Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
out.dll.dll

Overview

General Information

Sample Name:out.dll.dll
(renamed file extension from exe to dll, renamed because original name is a hash value)
Original Sample Name:out.dll.exe
Analysis ID:894471
MD5:5a3ee07759e23c507915fb3d473154de
SHA1:ef47ff06ad6a0db77183be19284dbe2c53b16a50
SHA256:14009b05324320da1f4942c35d0cfd24b5dbc49773ce4618e6e070d74a7ffb6a
Tags:exe
Infos:

Detection

Strela Stealer
Score:76
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Yara detected Strela Stealer
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
C2 URLs / IPs found in malware configuration
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
PE file contains sections with non-standard names
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
PE file contains more sections than normal
Program does not show much activity (idle)
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64
  • loaddll64.exe (PID: 5764 cmdline: loaddll64.exe "C:\Users\user\Desktop\out.dll.dll" MD5: 67C05BFD8F41B3421FE285E2FE9641C7)
    • conhost.exe (PID: 5748 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5696 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\out.dll.dll",#1 MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
      • rundll32.exe (PID: 2344 cmdline: rundll32.exe "C:\Users\user\Desktop\out.dll.dll",#1 MD5: 73C519F050C20580F8A62C849D49215A)
    • rundll32.exe (PID: 4924 cmdline: rundll32.exe C:\Users\user\Desktop\out.dll.dll,f MD5: 73C519F050C20580F8A62C849D49215A)
    • rundll32.exe (PID: 6964 cmdline: rundll32.exe "C:\Users\user\Desktop\out.dll.dll",f MD5: 73C519F050C20580F8A62C849D49215A)
  • cleanup
{"C2 url": "91.215.85.209/server.php"}
SourceRuleDescriptionAuthorStrings
00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmpJoeSecurity_StrelaStealerYara detected Strela StealerJoe Security
    00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_StrelaStealerYara detected Strela StealerJoe Security
      00000005.00000002.401547343.000000006D7ED000.00000004.00000001.01000000.00000003.sdmpJoeSecurity_StrelaStealerYara detected Strela StealerJoe Security
        00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_StrelaStealerYara detected Strela StealerJoe Security
          00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_StrelaStealerYara detected Strela StealerJoe Security
            Click to see the 4 entries
            SourceRuleDescriptionAuthorStrings
            4.2.rundll32.exe.6d7ed404.1.unpackJoeSecurity_StrelaStealerYara detected Strela StealerJoe Security
              5.2.rundll32.exe.6d7ed404.1.unpackJoeSecurity_StrelaStealerYara detected Strela StealerJoe Security
                3.2.rundll32.exe.6d7ed404.1.raw.unpackJoeSecurity_StrelaStealerYara detected Strela StealerJoe Security
                  5.2.rundll32.exe.6d7ed404.1.raw.unpackJoeSecurity_StrelaStealerYara detected Strela StealerJoe Security
                    4.2.rundll32.exe.6d7ed404.1.raw.unpackJoeSecurity_StrelaStealerYara detected Strela StealerJoe Security
                      Click to see the 4 entries
                      No Sigma rule has matched
                      No Snort rule has matched

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: 5.2.rundll32.exe.6d7ed404.1.raw.unpackMalware Configuration Extractor: Strela Stealer {"C2 url": "91.215.85.209/server.php"}
                      Source: 91.215.85.209/server.phpAvira URL Cloud: Label: malware
                      Source: 91.215.85.209/server.phpVirustotal: Detection: 17%Perma Link
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_0000018A52C71770 FindFirstFileA,3_2_0000018A52C71770
                      Source: C:\Windows\System32\rundll32.exeCode function: 4_2_0000023E74401770 FindFirstFileA,4_2_0000023E74401770
                      Source: C:\Windows\System32\rundll32.exeCode function: 5_2_0000017FE20A1770 FindFirstFileA,5_2_0000017FE20A1770

                      Networking

                      barindex
                      Source: Malware configuration extractorURLs: 91.215.85.209/server.php
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_6D7C13B03_2_6D7C13B0
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_0000018A52C712C03_2_0000018A52C712C0
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_0000018A52C717703_2_0000018A52C71770
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_0000018A52C7667C3_2_0000018A52C7667C
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_0000018A52C7E8A83_2_0000018A52C7E8A8
                      Source: C:\Windows\System32\rundll32.exeCode function: 4_2_0000023E744012C04_2_0000023E744012C0
                      Source: C:\Windows\System32\rundll32.exeCode function: 4_2_0000023E744017704_2_0000023E74401770
                      Source: C:\Windows\System32\rundll32.exeCode function: 4_2_0000023E7440E8A84_2_0000023E7440E8A8
                      Source: C:\Windows\System32\rundll32.exeCode function: 4_2_0000023E7440667C4_2_0000023E7440667C
                      Source: C:\Windows\System32\rundll32.exeCode function: 5_2_0000017FE20A12C05_2_0000017FE20A12C0
                      Source: C:\Windows\System32\rundll32.exeCode function: 5_2_0000017FE20A17705_2_0000017FE20A1770
                      Source: C:\Windows\System32\rundll32.exeCode function: 5_2_0000017FE20AE8A85_2_0000017FE20AE8A8
                      Source: C:\Windows\System32\rundll32.exeCode function: 5_2_0000017FE20A667C5_2_0000017FE20A667C
                      Source: out.dll.dllStatic PE information: Number of sections : 17 > 10
                      Source: out.dll.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: C:\Windows\System32\loaddll64.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\out.dll.dll,f
                      Source: unknownProcess created: C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\out.dll.dll"
                      Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\out.dll.dll",#1
                      Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\out.dll.dll,f
                      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\out.dll.dll",#1
                      Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\out.dll.dll",f
                      Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\out.dll.dll",#1Jump to behavior
                      Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\out.dll.dll,fJump to behavior
                      Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\out.dll.dll",fJump to behavior
                      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\out.dll.dll",#1Jump to behavior
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5748:120:WilError_01
                      Source: classification engineClassification label: mal76.troj.winDLL@10/0@0/0
                      Source: C:\Windows\System32\rundll32.exeAutomated click: OK
                      Source: C:\Windows\System32\rundll32.exeAutomated click: OK
                      Source: C:\Windows\System32\rundll32.exeAutomated click: OK
                      Source: Window RecorderWindow detected: More than 3 window changes detected
                      Source: out.dll.dllStatic PE information: Image base 0x6d7c0000 > 0x60000000
                      Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\Jump to behavior
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_0000018A52C7AF62 push esp; ret 3_2_0000018A52C7AF65
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_0000018A52C8652E push ecx; retf 003Fh3_2_0000018A52C8658E
                      Source: C:\Windows\System32\rundll32.exeCode function: 4_2_0000023E7440AF62 push esp; ret 4_2_0000023E7440AF65
                      Source: C:\Windows\System32\rundll32.exeCode function: 5_2_0000017FE20B652E push ecx; retf 003Fh5_2_0000017FE20B658E
                      Source: out.dll.dllStatic PE information: section name: .xdata
                      Source: out.dll.dllStatic PE information: section name: /4
                      Source: out.dll.dllStatic PE information: section name: /19
                      Source: out.dll.dllStatic PE information: section name: /31
                      Source: out.dll.dllStatic PE information: section name: /45
                      Source: out.dll.dllStatic PE information: section name: /57
                      Source: out.dll.dllStatic PE information: section name: /70
                      Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\loaddll64.exe TID: 5676Thread sleep time: -120000s >= -30000sJump to behavior
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_0000018A52C71770 FindFirstFileA,3_2_0000018A52C71770
                      Source: C:\Windows\System32\rundll32.exeCode function: 4_2_0000023E74401770 FindFirstFileA,4_2_0000023E74401770
                      Source: C:\Windows\System32\rundll32.exeCode function: 5_2_0000017FE20A1770 FindFirstFileA,5_2_0000017FE20A1770
                      Source: C:\Windows\System32\loaddll64.exeThread delayed: delay time: 120000Jump to behavior
                      Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_6D7EADE0 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort,3_2_6D7EADE0
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_0000018A52C71C88 SetUnhandledExceptionFilter,_invalid_parameter_noinfo,3_2_0000018A52C71C88
                      Source: C:\Windows\System32\rundll32.exeCode function: 4_2_0000023E74401C88 SetUnhandledExceptionFilter,_invalid_parameter_noinfo,4_2_0000023E74401C88
                      Source: C:\Windows\System32\rundll32.exeCode function: 5_2_0000017FE20A1C88 SetUnhandledExceptionFilter,_invalid_parameter_noinfo,5_2_0000017FE20A1C88
                      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\out.dll.dll",#1Jump to behavior
                      Source: C:\Windows\System32\rundll32.exeCode function: 3_2_6D7EAD00 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,3_2_6D7EAD00

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: 4.2.rundll32.exe.6d7ed404.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.6d7ed404.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.6d7ed404.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.6d7ed404.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.6d7ed404.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.6d7ed404.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.6d7c0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.6d7c0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.6d7c0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.401547343.000000006D7ED000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.389694685.000000006D7ED000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: rundll32.exe PID: 4924, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: rundll32.exe PID: 2344, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: rundll32.exe PID: 6964, type: MEMORYSTR

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: 4.2.rundll32.exe.6d7ed404.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.6d7ed404.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.6d7ed404.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.6d7ed404.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.6d7ed404.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.6d7ed404.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.6d7c0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.6d7c0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.2.rundll32.exe.6d7c0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.401547343.000000006D7ED000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.389694685.000000006D7ED000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: rundll32.exe PID: 4924, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: rundll32.exe PID: 2344, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: rundll32.exe PID: 6964, type: MEMORYSTR
                      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                      Valid AccountsWindows Management InstrumentationPath Interception11
                      Process Injection
                      1
                      Rundll32
                      OS Credential Dumping1
                      System Time Discovery
                      Remote Services1
                      Archive Collected Data
                      Exfiltration Over Other Network Medium1
                      Encrypted Channel
                      Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
                      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
                      Virtualization/Sandbox Evasion
                      LSASS Memory11
                      Virtualization/Sandbox Evasion
                      Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
                      Application Layer Protocol
                      Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)11
                      Process Injection
                      Security Account Manager1
                      File and Directory Discovery
                      SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
                      Obfuscated Files or Information
                      NTDS3
                      System Information Discovery
                      Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 signatures2 2 Behavior Graph ID: 894471 Sample: out.dll.exe Startdate: 26/06/2023 Architecture: WINDOWS Score: 76 19 Multi AV Scanner detection for domain / URL 2->19 21 Found malware configuration 2->21 23 Antivirus detection for URL or domain 2->23 25 2 other signatures 2->25 7 loaddll64.exe 1 2->7         started        process3 process4 9 cmd.exe 1 7->9         started        11 rundll32.exe 7->11         started        13 rundll32.exe 7->13         started        15 conhost.exe 7->15         started        process5 17 rundll32.exe 9->17         started       

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      No Antivirus matches
                      No Antivirus matches
                      No Antivirus matches
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      91.215.85.209/server.php18%VirustotalBrowse
                      91.215.85.209/server.php100%Avira URL Cloudmalware
                      No contacted domains info
                      NameMaliciousAntivirus DetectionReputation
                      91.215.85.209/server.phptrue
                      • 18%, Virustotal, Browse
                      • Avira URL Cloud: malware
                      low
                      No contacted IP infos
                      Joe Sandbox Version:37.1.0 Beryl
                      Analysis ID:894471
                      Start date and time:2023-06-26 14:52:08 +02:00
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:0h 4m 50s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                      Number of analysed new started processes analysed:6
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • HDC enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample file name:out.dll.dll
                      (renamed file extension from exe to dll, renamed because original name is a hash value)
                      Original Sample Name:out.dll.exe
                      Detection:MAL
                      Classification:mal76.troj.winDLL@10/0@0/0
                      EGA Information:
                      • Successful, ratio: 100%
                      HDC Information:
                      • Successful, ratio: 0.2% (good quality ratio 0.2%)
                      • Quality average: 65%
                      • Quality standard deviation: 0%
                      HCA Information:
                      • Successful, ratio: 98%
                      • Number of executed functions: 21
                      • Number of non-executed functions: 24
                      Cookbook Comments:
                      • Stop behavior analysis, all processes terminated
                      • Not all processes where analyzed, report is missing behavior information
                      TimeTypeDescription
                      14:53:07API Interceptor1x Sleep call for process: loaddll64.exe modified
                      No context
                      No context
                      No context
                      No context
                      No context
                      No created / dropped files found
                      File type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                      Entropy (8bit):7.034909599337373
                      TrID:
                      • Win64 Dynamic Link Library (generic) (102004/3) 86.41%
                      • Win64 Executable (generic) (12005/4) 10.17%
                      • Generic Win/DOS Executable (2004/3) 1.70%
                      • DOS Executable Generic (2002/1) 1.70%
                      • VXD Driver (31/22) 0.03%
                      File name:out.dll.dll
                      File size:330475
                      MD5:5a3ee07759e23c507915fb3d473154de
                      SHA1:ef47ff06ad6a0db77183be19284dbe2c53b16a50
                      SHA256:14009b05324320da1f4942c35d0cfd24b5dbc49773ce4618e6e070d74a7ffb6a
                      SHA512:003b0fbe7599eca2736398ff56dc440cbecf3fd426944da199f92ea4d88f633476e0ba0536aed635b3cf57bb1acb69df154217454eeecb909bab4ede6216cd5a
                      SSDEEP:6144:wkdK9Z31wC4HCzUI+krsKtZTWScGeDYNiaye0SWcCVTK/S:wkde4iqas+IScTUEC0LckKq
                      TLSH:DD647DAD68DB690AFE6188342FF8BBA1C77734B9C757D7F154E8503029204A3AC46727
                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....`.d..........& ................0.........|m.............................................. ............................
                      Icon Hash:7ae282899bbab082
                      Entrypoint:0x6d7c1330
                      Entrypoint Section:.text
                      Digitally signed:false
                      Imagebase:0x6d7c0000
                      Subsystem:windows cui
                      Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LARGE_ADDRESS_AWARE, DLL
                      DLL Characteristics:
                      Time Stamp:0x649960C1 [Mon Jun 26 09:56:17 2023 UTC]
                      TLS Callbacks:0x6d7eaf10
                      CLR (.Net) Version:
                      OS Version Major:4
                      OS Version Minor:0
                      File Version Major:4
                      File Version Minor:0
                      Subsystem Version Major:4
                      Subsystem Version Minor:0
                      Import Hash:fcfbe5457e76d2ac347d7db113c0ca3b
                      Instruction
                      dec eax
                      sub esp, 48h
                      dec eax
                      mov eax, dword ptr [00047F35h]
                      mov dword ptr [eax], 00000000h
                      cmp edx, 01h
                      je 00007F09449E0F2Ch
                      dec eax
                      add esp, 48h
                      jmp 00007F09449E0DD6h
                      nop
                      dec esp
                      mov dword ptr [esp+38h], eax
                      mov dword ptr [esp+34h], edx
                      dec eax
                      mov dword ptr [esp+28h], ecx
                      call 00007F0944A0A8C2h
                      call 00007F0944A0B1ADh
                      dec esp
                      mov eax, dword ptr [esp+38h]
                      mov edx, dword ptr [esp+34h]
                      dec eax
                      mov ecx, dword ptr [esp+28h]
                      dec eax
                      add esp, 48h
                      jmp 00007F09449E0DA6h
                      nop
                      dec eax
                      mov edx, ecx
                      dec eax
                      lea ecx, dword ptr [0004AC76h]
                      jmp 00007F0944A0BBA6h
                      nop
                      dec eax
                      lea ecx, dword ptr [00000009h]
                      jmp 00007F09449E0F09h
                      nop dword ptr [eax+00h]
                      ret
                      nop
                      nop
                      nop
                      nop
                      nop
                      nop
                      nop
                      nop
                      nop
                      nop
                      nop
                      nop
                      nop
                      nop
                      nop
                      push ebp
                      inc ecx
                      push edi
                      inc ecx
                      push esi
                      inc ecx
                      push ebp
                      inc ecx
                      push esp
                      push esi
                      push edi
                      push ebx
                      mov eax, 00001178h
                      call 00007F0944A0BA8Fh
                      dec eax
                      sub esp, eax
                      dec eax
                      lea ebp, dword ptr [esp+00000080h]
                      xor eax, eax
                      mov ecx, dword ptr [0004B537h]
                      mov edx, dword ptr [0004B539h]
                      sub eax, 01h
                      add eax, 00000000h
                      inc ecx
                      mov eax, ecx
                      inc ecx
                      sub eax, CCDAE09Dh
                      inc ecx
                      add eax, eax
                      inc ecx
                      add eax, 00DAE09Dh
                      NameVirtual AddressVirtual Size Is in Section
                      IMAGE_DIRECTORY_ENTRY_EXPORT0x4d0000x3c.edata
                      IMAGE_DIRECTORY_ENTRY_IMPORT0x4e0000x5b0.idata
                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x4a0000x234.pdata
                      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x510000x64.reloc
                      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                      IMAGE_DIRECTORY_ENTRY_TLS0x490400x28.rdata
                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IAT0x4e16c0x130.idata
                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                      NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                      .text0x10000x2b2e80x2b400False0.3706816744942196data6.148486969707782IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      .data0x2d0000x1b8c00x1ba00False0.8710142109728507data7.731351321018186IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .rdata0x490000x2800x400False0.275390625data2.4559837096468744IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
                      .pdata0x4a0000x2340x400False0.3330078125data3.0085099518562815IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
                      .xdata0x4b0000x1d00x200False0.400390625data3.7977123677025686IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
                      .bss0x4c0000x9300x0False0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .edata0x4d0000x3c0x200False0.111328125data0.5873405188610821IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ
                      .idata0x4e0000x5b00x600False0.373046875data4.144029993089026IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .CRT0x4f0000x580x200False0.05859375data0.2069200177871819IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .tls0x500000x100x200False0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .reloc0x510000x640x200False0.208984375data1.1768257918904406IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      /40x520000x500x200False0.072265625data0.23653878450968063IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      /190x530000x1f080x2000False0.459716796875data5.8268156910913795IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      /310x550000x1490x200False0.375data3.2872917906726884IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      /450x560000x2220x400False0.2880859375data3.229342673799407IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      /570x570000x480x200False0.12109375data0.7133318848005825IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      /700x580000x9b0x200False0.259765625data2.320780444544343IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      DLLImport
                      KERNEL32.dllDeleteCriticalSection, EnterCriticalSection, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, GetLastError, GetSystemTimeAsFileTime, GetTickCount, InitializeCriticalSection, LeaveCriticalSection, QueryPerformanceCounter, RtlAddFunctionTable, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, SetUnhandledExceptionFilter, Sleep, TerminateProcess, TlsGetValue, UnhandledExceptionFilter, VirtualProtect, VirtualQuery
                      msvcrt.dll__iob_func, _amsg_exit, _initterm, _lock, _unlock, abort, calloc, free, fwrite, realloc, signal, strlen, strncmp, vfprintf
                      NameOrdinalAddress
                      f10x6d7c13b0
                      No network behavior found

                      Click to jump to process

                      Click to jump to process

                      Click to dive into process behavior distribution

                      Click to jump to process

                      Target ID:0
                      Start time:14:53:03
                      Start date:26/06/2023
                      Path:C:\Windows\System32\loaddll64.exe
                      Wow64 process (32bit):false
                      Commandline:loaddll64.exe "C:\Users\user\Desktop\out.dll.dll"
                      Imagebase:0x7ff74a650000
                      File size:165888 bytes
                      MD5 hash:67C05BFD8F41B3421FE285E2FE9641C7
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:moderate

                      Target ID:1
                      Start time:14:53:03
                      Start date:26/06/2023
                      Path:C:\Windows\System32\conhost.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Imagebase:0x7ff7fcd70000
                      File size:625664 bytes
                      MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high

                      Target ID:2
                      Start time:14:53:04
                      Start date:26/06/2023
                      Path:C:\Windows\System32\cmd.exe
                      Wow64 process (32bit):false
                      Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\out.dll.dll",#1
                      Imagebase:0x7ff627730000
                      File size:273920 bytes
                      MD5 hash:4E2ACF4F8A396486AB4268C94A6A245F
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high

                      Target ID:3
                      Start time:14:53:04
                      Start date:26/06/2023
                      Path:C:\Windows\System32\rundll32.exe
                      Wow64 process (32bit):false
                      Commandline:rundll32.exe C:\Users\user\Desktop\out.dll.dll,f
                      Imagebase:0x7ff7b71c0000
                      File size:69632 bytes
                      MD5 hash:73C519F050C20580F8A62C849D49215A
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: JoeSecurity_StrelaStealer, Description: Yara detected Strela Stealer, Source: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_StrelaStealer, Description: Yara detected Strela Stealer, Source: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                      Reputation:high

                      Target ID:4
                      Start time:14:53:04
                      Start date:26/06/2023
                      Path:C:\Windows\System32\rundll32.exe
                      Wow64 process (32bit):false
                      Commandline:rundll32.exe "C:\Users\user\Desktop\out.dll.dll",#1
                      Imagebase:0x7ff7b71c0000
                      File size:69632 bytes
                      MD5 hash:73C519F050C20580F8A62C849D49215A
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: JoeSecurity_StrelaStealer, Description: Yara detected Strela Stealer, Source: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_StrelaStealer, Description: Yara detected Strela Stealer, Source: 00000004.00000002.389694685.000000006D7ED000.00000004.00000001.01000000.00000003.sdmp, Author: Joe Security
                      Reputation:high

                      Target ID:5
                      Start time:14:53:07
                      Start date:26/06/2023
                      Path:C:\Windows\System32\rundll32.exe
                      Wow64 process (32bit):false
                      Commandline:rundll32.exe "C:\Users\user\Desktop\out.dll.dll",f
                      Imagebase:0x7ff7b71c0000
                      File size:69632 bytes
                      MD5 hash:73C519F050C20580F8A62C849D49215A
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: JoeSecurity_StrelaStealer, Description: Yara detected Strela Stealer, Source: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_StrelaStealer, Description: Yara detected Strela Stealer, Source: 00000005.00000002.401547343.000000006D7ED000.00000004.00000001.01000000.00000003.sdmp, Author: Joe Security
                      Reputation:high

