ID: 2606172417-1703575416
    • Opcode ID: aa1bc4a1a80fd84e074e95a31e0a6e9600a0ef38bd7d5073c3ed9efc9d4e578c
    • Instruction ID: 447f23b03158d3b06da97c315be3e4bc28b27be67523ae4d8878ab77919f359c
    • Opcode Fuzzy Hash: aa1bc4a1a80fd84e074e95a31e0a6e9600a0ef38bd7d5073c3ed9efc9d4e578c
    • Instruction Fuzzy Hash: A7016261F5B24387F7247B34A8905B93EA0EF8A705F142639D65FC2292DE3CA44C875C
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0 ref: 00007FF6A8D1DA4F
    • IsValidCodePage.API-MS-WIN-CORE-LOCALIZATION-L1-2-0 ref: 00007FF6A8D1DA63
      • Part of subcall function 00007FF6A8CDD6A0: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,?,00000000,00007FF6A8D550E6,?,?,?,?,00000000,00007FF6A8CFA2D9), ref: 00007FF6A8CDD6D0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$CodeEnterLeavePageValid
    • String ID: onecore\windows\core\console\open\src\host\getset.cpp
    • API String ID: 2606172417-1703575416
    • Opcode ID: eeac89ab30f5716f2c6f614f5bf31ee91bf1dbf70a44c91d1ecd5e74844060c4
    • Instruction ID: 66d846ab11fc4f4b3641b0692b2cd081d5add49be59066cd225b0bbc98a0473f
    • Opcode Fuzzy Hash: eeac89ab30f5716f2c6f614f5bf31ee91bf1dbf70a44c91d1ecd5e74844060c4
    • Instruction Fuzzy Hash: 6E01A721E8E24387F720BB31A4905793EA0AF5A708F141735D51EC2282DF2CA44CC748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressInit_thread_footerProc
    • String ID: TranslateMessageEx
    • API String ID: 904429856-3229300106
    • Opcode ID: 60c9e0c2fd5893c3d32f996f31deac3f6319c7879c916a10395e5b9be2b88557
    • Instruction ID: c78c49c676486510e9e513d3d7eedf3d3abb343e9c1a0ad37f3a07179d780f3e
    • Opcode Fuzzy Hash: 60c9e0c2fd5893c3d32f996f31deac3f6319c7879c916a10395e5b9be2b88557
    • Instruction Fuzzy Hash: 9E118E21A0BA47C1EB60AB34E99027973B1FF44B94F144236D51E837A1DF7CE44AC748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8D2CCDC: LoadLibraryExW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8D2CD20
      • Part of subcall function 00007FF6A8D2CCDC: _Init_thread_footer.LIBCMT ref: 00007FF6A8D2CD46
      • Part of subcall function 00007FF6A8CEF0A0: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE769,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF0B0
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0(?,?,?,00007FF6A8D2CDE0), ref: 00007FF6A8D2CE81
    • _Init_thread_footer.LIBCMT ref: 00007FF6A8D2CE9B
      • Part of subcall function 00007FF6A8CEF038: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF048
      • Part of subcall function 00007FF6A8CEF038: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF088
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$EnterInit_thread_footer$AddressLeaveLibraryLoadProc
    • String ID: NtClose
    • API String ID: 3281356286-218744656
    • Opcode ID: 842bc42640c698296cd51d06cbdc68a5419c1964856a2bf04be548f620e309d7
    • Instruction ID: a339359902782fcbe75a356baa707d4066b0f38c3b417389ac78a01d8610b3ce
    • Opcode Fuzzy Hash: 842bc42640c698296cd51d06cbdc68a5419c1964856a2bf04be548f620e309d7
    • Instruction Fuzzy Hash: 0601A130A0BA8681FA40BB31F49017433A1FF457A4F854271D92E837A1DF3CE88AC348
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CEF0A0: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE769,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF0B0
    • GetProcAddress.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8D51C44
    • _Init_thread_footer.LIBCMT ref: 00007FF6A8D51C5E
      • Part of subcall function 00007FF6A8CEF038: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF048
      • Part of subcall function 00007FF6A8CEF038: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF088
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$Enter$AddressInit_thread_footerLeaveProc
    • String ID: EnterReaderModeHelper
    • API String ID: 3610791082-2410284899
    • Opcode ID: 68e02a01bc8ac2fb5b3c5ebaede5d99fd90e69165c38bcd02d288ad8224e422e