                      Reset < >

                        Execution Graph

                        Execution Coverage:12.6%
                        Dynamic/Decrypted Code Coverage:87.1%
                        Signature Coverage:3.8%
                        Total number of Nodes:1226
                        Total number of Limit Nodes:12
                        execution_graph 7447 18a52c7d798 7448 18a52c7d6ec 7447->7448 7449 18a52c79ab8 RtlAllocateHeap 7448->7449 7450 18a52c7d713 7449->7450 7451 18a52c7f58a 7454 18a52c7295c 7451->7454 7455 18a52c72986 7454->7455 7456 18a52c72974 7454->7456 7457 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7455->7457 7456->7455 7458 18a52c7297c 7456->7458 7460 18a52c7298b 7457->7460 7459 18a52c72984 7458->7459 7461 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7458->7461 7460->7459 7462 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7460->7462 7463 18a52c729ab 7461->7463 7462->7459 7464 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7463->7464 7465 18a52c729b8 7464->7465 7466 18a52c76b88 RtlAllocateHeap 7465->7466 7467 18a52c729c1 7466->7467 6929 18a52c7c098 6930 18a52c7c0a0 6929->6930 6931 18a52c7c0b5 6930->6931 6933 18a52c7c0ce 6930->6933 6932 18a52c77adc __std_exception_copy RtlAllocateHeap 6931->6932 6934 18a52c7c0ba 6932->6934 6935 18a52c785a8 RtlAllocateHeap 6933->6935 6937 18a52c7c0c5 6933->6937 6936 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 6934->6936 6935->6937 6936->6937 7468 18a52c72398 7469 18a52c723b0 7468->7469 7470 18a52c723cc 7468->7470 7469->7470 7477 18a52c729c4 7469->7477 7475 18a52c76b88 RtlAllocateHeap 7476 18a52c723f2 7475->7476 7478 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7477->7478 7479 18a52c723de 7478->7479 7480 18a52c729d8 7479->7480 7481 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7480->7481 7482 18a52c723ea 7481->7482 7482->7475 6938 18a52c7d48c 6939 18a52c7d495 6938->6939 6940 18a52c7d4a2 6938->6940 6941 18a52c77adc __std_exception_copy RtlAllocateHeap 6939->6941 6942 18a52c77adc __std_exception_copy RtlAllocateHeap 6940->6942 6943 18a52c7d49a 6940->6943 6941->6943 6944 18a52c7d4d9 6942->6944 6945 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 6944->6945 6945->6943 7174 18a52c75e14 7175 18a52c75e2d 7174->7175 7184 18a52c75e29 7174->7184 7176 18a52c79084 RtlAllocateHeap 7175->7176 7177 18a52c75e32 7176->7177 7189 18a52c795e0 7177->7189 7180 18a52c75e3f 7182 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7180->7182 7181 18a52c75e4b 7201 18a52c75e88 7181->7201 7182->7184 7186 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7187 18a52c75e72 7186->7187 7188 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7187->7188 7188->7184 7191 18a52c795ff 7189->7191 7190 18a52c75e37 7190->7180 7190->7181 7191->7190 7192 18a52c76ee4 RtlAllocateHeap 7191->7192 7193 18a52c7967b 7192->7193 7194 18a52c79683 7193->7194 7196 18a52c7968c 7193->7196 7195 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7194->7195 7195->7190 7197 18a52c796bd 7196->7197 7198 18a52c796b3 7196->7198 7200 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7197->7200 7199 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7198->7199 7199->7190 7200->7190 7202 18a52c75ead 7201->7202 7203 18a52c77afc __std_exception_copy RtlAllocateHeap 7202->7203 7214 18a52c75ee3 7203->7214 7204 18a52c75eeb 7205 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7204->7205 7206 18a52c75e53 7205->7206 7206->7186 7207 18a52c75f5e 7208 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7207->7208 7208->7206 7209 18a52c77afc __std_exception_copy RtlAllocateHeap 7209->7214 7210 18a52c75f4d 7218 18a52c75f98 7210->7218 7211 18a52c76bb4 __std_exception_copy RtlAllocateHeap 7211->7214 7214->7204 7214->7207 7214->7209 7214->7210 7214->7211 7215 18a52c75f83 _invalid_parameter_noinfo 7214->7215 7217 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7214->7217 7216 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7216->7204 7217->7214 7220 18a52c75f9d 7218->7220 7223 18a52c75f55 7218->7223 7219 18a52c75fc6 7222 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7219->7222 7220->7219 7221 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7220->7221 7221->7220 7222->7223 7223->7216 7483 18a52c7f3a6 7484 18a52c7f3be 7483->7484 7490 18a52c7f429 7483->7490 7485 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7484->7485 7484->7490 7486 18a52c7f40b 7485->7486 7487 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7486->7487 7488 18a52c7f420 7487->7488 7489 18a52c76b88 RtlAllocateHeap 7488->7489 7489->7490 6697 18a52c74f1c 6698 18a52c75758 6697->6698 6699 18a52c7576f 6698->6699 6700 18a52c75828 __std_exception_destroy RtlAllocateHeap 6698->6700 6700->6699 6496 18a52c71ca4 6513 18a52c71e68 6496->6513 6498 18a52c71cb8 __scrt_get_show_window_mode __scrt_acquire_startup_lock __scrt_release_startup_lock 6498->6496 6501 18a52c71d03 6498->6501 6502 18a52c71ae0 6498->6502 6517 18a52c76060 6498->6517 6522 18a52c72a30 6502->6522 6504 18a52c71aff GetComputerNameA 6506 18a52c71b27 6504->6506 6505 18a52c71b6b CreateMutexExA 6507 18a52c71b80 6505->6507 6506->6505 6506->6506 6508 18a52c71baa 6507->6508 6524 18a52c71770 6507->6524 6508->6498 6510 18a52c71b8c 6539 18a52c712c0 RegOpenKeyExA 6510->6539 6512 18a52c71b91 MessageBoxA 6512->6508 6563 18a52c7246c 6513->6563 6516 18a52c71e93 __scrt_initialize_crt 6516->6498 6565 18a52c79084 6517->6565 6519 18a52c760b5 6519->6498 6520 18a52c7606f 6520->6519 6571 18a52c79434 6520->6571 6523 18a52c72a10 6522->6523 6523->6504 6523->6523 6525 18a52c71794 __scrt_get_show_window_mode 6524->6525 6526 18a52c717fc FindFirstFileA 6525->6526 6527 18a52c71aa9 6526->6527 6529 18a52c7181a __scrt_get_show_window_mode 6526->6529 6527->6510 6528 18a52c718e2 6528->6510 6529->6528 6531 18a52c71992 6529->6531 6551 18a52c75828 6529->6551 6532 18a52c75828 __std_exception_destroy RtlAllocateHeap 6531->6532 6533 18a52c71a29 6531->6533 6532->6533 6533->6527 6534 18a52c75828 __std_exception_destroy RtlAllocateHeap 6533->6534 6535 18a52c71a95 6534->6535 6536 18a52c75828 __std_exception_destroy RtlAllocateHeap 6535->6536 6537 18a52c71a9d 6536->6537 6555 18a52c71240 6537->6555 6546 18a52c7173e 6539->6546 6550 18a52c71300 __scrt_get_show_window_mode 6539->6550 6540 18a52c71351 6540->6512 6541 18a52c7171a 6543 18a52c71736 6541->6543 6544 18a52c71240 RtlAllocateHeap 6541->6544 6542 18a52c713d4 RegEnumKeyExA 6542->6550 6545 18a52c75828 __std_exception_destroy RtlAllocateHeap 6543->6545 6544->6543 6545->6546 6546->6512 6547 18a52c71451 RegOpenKeyExA 6547->6546 6547->6550 6548 18a52c71701 RegCloseKey 6548->6550 6549 18a52c7154d RegEnumValueA 6549->6550 6550->6540 6550->6541 6550->6542 6550->6547 6550->6548 6550->6549 6553 18a52c76ea8 __free_lconv_mon 6551->6553 6552 18a52c76ede 6552->6531 6553->6552 6554 18a52c77adc __std_exception_copy RtlAllocateHeap 6553->6554 6554->6552 6556 18a52c71260 6555->6556 6558 18a52c71297 6556->6558 6559 18a52c71000 6556->6559 6558->6527 6561 18a52c71048 6559->6561 6560 18a52c711b4 6560->6556 6561->6560 6562 18a52c75828 __std_exception_destroy RtlAllocateHeap 6561->6562 6562->6560 6564 18a52c71e8a __scrt_dllmain_crt_thread_attach 6563->6564 6564->6516 6566 18a52c79091 6565->6566 6567 18a52c790d6 6565->6567 6575 18a52c77390 6566->6575 6567->6520 6569 18a52c790c0 6586 18a52c78d5c 6569->6586 6572 18a52c793c0 6571->6572 6573 18a52c785a8 RtlAllocateHeap 6572->6573 6574 18a52c793e4 6573->6574 6574->6520 6576 18a52c773a1 __std_exception_copy 6575->6576 6577 18a52c77afc __std_exception_copy RtlAllocateHeap 6576->6577 6578 18a52c773ae 6576->6578 6579 18a52c773d8 __std_exception_copy 6577->6579 6578->6569 6580 18a52c77414 6579->6580 6581 18a52c773e6 __std_exception_copy 6579->6581 6583 18a52c7706c __std_exception_copy RtlAllocateHeap 6580->6583 6582 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6581->6582 6582->6578 6584 18a52c7741c 6583->6584 6585 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6584->6585 6585->6578 6609 18a52c78fcc 6586->6609 6591 18a52c78dae 6591->6567 6594 18a52c78dc7 6595 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6594->6595 6595->6591 6596 18a52c78dd6 6596->6596 6624 18a52c79100 6596->6624 6598 18a52c78ec9 6599 18a52c78ed2 6598->6599 6605 18a52c78eec 6598->6605 6600 18a52c77adc __std_exception_copy RtlAllocateHeap 6599->6600 6601 18a52c78ed7 6600->6601 6604 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6601->6604 6602 18a52c78f2d 6603 18a52c78f94 6602->6603 6629 18a52c7888c 6602->6629 6608 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6603->6608 6604->6591 6605->6602 6606 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6605->6606 6606->6602 6608->6591 6611 18a52c78fef Concurrency::details::SchedulerProxy::DeleteThis 6609->6611 6610 18a52c78ff9 Concurrency::details::SchedulerProxy::DeleteThis 6612 18a52c78d91 6610->6612 6614 18a52c77390 RtlAllocateHeap 6610->6614 6611->6610 6613 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6611->6613 6617 18a52c78a5c 6612->6617 6613->6610 6615 18a52c790c0 6614->6615 6616 18a52c78d5c RtlAllocateHeap 6615->6616 6616->6612 6641 18a52c785a8 6617->6641 6619 18a52c78a70 6619->6591 6620 18a52c76ee4 6619->6620 6623 18a52c76ef3 __std_exception_copy 6620->6623 6621 18a52c77adc __std_exception_copy RtlAllocateHeap 6622 18a52c76f2d 6621->6622 6622->6594 6622->6596 6623->6621 6623->6622 6625 18a52c78a5c RtlAllocateHeap 6624->6625 6628 18a52c7912d __scrt_get_show_window_mode 6625->6628 6626 18a52c79283 _log10_special 6626->6598 6628->6626 6660 18a52c78b74 6628->6660 6630 18a52c788a8 Concurrency::details::SchedulerProxy::DeleteThis __scrt_get_show_window_mode 6629->6630 6631 18a52c77adc __std_exception_copy RtlAllocateHeap 6630->6631 6634 18a52c788d5 __scrt_get_show_window_mode 6630->6634 6632 18a52c78944 6631->6632 6669 18a52c779a0 6632->6669 6635 18a52c77adc __std_exception_copy RtlAllocateHeap 6634->6635 6639 18a52c78987 6634->6639 6636 18a52c789e5 6635->6636 6637 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 6636->6637 6637->6639 6638 18a52c78a21 Concurrency::details::SchedulerProxy::DeleteThis 6638->6603 6639->6638 6640 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6639->6640 6640->6638 6642 18a52c785cc 6641->6642 6643 18a52c785c7 6641->6643 6642->6643 6644 18a52c772bc RtlAllocateHeap 6642->6644 6643->6619 6645 18a52c785e7 6644->6645 6647 18a52c7b4b8 6645->6647 6648 18a52c7b4e0 6647->6648 6649 18a52c7b4cd 6647->6649 6648->6643 6649->6648 6651 18a52c7a538 6649->6651 6652 18a52c772bc RtlAllocateHeap 6651->6652 6653 18a52c7a547 Concurrency::details::SchedulerProxy::DeleteThis 6652->6653 6655 18a52c7a580 Concurrency::details::SchedulerProxy::DeleteThis 6653->6655 6656 18a52c7a5a8 6653->6656 6655->6648 6657 18a52c7a5c7 6656->6657 6658 18a52c7a5ba Concurrency::details::SchedulerProxy::DeleteThis 6656->6658 6657->6655 6658->6657 6659 18a52c7a290 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6658->6659 6659->6657 6661 18a52c78ca7 _log10_special 6660->6661 6662 18a52c78bb1 6660->6662 6661->6626 6662->6661 6666 18a52c7c468 6662->6666 6664 18a52c78c6e 6665 18a52c7c468 RtlAllocateHeap 6664->6665 6665->6661 6667 18a52c785a8 RtlAllocateHeap 6666->6667 6668 18a52c7c48d 6667->6668 6668->6664 6672 18a52c77838 6669->6672 6671 18a52c779b9 6671->6634 6673 18a52c77863 6672->6673 6676 18a52c778d4 6673->6676 6675 18a52c7788a 6675->6671 6682 18a52c7761c 6676->6682 6678 18a52c778fe _invalid_parameter_noinfo 6679 18a52c7790f 6678->6679 6680 18a52c77838 _invalid_parameter_noinfo RtlAllocateHeap 6678->6680 6679->6675 6681 18a52c779b9 6680->6681 6681->6675 6683 18a52c77663 6682->6683 6684 18a52c77638 6682->6684 6683->6678 6686 18a52c774fc 6684->6686 6687 18a52c7751b __std_exception_copy 6686->6687 6688 18a52c77528 6687->6688 6689 18a52c77afc __std_exception_copy RtlAllocateHeap 6687->6689 6688->6683 6690 18a52c77552 __std_exception_copy 6689->6690 6691 18a52c7758e 6690->6691 6692 18a52c77560 __std_exception_copy 6690->6692 6694 18a52c7706c __std_exception_copy RtlAllocateHeap 6691->6694 6693 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6692->6693 6693->6688 6695 18a52c77596 6694->6695 6696 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6695->6696 6696->6688 6950 6d7eade0 RtlCaptureContext RtlLookupFunctionEntry 6951 6d7eaebd 6950->6951 6952 6d7eae1a RtlVirtualUnwind 6950->6952 6953 6d7eae53 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess abort 6951->6953 6952->6953 6953->6951 7491 18a52c7f5a0 7492 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7491->7492 7493 18a52c7f5ae 7492->7493 7494 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7493->7494 7495 18a52c7f5b9 7493->7495 7494->7495 7496 6d7eaee0 7497 6d7eaee9 7496->7497 7498 6d7eaeed 7497->7498 7499 6d7eba60 3 API calls 7497->7499 7500 6d7eaf05 7499->7500 7501 6d7eb6e0 7506 6d7eb701 7501->7506 7502 6d7eb830 signal 7505 6d7eb846 signal 7502->7505 7508 6d7eb748 7502->7508 7503 6d7eb78b signal 7504 6d7eb880 signal 7503->7504 7503->7508 7507 6d7eb7a6 7504->7507 7505->7507 7506->7503 7506->7507 7506->7508 7510 6d7eb732 signal 7506->7510 7508->7502 7508->7503 7508->7507 7509 6d7eb7e7 signal 7508->7509 7509->7508 7511 6d7eb8b0 signal 7509->7511 7510->7508 7512 6d7eb899 signal 7510->7512 7511->7507 7512->7507 6701 18a52c7b322 6702 18a52c7b34e 6701->6702 6703 18a52c77afc __std_exception_copy RtlAllocateHeap 6702->6703 6704 18a52c7b36d 6703->6704 6705 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6704->6705 6706 18a52c7b37b 6705->6706 6707 18a52c77afc __std_exception_copy RtlAllocateHeap 6706->6707 6710 18a52c7b3a5 6706->6710 6708 18a52c7b397 6707->6708 6709 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6708->6709 6709->6710 6711 18a52c74f30 6714 18a52c75758 6711->6714 6713 18a52c74f52 6715 18a52c7576f 6714->6715 6716 18a52c75767 6714->6716 6715->6713 6717 18a52c75828 __std_exception_destroy RtlAllocateHeap 6716->6717 6717->6715 6718 18a52c7b730 6719 18a52c7b75d 6718->6719 6720 18a52c77adc __std_exception_copy RtlAllocateHeap 6719->6720 6723 18a52c7b772 _log10_special 6719->6723 6721 18a52c7b767 6720->6721 6722 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 6721->6722 6722->6723 6724 18a52c7652c 6727 18a52c764b0 6724->6727 6726 18a52c76555 6728 18a52c764ce Concurrency::details::SchedulerProxy::DeleteThis 6727->6728 6729 18a52c76507 Concurrency::details::SchedulerProxy::DeleteThis 6728->6729 6730 18a52c7a5a8 RtlAllocateHeap 6728->6730 6729->6726 6730->6728 7224 18a52c7ae39 7225 18a52c77adc __std_exception_copy RtlAllocateHeap 7224->7225 7226 18a52c7ae3e 7225->7226 7227 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 7226->7227 7228 18a52c7adf4 7227->7228 6954 6d7ec1d1 RtlCaptureContext 6731 18a52c7bb40 6735 18a52c7bb5d 6731->6735 6732 18a52c7bb62 6733 18a52c7bb78 6732->6733 6734 18a52c77adc __std_exception_copy RtlAllocateHeap 6732->6734 6736 18a52c7bb6c 6734->6736 6735->6732 6735->6733 6738 18a52c7bbac 6735->6738 6737 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 6736->6737 6737->6733 6738->6733 6739 18a52c77adc __std_exception_copy RtlAllocateHeap 6738->6739 6739->6736 7513 18a52c71bc0 7514 18a52c71bd0 7513->7514 7523 18a52c76470 7514->7523 7516 18a52c71bdc _RTC_Initialize 7522 18a52c71c49 7516->7522 7529 18a52c72064 7516->7529 7518 18a52c71c09 7532 18a52c75c8c 7518->7532 7520 18a52c71c15 7520->7522 7561 18a52c7655c 7520->7561 7524 18a52c76481 7523->7524 7525 18a52c77adc __std_exception_copy RtlAllocateHeap 7524->7525 7528 18a52c76489 7524->7528 7526 18a52c76498 7525->7526 7527 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 7526->7527 7527->7528 7528->7516 7568 18a52c72028 7529->7568 7531 18a52c7206d 7531->7518 7533 18a52c75cac 7532->7533 7560 18a52c75cc3 7532->7560 7534 18a52c75cca 7533->7534 7535 18a52c75cb4 7533->7535 7537 18a52c79084 RtlAllocateHeap 7534->7537 7536 18a52c77adc __std_exception_copy RtlAllocateHeap 7535->7536 7538 18a52c75cb9 7536->7538 7539 18a52c75ccf 7537->7539 7540 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 7538->7540 7614 18a52c78768 7539->7614 7540->7560 7542 18a52c75ce6 7623 18a52c75a64 7542->7623 7544 18a52c75d23 7545 18a52c75d41 7544->7545 7546 18a52c75d59 7544->7546 7547 18a52c77adc __std_exception_copy RtlAllocateHeap 7545->7547 7548 18a52c75a64 RtlAllocateHeap 7546->7548 7549 18a52c75d46 7547->7549 7553 18a52c75d75 7548->7553 7550 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7549->7550 7550->7560 7551 18a52c75d7b 7552 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7551->7552 7552->7560 7553->7551 7554 18a52c75dc0 7553->7554 7555 18a52c75da7 7553->7555 7557 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7554->7557 7556 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7555->7556 7558 18a52c75db0 7556->7558 7557->7551 7559 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7558->7559 7559->7560 7560->7520 7562 18a52c772bc RtlAllocateHeap 7561->7562 7563 18a52c76569 7562->7563 7564 18a52c7659d 7563->7564 7565 18a52c77adc __std_exception_copy RtlAllocateHeap 7563->7565 7564->7522 7566 18a52c76592 7565->7566 7567 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 7566->7567 7567->7564 7569 18a52c72042 7568->7569 7571 18a52c7203b 7568->7571 7572 18a52c769c8 7569->7572 7571->7531 7575 18a52c76604 7572->7575 7574 18a52c76a0a 7574->7571 7576 18a52c76620 Concurrency::details::SchedulerProxy::DeleteThis 7575->7576 7579 18a52c7667c 7576->7579 7578 18a52c76629 Concurrency::details::SchedulerProxy::DeleteThis 7578->7574 7580 18a52c766a8 7579->7580 7588 18a52c7673d 7579->7588 7581 18a52c76719 7580->7581 7580->7588 7589 18a52c7aaac 7580->7589 7583 18a52c7aaac RtlAllocateHeap 7581->7583 7581->7588 7585 18a52c76733 7583->7585 7584 18a52c7670f 7587 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7584->7587 7586 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7585->7586 7586->7588 7587->7581 7588->7578 7590 18a52c7aace 7589->7590 7591 18a52c7aaeb 7589->7591 7590->7591 7593 18a52c7aadc 7590->7593 7592 18a52c7aaf5 7591->7592 7598 18a52c7c608 7591->7598 7605 18a52c76e2c 7592->7605 7595 18a52c77adc __std_exception_copy RtlAllocateHeap 7593->7595 7597 18a52c7aae1 __scrt_get_show_window_mode 7595->7597 7597->7584 7599 18a52c7c611 7598->7599 7600 18a52c7c62a 7598->7600 7601 18a52c77adc __std_exception_copy RtlAllocateHeap 7599->7601 7602 18a52c7c616 7601->7602 7603 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 7602->7603 7604 18a52c7c621 7603->7604 7604->7592 7606 18a52c76e41 7605->7606 7607 18a52c76e4b 7605->7607 7608 18a52c76ee4 RtlAllocateHeap 7606->7608 7609 18a52c76e50 7607->7609 7613 18a52c76e57 __std_exception_copy 7607->7613 7612 18a52c76e49 7608->7612 7610 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7609->7610 7610->7612 7611 18a52c77adc __std_exception_copy RtlAllocateHeap 7611->7612 7612->7597 7613->7611 7613->7612 7615 18a52c787a9 7614->7615 7616 18a52c787c1 7615->7616 7617 18a52c787ad 7615->7617 7618 18a52c785a8 RtlAllocateHeap 7616->7618 7619 18a52c77a50 RtlAllocateHeap 7617->7619 7620 18a52c787ef 7618->7620 7622 18a52c787ba _log10_special 7619->7622 7629 18a52c7864c 7620->7629 7622->7542 7625 18a52c75aa2 7623->7625 7624 18a52c79434 RtlAllocateHeap 7624->7625 7625->7624 7627 18a52c75b0e 7625->7627 7626 18a52c75bff 7626->7544 7627->7626 7628 18a52c79434 RtlAllocateHeap 7627->7628 7628->7627 7630 18a52c7868b 7629->7630 7632 18a52c78670 7629->7632 7633 18a52c786ee 7630->7633 7634 18a52c78690 7630->7634 7631 18a52c77adc __std_exception_copy RtlAllocateHeap 7631->7632 7632->7622 7633->7632 7635 18a52c77a50 RtlAllocateHeap 7633->7635 7634->7631 7634->7632 7636 18a52c786fb 7635->7636 7637 18a52c77adc __std_exception_copy RtlAllocateHeap 7636->7637 7637->7632 6740 18a52c7713c 6741 18a52c77141 6740->6741 6745 18a52c77156 6740->6745 6746 18a52c7715c 6741->6746 6744 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6744->6745 6747 18a52c7719e 6746->6747 6748 18a52c771a6 6746->6748 6749 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6747->6749 6750 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6748->6750 6749->6748 6751 18a52c771b3 6750->6751 6752 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6751->6752 6753 18a52c771c0 6752->6753 6754 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6753->6754 6755 18a52c771cd 6754->6755 6756 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6755->6756 6757 18a52c771da 6756->6757 6758 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6757->6758 6759 18a52c771e7 6758->6759 6760 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6759->6760 6761 18a52c771f4 6760->6761 6762 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6761->6762 6763 18a52c77201 6762->6763 6764 