    • Instruction ID: 54a92ee40bbc4215810e6ea70a26bd793cf64a1862d919f0899d6af3a75699b6
    • Opcode Fuzzy Hash: 68e02a01bc8ac2fb5b3c5ebaede5d99fd90e69165c38bcd02d288ad8224e422e
    • Instruction Fuzzy Hash: 8D015E20A1AE4781FB54BB34E5A12747BA1EF44B94F58433AD52E827A1CE3DE44DC748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressProc
    • String ID: EnableChildWindowDpiMessage
    • API String ID: 190572456-233965631
    • Opcode ID: 11c5d5d5f1825b3ea9c2e3c733bf5fab6bdb46a0bd6339e435d2250c4adeb8df
    • Instruction ID: 0f1ecf890304844c6d90e4629cc36564dfa026fe9dbd9560688a323d7a21175c
    • Opcode Fuzzy Hash: 11c5d5d5f1825b3ea9c2e3c733bf5fab6bdb46a0bd6339e435d2250c4adeb8df
    • Instruction Fuzzy Hash: A4011A21A0BB4685FF54AB31E95123876A0AF8AB84F189275D95E82790DF3CE489C748
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressProc
    • String ID: GetWindowDPI
    • API String ID: 190572456-1607898006
    • Opcode ID: 90df66e4bcb26784599cd2db501384e6f880bcd0cc3c419648c282b29adcf5f8
    • Instruction ID: fef3e1ec5dd07d9009b3956cf291716215d29b8af93b9e71e5e214e4f41b6d23
    • Opcode Fuzzy Hash: 90df66e4bcb26784599cd2db501384e6f880bcd0cc3c419648c282b29adcf5f8
    • Instruction Fuzzy Hash: 41015E31A0FB8281FF54AB75E85023877A5BF49B80F184235EA5E86B64DF7CE458C708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: AddressProc
    • String ID: EnablePerMonitorDialogScaling
    • API String ID: 190572456-2779642180
    • Opcode ID: e440415e0280597bb85664c9d480a8957e2d96107144ade7a556261ed3a68774
    • Instruction ID: addd066978190f816055e506b6d1568136e86aa708e3f4c2c848b2d264805ab0
    • Opcode Fuzzy Hash: e440415e0280597bb85664c9d480a8957e2d96107144ade7a556261ed3a68774
    • Instruction Fuzzy Hash: 3E016D20E0BB46C1FF546B74B8513343AB4EF49B10F185274CA5EC2390DF3CA8888718
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • DeleteTimerQueueTimer.API-MS-WIN-CORE-THREADPOOL-LEGACY-L1-1-0(?,?,?,00007FF6A8D0DF51,?,?,?,00007FF6A8CFBCF6), ref: 00007FF6A8CECB60
    Strings
    • onecore\windows\core\console\open\src\host\cursorblinker.cpp, xrefs: 00007FF6A8D0629E
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Timer$DeleteQueue
    • String ID: onecore\windows\core\console\open\src\host\cursorblinker.cpp
    • API String ID: 672719580-1313982512
    • Opcode ID: 30ead9a2974ed9b0f01f851d18a667d87eecf35b4e5a2dda21f2f236293e6cea
    • Instruction ID: 0a64566c001c9b79b41bd87d6e8062084a2718a06708bfe1ab942a8e8ece3b5b
    • Opcode Fuzzy Hash: 30ead9a2974ed9b0f01f851d18a667d87eecf35b4e5a2dda21f2f236293e6cea
    • Instruction Fuzzy Hash: 60F0903291A986C1EB206B79E84117C6764EB4AB79F549331C93EC22D4DF2CD5498B08
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
      • Part of subcall function 00007FF6A8CEF0A0: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE769,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF0B0
    • LoadLibraryExW.API-MS-WIN-CORE-LIBRARYLOADER-L1-2-0 ref: 00007FF6A8D2CD20
    • _Init_thread_footer.LIBCMT ref: 00007FF6A8D2CD46
      • Part of subcall function 00007FF6A8CEF038: EnterCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF048
      • Part of subcall function 00007FF6A8CEF038: LeaveCriticalSection.API-MS-WIN-CORE-SYNCH-L1-1-0(?,?,00000001,00007FF6A8CDE790,?,?,?,?,00007FF6A8D1E5DD,?,?,00000000,00007FF6A8CF9FE0), ref: 00007FF6A8CEF088
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$Enter$Init_thread_footerLeaveLibraryLoad_onexit
    • String ID: ntdll.dll
    • API String ID: 626564473-2227199552
    • Opcode ID: 8c90f6ded97d1f5cc6911412ab8d768ee704d794e1c0e51c7f05a1ab7b5ba2c3
    • Instruction ID: bc03a4cf084b211e9dc8a3e13faa99d6edd3a3ca979eb8eee01323a6e702d780
    • Opcode Fuzzy Hash: 8c90f6ded97d1f5cc6911412ab8d768ee704d794e1c0e51c7f05a1ab7b5ba2c3
    • Instruction Fuzzy Hash: BCF01D74E0AA4281FA50E734E8A117437A1FB95751F814331C52EC36A2DF3CE58ECB49
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • ?_Xout_of_range@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,00007FF6A8CFF747), ref: 00007FF6A8D3A5C0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: Xout_of_range@std@@