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6763->6764 6765 18a52c77211 6764->6765 6766 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6765->6766 6767 18a52c77221 6766->6767 6772 18a52c7700c 6767->6772 6769 18a52c77236 6776 18a52c76f84 6769->6776 6771 18a52c7714e 6771->6744 6773 18a52c77028 Concurrency::details::SchedulerProxy::DeleteThis 6772->6773 6774 18a52c77058 Concurrency::details::SchedulerProxy::DeleteThis 6773->6774 6775 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6773->6775 6774->6769 6775->6774 6777 18a52c76fa0 Concurrency::details::SchedulerProxy::DeleteThis 6776->6777 6778 18a52c77254 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6777->6778 6779 18a52c76fae Concurrency::details::SchedulerProxy::DeleteThis 6778->6779 6779->6771 7229 18a52c72e3c 7230 18a52c72e56 7229->7230 7231 18a52c72e45 7229->7231 7231->7230 7232 18a52c75828 __std_exception_destroy RtlAllocateHeap 7231->7232 7232->7230 7638 18a52c775bc 7639 18a52c775cc 7638->7639 7640 18a52c77434 __std_exception_copy RtlAllocateHeap 7639->7640 7641 18a52c775d7 __vcrt_uninitialize_ptd 7639->7641 7640->7641 7233 18a52c75c3a 7235 18a52c75c3c 7233->7235 7234 18a52c75c7c 7235->7234 7236 18a52c77afc __std_exception_copy RtlAllocateHeap 7235->7236 7237 18a52c75c72 7236->7237 7238 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7237->7238 7238->7234 6780 18a52c79d44 6781 18a52c79d54 Concurrency::details::SchedulerProxy::DeleteThis 6780->6781 6786 18a52c79904 6781->6786 6783 18a52c79d5d 6785 18a52c79d66 Concurrency::details::SchedulerProxy::DeleteThis 6783->6785 6794 18a52c79b4c 6783->6794 6787 18a52c79923 6786->6787 6793 18a52c7994c Concurrency::details::SchedulerProxy::DeleteThis 6786->6793 6788 18a52c77adc __std_exception_copy RtlAllocateHeap 6787->6788 6789 18a52c79928 6788->6789 6790 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 6789->6790 6791 18a52c79934 Concurrency::details::SchedulerProxy::DeleteThis 6790->6791 6791->6783 6793->6791 6798 18a52c7980c 6793->6798 6795 18a52c79b72 6794->6795 6796 18a52c79904 RtlAllocateHeap 6795->6796 6797 18a52c79baa 6795->6797 6796->6797 6797->6785 6799 18a52c77afc __std_exception_copy RtlAllocateHeap 6798->6799 6802 18a52c7982d 6799->6802 6800 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6801 18a52c79899 6800->6801 6801->6793 6802->6800 7248 18a52c7b444 7249 18a52c7b44f 7248->7249 7256 18a52c7d394 7249->7256 7252 18a52c7b454 7253 18a52c7b485 7252->7253 7261 18a52c7d448 7252->7261 7254 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7253->7254 7255 18a52c7b491 7254->7255 7259 18a52c7d3ad Concurrency::details::SchedulerProxy::DeleteThis 7256->7259 7257 18a52c7d42d Concurrency::details::SchedulerProxy::DeleteThis 7257->7252 7259->7257 7260 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7259->7260 7265 18a52c7d900 7259->7265 7260->7259 7262 18a52c7d470 7261->7262 7263 18a52c7d45c 7261->7263 7262->7252 7263->7262 7264 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7263->7264 7264->7262 7266 18a52c7d930 7265->7266 7269 18a52c7d7dc 7266->7269 7268 18a52c7d949 7268->7259 7270 18a52c7d7f7 7269->7270 7272 18a52c7d825 7269->7272 7271 18a52c778d4 _invalid_parameter_noinfo RtlAllocateHeap 7270->7271 7274 18a52c7d817 7271->7274 7272->7274 7275 18a52c7d858 7272->7275 7274->7268 7276 18a52c7d873 7275->7276 7277 18a52c7d898 7275->7277 7278 18a52c778d4 _invalid_parameter_noinfo RtlAllocateHeap 7276->7278 7287 18a52c7d893 7277->7287 7289 18a52c7b1bc 7277->7289 7278->7287 7281 18a52c7d448 RtlAllocateHeap 7282 18a52c7d8b5 7281->7282 7295 18a52c7b708 7282->7295 7287->7274 7288 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7288->7287 7290 18a52c7b1e2 7289->7290 7294 18a52c7b213 7289->7294 7291 18a52c7b708 RtlAllocateHeap 7290->7291 7290->7294 7292 18a52c7b203 7291->7292 7308 18a52c7cf6c 7292->7308 7294->7281 7296 18a52c7b711 7295->7296 7297 18a52c7b721 7295->7297 7298 18a52c77adc __std_exception_copy RtlAllocateHeap 7296->7298 7301 18a52c7e2ec 7297->7301 7299 18a52c7b716 7298->7299 7300 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 7299->7300 7300->7297 7303 18a52c7e318 7301->7303 7307 18a52c7d8c7 7301->7307 7302 18a52c7e37c 7304 18a52c778d4 _invalid_parameter_noinfo RtlAllocateHeap 7302->7304 7303->7302 7305 18a52c7e348 7303->7305 7304->7307 7312 18a52c7e274 7305->7312 7307->7287 7307->7288 7309 18a52c7cf95 7308->7309 7310 18a52c7cfc2 7308->7310 7309->7294 7310->7309 7311 18a52c778d4 _invalid_parameter_noinfo RtlAllocateHeap 7310->7311 7311->7309 7313 18a52c7e290 7312->7313 7315 18a52c7e2c5 7313->7315 7316 18a52c7e3b0 7313->7316 7315->7307 7327 18a52c79ab8 7316->7327 7318 18a52c7e3d2 7339 18a52c799fc 7318->7339 7321 18a52c7e40f 7321->7318 7322 18a52c79ab8 RtlAllocateHeap 7321->7322 7322->7318 7323 18a52c79ab8 RtlAllocateHeap 7324 18a52c7e402 7323->7324 7325 18a52c79ab8 RtlAllocateHeap 7324->7325 7325->7321 7326 18a52c7e437 7326->7315 7328 18a52c79ac1 7327->7328 7329 18a52c79ad6 7327->7329 7345 18a52c77abc 7328->7345 7332 18a52c77abc RtlAllocateHeap 7329->7332 7335 18a52c79ace 7329->7335 7334 18a52c79b11 7332->7334 7333 18a52c77adc __std_exception_copy RtlAllocateHeap 7333->7335 7336 18a52c77adc __std_exception_copy RtlAllocateHeap 7334->7336 7335->7318 7335->7321 7335->7323 7337 18a52c79b19 7336->7337 7338 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 7337->7338 7338->7335 7340 18a52c79a18 7339->7340 7341 18a52c77adc __std_exception_copy RtlAllocateHeap 7340->7341 7344 18a52c79a4b 7340->7344 7342 18a52c79a8f 7341->7342 7343 18a52c77abc RtlAllocateHeap 7342->7343 7343->7344 7344->7326 7346 18a52c77434 __std_exception_copy RtlAllocateHeap 7345->7346 7347 18a52c77ac5 7346->7347 7347->7333 6955 6d7eb9c0 6956 6d7eb9e0 EnterCriticalSection 6955->6956 6957 6d7eb9d1 6955->6957 6958 6d7eba13 LeaveCriticalSection 6956->6958 6960 6d7eb9f9 6956->6960 6959 6d7eba20 6958->6959 6960->6958 6961 6d7eb9ff free LeaveCriticalSection 6960->6961 6961->6959 6963 6d7ec1c1 RtlVirtualUnwind 6964 18a52c74c4c 6965 18a52c74c79 __except_validate_context_record 6964->6965 6966 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6965->6966 6967 18a52c74c7e 6966->6967 6969 18a52c74d66 6967->6969 6971 18a52c74cd8 6967->6971 6979 18a52c74d2c 6967->6979 6968 18a52c74d85 6978 18a52c74dd4 6968->6978 6968->6979 7002 18a52c73800 6968->7002 6969->6968 6999 18a52c737ec 6969->6999 6972 18a52c74d53 6971->6972 6977 18a52c74cfa __GetCurrentState 6971->6977 6971->6979 6993 18a52c733e8 6972->6993 6975 18a52c74e7d 6977->6975 6981 18a52c751e8 6977->6981 6978->6979 7005 18a52c74418 6978->7005 6982 18a52c737ec Is_bad_exception_allowed RtlAllocateHeap 6981->6982 6983 18a52c75217 __GetCurrentState 6982->6983 6984 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6983->6984 6991 18a52c75234 __CxxCallCatchBlock __FrameHandler3::GetHandlerSearchState 6984->6991 6985 18a52c7532b 6986 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6985->6986 6987 18a52c75330 6986->6987 6988 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6987->6988 6989 18a52c7533b __FrameHandler3::GetHandlerSearchState 6987->6989 6988->6989 6989->6979 6990 18a52c737ec RtlAllocateHeap Is_bad_exception_allowed 6990->6991 6991->6985 6991->6989 6991->6990 6992 18a52c73814 __FrameHandler3::FrameUnwindToEmptyState RtlAllocateHeap 6991->6992 6992->6991 6994 18a52c73407 __FrameHandler3::GetHandlerSearchState 6993->6994 7052 18a52c73358 6994->7052 6997 18a52c751e8 __FrameHandler3::FrameUnwindToEmptyState RtlAllocateHeap 6998 18a52c7343c 6997->6998 6998->6979 7000 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6999->7000 7001 18a52c737f5 7000->7001 7001->6968 7003 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7002->7003 7004 18a52c73809 7003->7004 7004->6978 7007 18a52c7447a __FrameHandler3::GetHandlerSearchState 7005->7007 7006 18a52c74837 7015 18a52c74879 _log10_special 7006->7015 7037 18a52c747df __FrameHandler3::GetHandlerSearchState 7006->7037 7092 18a52c748f0 7006->7092 7010 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7007->7010 7007->7015 7047 18a52c7455f 7007->7047 7008 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7008->7015 7009 18a52c74768 7013 18a52c74785 7009->7013 7016 18a52c737ec Is_bad_exception_allowed RtlAllocateHeap 7009->7016 7009->7037 7012 18a52c744c6 7010->7012 7014 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7012->7014 7012->7015 7019 18a52c747a7 7013->7019 7013->7037 7088 18a52c733bc 7013->7088 7018 18a52c744d6 7014->7018 7015->6979 7016->7013 7020 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7018->7020 7021 18a52c747bd 7019->7021 7022 18a52c748c9 7019->7022 7019->7037 7023 18a52c744df 7020->7023 7024 18a52c747c8 7021->7024 7027 18a52c737ec Is_bad_exception_allowed RtlAllocateHeap 7021->7027 7025 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7022->7025 7056 18a52c7382c 7023->7056 7032 18a52c7540c RtlAllocateHeap 7024->7032 7029 18a52c748cf 7025->7029 7027->7024 7028 18a52c73800 RtlAllocateHeap 7043 18a52c74597 7028->7043 7031 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7029->7031 7033 18a52c748d8 7031->7033 7032->7037 7035 18a52c76b88 RtlAllocateHeap 7033->7035 7034 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7036 18a52c74521 7034->7036 7035->7015 7038 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7036->7038 7036->7047 7037->7008 7039 18a52c7452d 7038->7039 7040 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7039->7040 7042 18a52c74536 7040->7042 7059 18a52c7540c 7042->7059 7043->7009 7043->7028 7070 18a52c74b0c 7043->7070 7084 18a52c74344 7043->7084 7047->7006 7047->7043 7048 18a52c7454a 7066 18a52c754fc 7048->7066 7050 18a52c76b88 RtlAllocateHeap 7050->7022 7051 18a52c74552 __CxxCallCatchBlock std::bad_alloc::bad_alloc 7051->7050 7055 18a52c73376 7052->7055 7053 18a52c733a3 7053->6997 7054 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7054->7055 7055->7053 7055->7054 7057 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7056->7057 7058 18a52c7383a 7057->7058 7058->7015 7058->7034 7060 18a52c754f3 7059->7060 7065 18a52c75437 7059->7065 7061 18a52c74546 7061->7047 7061->7048 7062 18a52c73800 RtlAllocateHeap 7062->7065 7063 18a52c737ec Is_bad_exception_allowed RtlAllocateHeap 7063->7065 7064 18a52c74b0c RtlAllocateHeap 7064->7065 7065->7061 7065->7062 7065->7063 7065->7064 7067 18a52c75569 7066->7067 7069 18a52c75519 Is_bad_exception_allowed 7066->7069 7067->7051 7068 18a52c737ec RtlAllocateHeap Is_bad_exception_allowed 7068->7069 7069->7067 7069->7068 7071 18a52c74b39 7070->7071 7082 18a52c74bc8 7070->7082 7072 18a52c737ec Is_bad_exception_allowed RtlAllocateHeap 7071->7072 7073 18a52c74b42 7072->7073 7074 18a52c737ec Is_bad_exception_allowed RtlAllocateHeap 7073->7074 7075 18a52c74b5b 7073->7075 7073->7082 7074->7075 7076 18a52c74b87 7075->7076 7077 18a52c737ec Is_bad_exception_allowed RtlAllocateHeap 7075->7077 7075->7082 7078 18a52c73800 RtlAllocateHeap 7076->7078 7077->7076 7079 18a52c74b9b 7078->7079 7080 18a52c74bb4 7079->7080 7081 18a52c737ec Is_bad_exception_allowed RtlAllocateHeap 7079->7081 7079->7082 7083 18a52c73800 RtlAllocateHeap 7080->7083 7081->7080 7082->7043 7083->7082 7085 18a52c74381 __FrameHandler3::GetHandlerSearchState 7084->7085 7086 18a52c737ec Is_bad_exception_allowed RtlAllocateHeap 7085->7086 7087 18a52c743b9 7086->7087 7087->7043 7089 18a52c733d0 __FrameHandler3::GetHandlerSearchState 7088->7089 7090 18a52c73358 __FrameHandler3::FrameUnwindToEmptyState RtlAllocateHeap 7089->7090 7091 18a52c733da 7090->7091 7091->7019 7093 18a52c74926 7092->7093 7096 18a52c74994 7092->7096 7094 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7093->7094 7095 18a52c7492b 7094->7095 7097 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7095->7097 7102 18a52c74990 7095->7102 7096->7037 7098 18a52c7494a 7097->7098 7098->7102 7103 18a52c73304 7098->7103 7100 18a52c737ec RtlAllocateHeap Is_bad_exception_allowed 7100->7102 7101 18a52c74344 RtlAllocateHeap 7101->7102 7102->7096 7102->7100 7102->7101 7104 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7103->7104 7105 18a52c73330 7104->7105 7105->7102 6803 18a52c7f2d8 6805 18a52c7f2ed 6803->6805 6804 18a52c7f300 6805->6804 6812 18a52c72e5c 6805->6812 6807 18a52c7f310 6808 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6807->6808 6809 18a52c7f319 6808->6809 6810 18a52c76b88 RtlAllocateHeap 6809->6810 6811 18a52c7f322 6810->6811 6815 18a52c72e78 6812->6815 6814 18a52c72e65 6814->6807 6816 18a52c72e90 6815->6816 6817 18a52c72e97 ExFilterRethrow __vcrt_FlsSetValue 6815->6817 6816->6814 6817->6816 6818 18a52c75828 __std_exception_destroy RtlAllocateHeap 6817->6818 6818->6816 6315 18a52c76259 6323 18a52c76b88 6315->6323 6317 18a52c7615c RtlAllocateHeap 6318 18a52c7630b 6317->6318 6319 18a52c76312 6318->6319 6320 18a52c76328 ExitProcess 6318->6320 6321 18a52c76324 6320->6321 6322 18a52c7625e 6322->6317 6326 18a52c772bc 6323->6326 6325 18a52c76b91 6327 18a52c772d1 __std_exception_copy 6326->6327 6329 18a52c772ed 6327->6329 6337 18a52c77afc 6327->6337 6329->6325 6330 18a52c7731e __std_exception_copy 6331 18a52c7735a 6330->6331 6332 18a52c7732c __std_exception_copy 6330->6332 6345 18a52c7706c 6331->6345 6341 18a52c76ea8 6332->6341 6336 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6336->6329 6340 18a52c77b0d __std_exception_copy 6337->6340 6338 18a52c77b42 RtlAllocateHeap 6339 18a52c77b5c __std_exception_copy 6338->6339 6338->6340 6339->6330 6340->6338 6340->6339 6342 18a52c76ede 6341->6342 6343 18a52c76ead __free_lconv_mon 6341->6343 6342->6329 6343->6342 6349 18a52c77adc 6343->6349 6346 18a52c7711e __std_exception_copy 6345->6346 6363 18a52c76fc4 6346->6363 6348 18a52c77133 6348->6336 6352 18a52c77434 6349->6352 6353 18a52c77449 __std_exception_copy 6352->6353 6354 18a52c77afc __std_exception_copy RtlAllocateHeap 6353->6354 6360 18a52c77465 6353->6360 6355 18a52c77496 __std_exception_copy 6354->6355 6356 18a52c774d2 6355->6356 6357 18a52c774a4 __std_exception_copy 6355->6357 6359 18a52c7706c __std_exception_copy RtlAllocateHeap 6356->6359 6358 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6357->6358 6358->6360 6361 18a52c774da 6359->6361 6360->6342 6362 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6361->6362 6362->6360 6364 18a52c76fe0 Concurrency::details::SchedulerProxy::DeleteThis 6363->6364 6367 18a52c77254 6364->6367 6366 18a52c76ff6 Concurrency::details::SchedulerProxy::DeleteThis 6366->6348 6368 18a52c77270 Concurrency::details::SchedulerProxy::DeleteThis 6367->6368 6369 18a52c7729c Concurrency::details::SchedulerProxy::DeleteThis 6367->6369 6368->6369 6371 18a52c7a290 6368->6371 6369->6366 6372 18a52c7a32c 6371->6372 6375 18a52c7a2b3 6371->6375 6373 18a52c7a37f 6372->6373 6376 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6372->6376 6437 18a52c7a430 6373->6437 6375->6372 6377 18a52c7a2f2 6375->6377 6382 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6375->6382 6378 18a52c7a350 6376->6378 6379 18a52c7a314 6377->6379 6385 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6377->6385 6380 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6378->6380 6381 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6379->6381 6383 18a52c7a364 6380->6383 6387 18a52c7a320 6381->6387 6388 18a52c7a2e6 6382->6388 6384 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6383->6384 6389 18a52c7a373 6384->6389 6390 18a52c7a308 6385->6390 6386 18a52c7a3ea 6391 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6387->6391 6397 18a52c79dc0 6388->6397 6394 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6389->6394 6425 18a52c79ecc 6390->6425 6391->6372 6393 18a52c76ea8 RtlAllocateHeap __free_lconv_mon 6396 18a52c7a38b 6393->6396 6394->6373 6396->6386 6396->6393 6398 18a52c79ec4 6397->6398 6399 18a52c79dc9 6397->6399 6398->6377 6400 18a52c79de3 6399->6400 6401 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6399->6401 6402 18a52c79df5 6400->6402 6403 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6400->6403 6401->6400 6404 18a52c79e07 6402->6404 6405 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6402->6405 6403->6402 6406 18a52c79e19 6404->6406 6408 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6404->6408 6405->6404 6407 18a52c79e2b 6406->6407 6409 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6406->6409 6410 18a52c79e3d 6407->6410 6411 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6407->6411 6408->6406 6409->6407 6412 18a52c79e4f 6410->6412 6413 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6410->6413 6411->6410 6414 18a52c79e61 6412->6414 6415 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6412->6415 6413->6412 6416 18a52c79e73 6414->6416 6417 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6414->6417 6415->6414 6418 18a52c79e85 6416->6418 6419 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6416->6419 6417->6416 6420 18a52c79e9a 6418->6420 6421 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6418->6421 6419->6418 6422 18a52c79eaf 6420->6422 6423 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6420->6423 6421->6420 6422->6398 6424 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6422->6424 6423->6422 6424->6398 6426 18a52c79ed1 6425->6426 6435 18a52c79f32 6425->6435 6428 18a52c79eea 6426->6428 6429 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6426->6429 6427 18a52c79efc 6431 18a52c79f0e 6427->6431 6432 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6427->6432 6428->6427 6430 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6428->6430 6429->6428 6430->6427 6433 18a52c79f20 6431->6433 6434 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6431->6434 6432->6431 6433->6435 6436 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6433->6436 6434->6433 6435->6379 6436->6435 6438 18a52c7a461 6437->6438 6439 18a52c7a435 6437->6439 6438->6396 6439->6438 6443 18a52c79f6c 6439->6443 6442 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6442->6438 6444 18a52c79f75 6443->6444 6445 18a52c7a064 6443->6445 6479 18a52c79f38 6444->6479 6445->6442 6448 18a52c79f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6449 18a52c79f9e 6448->6449 6450 18a52c79f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6449->6450 6451 18a52c79fac 6450->6451 6452 18a52c79f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6451->6452 6453 18a52c79fba 6452->6453 6454 18a52c79f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6453->6454 6455 18a52c79fc9 6454->6455 6456 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6455->6456 6457 18a52c79fd5 6456->6457 6458 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6457->6458 6459 18a52c79fe1 6458->6459 6460 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6459->6460 6461 18a52c79fed 6460->6461 6462 18a52c79f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6461->6462 6463 18a52c79ffb 6462->6463 6464 18a52c79f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6463->6464 6465 18a52c7a009 6464->6465 6466 18a52c79f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6465->6466 6467 18a52c7a017 6466->6467 6468 18a52c79f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6467->6468 6469 18a52c7a025 6468->6469 6470 18a52c79f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6469->6470 6471 18a52c7a034 6470->6471 6472 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6471->6472 6473 18a52c7a040 6472->6473 6474 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6473->6474 6475 18a52c7a04c 6474->6475 6476 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6475->6476 6477 18a52c7a058 6476->6477 6478 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6477->6478 6478->6445 6480 18a52c79f5f 6479->6480 6481 18a52c79f4e 6479->6481 6480->6448 6481->6480 6482 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6481->6482 6482->6481 7106 18a52c78258 7107 18a52c782ba 7106->7107 7108 18a52c785a8 RtlAllocateHeap 7107->7108 7109 18a52c7833a 7108->7109 7116 18a52c77b88 7109->7116 7112 18a52c785a8 RtlAllocateHeap 7113 18a52c78431 7112->7113 7133 18a52c77d04 7113->7133 7115 18a52c7849d 7117 18a52c77bd6 7116->7117 7118 18a52c77bb2 7116->7118 7120 18a52c77bdb 7117->7120 7124 18a52c77c30 7117->7124 7119 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7118->7119 7132 18a52c77bc1 7118->7132 7119->7132 7121 18a52c77bf0 7120->7121 7122 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7120->7122 7120->7132 7123 18a52c76ee4 RtlAllocateHeap 7121->7123 7122->7121 7123->7132 7125 18a52c77c81 7124->7125 7127 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7124->7127 7130 18a52c77c53 7124->7130 7128 18a52c76ee4 RtlAllocateHeap 7125->7128 7127->7125 7128->7130 7130->7132 7150 18a52c77a50 7130->7150 7131 18a52c77adc __std_exception_copy RtlAllocateHeap 7131->7132 7132->7112 7134 18a52c77d2e 7133->7134 7135 18a52c77d52 7133->7135 7137 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7134->7137 7146 18a52c77d3d 7134->7146 7136 18a52c77d58 7135->7136 7139 18a52c77dac 7135->7139 7138 18a52c77d6d 7136->7138 7141 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7136->7141 7136->7146 7137->7146 7142 18a52c76ee4 RtlAllocateHeap 7138->7142 7140 18a52c77dd7 7139->7140 7144 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7139->7144 7148 18a52c77e08 7139->7148 7143 18a52c77a50 RtlAllocateHeap 7140->7143 7140->7146 7141->7138 7142->7146 7147 18a52c77de4 7143->7147 7144->7148 7145 18a52c76ee4 RtlAllocateHeap 7145->7140 7146->7115 7149 18a52c77adc __std_exception_copy RtlAllocateHeap 7147->7149 7148->7145 7149->7146 7151 18a52c77434 __std_exception_copy RtlAllocateHeap 7150->7151 7152 18a52c77a5d __free_lconv_mon 7151->7152 7153 18a52c77434 __std_exception_copy RtlAllocateHeap 7152->7153 7154 18a52c77a7f 7153->7154 7154->7131 6819 6d7eb935 6820 6d7eb959 6819->6820 6821 6d7eb964 calloc 6819->6821 6821->6820 6822 6d7eb97b EnterCriticalSection LeaveCriticalSection 6821->6822 6492 6d7c13b0 6494 6d7c13c6 6492->6494 6493 6d7c83ec VirtualAlloc 6493->6494 6494->6493 6495 6d7c5b9c 6494->6495 6823 6d7c1330 6824 6d7c1346 6823->6824 6829 6d7ead00 6824->6829 6826 6d7c1363 6833 6d7eb5f0 6826->6833 6830 6d7ead29 6829->6830 6831 6d7ead40 GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 6829->6831 6830->6826 6832 6d7ead9b 6831->6832 6832->6826 6834 6d7eb5ff 6833->6834 6835 6d7c1368 6834->6835 6839 6d7ebbd0 6834->6839 6837 6d7eb627 6837->6835 6838 6d7eb6c0 RtlAddFunctionTable 6837->6838 6838->6835 6841 6d7ebbdf 6839->6841 6840 6d7ebc50 6840->6837 6841->6840 6842 6d7ebc2e strncmp 6841->6842 6842->6841 6843 6d7ebc43 6842->6843 6843->6837 6844 18a52c76ae0 6845 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6844->6845 6846 18a52c76af0 6845->6846 6847 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6846->6847 6848 18a52c76b04 6847->6848 6849 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6848->6849 6850 18a52c76b18 6849->6850 6851 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 6850->6851 6852 18a52c76b2c 6851->6852 7348 18a52c75fdc 7349 18a52c75ff1 7348->7349 7350 18a52c75fec 7348->7350 7351 18a52c75f98 RtlAllocateHeap 7350->7351 7351->7349 6853 18a52c74ee8 6856 18a52c756c8 6853->6856 6857 18a52c756e9 6856->6857 6861 18a52c74f11 6856->6861 6860 18a52c7571e 6857->6860 6857->6861 6862 18a52c76bb4 6857->6862 6859 18a52c75828 __std_exception_destroy RtlAllocateHeap 6859->6861 6860->6859 6863 18a52c76bc1 6862->6863 6864 18a52c76bcb 6862->6864 6863->6864 6869 18a52c76be6 6863->6869 6865 18a52c77adc __std_exception_copy RtlAllocateHeap 6864->6865 6866 18a52c76bd2 6865->6866 6868 18a52c779a0 _invalid_parameter_noinfo RtlAllocateHeap 6866->6868 6867 18a52c76bde 6867->6860 6868->6867 6869->6867 6870 18a52c77adc __std_exception_copy RtlAllocateHeap 6869->6870 6870->6866 6871 18a52c7f4df 6874 18a52c75160 6871->6874 6875 18a52c751d0 6874->6875 6876 18a52c7517f 6874->6876 6876->6875 6877 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6876->6877 6877->6875 7642 18a52c7c764 7643 18a52c7c7e9 7642->7643 7646 18a52c7c800 7643->7646 7648 18a52c76cf0 7643->7648 7645 18a52c7cb2c _log10_special 7646->7645 7647 18a52c7b590 RtlAllocateHeap 7646->7647 7647->7646 7649 18a52c76d07 7648->7649 7652 18a52c7b4ec 7649->7652 7651 18a52c76d2f 7651->7646 7653 18a52c7b518 7652->7653 7654 18a52c7b505 7652->7654 7653->7651 7654->7653 7655 18a52c7a538 RtlAllocateHeap 7654->7655 7655->7653 7656 18a52c7e760 7659 18a52c7e780 7656->7659 7660 18a52c7e79a 7659->7660 7661 18a52c7e77b 7660->7661 7663 18a52c7e5c0 7660->7663 7664 18a52c7e600 _raise_exc _log10_special 7663->7664 7665 18a52c7e6a9 7664->7665 7667 18a52c7e679 7664->7667 7674 18a52c7ebb0 7665->7674 7670 18a52c7e49c 7667->7670 7669 18a52c7e6a7 _log10_special 7669->7661 7671 18a52c7e4e0 _log10_special 7670->7671 7672 18a52c7e4f5 7671->7672 7673 18a52c7ebb0 _log10_special RtlAllocateHeap 7671->7673 7672->7669 7673->7672 7675 18a52c7ebb9 7674->7675 7676 18a52c7ebd0 7674->7676 7678 18a52c77adc __std_exception_copy RtlAllocateHeap 7675->7678 7679 18a52c7ebc8 7675->7679 7677 18a52c77adc __std_exception_copy RtlAllocateHeap 7676->7677 7677->7679 7678->7679 7679->7669 7155 18a52c7506e 7156 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7155->7156 7157 18a52c7507b __CxxCallCatchBlock 7156->7157 7158 18a52c73798 __CxxCallCatchBlock RtlAllocateHeap 7157->7158 7161 18a52c750ee 7158->7161 7159 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7160 18a52c7512a 7159->7160 7162 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7160->7162 7163 18a52c72908 __CxxCallCatchBlock RtlAllocateHeap 7161->7163 7165 18a52c75117 __CxxCallCatchBlock 7161->7165 7164 18a52c75133 7162->7164 7163->7165 7165->7159 7352 18a52c729ec 7353 18a52c76b88 RtlAllocateHeap 7352->7353 7354 18a52c729f5 7353->7354 7680 18a52c7f16c 7681 18a52c7f1a8 7680->7681 7682 18a52c7f1d4 7681->7682 7684 18a52c73844 7681->7684 7685 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7684->7685 7686 18a52c7386e 7685->7686 7687 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7686->7687 7688 18a52c7387b 7687->7688 7689 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7688->7689 7690 18a52c73884 7689->7690 7690->7682 7691 18a52c74f74 7692 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7691->7692 7693 18a52c74fa9 7692->7693 7694 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7693->7694 7695 18a52c74fb7 __except_validate_context_record 7694->7695 7696 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7695->7696 7697 18a52c74ffb 7696->7697 7698 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7697->7698 7699 18a52c75004 7698->7699 7700 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7699->7700 7701 18a52c7500d 7700->7701 7714 18a52c7375c 7701->7714 7704 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7705 18a52c7503d __CxxCallCatchBlock 7704->7705 7706 18a52c73798 __CxxCallCatchBlock RtlAllocateHeap 7705->7706 7709 18a52c750ee 7706->7709 7707 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7708 18a52c7512a 7707->7708 7710 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7708->7710 7711 18a52c72908 __CxxCallCatchBlock RtlAllocateHeap 7709->7711 7713 18a52c75117 __CxxCallCatchBlock 7709->7713 7712 18a52c75133 7710->7712 7711->7713 7713->7707 7715 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7714->7715 7716 18a52c7376d 7715->7716 7717 18a52c73778 7716->7717 7718 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7716->7718 7719 18a52c72e5c ExFilterRethrow RtlAllocateHeap 7717->7719 7718->7717 7720 18a52c73789 7719->7720 7720->7704 7720->7705 6878 6d7eaf10 6879 6d7eaf22 6878->6879 6880 6d7eaf32 6879->6880 6883 6d7eba60 6879->6883 6882 6d7eaf77 6884 6d7ebb00 6883->6884 6887 6d7eba6e 6883->6887 6885 6d7ebb0a 6884->6885 6886 6d7ebb20 InitializeCriticalSection 6884->6886 6885->6882 6886->6885 6888 6d7ebad6 DeleteCriticalSection 6887->6888 6889 6d7ebac5 free 6887->6889 6890 6d7eba70 6887->6890 6888->6890 6889->6888 6889->6889 6890->6882 7721 18a52c79d80 7722 18a52c79d8c 7721->7722 7724 18a52c79db3 7722->7724 7725 18a52c798b4 7722->7725 7726 18a52c798b9 7725->7726 7727 18a52c798f4 7725->7727 7728 18a52c76ea8 __free_lconv_mon RtlAllocateHeap 7726->7728 7727->7722 7728->7727 6894 18a52c7f504 6903 18a52c73798 6894->6903 6896 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6898 18a52c7f56a 6896->6898 6899 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6898->6899 6901 18a52c7f57a 6899->6901 6902 18a52c7f556 __CxxCallCatchBlock 6902->6896 6904 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6903->6904 6905 18a52c737aa 6904->6905 6906 18a52c737e5 6905->6906 6907 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6905->6907 6908 18a52c737b5 6907->6908 6908->6906 6909 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6908->6909 6910 18a52c737d6 6909->6910 6910->6902 6911 18a52c72908 6910->6911 6912 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6911->6912 6913 18a52c72916 6912->6913 6913->6902 6311 18a52c77afc 6314 18a52c77b0d __std_exception_copy 6311->6314 6312 18a52c77b42 RtlAllocateHeap 6313 18a52c77b5c __std_exception_copy 6312->6313 6312->6314 6314->6312 6314->6313 6483 18a52c71c88 6491 18a52c72388 6483->6491 7166 6d7c1380 7167 6d7ec010 7166->7167 7168 6d7ec027 _lock 7167->7168 7169 6d7ec05b 7167->7169 7170 6d7ec037 7168->7170 7171 6d7ec044 _unlock 7170->7171 7172 6d7ec0c7 _unlock 7170->7172 7173 6d7ec085 7170->7173 7171->7169 7172->7169 7173->7171 7359 6d7c1200 7360 6d7c121f 7359->7360 7361 6d7c1273 7359->7361 7368 6d7c1258 7360->7368 7372 6d7eb190 7360->7372 7362 6d7eb190 19 API calls 7361->7362 7364 6d7c1278 7362->7364 7365 6d7c122e 7364->7365 7366 6d7c1010 5 API calls 7364->7366 7365->7368 7399 6d7c1010 7365->7399 7369 6d7c12ad 7366->7369 7369->7365 7369->7368 7371 6d7c12ca 7369->7371 7370 6d7c1010 5 API calls 7370->7368 7371->7368 7371->7370 7373 6d7eb1b2 7372->7373 7374 6d7eb1c3 7372->7374 7373->7365 7374->7373 7377 6d7eb230 7374->7377 7386 6d7eb303 7374->7386 7375 6d7eb42a 7379 6d7eb45d 7375->7379 7380 6d7eb4c0 7375->7380 7377->7373 7378 6d7eb287 7377->7378 7414 6d7eafc0 7377->7414 7378->7373 7390 6d7eb2b2 VirtualProtect 7378->7390 7384 6d7eb4df signal 7379->7384 7385 6d7eb464 7379->7385 7382 6d7eb4cb 7380->7382 7383 6d7eb580 7380->7383 7381 6d7eafc0 11 API calls 7381->7386 7387 6d7eb4cd 7382->7387 7392 6d7eb504 7382->7392 7389 6d7eb4f1 7383->7389 7394 6d7eb596 signal 7383->7394 7388 6d7eb560 signal 7384->7388 7384->7389 7385->7389 7391 6d7eb475 7385->7391 7385->7392 7386->7373 7386->7375 7386->7378 7386->7381 7387->7384 7387->7389 7388->7389 7389->7365 7390->7378 7391->7389 7396 6d7eb48b signal 7391->7396 7392->7389 7393 6d7eb512 signal 7392->7393 7395 6d7eb5b0 signal 7393->7395 7398 6d7eb4a1 7393->7398 7394->7398 7395->7398 7397 6d7eb5d0 signal 7396->7397 7396->7398 7397->7398 7398->7365 7400 6d7c1026 7399->7400 7406 6d7c10a0 7399->7406 7401 6d7c108b 7400->7401 7403 6d7c106a 7400->7403 7404 6d7c1052 Sleep 7400->7404 7401->7368 7402 6d7c1153 7402->7368 7407 6d7c107c _amsg_exit 7403->7407 7408 6d7c1165 7403->7408 7404->7400 7405 6d7c10ed 7412 6d7c11b0 _initterm 7405->7412 7413 6d7c110b 7405->7413 7406->7402 7406->7405 7409 6d7c10d9 Sleep 7406->7409 7407->7401 7443 6d7ec0e0 7408->7443 7409->7406 7412->7413 7413->7368 7415 6d7eb08e 7414->7415 7416 6d7eafe2 7414->7416 7415->7377 7415->7415 7416->7415 7417 6d7eb04c VirtualQuery 7416->7417 7430 6d7eb160 7416->7430 7418 6d7eb07a 7417->7418 7417->7430 7418->7415 7420 6d7eb0f0 VirtualProtect 7418->7420 7419 6d7eb1b2 7419->7377 7420->7415 7421 6d7eb120 GetLastError 7420->7421 7421->7415 7422 6d7eb42a 7424 6d7eb45d 7422->7424 7425 6d7eb4c0 7422->7425 7423 6d7eb230 7423->7419 7434 6d7eb2b2 VirtualProtect 7423->7434 7428 6d7eb4df signal 7424->7428 7429 6d7eb464 7424->7429 7426 6d7eb4cb 7425->7426 7427 6d7eb580 7425->7427 7431 6d7eb4cd 7426->7431 7436 6d7eb504 7426->7436 7433 6d7eb4f1 7427->7433 7438 6d7eb596 signal 7427->7438 7432 6d7eb560 signal 7428->7432 7428->7433 7429->7433 7435 6d7eb475 7429->7435 7429->7436 7430->7419 7430->7422 7430->7423 7431->7428 7431->7433 7432->7433 7433->7377 7434->7423 7435->7433 7440 6d7eb48b signal 7435->7440 7436->7433 7437 6d7eb512 signal 7436->7437 7439 6d7eb5b0 signal 7437->7439 7442 6d7eb4a1 7437->7442 7438->7442 7439->7442 7441 6d7eb5d0 signal 7440->7441 7440->7442 7441->7442 7442->7377 7446 6d7ec0f4 7443->7446 7444 6d7c1171 7444->7368 7445 6d7ec13d free 7445->7444 7446->7444 7446->7445 6914 18a52c75304 6921 18a52c75237 __CxxCallCatchBlock __FrameHandler3::GetHandlerSearchState 6914->6921 6915 18a52c7532b 6916 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6915->6916 6917 18a52c75330 6916->6917 6918 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6917->6918 6919 18a52c7533b __FrameHandler3::GetHandlerSearchState 6917->6919 6918->6919 6920 18a52c737ec RtlAllocateHeap Is_bad_exception_allowed 6920->6921 6921->6915 6921->6919 6921->6920 6923 18a52c73814 6921->6923 6924 18a52c72e5c ExFilterRethrow RtlAllocateHeap 6923->6924 6925 18a52c73822 6924->6925 6925->6921
                        Memory Dump Source
                        • Source File: 00000003.00000002.395310059.000000006D7C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 6D7C0000, based on PE: true
                        • Associated: 00000003.00000002.395304928.000000006D7C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395364082.000000006D809000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395371412.000000006D80E000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D813000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D818000.00000002.00000001.01000000.00000003.sdmpDownload File
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_6d7c0000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ca2c65aa9d8fdb84e188641d441d8a8efd869f2063b41fe2a9811ea81d7ac98d
                        • Instruction ID: c529e21995d59a7bba657c62df19e20bb1b31903ede5f35e1779d22f00c4d353
                        • Opcode Fuzzy Hash: ca2c65aa9d8fdb84e188641d441d8a8efd869f2063b41fe2a9811ea81d7ac98d
                        • Instruction Fuzzy Hash: AD44F5B77A1A810DF7264A3A8B207DF2F71A3527B8F167B01DE345B7F5DA7A82454200
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: Open$Enum
                        • String ID:
                        • API String ID: 462099255-0
                        • Opcode ID: 2a02730be39cc75ee99e02b240c38d7de0b4f72d589f073dcba7369fd32cc831
                        • Instruction ID: 86a5bbd5675f779a4d8ca654bae9a4e932e112d87f69b8a45bac72a78f494882
                        • Opcode Fuzzy Hash: 2a02730be39cc75ee99e02b240c38d7de0b4f72d589f073dcba7369fd32cc831
                        • Instruction Fuzzy Hash: 29D17D30518B888FEB65DF18D8946EAB7E1FF98304F44462FA58BD3161DF749681CB82
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ExceptionFilterUnhandled_invalid_parameter_noinfo
                        • String ID:
                        • API String ID: 59578552-0
                        • Opcode ID: f95e01fbf38a281d9255cdf92b69475522e65d4a66deb1467f342da968b848f1
                        • Instruction ID: fc0cfa88302a60eb51de5391cc5bb3da78542019ebfad39e4037d39490e1604e
                        • Opcode Fuzzy Hash: f95e01fbf38a281d9255cdf92b69475522e65d4a66deb1467f342da968b848f1
                        • Instruction Fuzzy Hash: BAE08C309156094BFA5833BA0C662EC22B0AF05320FEC821FB715C61D7ED6946D493A3
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: FileFindFirst
                        • String ID:
                        • API String ID: 1974802433-0
                        • Opcode ID: 81c7c7fd01d69da00775a62d13099b4ead950d999e7021fb467b756ffc4a194f
                        • Instruction ID: d0e73f6234ad04f57327138251c2ea765eb5a4a18d8703d526dc42315709abb6
                        • Opcode Fuzzy Hash: 81c7c7fd01d69da00775a62d13099b4ead950d999e7021fb467b756ffc4a194f
                        • Instruction Fuzzy Hash: 36A1B531218A484BFB29EF24DC596EA73E1FF94310F54861EE54BC3192DF349A458B82
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ComputerCreateMessageMutexName
                        • String ID:
                        • API String ID: 2342047096-0
                        • Opcode ID: bf0b7409f839259ce88bb476a521653d71adaaef5a7294aa3565bebdb25f1347
                        • Instruction ID: 2cb92e1e15504ec5edded03f872f3101e7c81fed2adecbf9bf8c7fb03497b1dc
                        • Opcode Fuzzy Hash: bf0b7409f839259ce88bb476a521653d71adaaef5a7294aa3565bebdb25f1347
                        • Instruction Fuzzy Hash: 9221CC30118A448BF719DB34DC995EA77E1FFD9305F44897EF14BC60A2EE7485458B42
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: AllocateHeap
                        • String ID:
                        • API String ID: 1279760036-0
                        • Opcode ID: 30d4bf1e297d70a882b7f1add7ff9fded3996ca996f5e333fb51e94ed5290b56
                        • Instruction ID: 689a3d0d4730cfc123b5929d6e45ca276ac6c26972bf04d2ca2a1aff431ec4cd
                        • Opcode Fuzzy Hash: 30d4bf1e297d70a882b7f1add7ff9fded3996ca996f5e333fb51e94ed5290b56
                        • Instruction Fuzzy Hash: D7011D30310A0E4BFB586BA948A93A572E5DF58301F98903F7605C61D3EE55CA984352
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ExitProcess
                        • String ID:
                        • API String ID: 621844428-0
                        • Opcode ID: 0c3185d8b51bac4eb50b0166e6d79b52d76e7ad81d5639061b00e529f1dc9730
                        • Instruction ID: 27e1169f8f8c95238e20a0b3f0d4fec2882ad373c57a56ba2a120d3f26df5ad4
                        • Opcode Fuzzy Hash: 0c3185d8b51bac4eb50b0166e6d79b52d76e7ad81d5639061b00e529f1dc9730
                        • Instruction Fuzzy Hash: F0D017303012044BFB28BBB099A92B92B618B44305F54582DB66BCB697CD798C448752
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        • RtlCaptureContext.KERNEL32 ref: 6D7EADF4
                        • RtlLookupFunctionEntry.KERNEL32 ref: 6D7EAE0B
                        • RtlVirtualUnwind.KERNEL32 ref: 6D7EAE4D
                        • SetUnhandledExceptionFilter.KERNEL32 ref: 6D7EAE91
                        • UnhandledExceptionFilter.KERNEL32 ref: 6D7EAE9E
                        • GetCurrentProcess.KERNEL32 ref: 6D7EAEA4
                        • TerminateProcess.KERNEL32 ref: 6D7EAEB2
                        • abort.MSVCRT ref: 6D7EAEB8
                        Memory Dump Source
                        • Source File: 00000003.00000002.395310059.000000006D7C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 6D7C0000, based on PE: true
                        • Associated: 00000003.00000002.395304928.000000006D7C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395364082.000000006D809000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395371412.000000006D80E000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D813000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D818000.00000002.00000001.01000000.00000003.sdmpDownload File
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_6d7c0000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ExceptionFilterProcessUnhandled$CaptureContextCurrentEntryFunctionLookupTerminateUnwindVirtualabort
                        • String ID:
                        • API String ID: 4278921479-0
                        • Opcode ID: 0df65104002afcf3a5308d72e2e55d3e2305cf2fbe05d96474d79cf730cac82b
                        • Instruction ID: 7e7dc6ca435440cde9480edaf27f57701c5d8a51c7a772b8baa5bed59b50fc21
                        • Opcode Fuzzy Hash: 0df65104002afcf3a5308d72e2e55d3e2305cf2fbe05d96474d79cf730cac82b
                        • Instruction Fuzzy Hash: 9021E275B10B0089FB019F65F88939A33B6B749B99F448127EA4E93765EF39C168C310
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        • GetSystemTimeAsFileTime.KERNEL32 ref: 6D7EAD45
                        • GetCurrentProcessId.KERNEL32 ref: 6D7EAD50
                        • GetCurrentThreadId.KERNEL32 ref: 6D7EAD59
                        • GetTickCount.KERNEL32 ref: 6D7EAD61
                        • QueryPerformanceCounter.KERNEL32 ref: 6D7EAD6E
                        Memory Dump Source
                        • Source File: 00000003.00000002.395310059.000000006D7C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 6D7C0000, based on PE: true
                        • Associated: 00000003.00000002.395304928.000000006D7C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395364082.000000006D809000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395371412.000000006D80E000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D813000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D818000.00000002.00000001.01000000.00000003.sdmpDownload File
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_6d7c0000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: CurrentTime$CountCounterFilePerformanceProcessQuerySystemThreadTick
                        • String ID:
                        • API String ID: 1445889803-0
                        • Opcode ID: 67207b604c025b437f20d6c5347240990710dbd6181aa0d293a29e7a5e0b68e1
                        • Instruction ID: c686f1a8d7b80d35322faf7e0a89bedf2ba13350a0edd1b317562447d65a69ac
                        • Opcode Fuzzy Hash: 67207b604c025b437f20d6c5347240990710dbd6181aa0d293a29e7a5e0b68e1
                        • Instruction Fuzzy Hash: 8911A026B15A1489FB119B25FD08316B3A1B7497F2F0846329E9C437A4EF3DC499C300
                        Uniqueness