    • String ID: VUUUUUUU$invalid vector<T> subscript
    • API String ID: 1960685668-3105710005
    • Opcode ID: a8a62ccc7bc752bb0505fb2f3bb9a4da8a8b0d721cdf40aa5692a34a9e6bfe2b
    • Instruction ID: 93f66fbbcf3ecfca59323cae6b745fddfa421cc0c0b429f7379a23763b60306a
    • Opcode Fuzzy Hash: a8a62ccc7bc752bb0505fb2f3bb9a4da8a8b0d721cdf40aa5692a34a9e6bfe2b
    • Instruction Fuzzy Hash: CAE04FB5F12E8D82C904A715A444758E7A5EB59BC4B958232DA0D4B324EE2C9259C704
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$Leave$Enter
    • String ID:
    • API String ID: 2978645861-0
    • Opcode ID: c3de73c3a98770b863e5c576073369cac29465ec41c210aba14fe4bf26b31eb6
    • Instruction ID: 291c29851ae325e8b3c40fbc854634fb779b19da1186fdfaad66380caf48f3b5
    • Opcode Fuzzy Hash: c3de73c3a98770b863e5c576073369cac29465ec41c210aba14fe4bf26b31eb6
    • Instruction Fuzzy Hash: 4851C322A1968286E714EB31E4043BAB760FB89784F449631E99ED7759DF3CD80DCB48
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: CriticalSection$Leave$Enter
    • String ID:
    • API String ID: 2978645861-0
    • Opcode ID: 607da26501a6779d78a9c1197a2f2cad458d2e03032bd07bdbd5d3b5e3ae0965
    • Instruction ID: 370551c5266250f49f8da2ecad88e053ef6cc865332eb094d33271e6e6be8520
    • Opcode Fuzzy Hash: 607da26501a6779d78a9c1197a2f2cad458d2e03032bd07bdbd5d3b5e3ae0965
    • Instruction Fuzzy Hash: CC51B536619B4282E714EB21E45027ABBB0FB88B98F505632EE5E83764DF3DD409CB04
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • _CxxThrowException.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D0FAC5
    • _CxxThrowException.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D0FAED
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D0FB93
      • Part of subcall function 00007FF6A8D0AAAC: ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,00007FF6A8CE087E,?,?,?,00007FF6A8CE065E,?,?,?,00007FF6A8CE0A81), ref: 00007FF6A8D0AAB7
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0 ref: 00007FF6A8D0FBB9
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: ExceptionThrowmemcpy$Xlength_error@std@@
    • String ID:
    • API String ID: 1814077371-0
    • Opcode ID: 1ca9ff5e2540909df7674e3eccaf3d27f4541b87ffd2b2f1a0c509f21d2a98db
    • Instruction ID: 566868de04fc1de7ea36e0fb7afc1df84b5864a1e6f725713784d56beb8008a7
    • Opcode Fuzzy Hash: 1ca9ff5e2540909df7674e3eccaf3d27f4541b87ffd2b2f1a0c509f21d2a98db
    • Instruction Fuzzy Hash: B331D062614B4185DA04EF32A8410AA6371FB49BE0B148336EF7E8B7D9DF78E052C308
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D01DD5), ref: 00007FF6A8D0FC99
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D01DD5), ref: 00007FF6A8D0FCA7
      • Part of subcall function 00007FF6A8D0AAAC: ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,00007FF6A8CE087E,?,?,?,00007FF6A8CE065E,?,?,?,00007FF6A8CE0A81), ref: 00007FF6A8D0AAB7
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D01DD5), ref: 00007FF6A8D0FCC8
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D01DD5), ref: 00007FF6A8D0FCD6
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memcpy$Xlength_error@std@@
    • String ID:
    • API String ID: 1990334673-0
    • Opcode ID: a0ab2e07f62fc82395849d322ca44274fed98a21492046137a19613c1d6e79e7
    • Instruction ID: 04c15a1fce4d881b13fb0871dfcc8f923a6d3c55f54a8362685b4526ead4683d
    • Opcode Fuzzy Hash: a0ab2e07f62fc82395849d322ca44274fed98a21492046137a19613c1d6e79e7
    • Instruction Fuzzy Hash: 0121E172705B4591DA00EF22A44909AB761FB59BF0B544732EE7E8B7D6DE3CE0428708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,00000000,?,00007FF6A8D3856A,?,?,?,?,?,00007FF6A8D343AC), ref: 00007FF6A8D34D60
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,00000000,?,00007FF6A8D3856A,?,?,?,?,?,00007FF6A8D343AC), ref: 00007FF6A8D34D6E