                        Uniqueness Score: -1.00%

                        APIs
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: _clrfp
                        • String ID:
                        • API String ID: 3618594692-0
                        • Opcode ID: 366ece8fd4243e10d17ea9cc99fe40b0e0fe10ffefe9f6541844f2a7d48a03a3
                        • Instruction ID: 92f63ea425edc4701ad2f6bf5a86d7bc6cfafa53da1d6856863cfe5b174957f8
                        • Opcode Fuzzy Hash: 366ece8fd4243e10d17ea9cc99fe40b0e0fe10ffefe9f6541844f2a7d48a03a3
                        • Instruction Fuzzy Hash: 67C17032510A5D8FEB98CF1CC49AB953BF0FF56314F58859AE85ACB2A2C735D891CB01
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 938e5dc5f931898c53ab94ddb6ba8926b6e3c4df36339bc41ef0f30e53ab89a1
                        • Instruction ID: d870b2d8038ee176f6d7825ec935b1ec659e497c58a61ba7f923d1bf5e8b31a6
                        • Opcode Fuzzy Hash: 938e5dc5f931898c53ab94ddb6ba8926b6e3c4df36339bc41ef0f30e53ab89a1
                        • Instruction Fuzzy Hash: B451F732318E084FEB1CDF6CD4996B573D2EBA8310755822FF50AD72A6DE70D9868781
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 798 6d7eb190-6d7eb1b0 799 6d7eb1b2-6d7eb1c2 798->799 800 6d7eb1c3-6d7eb21a call 6d7ebce0 call 6d7ebf30 798->800 800->799 805 6d7eb21c-6d7eb222 800->805 806 6d7eb228-6d7eb22a 805->806 807 6d7eb2f0-6d7eb2f2 805->807 808 6d7eb2d4-6d7eb2d9 806->808 809 6d7eb230-6d7eb233 806->809 807->809 810 6d7eb2f8-6d7eb2fd 807->810 808->809 811 6d7eb2df-6d7eb2e4 808->811 809->799 812 6d7eb239-6d7eb258 809->812 810->809 813 6d7eb303-6d7eb309 810->813 811->813 814 6d7eb2e6-6d7eb2ed 811->814 815 6d7eb264-6d7eb285 call 6d7eafc0 812->815 816 6d7eb43e-6d7eb45b call 6d7ec240 813->816 817 6d7eb30f-6d7eb32b 813->817 814->807 826 6d7eb287-6d7eb298 815->826 827 6d7eb260 815->827 828 6d7eb45d-6d7eb462 816->828 829 6d7eb4c0-6d7eb4c5 816->829 819 6d7eb32d 817->819 820 6d7eb375-6d7eb38a 817->820 819->799 823 6d7eb38c-6d7eb3bd call 6d7eafc0 820->823 824 6d7eb332 820->824 853 6d7eb368-6d7eb36f 823->853 831 6d7eb338-6d7eb33b 824->831 832 6d7eb3f0-6d7eb3f3 824->832 826->799 837 6d7eb29e 826->837 827->815 838 6d7eb4df-6d7eb4ef signal 828->838 839 6d7eb464-6d7eb469 828->839 833 6d7eb4cb 829->833 834 6d7eb580-6d7eb590 call 6d7ebfa8 829->834 835 6d7eb3c0-6d7eb3ea call 6d7eafc0 831->835 836 6d7eb341-6d7eb344 831->836 841 6d7eb42a-6d7eb439 call 6d7ec240 832->841 842 6d7eb3f5-6d7eb425 call 6d7eafc0 832->842 844 6d7eb4cd-6d7eb4d2 833->844 845 6d7eb504-6d7eb509 833->845 849 6d7eb4f1-6d7eb4f4 834->849 872 6d7eb596-6d7eb5a7 signal 834->872 835->853 836->841 846 6d7eb34a-6d7eb363 call 6d7eafc0 836->846 847 6d7eb2a0-6d7eb2b0 837->847 848 6d7eb560-6d7eb56f signal call 6d7ebf20 838->848 838->849 851 6d7eb46f 839->851 852 6d7eb574-6d7eb57a 839->852 841->816 842->853 844->852 856 6d7eb4d8-6d7eb4dd 844->856 845->852 860 6d7eb50b-6d7eb510 845->860 846->853 863 6d7eb2b2-6d7eb2bd VirtualProtect 847->863 864 6d7eb2c0-6d7eb2cd 847->864 848->852 858 6d7eb54e-6d7eb557 849->858 859 6d7eb4f6-6d7eb503 849->859 867 6d7eb475-6d7eb47a 851->867 868 6d7eb540-6d7eb545 851->868 853->820 853->826 856->838 856->858 860->858 869 6d7eb512-6d7eb522 signal 860->869 863->864 864->847 871 6d7eb2cf 864->871 867->852 873 6d7eb480-6d7eb485 867->873 868->869 870 6d7eb547-6d7eb54c 868->870 875 6d7eb528-6d7eb52b 869->875 876 6d7eb5b0-6d7eb5c1 signal 869->876 870->852 870->858 871->799 877 6d7eb4b3-6d7eb4b7 872->877 873->858 878 6d7eb48b-6d7eb49b signal 873->878 879 6d7eb5e6-6d7eb5eb 875->879 880 6d7eb531-6d7eb53e 875->880 876->877 881 6d7eb5d0-6d7eb5e1 signal 878->881 882 6d7eb4a1-6d7eb4a4 878->882 879->877 881->877 882->879 883 6d7eb4aa-6d7eb4b1 882->883 883->877
                        C-Code - Quality: 65%
                        			E6D7EB190(int __eax, signed long long __rax, void* __rbx, signed short* __rcx, void* __rdi, void* __rsi, signed long long __r8, void* __r12, void* __r13, void* __r14, void* __r15) {
                        				int _t30;
                        				int _t33;
                        				intOrPtr _t37;
                        				signed int _t41;
                        				signed int _t53;
                        				int _t68;
                        				signed int _t78;
                        				void* _t81;
                        				void* _t82;
                        				signed long long _t85;
                        				intOrPtr* _t91;
                        				signed short* _t96;
                        				intOrPtr* _t98;
                        				signed long long _t100;
                        				int _t109;
                        				int _t114;
                        				void* _t116;
                        				void* _t118;
                        				void* _t120;
                        				void* _t121;
                        				signed long long _t130;
                        				intOrPtr _t135;
                        				intOrPtr _t142;
                        				void* _t147;
                        				intOrPtr _t151;
                        				intOrPtr _t152;
                        				int _t155;
                        				signed long long _t156;
                        
                        				_t157 = __r15;
                        				_t130 = __r8;
                        				_t96 = __rcx;
                        				_t94 = __rbx;
                        				_t85 = __rax;
                        				_t30 = __eax;
                        				_push(__r15);
                        				_push(__rbx);
                        				_t121 = _t120 - 0x38;
                        				_t118 = _t121 + 0x80;
                        				_t53 =  *0x6d80c5e0;
                        				if(_t53 == 0) {
                        					 *0x6d80c5e0 = 1;
                        					E6D7EBCE0();
                        					_t30 = E6D7EBF30(_t85);
                        					_t142 =  *0x6d8091c0; // 0x6d809280
                        					 *0x6d80c5e4 = 0;
                        					_t114 =  *0x6d8091d0; // 0x6d809280
                        					 *0x6d80c5e8 = _t121 - (0x0000001e + (_t85 + _t85 * 0x00000004) * 0x00000008 & 0xfffffff0) + 0x20;
                        					_t91 = _t142 - _t114;
                        					__eflags = _t91 - 7;
                        					if(_t91 <= 7) {
                        						goto L1;
                        					} else {
                        						__eflags = _t91 - 0xb;
                        						_t68 =  *_t114;
                        						if(_t91 <= 0xb) {
                        							L18:
                        							__eflags = _t68;
                        							if(_t68 != 0) {
                        								goto L5;
                        							} else {
                        								_t20 = _t114 + 4; // 0x0
                        								_t30 =  *_t20;
                        								__eflags = _t30;
                        								if(_t30 != 0) {
                        									goto L5;
                        								} else {
                        									goto L20;
                        								}
                        							}
                        						} else {
                        							__eflags = _t68;
                        							if(_t68 == 0) {
                        								_t17 = _t114 + 4; // 0x0
                        								__eflags =  *_t17;
                        								if( *_t17 != 0) {
                        									goto L5;
                        								} else {
                        									_t18 = _t114 + 8; // 0x0
                        									__eflags =  *_t18;
                        									if( *_t18 != 0) {
                        										L20:
                        										_t21 = _t114 + 8; // 0x0
                        										__eflags =  *_t21 - 1;
                        										if(__eflags != 0) {
                        											L34:
                        											_t98 = "  Unknown pseudo relocation protocol version %d.\n";
                        											E6D7EC240(__eflags, _t98, _t100, _t130, _t135);
                        											_t37 =  *_t98;
                        											__eflags = _t37 - 0xc0000091;
                        											if(_t37 > 0xc0000091) {
                        												__eflags = _t37 - 0xc0000094;
                        												if(__eflags == 0) {
                        													L6D7EBFA8();
                        													__eflags = _t91 - 1;
                        													if(_t91 != 1) {
                        														goto L49;
                        													} else {
                        														L6D7EBFA8();
                        														_t41 = 0;
                        														goto L43;
                        													}
                        												} else {
                        													if(__eflags > 0) {
                        														__eflags = _t37 - 0xc0000095;
                        														if(_t37 == 0xc0000095) {
                        															goto L60;
                        														} else {
                        															__eflags = _t37 - 0xc0000096;
                        															if(_t37 != 0xc0000096) {
                        																goto L58;
                        															} else {
                        																goto L53;
                        															}
                        														}
                        													} else {
                        														__eflags = _t37 - 0xc0000092;
                        														if(_t37 == 0xc0000092) {
                        															goto L60;
                        														} else {
                        															__eflags = _t37 - 0xc0000093;
                        															if(_t37 != 0xc0000093) {
                        																goto L58;
                        															} else {
                        																goto L48;
                        															}
                        														}
                        													}
                        												}
                        											} else {
                        												__eflags = _t37 - 0xc000008d;
                        												if(_t37 >= 0xc000008d) {
                        													L48:
                        													L6D7EBFA8();
                        													__eflags = _t91 - 1;
                        													if(_t91 == 1) {
                        														L6D7EBFA8();
                        														E6D7EBF20(_t37);
                        														goto L60;
                        													} else {
                        														L49:
                        														__eflags = _t91;
                        														if(_t91 == 0) {
                        															goto L58;
                        														} else {
                        															 *_t91();
                        															__eflags = 0;
                        															return 0;
                        														}
                        													}
                        												} else {
                        													__eflags = _t37 - 0xc0000008;
                        													if(__eflags == 0) {
                        														L60:
                        														__eflags = 0;
                        														return 0;
                        													} else {
                        														if(__eflags > 0) {
                        															__eflags = _t37 - 0xc000001d;
                        															if(_t37 == 0xc000001d) {
                        																L53:
                        																L6D7EBFA8();
                        																__eflags = _t91 - 1;
                        																if(_t91 == 1) {
                        																	L6D7EBFA8();
                        																	_t41 = 0;
                        																	goto L43;
                        																} else {
                        																	__eflags = _t91;
                        																	if(_t91 == 0) {
                        																		goto L65;
                        																	} else {
                        																		 *_t91();
                        																		__eflags = 0;
                        																		return 0;
                        																	}
                        																}
                        															} else {
                        																__eflags = _t37 - 0xc000008c;
                        																if(_t37 == 0xc000008c) {
                        																	goto L60;
                        																} else {
                        																	goto L58;
                        																}
                        															}
                        														} else {
                        															__eflags = _t37 - 0x80000002;
                        															if(_t37 == 0x80000002) {
                        																goto L60;
                        															} else {
                        																__eflags = _t37 - 0xc0000005;
                        																if(_t37 != 0xc0000005) {
                        																	L58:
                        																	return 1;
                        																} else {
                        																	L6D7EBFA8();
                        																	__eflags = _t91 - 1;
                        																	if(_t91 == 1) {
                        																		L6D7EBFA8();
                        																		_t41 = 0;
                        																	} else {
                        																		__eflags = _t91;
                        																		if(_t91 == 0) {
                        																			L65:
                        																			_t41 = 4;
                        																		} else {
                        																			 *_t91();
                        																			_t41 = 0;
                        																			__eflags = 0;
                        																		}
                        																	}
                        																	L43:
                        																	return _t41;
                        																}
                        															}
                        														}
                        													}
                        												}
                        											}
                        										} else {
                        											_t152 =  *0x6d8091f0; // 0x6d7c0000
                        											_t116 = _t114 + 0xc;
                        											_t156 = _t118 - 0x58;
                        											__eflags = _t116 - _t142;
                        											if(_t116 < _t142) {
                        												do {
                        													_t25 = _t116 + 8; // 0x6d80c5d0
                        													_t78 =  *_t25 & 0x000000ff;
                        													_t96 = _t96 + _t152;
                        													_t91 = _t91 + _t152;
                        													__eflags = _t78 - 0x10;
                        													_t135 =  *_t91;
                        													if(__eflags != 0) {
                        														if(__eflags <= 0) {
                        															__eflags = _t78 - 8;
                        															if(__eflags != 0) {
                        																goto L33;
                        															} else {
                        																r8d =  *_t96 & 0x000000ff;
                        																_t100 = _t156;
                        																_t112 = _t156;
                        																__eflags = r8b;
                        																_t131 =  <  ? _t130 | 0xffffff00 : _t130;
                        																_t132 = ( <  ? _t130 | 0xffffff00 : _t130) - _t91;
                        																_t130 = ( <  ? _t130 | 0xffffff00 : _t130) - _t91 + _t135;
                        																 *(_t118 - 0x58) = _t130;
                        																r8d = 1;
                        																E6D7EAFC0(_t81, _t82, _t94, _t96, _t100, _t156, _t116, _t130, _t142, _t152, _t156, 0);
                        																goto L27;
                        															}
                        														} else {
                        															__eflags = _t78 - 0x20;
                        															if(_t78 == 0x20) {
                        																_t112 = _t156;
                        																_t130 = _t100;
                        																__eflags = r8d;
                        																_t104 =  >=  ? _t130 : _t100 | 0x00000000;
                        																r8d = 4;
                        																_t105 = ( >=  ? _t130 : _t100 | 0x00000000) - _t91;
                        																_t106 = ( >=  ? _t130 : _t100 | 0x00000000) - _t91 + _t135;
                        																 *(_t118 - 0x58) = ( >=  ? _t130 : _t100 | 0x00000000) - _t91 + _t135;
                        																_t100 = _t156;
                        																E6D7EAFC0(_t81, _t82, _t94, _t96, _t100, _t156, _t116, _t130, _t142, _t152, _t156, 0);
                        																goto L27;
                        															} else {
                        																__eflags = _t78 - 0x40;
                        																if(__eflags != 0) {
                        																	L33:
                        																	 *(_t118 - 0x58) = 0;
                        																	E6D7EC240(__eflags, "  Unknown pseudo relocation bit size %d.\n", _t100, _t130, _t135);
                        																	goto L34;
                        																} else {
                        																	r8d = 8;
                        																	_t112 = _t156;
                        																	_t109 =  *_t96 - _t91 + _t135;
                        																	__eflags = _t109;
                        																	 *(_t118 - 0x58) = _t109;
                        																	_t100 = _t156;
                        																	E6D7EAFC0(_t81, _t82, _t94, _t96, _t100, _t156, _t116, _t130, _t142, _t152, _t156, 0);
                        																	goto L27;
                        																}
                        															}
                        														}
                        													} else {
                        														r8d =  *_t96 & 0x0000ffff;
                        														_t100 = _t156;
                        														_t112 = _t156;
                        														__eflags = r8w;
                        														_t133 =  <  ? _t130 | 0xffff0000 : _t130;
                        														_t134 = ( <  ? _t130 | 0xffff0000 : _t130) - _t91;
                        														_t130 = ( <  ? _t130 | 0xffff0000 : _t130) - _t91 + _t135;
                        														 *(_t118 - 0x58) = _t130;
                        														r8d = 2;
                        														E6D7EAFC0(_t81, _t82, _t94, _t96, _t100, _t156, _t116, _t130, _t142, _t152, _t156, 0);
                        														goto L27;
                        													}
                        													goto L66;
                        													L27:
                        													_t114 = _t116 + 0xc;
                        													__eflags = _t114 - _t142;
                        												} while (_t114 < _t142);
                        												goto L9;
                        											} else {
                        												goto L1;
                        											}
                        										}
                        									} else {
                        										_t19 = _t114 + 0xc; // 0x0
                        										_t68 =  *_t19;
                        										_t114 = _t114 + 0xc;
                        										__eflags = _t114;
                        										goto L18;
                        									}
                        								}
                        							} else {
                        								L5:
                        								__eflags = _t114 - _t142;
                        								if(_t114 < _t142) {
                        									_t8 = _t114 + 8; // 0x6d809288
                        									_t155 = _t8;
                        									_t151 =  *0x6d8091f0; // 0x6d7c0000
                        									_t112 = _t118 - 0x58;
                        									_t11 = (_t142 + 7 - _t155 >> 3) * 8; // 0x6d809288
                        									_t147 = _t114 + _t11 + 8;
                        									while(1) {
                        										r8d = 4;
                        										_t33 =  *_t114;
                        										_t114 = _t155;
                        										_t96 = _t96 + _t151;
                        										 *(_t118 - 0x58) = _t33 +  *_t96;
                        										E6D7EAFC0(_t81, _t82, _t94, _t96, _t112, _t112, _t114, _t130, _t147, _t151, _t155, _t157);
                        										__eflags = _t155 - _t147;
                        										if(_t155 == _t147) {
                        											break;
                        										}
                        										_t155 = _t155 + 8;
                        										__eflags = _t155;
                        									}
                        									L9:
                        									_t30 =  *0x6d80c5e4;
                        									__eflags = _t30;
                        									if(_t30 > 0) {
                        										do {
                        											r8d =  *( *0x6d80c5e8 + _t114);
                        											__eflags = r8d;
                        											if(r8d != 0) {
                        												_t30 = VirtualProtect();
                        											}
                        											_t53 = _t53 + 1;
                        											_t114 = _t114 + 0x28;
                        											__eflags = _t53 -  *0x6d80c5e4;
                        										} while (_t53 <  *0x6d80c5e4);
                        									}
                        								}
                        								goto L1;
                        							}
                        						}
                        					}
                        				} else {
                        					L1:
                        					return _t30;
                        				}
                        				L66:
                        			}































                        0x6d7eb190
                        0x6d7eb190
                        0x6d7eb190
                        0x6d7eb190
                        0x6d7eb190
                        0x6d7eb190
                        0x6d7eb191
                        0x6d7eb19b
                        0x6d7eb19c
                        0x6d7eb1a0
                        0x6d7eb1a8
                        0x6d7eb1b0
                        0x6d7eb1c3
                        0x6d7eb1cd
                        0x6d7eb1e4
                        0x6d7eb1e9
                        0x6d7eb1f0
                        0x6d7eb1fa
                        0x6d7eb209
                        0x6d7eb213
                        0x6d7eb216
                        0x6d7eb21a
                        0x00000000
                        0x6d7eb21c
                        0x6d7eb21c
                        0x6d7eb220
                        0x6d7eb222
                        0x6d7eb2f0
                        0x6d7eb2f0
                        0x6d7eb2f2
                        0x00000000
                        0x6d7eb2f8
                        0x6d7eb2f8
                        0x6d7eb2f8
                        0x6d7eb2fb
                        0x6d7eb2fd
                        0x00000000
                        0x00000000
                        0x00000000
                        0x00000000
                        0x6d7eb2fd
                        0x6d7eb228
                        0x6d7eb228
                        0x6d7eb22a
                        0x6d7eb2d4
                        0x6d7eb2d7
                        0x6d7eb2d9
                        0x00000000
                        0x6d7eb2df
                        0x6d7eb2df
                        0x6d7eb2e2
                        0x6d7eb2e4
                        0x6d7eb303
                        0x6d7eb303
                        0x6d7eb306
                        0x6d7eb309
                        0x6d7eb43e
                        0x6d7eb43e
                        0x6d7eb445
                        0x6d7eb454
                        0x6d7eb456
                        0x6d7eb45b
                        0x6d7eb4c0
                        0x6d7eb4c5
                        0x6d7eb587
                        0x6d7eb58c
                        0x6d7eb590
                        0x00000000
                        0x6d7eb596
                        0x6d7eb5a0
                        0x6d7eb5a5
                        0x00000000
                        0x6d7eb5a5
                        0x6d7eb4cb
                        0x6d7eb4cb
                        0x6d7eb504
                        0x6d7eb509
                        0x00000000
                        0x6d7eb50b
                        0x6d7eb50b
                        0x6d7eb510
                        0x00000000
                        0x00000000
                        0x00000000
                        0x00000000
                        0x6d7eb510
                        0x6d7eb4cd
                        0x6d7eb4cd
                        0x6d7eb4d2
                        0x00000000
                        0x6d7eb4d8
                        0x6d7eb4d8
                        0x6d7eb4dd
                        0x00000000
                        0x00000000
                        0x00000000
                        0x00000000
                        0x6d7eb4dd
                        0x6d7eb4d2
                        0x6d7eb4cb
                        0x6d7eb45d
                        0x6d7eb45d
                        0x6d7eb462
                        0x6d7eb4df
                        0x6d7eb4e6
                        0x6d7eb4eb
                        0x6d7eb4ef
                        0x6d7eb56a
                        0x6d7eb56f
                        0x00000000
                        0x6d7eb4f1
                        0x6d7eb4f1
                        0x6d7eb4f1
                        0x6d7eb4f4
                        0x00000000
                        0x6d7eb4f6
                        0x6d7eb4fb
                        0x6d7eb4fd
                        0x6d7eb503
                        0x6d7eb503
                        0x6d7eb4f4
                        0x6d7eb464
                        0x6d7eb464
                        0x6d7eb469
                        0x6d7eb574
                        0x6d7eb574
                        0x6d7eb57a
                        0x6d7eb46f
                        0x6d7eb46f
                        0x6d7eb540
                        0x6d7eb545
                        0x6d7eb512
                        0x6d7eb519
                        0x6d7eb51e
                        0x6d7eb522
                        0x6d7eb5ba
                        0x6d7eb5bf
                        0x00000000
                        0x6d7eb528
                        0x6d7eb528
                        0x6d7eb52b
                        0x00000000
                        0x6d7eb531
                        0x6d7eb536
                        0x6d7eb538
                        0x6d7eb53e
                        0x6d7eb53e
                        0x6d7eb52b
                        0x6d7eb547
                        0x6d7eb547
                        0x6d7eb54c
                        0x00000000
                        0x00000000
                        0x00000000
                        0x00000000
                        0x6d7eb54c
                        0x6d7eb475
                        0x6d7eb475
                        0x6d7eb47a
                        0x00000000
                        0x6d7eb480
                        0x6d7eb480
                        0x6d7eb485
                        0x6d7eb54e
                        0x6d7eb557
                        0x6d7eb48b
                        0x6d7eb492
                        0x6d7eb497
                        0x6d7eb49b
                        0x6d7eb5da
                        0x6d7eb5df
                        0x6d7eb4a1
                        0x6d7eb4a1
                        0x6d7eb4a4
                        0x6d7eb5e6
                        0x6d7eb5e6
                        0x6d7eb4aa
                        0x6d7eb4af
                        0x6d7eb4b1
                        0x6d7eb4b1
                        0x6d7eb4b1
                        0x6d7eb4a4
                        0x6d7eb4b3
                        0x6d7eb4b7
                        0x6d7eb4b7
                        0x6d7eb485
                        0x6d7eb47a
                        0x6d7eb46f
                        0x6d7eb469
                        0x6d7eb462
                        0x6d7eb30f
                        0x6d7eb30f
                        0x6d7eb316
                        0x6d7eb324
                        0x6d7eb328
                        0x6d7eb32b
                        0x6d7eb375
                        0x6d7eb37a
                        0x6d7eb37a
                        0x6d7eb37e
                        0x6d7eb381
                        0x6d7eb384
                        0x6d7eb387
                        0x6d7eb38a
                        0x6d7eb332
                        0x6d7eb3f0
                        0x6d7eb3f3
                        0x00000000
                        0x6d7eb3f5
                        0x6d7eb3f5
                        0x6d7eb3f9
                        0x6d7eb3fc
                        0x6d7eb409
                        0x6d7eb40c
                        0x6d7eb410
                        0x6d7eb413
                        0x6d7eb416
                        0x6d7eb41a
                        0x6d7eb420
                        0x00000000
                        0x6d7eb420
                        0x6d7eb338
                        0x6d7eb338
                        0x6d7eb33b
                        0x6d7eb3c2
                        0x6d7eb3c5
                        0x6d7eb3cb
                        0x6d7eb3ce
                        0x6d7eb3d2
                        0x6d7eb3d8
                        0x6d7eb3db
                        0x6d7eb3de
                        0x6d7eb3e2
                        0x6d7eb3e5
                        0x00000000
                        0x6d7eb341
                        0x6d7eb341
                        0x6d7eb344
                        0x6d7eb42a
                        0x6d7eb431
                        0x6d7eb439
                        0x00000000
                        0x6d7eb34a
                        0x6d7eb34d
                        0x6d7eb353
                        0x6d7eb359
                        0x6d7eb359
                        0x6d7eb35c
                        0x6d7eb360
                        0x6d7eb363
                        0x00000000
                        0x6d7eb363
                        0x6d7eb344
                        0x6d7eb33b
                        0x6d7eb38c
                        0x6d7eb38c
                        0x6d7eb390
                        0x6d7eb393
                        0x6d7eb3a0
                        0x6d7eb3a4
                        0x6d7eb3a8
                        0x6d7eb3ab
                        0x6d7eb3ae
                        0x6d7eb3b2
                        0x6d7eb3b8
                        0x00000000
                        0x6d7eb3b8
                        0x00000000
                        0x6d7eb368
                        0x6d7eb368
                        0x6d7eb36c
                        0x6d7eb36c
                        0x00000000
                        0x6d7eb32d
                        0x00000000
                        0x6d7eb32d
                        0x6d7eb32b
                        0x6d7eb2e6
                        0x6d7eb2e6
                        0x6d7eb2e6
                        0x6d7eb2e9
                        0x6d7eb2e9
                        0x00000000
                        0x6d7eb2e9
                        0x6d7eb2e4
                        0x6d7eb230
                        0x6d7eb230
                        0x6d7eb230
                        0x6d7eb233
                        0x6d7eb239
                        0x6d7eb239
                        0x6d7eb241
                        0x6d7eb248
                        0x6d7eb253
                        0x6d7eb253
                        0x6d7eb264
                        0x6d7eb267
                        0x6d7eb270
                        0x6d7eb272
                        0x6d7eb275
                        0x6d7eb27a
                        0x6d7eb27d
                        0x6d7eb282
                        0x6d7eb285
                        0x00000000
                        0x00000000
                        0x6d7eb260
                        0x6d7eb260
                        0x6d7eb260
                        0x6d7eb287
                        0x6d7eb287
                        0x6d7eb296
                        0x6d7eb298
                        0x6d7eb2a0
                        0x6d7eb2aa
                        0x6d7eb2ad
                        0x6d7eb2b0
                        0x6d7eb2bd
                        0x6d7eb2bd
                        0x6d7eb2c0
                        0x6d7eb2c3
                        0x6d7eb2c7
                        0x6d7eb2c7
                        0x6d7eb2cf
                        0x6d7eb298
                        0x00000000
                        0x6d7eb233
                        0x6d7eb22a
                        0x6d7eb222
                        0x6d7eb1b2
                        0x6d7eb1b2
                        0x6d7eb1c2
                        0x6d7eb1c2
                        0x00000000

                        APIs
                        • VirtualProtect.KERNEL32(?,?,?,?,?,?,6D7C1278), ref: 6D7EB2BD
                        Strings
                        • Unknown pseudo relocation bit size %d., xrefs: 6D7EB42A
                        • Unknown pseudo relocation protocol version %d., xrefs: 6D7EB43E
                        Memory Dump Source
                        • Source File: 00000003.00000002.395310059.000000006D7C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 6D7C0000, based on PE: true
                        • Associated: 00000003.00000002.395304928.000000006D7C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395364082.000000006D809000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395371412.000000006D80E000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D813000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D818000.00000002.00000001.01000000.00000003.sdmpDownload File
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_6d7c0000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ProtectVirtual
                        • String ID: Unknown pseudo relocation bit size %d.$ Unknown pseudo relocation protocol version %d.
                        • API String ID: 544645111-395989641
                        • Opcode ID: 95223d1137b75e46f2554debcc49d3619d8e7e1de36342d529655317680d5494
                        • Instruction ID: da2461e26f7999454393f07e082508ae2b376d1b157602e95129a658e2a58f83
                        • Opcode Fuzzy Hash: 95223d1137b75e46f2554debcc49d3619d8e7e1de36342d529655317680d5494
                        • Instruction Fuzzy Hash: E6916B71B103428AEB148BA5DB4572D6B62BB453F8F518523CF2887798DB3DE485C743
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 886 6d7eb6e0-6d7eb6fb 887 6d7eb7c0-6d7eb7c4 886->887 888 6d7eb701-6d7eb706 886->888 887->888 891 6d7eb7ca-6d7eb7d4 887->891 889 6d7eb708-6d7eb70d 888->889 890 6d7eb770-6d7eb775 888->890 894 6d7eb70f-6d7eb714 889->894 895 6d7eb78b-6d7eb79b signal 889->895 892 6d7eb77b 890->892 893 6d7eb830-6d7eb840 signal 890->893 896 6d7eb77d-6d7eb782 892->896 897 6d7eb7d5-6d7eb7da 892->897 899 6d7eb7a1-6d7eb7a4 893->899 900 6d7eb846-6d7eb85a signal 893->900 894->891 901 6d7eb71a 894->901 898 6d7eb880-6d7eb894 signal call 6d7ebf20 895->898 895->899 896->891 902 6d7eb784-6d7eb789 896->902 897->891 908 6d7eb7dc-6d7eb7e1 897->908 898->891 903 6d7eb7a6-6d7eb7ad 899->903 904 6d7eb751-6d7eb75b 899->904 905 6d7eb7b2-6d7eb7b7 900->905 906 6d7eb814-6d7eb819 901->906 907 6d7eb720-6d7eb725 901->907 902->895 902->904 903->905 913 6d7eb871-6d7eb873 904->913 914 6d7eb761-6d7eb768 904->914 910 6d7eb81b-6d7eb820 906->910 911 6d7eb7e7-6d7eb7f7 signal 906->911 907->891 912 6d7eb72b-6d7eb730 907->912 908->904 908->911 910->904 916 6d7eb826 910->916 919 6d7eb7fd-6d7eb800 911->919 920 6d7eb8b0-6d7eb8c2 signal 911->920 912->904 918 6d7eb732-6d7eb742 signal 912->918 913->905 914->890 916->891 922 6d7eb748-6d7eb74b 918->922 923 6d7eb899-6d7eb8ab signal 918->923 919->904 921 6d7eb806-6d7eb812 919->921 920->905 921->905 922->904 924 6d7eb860-6d7eb86c 922->924 923->905 924->905
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000003.00000002.395310059.000000006D7C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 6D7C0000, based on PE: true
                        • Associated: 00000003.00000002.395304928.000000006D7C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395364082.000000006D809000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395371412.000000006D80E000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D813000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D818000.00000002.00000001.01000000.00000003.sdmpDownload File
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_6d7c0000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: signal
                        • String ID: CCG
                        • API String ID: 1946981877-1584390748
                        • Opcode ID: 510415687b53fdd25d11655551667f340b59ec9c6ebe74d298f09f1eda2ae476
                        • Instruction ID: b2bbc8561d5baf325b58bf9692c8fe2e0579aed71f046c77a07e83de23c1fe6c
                        • Opcode Fuzzy Hash: 510415687b53fdd25d11655551667f340b59ec9c6ebe74d298f09f1eda2ae476
                        • Instruction Fuzzy Hash: 2831702071572646FB19427947943342C02AF8A7F9F258A3BCA7DC7BE4CE58F4C00A53
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 927 18a52c74418-18a52c74480 call 18a52c75374 930 18a52c748e7-18a52c748ef call 18a52c76c14 927->930 931 18a52c74486-18a52c74489 927->931 931->930 932 18a52c7448f-18a52c74495 931->932 935 18a52c7449b-18a52c7449f 932->935 936 18a52c74564-18a52c74576 932->936 935->936 939 18a52c744a5-18a52c744b0 935->939 937 18a52c7457c-18a52c74580 936->937 938 18a52c74837-18a52c7483b 936->938 937->938 942 18a52c74586-18a52c74591 937->942 940 18a52c7483d-18a52c74844 938->940 941 18a52c74874-18a52c7487e call 18a52c72e5c 938->941 939->936 943 18a52c744b6-18a52c744bb 939->943 940->930 945 18a52c7484a-18a52c7486f call 18a52c748f0 940->945 941->930 955 18a52c74880-18a52c7489f call 18a52c7ee40 941->955 942->938 947 18a52c74597-18a52c7459e 942->947 943->936 944 18a52c744c1-18a52c744cb call 18a52c72e5c 943->944 944->955 958 18a52c744d1-18a52c744fc call 18a52c72e5c * 2 call 18a52c7382c 944->958 945->941 948 18a52c74768-18a52c74774 947->948 949 18a52c745a4-18a52c745db call 18a52c73518 947->949 948->941 956 18a52c7477a-18a52c7477e 948->956 949->948 963 18a52c745e1-18a52c745ea 949->963 960 18a52c74780-18a52c7478c call 18a52c737ec 956->960 961 18a52c7478e-18a52c74796 956->961 995 18a52c744fe-18a52c74502 958->995 996 18a52c7451c-18a52c74526 call 18a52c72e5c 958->996 960->961 971 18a52c747af-18a52c747b7 960->971 961->941 962 18a52c7479c-18a52c747a9 call 18a52c733bc 961->962 962->941 962->971 969 18a52c745ed-18a52c7461f 963->969 973 18a52c7475b-18a52c74762 969->973 974 18a52c74625-18a52c74630 969->974 976 18a52c747bd-18a52c747c1 971->976 977 18a52c748ca-18a52c748e6 call 18a52c72e5c * 2 call 18a52c76b88 971->977 973->948 973->969 974->973 978 18a52c74636-18a52c7464f 974->978 980 18a52c747d4-18a52c747d5 976->980 981 18a52c747c3-18a52c747d2 call 18a52c737ec 976->981 977->930 982 18a52c74748-18a52c7474d 978->982 983 18a52c74655-18a52c7469a call 18a52c73800 * 2 978->983 991 18a52c747d7-18a52c747e1 call 18a52c7540c 980->991 981->991 987 18a52c74758-18a52c74759 982->987 1009 18a52c7469c-18a52c746c2 call 18a52c73800 call 18a52c74b0c 983->1009 1010 18a52c746d8-18a52c746de 983->1010 987->973 991->941 1006 18a52c747e7-18a52c74835 call 18a52c7344c call 18a52c73658 991->1006 995->996 1000 18a52c74504-18a52c7450f 995->1000 996->936 1008 18a52c74528-18a52c74548 call 18a52c72e5c * 2 call 18a52c7540c 996->1008 1000->996 1005 18a52c74511-18a52c74516 1000->1005 1005->930 1005->996 1006->941 1033 18a52c7455f-18a52c74560 1008->1033 1034 18a52c7454a-18a52c74554 call 18a52c754fc 1008->1034 1027 18a52c746e9-18a52c74746 call 18a52c74344 1009->1027 1028 18a52c746c4-18a52c746d6 1009->1028 1015 18a52c746e0-18a52c746e4 1010->1015 1016 18a52c7474f-18a52c74750 1010->1016 1015->983 1020 18a52c74754-18a52c74755 1016->1020 1020->987 1027->1020 1028->1009 1028->1010 1033->936 1037 18a52c7455a-18a52c748c3 call 18a52c72894 call 18a52c74ec8 call 18a52c75780 1034->1037 1038 18a52c748c4-18a52c748c9 call 18a52c76b88 1034->1038 1037->1038 1038->977
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                        • String ID: csm$csm$csm
                        • API String ID: 849930591-393685449
                        • Opcode ID: 2ed4cc99f58428dff43d3f01cc5e852e5bb786ad8812c5a133ade536f624ce79
                        • Instruction ID: 8c43a929d2cb89db2134866c58729d6d6136eae4995cf05e501582196454ddfc
                        • Opcode Fuzzy Hash: 2ed4cc99f58428dff43d3f01cc5e852e5bb786ad8812c5a133ade536f624ce79
                        • Instruction Fuzzy Hash: 5AF13E30518A488BEB64EB6884957E977F0FF55310F98869EE549C7293DB30D9C1CB83
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1052 6d7eafc0-6d7eafdc 1053 6d7eb148 1052->1053 1054 6d7eafe2-6d7eafef 1052->1054 1058 6d7eb14f-6d7eb15b 1053->1058 1055 6d7eaff0-6d7eaff6 1054->1055 1056 6d7eb00c-6d7eb015 1055->1056 1057 6d7eaff8-6d7eb006 1055->1057 1056->1055 1060 6d7eb017-6d7eb025 call 6d7ebc60 1056->1060 1057->1056 1059 6d7eb095-6d7eb098 1057->1059 1061 6d7eb0b8-6d7eb0c2 1058->1061 1063 6d7eb09a-6d7eb09e 1059->1063 1064 6d7eb0c3-6d7eb0d5 1059->1064 1070 6d7eb17d-6d7eb1b0 call 6d7ec240 1060->1070 1071 6d7eb02b-6d7eb074 call 6d7ebd90 VirtualQuery 1060->1071 1067 6d7eb134-6d7eb143 1063->1067 1068 6d7eb0a4-6d7eb0a6 1063->1068 1064->1061 1065 6d7eb0d7-6d7eb0da 1064->1065 1069 6d7eb0dc-6d7eb0ec 1065->1069 1067->1061 1068->1061 1072 6d7eb0a8-6d7eb0b2 1068->1072 1069->1069 1073 6d7eb0ee 1069->1073 1081 6d7eb1b2-6d7eb1c2 1070->1081 1082 6d7eb1c3-6d7eb21a call 6d7ebce0 call 6d7ebf30 1070->1082 1079 6d7eb07a-6d7eb084 1071->1079 1080 6d7eb160-6d7eb178 call 6d7ec240 1071->1080 1072->1058 1072->1061 1073->1061 1083 6d7eb08e 1079->1083 1084 6d7eb086-6d7eb08c 1079->1084 1080->1070 1082->1081 1093 6d7eb21c-6d7eb222 1082->1093 1083->1059 1084->1083 1087 6d7eb0f0-6d7eb11a VirtualProtect 1084->1087 1087->1083 1089 6d7eb120-6d7eb12f GetLastError call 6d7ec240 1087->1089 1089->1067 1094 6d7eb228-6d7eb22a 1093->1094 1095 6d7eb2f0-6d7eb2f2 1093->1095 1096 6d7eb2d4-6d7eb2d9 1094->1096 1097 6d7eb230-6d7eb233 1094->1097 1095->1097 1098 6d7eb2f8-6d7eb2fd 1095->1098 1096->1097 1099 6d7eb2df-6d7eb2e4 1096->1099 1097->1081 1100 6d7eb239-6d7eb258 1097->1100 1098->1097 1101 6d7eb303-6d7eb309 1098->1101 1099->1101 1102 6d7eb2e6-6d7eb2ed 1099->1102 1103 6d7eb264-6d7eb285 call 6d7eafc0 1100->1103 1104 6d7eb43e-6d7eb45b call 6d7ec240 1101->1104 1105 6d7eb30f-6d7eb32b 1101->1105 1102->1095 1114 6d7eb287-6d7eb298 1103->1114 1115 6d7eb260 1103->1115 1116 6d7eb45d-6d7eb462 1104->1116 1117 6d7eb4c0-6d7eb4c5 1104->1117 1107 6d7eb32d 1105->1107 1108 6d7eb375-6d7eb38a 1105->1108 1107->1081 1111 6d7eb38c-6d7eb3bd call 6d7eafc0 1108->1111 1112 6d7eb332 1108->1112 1141 6d7eb368-6d7eb36f 1111->1141 1119 6d7eb338-6d7eb33b 1112->1119 1120 6d7eb3f0-6d7eb3f3 1112->1120 1114->1081 1125 6d7eb29e 1114->1125 1115->1103 1126 6d7eb4df-6d7eb4ef signal 1116->1126 1127 6d7eb464-6d7eb469 1116->1127 1121 6d7eb4cb 1117->1121 1122 6d7eb580-6d7eb590 call 6d7ebfa8 1117->1122 1123 6d7eb3c0-6d7eb3ea call 6d7eafc0 1119->1123 1124 6d7eb341-6d7eb344 1119->1124 1129 6d7eb42a-6d7eb439 call 6d7ec240 1120->1129 1130 6d7eb3f5-6d7eb425 call 6d7eafc0 1120->1130 1132 6d7eb4cd-6d7eb4d2 1121->1132 1133 6d7eb504-6d7eb509 1121->1133 1137 6d7eb4f1-6d7eb4f4 1122->1137 1160 6d7eb596-6d7eb5a7 signal 1122->1160 1123->1141 1124->1129 1134 6d7eb34a-6d7eb363 call 6d7eafc0 1124->1134 1135 6d7eb2a0-6d7eb2b0 1125->1135 1136 6d7eb560-6d7eb56f signal call 6d7ebf20 1126->1136 1126->1137 1139 6d7eb46f 1127->1139 1140 6d7eb574-6d7eb57a 1127->1140 1129->1104 1130->1141 1132->1140 1144 6d7eb4d8-6d7eb4dd 1132->1144 1133->1140 1148 6d7eb50b-6d7eb510 1133->1148 1134->1141 1151 6d7eb2b2-6d7eb2bd VirtualProtect 1135->1151 1152 6d7eb2c0-6d7eb2cd 1135->1152 1136->1140 1146 6d7eb54e-6d7eb557 1137->1146 1147 6d7eb4f6-6d7eb503 1137->1147 1155 6d7eb475-6d7eb47a 1139->1155 1156 6d7eb540-6d7eb545 1139->1156 1141->1108 1141->1114 1144->1126 1144->1146 1148->1146 1157 6d7eb512-6d7eb522 signal 1148->1157 1151->1152 1152->1135 1159 6d7eb2cf 1152->1159 1155->1140 1161 6d7eb480-6d7eb485 1155->1161 1156->1157 1158 6d7eb547-6d7eb54c 1156->1158 1163 6d7eb528-6d7eb52b 1157->1163 1164 6d7eb5b0-6d7eb5c1 signal 1157->1164 1158->1140 1158->1146 1159->1081 1165 6d7eb4b3-6d7eb4b7 1160->1165 1161->1146 1166 6d7eb48b-6d7eb49b signal 1161->1166 1167 6d7eb5e6-6d7eb5eb 1163->1167 1168 6d7eb531-6d7eb53e 1163->1168 1164->1165 1169 6d7eb5d0-6d7eb5e1 signal 1166->1169 1170 6d7eb4a1-6d7eb4a4 1166->1170 1167->1165 1169->1165 1170->1167 1171 6d7eb4aa-6d7eb4b1 1170->1171 1171->1165
                        APIs
                        Strings
                        • VirtualQuery failed for %d bytes at address %p, xrefs: 6D7EB167
                        • Address %p has no image-section, xrefs: 6D7EB17D
                        • VirtualProtect failed with code 0x%x, xrefs: 6D7EB126
                        Memory Dump Source
                        • Source File: 00000003.00000002.395310059.000000006D7C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 6D7C0000, based on PE: true
                        • Associated: 00000003.00000002.395304928.000000006D7C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395364082.000000006D809000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395371412.000000006D80E000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D813000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D818000.00000002.00000001.01000000.00000003.sdmpDownload File
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_6d7c0000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: Virtual$ErrorLastProtectQuery
                        • String ID: VirtualProtect failed with code 0x%x$ VirtualQuery failed for %d bytes at address %p$Address %p has no image-section
                        • API String ID: 637304234-2123141913
                        • Opcode ID: 66db1a8f00c5bf92c22be664163873b503bc839fe269d61d8950b9a0737bf724
                        • Instruction ID: 6f69fe01bd496c6dc4025131fc83259c25de86d837172212a77ffc67528a88a8
                        • Opcode Fuzzy Hash: 66db1a8f00c5bf92c22be664163873b503bc839fe269d61d8950b9a0737bf724
                        • Instruction Fuzzy Hash: 94512277B007418AEB158F2AEA4475D7B61B785BF4F848122DE2D873A4EF38E545C301
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1180 18a52c72630-18a52c72676 call 18a52c72e04 1183 18a52c7267c-18a52c72682 1180->1183 1184 18a52c72758-18a52c7275f 1180->1184 1186 18a52c72686-18a52c72688 1183->1186 1185 18a52c727fa-18a52c727fe 1184->1185 1188 18a52c72804 1185->1188 1189 18a52c72764-18a52c72770 1185->1189 1187 18a52c7268e-18a52c7269a 1186->1187 1186->1188 1190 18a52c726a0-18a52c726a7 1187->1190 1191 18a52c7274a-18a52c7274c 1187->1191 1194 18a52c72809-18a52c72826 1188->1194 1192 18a52c727f8 1189->1192 1193 18a52c72776-18a52c7277d 1189->1193 1190->1191 1195 18a52c726ad-18a52c726b2 1190->1195 1191->1186 1192->1185 1193->1192 1196 18a52c7277f-18a52c72787 1193->1196 1195->1191 1197 18a52c726b8-18a52c726bd 1195->1197 1198 18a52c727cd-18a52c727d3 1196->1198 1199 18a52c72789-18a52c7278e 1196->1199 1202 18a52c726bf-18a52c726d2 1197->1202 1203 18a52c726d6-18a52c726dd 1197->1203 1200 18a52c727e1-18a52c727f5 1198->1200 1201 18a52c727d5-18a52c727d8 1198->1201 1204 18a52c72790-18a52c7279e 1199->1204 1205 18a52c727c8-18a52c727cb 1199->1205 1200->1192 1201->1192 1206 18a52c727da-18a52c727dd 1201->1206 1217 18a52c72751-18a52c72753 1202->1217 1218 18a52c726d4 1202->1218 1207 18a52c726df-18a52c726e7 1203->1207 1208 18a52c72707-18a52c72745 call 18a52c72dd0 call 18a52c72e00 1203->1208 1209 18a52c727c0-18a52c727c6 1204->1209 1210 18a52c727a0-18a52c727a8 1204->1210 1205->1188 1205->1198 1206->1188 1212 18a52c727df 1206->1212 1207->1208 1214 18a52c726e9-18a52c726f7 call 18a52c7ed00 1207->1214 1208->1191 1209->1204 1209->1205 1210->1209 1215 18a52c727aa-18a52c727b3 1210->1215 1212->1192 1214->1208 1223 18a52c726f9-18a52c726ff 1214->1223 1215->1209 1220 18a52c727b5-18a52c727be 1215->1220 1217->1194 1218->1191 1218->1203 1220->1205 1220->1209 1223->1208
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: CurrentImageNonwritable__except_validate_context_record
                        • String ID: csm$f
                        • API String ID: 3242871069-629598281
                        • Opcode ID: cbb6678aba45670b62180b90d032deeebbb74b39f1951d1e686324c8961a414a
                        • Instruction ID: f141ebcc0462de4ca6433704b09fc38813e2bab9c796e25613bce687d93f173b
                        • Opcode Fuzzy Hash: cbb6678aba45670b62180b90d032deeebbb74b39f1951d1e686324c8961a414a
                        • Instruction Fuzzy Hash: 2861A430608A058BEB28AF1CD5956A473E5FF54350F98815EF947C7187DA30ED828787
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1225 18a52c74c4c-18a52c74c94 call 18a52c72e04 call 18a52c72e5c 1230 18a52c74cce-18a52c74cd2 1225->1230 1231 18a52c74c96-18a52c74c9c 1225->1231 1233 18a52c74cd8-18a52c74cdc 1230->1233 1234 18a52c74d66-18a52c74d6a 1230->1234 1231->1230 1232 18a52c74c9e-18a52c74ca0 1231->1232 1235 18a52c74cb2-18a52c74cb4 1232->1235 1236 18a52c74ca2-18a52c74ca6 1232->1236 1237 18a52c74e5d 1233->1237 1238 18a52c74ce2-18a52c74cea 1233->1238 1239 18a52c74dae-18a52c74db4 1234->1239 1240 18a52c74d6c-18a52c74d78 1234->1240 1235->1230 1245 18a52c74cb6-18a52c74cc2 1235->1245 1244 18a52c74ca8-18a52c74cb0 1236->1244 1236->1245 1243 18a52c74e62-18a52c74e7c 1237->1243 1238->1237 1248 18a52c74cf0-18a52c74cf4 1238->1248 1246 18a52c74db6-18a52c74dba 1239->1246 1247 18a52c74e24-18a52c74e58 call 18a52c74418 1239->1247 1241 18a52c74d8e-18a52c74d9a 1240->1241 1242 18a52c74d7a-18a52c74d7e 1240->1242 1241->1237 1251 18a52c74da0-18a52c74da8 1241->1251 1242->1241 1249 18a52c74d80-18a52c74d8c call 18a52c737ec 1242->1249 1244->1230 1244->1235 1245->1230 1253 18a52c74cc4-18a52c74cc8 1245->1253 1246->1247 1252 18a52c74dbc-18a52c74dc3 1246->1252 1247->1237 1254 18a52c74cf6-18a52c74cf8 1248->1254 1255 18a52c74d53-18a52c74d61 call 18a52c733e8 1248->1255 1249->1239 1249->1241 1251->1237 1251->1239 1252->1247 1257 18a52c74dc5-18a52c74dcd 1252->1257 1253->1230 1253->1237 1259 18a52c74d31-18a52c74d33 1254->1259 1260 18a52c74cfa-18a52c74d0c call 18a52c7401c 1254->1260 1255->1237 1257->1247 1264 18a52c74dcf-18a52c74de2 call 18a52c73800 1257->1264 1259->1255 1263 18a52c74d35-18a52c74d3d 1259->1263 1267 18a52c74e7d-18a52c74e83 call 18a52c76c14 1260->1267 1270 18a52c74d12-18a52c74d15 1260->1270 1263->1267 1268 18a52c74d43-18a52c74d47 1263->1268 1264->1247 1277 18a52c74de4-18a52c74e22 1264->1277 1268->1267 1272 18a52c74d4d-18a52c74d51 1268->1272 1270->1267 1274 18a52c74d1b-18a52c74d1f 1270->1274 1276 18a52c74d21-18a52c74d2c call 18a52c751e8 1272->1276 1274->1276 1276->1237 1277->1243
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
                        • String ID: csm$csm
                        • API String ID: 3896166516-3733052814
                        • Opcode ID: 179d466ca7e911971df6fec40f864e8670ee48de26d9b50b7fdfc5552c99cf0b
                        • Instruction ID: e52c888dd0c5a232ae2e8e941ed4ee23de696e6d6e66649ae28d9b02638d5a5d
                        • Opcode Fuzzy Hash: 179d466ca7e911971df6fec40f864e8670ee48de26d9b50b7fdfc5552c99cf0b
                        • Instruction Fuzzy Hash: 31713C30214A448BFFB89B1884A47A5B7F1EF68715F98869FE599C6693CF3099C0C743
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1281 6d7c1010-6d7c1024 1282 6d7c1026-6d7c1030 1281->1282 1283 6d7c10a0-6d7c10a3 1281->1283 1284 6d7c108b-6d7c1097 1282->1284 1285 6d7c1032-6d7c1050 1282->1285 1286 6d7c10a9-6d7c10c6 1283->1286 1287 6d7c1153-6d7c1164 1283->1287 1288 6d7c105a-6d7c1068 1285->1288 1289 6d7c10e0-6d7c10eb 1286->1289 1290 6d7c106a-6d7c1076 1288->1290 1291 6d7c1052-6d7c1057 Sleep 1288->1291 1292 6d7c10ed 1289->1292 1293 6d7c10d0-6d7c10d3 1289->1293 1294 6d7c107c-6d7c1086 _amsg_exit 1290->1294 1295 6d7c1165-6d7c118b call 6d7ec0e0 1290->1295 1291->1288 1298 6d7c10ef-6d7c10fb 1292->1298 1296 6d7c10d9-6d7c10de Sleep 1293->1296 1297 6d7c1190-6d7c1195 1293->1297 1294->1284 1296->1289 1297->1298 1300 6d7c11f0-6d7c11fa call 6d7ebfd8 1298->1300 1301 6d7c1101-6d7c1105 1298->1301 1303 6d7c110b-6d7c1110 1300->1303 1301->1303 1304 6d7c11b0-6d7c11c9 _initterm 1301->1304 1307 6d7c1116-6d7c1118 1303->1307 1308 6d7c11d0-6d7c11e9 call 6d7ebfd0 1303->1308 1304->1303 1309 6d7c111e-6d7c112b 1307->1309 1310 6d7c11a0-6d7c11a5 1307->1310 1308->1307 1312 6d7c112d-6d7c1135 1309->1312 1313 6d7c113a-6d7c1152 1309->1313 1310->1309 1312->1313
                        APIs
                        Memory Dump Source
                        • Source File: 00000003.00000002.395310059.000000006D7C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 6D7C0000, based on PE: true
                        • Associated: 00000003.00000002.395304928.000000006D7C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395364082.000000006D809000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395371412.000000006D80E000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D813000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D818000.00000002.00000001.01000000.00000003.sdmpDownload File
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_6d7c0000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: Sleep_amsg_exit
                        • String ID:
                        • API String ID: 1015461914-0
                        • Opcode ID: e27fe5a8971d6827a824ceaca1c9c04ab70d9526602116c550646743b90f6313
                        • Instruction ID: ab5cf6504fecb38ecfa05007e94ff7ccef8b92edce53eeaa8f06038a63debbbb
                        • Opcode Fuzzy Hash: e27fe5a8971d6827a824ceaca1c9c04ab70d9526602116c550646743b90f6313
                        • Instruction Fuzzy Hash: 08419F32B456458EE7029B1AEE543656266B7897E5F898037CE2C47350DE3DC4D6C302
                        Uniqueness