      • Part of subcall function 00007FF6A8D0AAAC: ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,00007FF6A8CE087E,?,?,?,00007FF6A8CE065E,?,?,?,00007FF6A8CE0A81), ref: 00007FF6A8D0AAB7
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,00000000,?,00007FF6A8D3856A,?,?,?,?,?,00007FF6A8D343AC), ref: 00007FF6A8D34D88
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,00000000,?,00007FF6A8D3856A,?,?,?,?,?,00007FF6A8D343AC), ref: 00007FF6A8D34D96
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memcpy$Xlength_error@std@@
    • String ID:
    • API String ID: 1990334673-0
    • Opcode ID: 2f1a2a766d009109e2469c284df8b08adc751d5f1eb13326f39d9b9d190d8316
    • Instruction ID: b64ac9f94eafb72fe8b06d4a54f15fb8a7fdc6a5d7ea86d5b58ea858b96e5c17
    • Opcode Fuzzy Hash: 2f1a2a766d009109e2469c284df8b08adc751d5f1eb13326f39d9b9d190d8316
    • Instruction Fuzzy Hash: C521D72260974581EA00EF23A5444AABB61FB55FD0F544635EF6E4BBC6CF7CE056C708
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D58EEF,?,?,?,?,?,00007FF6A8D583C3), ref: 00007FF6A8D58098
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,00007FF6A8D58EEF,?,?,?,?,?,00007FF6A8D583C3), ref: 00007FF6A8D580A5
      • Part of subcall function 00007FF6A8D0AAAC: ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,00007FF6A8CE087E,?,?,?,00007FF6A8CE065E,?,?,?,00007FF6A8CE0A81), ref: 00007FF6A8D0AAB7
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D58EEF,?,?,?,?,?,00007FF6A8D583C3), ref: 00007FF6A8D580BF
    • memset.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,00007FF6A8D58EEF,?,?,?,?,?,00007FF6A8D583C3), ref: 00007FF6A8D580CC
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memcpymemset$Xlength_error@std@@
    • String ID:
    • API String ID: 1067220161-0
    • Opcode ID: ed24ecf4fda35e6150096bf7ab5708db51cbaf6aa411e7afd84820df57119840
    • Instruction ID: 823a74de928501408512f7d7a5eeec2f8e2ba8103818a27d9c4a0bca4dd11b1b
    • Opcode Fuzzy Hash: ed24ecf4fda35e6150096bf7ab5708db51cbaf6aa411e7afd84820df57119840
    • Instruction Fuzzy Hash: 5A210122609B4481EA04EF2795410AE7761FB56FD0F154232DFAE5BBD2CF7CE0128308
    Uniqueness

    Uniqueness Score: -1.00%

    APIs
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D38767), ref: 00007FF6A8D34EF8
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D38767), ref: 00007FF6A8D34F07
      • Part of subcall function 00007FF6A8D0AAAC: ?_Xlength_error@std@@YAXPEBD@Z.MSVCP_WIN(?,?,?,?,00007FF6A8CE087E,?,?,?,00007FF6A8CE065E,?,?,?,00007FF6A8CE0A81), ref: 00007FF6A8D0AAB7
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D38767), ref: 00007FF6A8D34F1A
    • memcpy.API-MS-WIN-CRT-PRIVATE-L1-1-0(?,?,?,00007FF6A8D38767), ref: 00007FF6A8D34F29
    Memory Dump Source
    • Source File: 00000000.00000002.523489180.00007FF6A8CD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6A8CD0000, based on PE: true
    • Associated: 00000000.00000002.523477348.00007FF6A8CD0000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523902536.00007FF6A8D6B000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523917290.00007FF6A8D6D000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.523955904.00007FF6A8D6F000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524026943.00007FF6A8D90000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524038343.00007FF6A8D91000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.524058562.00007FF6A8D95000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6a8cd0000_conhost.jbxd
    Similarity
    • API ID: memcpy$Xlength_error@std@@
    • String ID:
    • API String ID: 1990334673-0
    • Opcode ID: 36bdf2c84232d4dd49a8710ee2e688d640b62c393f5ee24b368f56eefb5fec6d
    • Instruction ID: 5aba1febc2d83d6b2c001333d484cb98f845501d209b4d6789089590497e7448
    • Opcode Fuzzy Hash: 36bdf2c84232d4dd49a8710ee2e688d640b62c393f5ee24b368f56eefb5fec6d
    • Instruction Fuzzy Hash: 62119032609B4181EA00EF22A5440AAB772FB59BD0F544232EE6E47BD6DF7CE446C708
    Uniqueness

    Uniqueness Score: -1.00%