                        Uniqueness Score: -1.00%

                        APIs
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_initialize_crt__scrt_release_startup_lock
                        • String ID:
                        • API String ID: 1452418845-0
                        • Opcode ID: 02bd2f8f1202d19f588490249a19570c034d6b83775ef71651d1b56b0c06cdeb
                        • Instruction ID: a4ce496bb267104f9e8ad8d7e2f1ff0087a29053a21f0503dd8feb613489cfb5
                        • Opcode Fuzzy Hash: 02bd2f8f1202d19f588490249a19570c034d6b83775ef71651d1b56b0c06cdeb
                        • Instruction Fuzzy Hash: 9041AD306006048BF759AB7898753E933B1AF65340F9CC52EB647872D7CEA94B848743
                        Uniqueness

                        Uniqueness Score: -1.00%

                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000003.00000002.395509512.0000018A52C71000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000018A52C71000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_18a52c71000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: CallTranslator
                        • String ID: MOC$RCC
                        • API String ID: 3163161869-2084237596
                        • Opcode ID: 837fe712d1c841b9689310fb0e3b5e3a97da388e70ee50221832e68052b7cfc4
                        • Instruction ID: 81bde4c076e1e1b1733f59470ed6b74a6f25149c309c0ba2c8b6186eda907934
                        • Opcode Fuzzy Hash: 837fe712d1c841b9689310fb0e3b5e3a97da388e70ee50221832e68052b7cfc4
                        • Instruction Fuzzy Hash: 30715A30518A0C8FEB68EF58D452BE9B7F0FF58310F58429EE549D3152DA74EA81CB86
                        Uniqueness

                        Uniqueness Score: -1.00%

                        APIs
                        Memory Dump Source
                        • Source File: 00000003.00000002.395310059.000000006D7C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 6D7C0000, based on PE: true
                        • Associated: 00000003.00000002.395304928.000000006D7C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395344757.000000006D7ED000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395364082.000000006D809000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395371412.000000006D80E000.00000004.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D813000.00000002.00000001.01000000.00000003.sdmpDownload File
                        • Associated: 00000003.00000002.395377221.000000006D818000.00000002.00000001.01000000.00000003.sdmpDownload File
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_3_2_6d7c0000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: CriticalSection$EnterLeavefree
                        • String ID:
                        • API String ID: 4020351045-0
                        • Opcode ID: 850590f39cbab215475ea261977678cee1c56e4dda0905269a505c2f615f3b60
                        • Instruction ID: bb1f2ce6b23d4df659204ec08620020be86bc7e7ed139501eec4f72df4f5847c
                        • Opcode Fuzzy Hash: 850590f39cbab215475ea261977678cee1c56e4dda0905269a505c2f615f3b60
                        • Instruction Fuzzy Hash: 79017172B14705CAEF09DF6AE9C432927E2F784B90F408426C91983350EF39D469C751
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Execution Graph

                        Execution Coverage:3.2%
                        Dynamic/Decrypted Code Coverage:100%
                        Signature Coverage:0%
                        Total number of Nodes:1041
                        Total number of Limit Nodes:14
                        execution_graph 5238 23e74401bc0 5239 23e74401bd0 5238->5239 5248 23e74406470 5239->5248 5241 23e74401bdc _RTC_Initialize 5242 23e74401c49 5241->5242 5254 23e74402064 5241->5254 5244 23e74401c09 5257 23e74405c8c 5244->5257 5246 23e74401c15 5246->5242 5286 23e7440655c 5246->5286 5249 23e74406481 5248->5249 5250 23e74406489 5249->5250 5251 23e74407adc __std_exception_copy RtlAllocateHeap 5249->5251 5250->5241 5252 23e74406498 5251->5252 5253 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5252->5253 5253->5250 5293 23e74402028 5254->5293 5256 23e7440206d 5256->5244 5258 23e74405cc3 5257->5258 5259 23e74405cac 5257->5259 5258->5246 5260 23e74405cb4 5259->5260 5261 23e74405cca 5259->5261 5262 23e74407adc __std_exception_copy RtlAllocateHeap 5260->5262 5263 23e74409084 RtlAllocateHeap 5261->5263 5264 23e74405cb9 5262->5264 5265 23e74405ccf 5263->5265 5266 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5264->5266 5339 23e74408768 5265->5339 5266->5258 5268 23e74405ce6 5348 23e74405a64 5268->5348 5270 23e74405d23 5271 23e74405d41 5270->5271 5272 23e74405d59 5270->5272 5273 23e74407adc __std_exception_copy RtlAllocateHeap 5271->5273 5274 23e74405a64 RtlAllocateHeap 5272->5274 5275 23e74405d46 5273->5275 5279 23e74405d75 5274->5279 5276 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5275->5276 5276->5258 5277 23e74405d7b 5278 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5277->5278 5278->5258 5279->5277 5280 23e74405dc0 5279->5280 5281 23e74405da7 5279->5281 5283 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5280->5283 5282 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5281->5282 5284 23e74405db0 5282->5284 5283->5277 5285 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5284->5285 5285->5258 5287 23e744072bc RtlAllocateHeap 5286->5287 5288 23e74406569 5287->5288 5289 23e7440659d 5288->5289 5290 23e74407adc __std_exception_copy RtlAllocateHeap 5288->5290 5289->5242 5291 23e74406592 5290->5291 5292 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5291->5292 5292->5289 5294 23e74402042 5293->5294 5295 23e7440203b 5293->5295 5297 23e744069c8 5294->5297 5295->5256 5300 23e74406604 5297->5300 5299 23e74406a0a 5299->5295 5301 23e74406620 Concurrency::details::SchedulerProxy::DeleteThis 5300->5301 5304 23e7440667c 5301->5304 5303 23e74406629 Concurrency::details::SchedulerProxy::DeleteThis 5303->5299 5305 23e744066a8 5304->5305 5313 23e7440673d 5304->5313 5312 23e74406719 5305->5312 5305->5313 5314 23e7440aaac 5305->5314 5307 23e7440aaac RtlAllocateHeap 5309 23e74406733 5307->5309 5308 23e7440670f 5310 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5308->5310 5311 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5309->5311 5310->5312 5311->5313 5312->5307 5312->5313 5313->5303 5315 23e7440aace 5314->5315 5316 23e7440aaeb 5314->5316 5315->5316 5317 23e7440aadc 5315->5317 5318 23e7440aaf5 5316->5318 5323 23e7440c608 5316->5323 5319 23e74407adc __std_exception_copy RtlAllocateHeap 5317->5319 5330 23e74406e2c 5318->5330 5322 23e7440aae1 __scrt_get_show_window_mode 5319->5322 5322->5308 5324 23e7440c611 5323->5324 5325 23e7440c62a 5323->5325 5326 23e74407adc __std_exception_copy RtlAllocateHeap 5324->5326 5327 23e7440c616 5326->5327 5328 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5327->5328 5329 23e7440c621 5328->5329 5329->5318 5331 23e74406e41 5330->5331 5332 23e74406e4b 5330->5332 5333 23e74406ee4 RtlAllocateHeap 5331->5333 5334 23e74406e50 5332->5334 5338 23e74406e57 __std_exception_copy 5332->5338 5336 23e74406e49 5333->5336 5335 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5334->5335 5335->5336 5336->5322 5337 23e74407adc __std_exception_copy RtlAllocateHeap 5337->5336 5338->5336 5338->5337 5340 23e744087a9 5339->5340 5341 23e744087c1 5340->5341 5343 23e744087ad 5340->5343 5342 23e744085a8 RtlAllocateHeap 5341->5342 5345 23e744087ef 5342->5345 5354 23e74407a50 5343->5354 5359 23e7440864c 5345->5359 5347 23e744087ba _log10_special 5347->5268 5350 23e74405aa2 5348->5350 5349 23e74409434 RtlAllocateHeap 5349->5350 5350->5349 5352 23e74405b0e 5350->5352 5351 23e74405bff 5351->5270 5352->5351 5353 23e74409434 RtlAllocateHeap 5352->5353 5353->5352 5355 23e74407434 __std_exception_copy RtlAllocateHeap 5354->5355 5356 23e74407a5d __free_lconv_mon 5355->5356 5357 23e74407434 __std_exception_copy RtlAllocateHeap 5356->5357 5358 23e74407a7f 5357->5358 5358->5347 5360 23e7440868b 5359->5360 5362 23e74408670 5359->5362 5363 23e744086ee 5360->5363 5364 23e74408690 5360->5364 5361 23e74407adc __std_exception_copy RtlAllocateHeap 5361->5362 5362->5347 5363->5362 5365 23e74407a50 RtlAllocateHeap 5363->5365 5364->5361 5364->5362 5366 23e744086fb 5365->5366 5367 23e74407adc __std_exception_copy RtlAllocateHeap 5366->5367 5367->5362 5435 23e74409d80 5436 23e74409d8c 5435->5436 5438 23e74409db3 5436->5438 5439 23e744098b4 5436->5439 5440 23e744098f4 5439->5440 5441 23e744098b9 5439->5441 5440->5436 5442 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5441->5442 5442->5440 5535 23e7440bb40 5540 23e7440bb5d 5535->5540 5536 23e7440bb62 5537 23e7440bb78 5536->5537 5538 23e74407adc __std_exception_copy RtlAllocateHeap 5536->5538 5539 23e7440bb6c 5538->5539 5541 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5539->5541 5540->5536 5540->5537 5542 23e7440bbac 5540->5542 5541->5537 5542->5537 5543 23e74407adc __std_exception_copy RtlAllocateHeap 5542->5543 5543->5539 5185 23e74409d44 5186 23e74409d54 Concurrency::details::SchedulerProxy::DeleteThis 5185->5186 5193 23e74409904 5186->5193 5188 23e74409d5d 5189 23e74409d6b Concurrency::details::SchedulerProxy::DeleteThis 5188->5189 5201 23e74409b4c 5188->5201 5194 23e74409923 5193->5194 5200 23e7440994c Concurrency::details::SchedulerProxy::DeleteThis 5193->5200 5195 23e74407adc __std_exception_copy RtlAllocateHeap 5194->5195 5196 23e74409928 5195->5196 5197 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5196->5197 5198 23e74409934 Concurrency::details::SchedulerProxy::DeleteThis 5197->5198 5198->5188 5200->5198 5209 23e7440980c 5200->5209 5202 23e74409b72 5201->5202 5203 23e74409904 RtlAllocateHeap 5202->5203 5204 23e74409baa 5202->5204 5203->5204 5205 23e74409c3c 5204->5205 5206 23e74409c5a 5205->5206 5207 23e74409d29 5206->5207 5208 23e74409cc8 GetFileType 5206->5208 5207->5189 5208->5206 5210 23e74407afc __std_exception_copy RtlAllocateHeap 5209->5210 5212 23e7440982d 5210->5212 5211 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5213 23e74409899 5211->5213 5212->5211 5213->5200 5544 23e7440b444 5545 23e7440b44f 5544->5545 5552 23e7440d394 5545->5552 5547 23e7440b454 5549 23e7440b485 5547->5549 5557 23e7440d448 5547->5557 5550 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5549->5550 5551 23e7440b491 5550->5551 5555 23e7440d3ad Concurrency::details::SchedulerProxy::DeleteThis 5552->5555 5553 23e7440d42d Concurrency::details::SchedulerProxy::DeleteThis 5553->5547 5555->5553 5556 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5555->5556 5561 23e7440d900 5555->5561 5556->5555 5558 23e7440d470 5557->5558 5559 23e7440d45c 5557->5559 5558->5547 5559->5558 5560 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5559->5560 5560->5558 5562 23e7440d930 5561->5562 5565 23e7440d7dc 5562->5565 5564 23e7440d949 5564->5555 5566 23e7440d7f7 5565->5566 5569 23e7440d825 5565->5569 5567 23e744078d4 _invalid_parameter_noinfo RtlAllocateHeap 5566->5567 5568 23e7440d817 5567->5568 5568->5564 5569->5568 5571 23e7440d858 5569->5571 5572 23e7440d873 5571->5572 5573 23e7440d898 5571->5573 5574 23e744078d4 _invalid_parameter_noinfo RtlAllocateHeap 5572->5574 5576 23e7440d893 5573->5576 5585 23e7440b1bc 5573->5585 5574->5576 5576->5568 5578 23e7440d448 RtlAllocateHeap 5579 23e7440d8b5 5578->5579 5591 23e7440b708 5579->5591 5584 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5584->5576 5586 23e7440b1e2 5585->5586 5590 23e7440b213 5585->5590 5587 23e7440b708 RtlAllocateHeap 5586->5587 5586->5590 5588 23e7440b203 5587->5588 5604 23e7440cf6c 5588->5604 5590->5578 5592 23e7440b711 5591->5592 5593 23e7440b721 5591->5593 5594 23e74407adc __std_exception_copy RtlAllocateHeap 5592->5594 5597 23e7440e2ec 5593->5597 5595 23e7440b716 5594->5595 5596 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5595->5596 5596->5593 5598 23e7440d8c7 5597->5598 5599 23e7440e318 5597->5599 5598->5576 5598->5584 5600 23e7440e37c 5599->5600 5602 23e7440e348 5599->5602 5601 23e744078d4 _invalid_parameter_noinfo RtlAllocateHeap 5600->5601 5601->5598 5608 23e7440e274 5602->5608 5605 23e7440cf95 5604->5605 5606 23e7440cfc2 5604->5606 5605->5590 5606->5605 5607 23e744078d4 _invalid_parameter_noinfo RtlAllocateHeap 5606->5607 5607->5605 5609 23e7440e290 5608->5609 5611 23e7440e2c5 5609->5611 5612 23e7440e3b0 5609->5612 5611->5598 5613 23e74409ab8 RtlAllocateHeap 5612->5613 5616 23e7440e3cc 5613->5616 5614 23e7440e3d2 5623 23e744099fc 5614->5623 5616->5614 5617 23e7440e40f 5616->5617 5618 23e74409ab8 RtlAllocateHeap 5616->5618 5617->5614 5619 23e74409ab8 RtlAllocateHeap 5617->5619 5620 23e7440e402 5618->5620 5619->5614 5621 23e74409ab8 RtlAllocateHeap 5620->5621 5621->5617 5622 23e7440e437 5622->5611 5624 23e74409a18 5623->5624 5625 23e74407adc __std_exception_copy RtlAllocateHeap 5624->5625 5628 23e74409a4b 5624->5628 5626 23e74409a8f 5625->5626 5627 23e74407abc RtlAllocateHeap 5626->5627 5627->5628 5628->5622 5922 23e74405304 5929 23e74405237 __CxxCallCatchBlock __FrameHandler3::GetHandlerSearchState 5922->5929 5923 23e7440532b 5924 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5923->5924 5925 23e74405330 5924->5925 5926 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5925->5926 5927 23e7440533b __FrameHandler3::GetHandlerSearchState 5925->5927 5926->5927 5928 23e744037ec RtlAllocateHeap Is_bad_exception_allowed 5928->5929 5929->5923 5929->5927 5929->5928 5930 23e74403814 __FrameHandler3::FrameUnwindToEmptyState RtlAllocateHeap 5929->5930 5930->5929 5931 23e7440f504 5932 23e74403798 __CxxCallCatchBlock RtlAllocateHeap 5931->5932 5935 23e7440f517 5932->5935 5933 23e7440f556 __CxxCallCatchBlock 5934 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5933->5934 5936 23e7440f56a 5934->5936 5935->5933 5938 23e74402908 __CxxCallCatchBlock RtlAllocateHeap 5935->5938 5937 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5936->5937 5939 23e7440f57a 5937->5939 5938->5933 5214 23e74401c88 5222 23e74402388 5214->5222 5443 23e7440f58a 5446 23e7440295c 5443->5446 5447 23e74402974 5446->5447 5448 23e74402986 5446->5448 5447->5448 5450 23e7440297c 5447->5450 5449 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5448->5449 5451 23e7440298b 5449->5451 5452 23e74402984 5450->5452 5453 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5450->5453 5451->5452 5454 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5451->5454 5455 23e744029ab 5453->5455 5454->5452 5456 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5455->5456 5457 23e744029b8 5456->5457 5458 23e74406b88 RtlAllocateHeap 5457->5458 5459 23e744029c1 5458->5459 5629 23e74404c4c 5630 23e74404c79 __except_validate_context_record 5629->5630 5631 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5630->5631 5632 23e74404c7e 5631->5632 5635 23e74404cd8 5632->5635 5637 23e74404d66 5632->5637 5645 23e74404d2c 5632->5645 5633 23e74404dd4 5633->5645 5670 23e74404418 5633->5670 5634 23e74404d53 5658 23e744033e8 5634->5658 5635->5634 5643 23e74404cfa __GetCurrentState 5635->5643 5635->5645 5640 23e74404d85 5637->5640 5664 23e744037ec 5637->5664 5640->5633 5640->5645 5667 23e74403800 5640->5667 5641 23e74404e7d 5643->5641 5646 23e744051e8 5643->5646 5647 23e744037ec Is_bad_exception_allowed RtlAllocateHeap 5646->5647 5648 23e74405217 __GetCurrentState 5647->5648 5649 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5648->5649 5655 23e74405234 __CxxCallCatchBlock __FrameHandler3::GetHandlerSearchState 5649->5655 5650 23e7440532b 5651 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5650->5651 5652 23e74405330 5651->5652 5653 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5652->5653 5654 23e7440533b __FrameHandler3::GetHandlerSearchState 5652->5654 5653->5654 5654->5645 5655->5650 5655->5654 5656 23e744037ec RtlAllocateHeap Is_bad_exception_allowed 5655->5656 5717 23e74403814 5655->5717 5656->5655 5659 23e74403407 __FrameHandler3::GetHandlerSearchState 5658->5659 5720 23e74403358 5659->5720 5662 23e744051e8 __FrameHandler3::FrameUnwindToEmptyState RtlAllocateHeap 5663 23e7440343c 5662->5663 5663->5645 5665 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5664->5665 5666 23e744037f5 5665->5666 5666->5640 5668 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5667->5668 5669 23e74403809 5668->5669 5669->5633 5674 23e7440447a __FrameHandler3::GetHandlerSearchState 5670->5674 5671 23e74404837 5679 23e74404879 _log10_special 5671->5679 5703 23e744047df __FrameHandler3::GetHandlerSearchState 5671->5703 5760 23e744048f0 5671->5760 5672 23e7440455f 5672->5671 5682 23e74404597 5672->5682 5673 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5673->5679 5674->5672 5676 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5674->5676 5674->5679 5675 23e74404768 5680 23e74404785 5675->5680 5681 23e744037ec Is_bad_exception_allowed RtlAllocateHeap 5675->5681 5675->5703 5678 23e744044c6 5676->5678 5678->5679 5683 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5678->5683 5679->5645 5686 23e744047a7 5680->5686 5680->5703 5756 23e744033bc 5680->5756 5681->5680 5682->5675 5702 23e74403800 RtlAllocateHeap 5682->5702 5738 23e74404b0c 5682->5738 5752 23e74404344 5682->5752 5685 23e744044d6 5683->5685 5687 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5685->5687 5688 23e744047bd 5686->5688 5686->5703 5715 23e744048c9 5686->5715 5689 23e744044df 5687->5689 5692 23e744037ec Is_bad_exception_allowed RtlAllocateHeap 5688->5692 5694 23e744047c8 5688->5694 5724 23e7440382c 5689->5724 5690 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5693 23e744048cf 5690->5693 5692->5694 5695 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5693->5695 5697 23e7440540c RtlAllocateHeap 5694->5697 5698 23e744048d8 5695->5698 5697->5703 5700 23e74406b88 RtlAllocateHeap 5698->5700 5699 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5701 23e74404521 5699->5701 5700->5679 5701->5672 5704 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5701->5704 5702->5682 5703->5673 5705 23e7440452d 5704->5705 5707 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5705->5707 5708 23e74404536 5707->5708 5727 23e7440540c 5708->5727 5712 23e7440454a 5734 23e744054fc 5712->5734 5714 23e74406b88 RtlAllocateHeap 5714->5715 5715->5690 5716 23e74404552 __CxxCallCatchBlock std::bad_alloc::bad_alloc 5716->5714 5718 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5717->5718 5719 23e74403822 5718->5719 5719->5655 5721 23e74403376 5720->5721 5722 23e744033a3 5721->5722 5723 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5721->5723 5722->5662 5723->5721 5725 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5724->5725 5726 23e7440383a 5725->5726 5726->5679 5726->5699 5728 23e744054f3 5727->5728 5733 23e74405437 5727->5733 5729 23e74404546 5729->5672 5729->5712 5730 23e74403800 RtlAllocateHeap 5730->5733 5731 23e744037ec Is_bad_exception_allowed RtlAllocateHeap 5731->5733 5732 23e74404b0c RtlAllocateHeap 5732->5733 5733->5729 5733->5730 5733->5731 5733->5732 5736 23e74405519 Is_bad_exception_allowed 5734->5736 5737 23e74405569 5734->5737 5735 23e744037ec RtlAllocateHeap Is_bad_exception_allowed 5735->5736 5736->5735 5736->5737 5737->5716 5739 23e74404b39 5738->5739 5750 23e74404bc8 5738->5750 5740 23e744037ec Is_bad_exception_allowed RtlAllocateHeap 5739->5740 5741 23e74404b42 5740->5741 5742 23e744037ec Is_bad_exception_allowed RtlAllocateHeap 5741->5742 5743 23e74404b5b 5741->5743 5741->5750 5742->5743 5744 23e74404b87 5743->5744 5745 23e744037ec Is_bad_exception_allowed RtlAllocateHeap 5743->5745 5743->5750 5746 23e74403800 RtlAllocateHeap 5744->5746 5745->5744 5747 23e74404b9b 5746->5747 5748 23e74404bb4 5747->5748 5749 23e744037ec Is_bad_exception_allowed RtlAllocateHeap 5747->5749 5747->5750 5751 23e74403800 RtlAllocateHeap 5748->5751 5749->5748 5750->5682 5751->5750 5753 23e74404381 __FrameHandler3::GetHandlerSearchState 5752->5753 5754 23e744037ec Is_bad_exception_allowed RtlAllocateHeap 5753->5754 5755 23e744043b9 5754->5755 5755->5682 5757 23e744033d0 __FrameHandler3::GetHandlerSearchState 5756->5757 5758 23e74403358 __FrameHandler3::ExecutionInCatch RtlAllocateHeap 5757->5758 5759 23e744033da 5758->5759 5759->5686 5761 23e74404926 5760->5761 5764 23e74404994 5760->5764 5762 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5761->5762 5763 23e7440492b 5762->5763 5765 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5763->5765 5770 23e74404990 5763->5770 5764->5703 5766 23e7440494a 5765->5766 5766->5770 5771 23e74403304 5766->5771 5768 23e744037ec RtlAllocateHeap Is_bad_exception_allowed 5768->5770 5769 23e74404344 RtlAllocateHeap 5769->5770 5770->5764 5770->5768 5770->5769 5772 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5771->5772 5773 23e74403330 5772->5773 5773->5770 5463 23e7440d48c 5464 23e7440d495 5463->5464 5466 23e7440d4a2 5463->5466 5465 23e74407adc __std_exception_copy RtlAllocateHeap 5464->5465 5468 23e7440d49a 5465->5468 5467 23e74407adc __std_exception_copy RtlAllocateHeap 5466->5467 5466->5468 5469 23e7440d4d9 5467->5469 5470 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5469->5470 5470->5468 5940 23e74405e14 5941 23e74405e29 5940->5941 5942 23e74405e2d 5940->5942 5943 23e74409084 RtlAllocateHeap 5942->5943 5944 23e74405e32 5943->5944 5955 23e744095e0 5944->5955 5947 23e74405e3f 5950 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5947->5950 5948 23e74405e4b 5967 23e74405e88 5948->5967 5950->5941 5952 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5953 23e74405e72 5952->5953 5954 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5953->5954 5954->5941 5956 23e744095ff 5955->5956 5956->5956 5957 23e74406ee4 RtlAllocateHeap 5956->5957 5958 23e74405e37 5956->5958 5959 23e7440967b 5957->5959 5958->5947 5958->5948 5960 23e74409683 5959->5960 5961 23e7440968c 5959->5961 5962 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5960->5962 5963 23e744096b3 5961->5963 5964 23e744096bd 5961->5964 5962->5958 5965 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5963->5965 5966 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5964->5966 5965->5958 5966->5958 5968 23e74405ead 5967->5968 5969 23e74407afc __std_exception_copy RtlAllocateHeap 5968->5969 5982 23e74405ee3 5969->5982 5970 23e74405eeb 5971 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5970->5971 5972 23e74405e53 5971->5972 5972->5952 5973 23e74405f5e 5974 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5973->5974 5974->5972 5975 23e74407afc __std_exception_copy RtlAllocateHeap 5975->5982 5976 23e74405f4d 5977 23e74405f98 RtlAllocateHeap 5976->5977 5979 23e74405f55 5977->5979 5978 23e74406bb4 __std_exception_copy RtlAllocateHeap 5978->5982 5980 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5979->5980 5980->5970 5981 23e74405f83 _invalid_parameter_noinfo 5982->5970 5982->5973 5982->5975 5982->5976 5982->5978 5982->5981 5983 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5982->5983 5983->5982 5471 23e74402398 5472 23e744023b0 5471->5472 5473 23e744023cc 5471->5473 5472->5473 5480 23e744029c4 5472->5480 5478 23e74406b88 RtlAllocateHeap 5479 23e744023f2 5478->5479 5481 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5480->5481 5482 23e744023de 5481->5482 5483 23e744029d8 5482->5483 5484 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5483->5484 5485 23e744023ea 5484->5485 5485->5478 5774 23e74408258 5775 23e744082ba 5774->5775 5776 23e744085a8 RtlAllocateHeap 5775->5776 5777 23e7440833a 5776->5777 5784 23e74407b88 5777->5784 5780 23e744085a8 RtlAllocateHeap 5781 23e74408431 5780->5781 5801 23e74407d04 5781->5801 5783 23e7440849d 5785 23e74407bb2 5784->5785 5786 23e74407bd6 5784->5786 5788 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5785->5788 5790 23e74407bc1 5785->5790 5787 23e74407bdb 5786->5787 5793 23e74407c30 5786->5793 5789 23e74407bf0 5787->5789 5787->5790 5791 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5787->5791 5788->5790 5792 23e74406ee4 RtlAllocateHeap 5789->5792 5790->5780 5791->5789 5792->5790 5794 23e74407c53 5793->5794 5795 23e74407c81 5793->5795 5796 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5793->5796 5794->5790 5798 23e74407a50 RtlAllocateHeap 5794->5798 5797 23e74406ee4 RtlAllocateHeap 5795->5797 5796->5795 5797->5794 5799 23e74407c60 5798->5799 5800 23e74407adc __std_exception_copy RtlAllocateHeap 5799->5800 5800->5790 5802 23e74407d2e 5801->5802 5803 23e74407d52 5801->5803 5805 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5802->5805 5809 23e74407d3d 5802->5809 5804 23e74407d58 5803->5804 5808 23e74407dac 5803->5808 5806 23e74407d6d 5804->5806 5804->5809 5810 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5804->5810 5805->5809 5807 23e74406ee4 RtlAllocateHeap 5806->5807 5807->5809 5811 23e74407e08 5808->5811 5812 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5808->5812 5815 23e74407dd7 5808->5815 5809->5783 5810->5806 5813 23e74406ee4 RtlAllocateHeap 5811->5813 5812->5811 5813->5815 5814 23e74407a50 RtlAllocateHeap 5816 23e74407de4 5814->5816 5815->5809 5815->5814 5817 23e74407adc __std_exception_copy RtlAllocateHeap 5816->5817 5817->5809 5223 23e74406259 5231 23e74406b88 5223->5231 5225 23e7440625e 5226 23e7440615c RtlAllocateHeap 5225->5226 5227 23e7440630b 5226->5227 5228 23e74406312 5227->5228 5229 23e74406328 ExitProcess 5227->5229 5230 23e74406324 5229->5230 5232 23e744072bc RtlAllocateHeap 5231->5232 5233 23e74406b91 5232->5233 5368 23e7440f2d8 5370 23e7440f2ed 5368->5370 5369 23e7440f300 5370->5369 5377 23e74402e5c 5370->5377 5372 23e7440f310 5373 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5372->5373 5374 23e7440f319 5373->5374 5375 23e74406b88 RtlAllocateHeap 5374->5375 5376 23e7440f322 5375->5376 5380 23e74402e78 5377->5380 5379 23e74402e65 5379->5372 5381 23e74402e90 5380->5381 5382 23e74402e97 __CxxCallCatchBlock __vcrt_FlsSetValue 5380->5382 5381->5379 5382->5381 5383 23e74405828 __std_exception_copy RtlAllocateHeap 5382->5383 5383->5381 5486 23e7440d798 5487 23e7440d6ec 5486->5487 5490 23e74409ab8 5487->5490 5489 23e7440d713 5491 23e74409ac1 5490->5491 5492 23e74409ad6 5490->5492 5502 23e74407abc 5491->5502 5494 23e74407abc RtlAllocateHeap 5492->5494 5497 23e74409ace 5492->5497 5498 23e74409b11 5494->5498 5496 23e74407adc __std_exception_copy RtlAllocateHeap 5496->5497 5497->5489 5499 23e74407adc __std_exception_copy RtlAllocateHeap 5498->5499 5500 23e74409b19 5499->5500 5501 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5500->5501 5501->5497 5503 23e74407434 __std_exception_copy RtlAllocateHeap 5502->5503 5504 23e74407ac5 5503->5504 5504->5496 5505 23e7440c098 5506 23e7440c0a0 5505->5506 5507 23e7440c0b5 5506->5507 5508 23e7440c0ce 5506->5508 5509 23e74407adc __std_exception_copy RtlAllocateHeap 5507->5509 5511 23e744085a8 RtlAllocateHeap 5508->5511 5513 23e7440c0c5 5508->5513 5510 23e7440c0ba 5509->5510 5512 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5510->5512 5511->5513 5512->5513 5384 23e74405fdc 5385 23e74405ff1 5384->5385 5386 23e74405fec 5384->5386 5388 23e74405f98 5386->5388 5389 23e74405fce 5388->5389 5390 23e74405f9d 5388->5390 5389->5385 5391 23e74405fc6 5390->5391 5392 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5390->5392 5393 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5391->5393 5392->5390 5393->5389 5984 23e74404f1c 5985 23e74405758 5984->5985 5986 23e7440576f 5985->5986 5987 23e74405828 __std_exception_copy RtlAllocateHeap 5985->5987 5987->5986 5394 23e7440f4df 5397 23e74405160 5394->5397 5398 23e7440517f 5397->5398 5400 23e744051d0 5397->5400 5399 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5398->5399 5398->5400 5399->5400 5401 23e74406ae0 5402 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5401->5402 5403 23e74406af0 5402->5403 5404 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5403->5404 5405 23e74406b04 5404->5405 5406 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5405->5406 5407 23e74406b18 5406->5407 5408 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5407->5408 5409 23e74406b2c 5408->5409 5518 23e7440f5a0 5519 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5518->5519 5520 23e7440f5ae 5519->5520 5521 23e7440f5b9 5520->5521 5522 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5520->5522 5522->5521 5818 23e7440e760 5821 23e7440e780 5818->5821 5823 23e7440e79a 5821->5823 5822 23e7440e77b 5823->5822 5825 23e7440e5c0 5823->5825 5826 23e7440e600 _raise_exc _log10_special 5825->5826 5827 23e7440e6a9 5826->5827 5828 23e7440e679 5826->5828 5836 23e7440ebb0 5827->5836 5832 23e7440e49c 5828->5832 5831 23e7440e6a7 _log10_special 5831->5822 5833 23e7440e4e0 _log10_special 5832->5833 5834 23e7440e4f5 5833->5834 5835 23e7440ebb0 _log10_special RtlAllocateHeap 5833->5835 5834->5831 5835->5834 5837 23e7440ebd0 5836->5837 5838 23e7440ebb9 5836->5838 5839 23e74407adc __std_exception_copy RtlAllocateHeap 5837->5839 5840 23e7440ebc8 5838->5840 5841 23e74407adc __std_exception_copy RtlAllocateHeap 5838->5841 5839->5840 5840->5831 5841->5840 5988 23e7440b322 5989 23e7440b34e 5988->5989 5990 23e74407afc __std_exception_copy RtlAllocateHeap 5989->5990 5991 23e7440b36d 5990->5991 5992 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5991->5992 5993 23e7440b37b 5992->5993 5994 23e74407afc __std_exception_copy RtlAllocateHeap 5993->5994 5997 23e7440b3a5 5993->5997 5995 23e7440b397 5994->5995 5996 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5995->5996 5996->5997 4867 23e74401ca4 4884 23e74401e68 4867->4884 4869 23e74401cb8 __scrt_get_show_window_mode __scrt_acquire_startup_lock __scrt_release_startup_lock 4869->4867 4872 23e74401d03 4869->4872 4873 23e74401ae0 4869->4873 4888 23e74406060 4869->4888 4893 23e74402a30 4873->4893 4876 23e74401b27 CreateMutexExA 4878 23e74401b80 4876->4878 4879 23e74401baa 4878->4879 4895 23e74401770 4878->4895 4879->4869 4881 23e74401b8c 4910 23e744012c0 RegOpenKeyExA 4881->4910 4883 23e74401b91 MessageBoxA 4883->4879 5040 23e7440246c 4884->5040 4887 23e74401e93 __scrt_initialize_crt 4887->4869 5042 23e74409084 4888->5042 4890 23e744060b5 4890->4869 4892 23e7440606f 4892->4890 5048 23e74409434 4892->5048 4894 23e74401aff GetComputerNameA 4893->4894 4894->4876 4896 23e74401794 __scrt_get_show_window_mode 4895->4896 4897 23e744017fc FindFirstFileA 4896->4897 4899 23e7440181a __scrt_get_show_window_mode 4897->4899 4901 23e74401aa9 4897->4901 4898 23e744018e2 4898->4881 4899->4898 4902 23e74401992 4899->4902 4922 23e74405828 4899->4922 4901->4881 4903 23e74405828 __std_exception_copy RtlAllocateHeap 4902->4903 4904 23e74401a29 4902->4904 4903->4904 4904->4901 4905 23e74405828 __std_exception_copy RtlAllocateHeap 4904->4905 4906 23e74401a95 4905->4906 4907 23e74405828 __std_exception_copy RtlAllocateHeap 4906->4907 4908 23e74401a9d 4907->4908 4926 23e74401240 4908->4926 4911 23e7440173e 4910->4911 4921 23e74401300 __scrt_get_show_window_mode 4910->4921 4911->4883 4912 23e74401351 4912->4883 4913 23e7440171a 4915 23e74401736 4913->4915 4916 23e74401240 RtlAllocateHeap 4913->4916 4914 23e744013d4 RegEnumKeyExA 4914->4921 4917 23e74405828 __std_exception_copy RtlAllocateHeap 4915->4917 4916->4915 4917->4911 4918 23e74401451 RegOpenKeyExA 4918->4911 4918->4921 4919 23e74401701 RegCloseKey 4919->4921 4920 23e7440154d RegEnumValueA 4920->4921 4921->4912 4921->4913 4921->4914 4921->4918 4921->4919 4921->4920 4924 23e74406ea8 __free_lconv_mon 4922->4924 4923 23e74406ede 4923->4902 4924->4923 4930 23e74407adc 4924->4930 4927 23e74401260 4926->4927 4929 23e74401297 4927->4929 5036 23e74401000 4927->5036 4929->4901 4933 23e74407434 4930->4933 4934 23e74407449 __std_exception_copy 4933->4934 4942 23e74407465 4934->4942 4944 23e74407afc 4934->4944 4936 23e74407496 __std_exception_copy 4937 23e744074a4 __std_exception_copy 4936->4937 4938 23e744074d2 4936->4938 4948 23e74406ea8 4937->4948 4952 23e7440706c 4938->4952 4942->4923 4943 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4943->4942 4945 23e74407b0d __std_exception_copy 4944->4945 4946 23e74407b42 RtlAllocateHeap 4945->4946 4947 23e74407b5c __std_exception_copy 4945->4947 4946->4945 4946->4947 4947->4936 4949 23e74406ede 4948->4949 4950 23e74406ead __free_lconv_mon 4948->4950 4949->4942 4950->4949 4951 23e74407adc __std_exception_copy RtlAllocateHeap 4950->4951 4951->4949 4953 23e7440711e __std_exception_copy 4952->4953 4956 23e74406fc4 4953->4956 4955 23e74407133 4955->4943 4957 23e74406fe0 Concurrency::details::SchedulerProxy::DeleteThis 4956->4957 4960 23e74407254 4957->4960 4959 23e74406ff6 Concurrency::details::SchedulerProxy::DeleteThis 4959->4955 4961 23e74407270 Concurrency::details::SchedulerProxy::DeleteThis 4960->4961 4962 23e7440729c Concurrency::details::SchedulerProxy::DeleteThis 4960->4962 4961->4962 4964 23e7440a290 4961->4964 4962->4959 4965 23e7440a32c 4964->4965 4968 23e7440a2b3 4964->4968 4966 23e7440a37f 4965->4966 4969 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4965->4969 5030 23e7440a430 4966->5030 4968->4965 4970 23e7440a2f2 4968->4970 4975 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4968->4975 4971 23e7440a350 4969->4971 4973 23e7440a314 4970->4973 4980 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4970->4980 4972 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4971->4972 4976 23e7440a364 4972->4976 4974 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4973->4974 4977 23e7440a320 4974->4977 4978 23e7440a2e6 4975->4978 4979 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4976->4979 4982 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4977->4982 4990 23e74409dc0 4978->4990 4985 23e7440a373 4979->4985 4986 23e7440a308 4980->4986 4981 23e7440a3ea 4982->4965 4983 23e74406ea8 RtlAllocateHeap __free_lconv_mon 4988 23e7440a38b 4983->4988 4989 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4985->4989 5018 23e74409ecc 4986->5018 4988->4981 4988->4983 4989->4966 4991 23e74409ec4 4990->4991 4992 23e74409dc9 4990->4992 4991->4970 4993 23e74409de3 4992->4993 4994 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4992->4994 4995 23e74409df5 4993->4995 4996 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4993->4996 4994->4993 4997 23e74409e07 4995->4997 4998 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4995->4998 4996->4995 4999 23e74409e19 4997->4999 5000 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4997->5000 4998->4997 5001 23e74409e2b 4999->5001 5002 23e74406ea8 __free_lconv_mon RtlAllocateHeap 4999->5002 5000->4999 5003 23e74409e3d 5001->5003 5005 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5001->5005 5002->5001 5004 23e74409e4f 5003->5004 5006 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5003->5006 5007 23e74409e61 5004->5007 5008 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5004->5008 5005->5003 5006->5004 5009 23e74409e73 5007->5009 5010 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5007->5010 5008->5007 5011 23e74409e85 5009->5011 5012 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5009->5012 5010->5009 5013 23e74409e9a 5011->5013 5015 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5011->5015 5012->5011 5014 23e74409eaf 5013->5014 5016 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5013->5016 5014->4991 5017 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5014->5017 5015->5013 5016->5014 5017->4991 5019 23e74409ed1 5018->5019 5027 23e74409f32 5018->5027 5020 23e74409eea 5019->5020 5021 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5019->5021 5022 23e74409efc 5020->5022 5023 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5020->5023 5021->5020 5024 23e74409f0e 5022->5024 5025 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5022->5025 5023->5022 5026 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5024->5026 5028 23e74409f20 5024->5028 5025->5024 5026->5028 5027->4973 5028->5027 5029 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5028->5029 5029->5027 5031 23e7440a435 5030->5031 5032 23e7440a461 5030->5032 5031->5032 5033 23e74409f6c Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5031->5033 5032->4988 5034 23e7440a459 5033->5034 5035 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5034->5035 5035->5032 5038 23e74401048 5036->5038 5037 23e744011b4 5037->4927 5038->5037 5039 23e74405828 __std_exception_copy RtlAllocateHeap 5038->5039 5039->5037 5041 23e74401e8a __scrt_dllmain_crt_thread_attach 5040->5041 5041->4887 5043 23e74409091 5042->5043 5044 23e744090d6 5042->5044 5052 23e74407390 5043->5052 5044->4892 5046 23e744090c0 5063 23e74408d5c 5046->5063 5049 23e744093c0 5048->5049 5050 23e744085a8 RtlAllocateHeap 5049->5050 5051 23e744093e4 5050->5051 5051->4892 5053 23e744073a1 __std_exception_copy 5052->5053 5054 23e74407afc __std_exception_copy RtlAllocateHeap 5053->5054 5055 23e744073ae 5053->5055 5056 23e744073d8 __std_exception_copy 5054->5056 5055->5046 5057 23e74407414 5056->5057 5058 23e744073e6 __std_exception_copy 5056->5058 5059 23e7440706c __std_exception_copy RtlAllocateHeap 5057->5059 5060 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5058->5060 5061 23e7440741c 5059->5061 5060->5055 5062 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5061->5062 5062->5055 5086 23e74408fcc 5063->5086 5070 23e74408dc7 5071 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5070->5071 5085 23e74408dae 5071->5085 5072 23e74408dd6 5101 23e74409100 5072->5101 5074 23e74408ec9 5075 23e74408ed2 5074->5075 5079 23e74408eec 5074->5079 5076 23e74407adc __std_exception_copy RtlAllocateHeap 5075->5076 5078 23e74408ed7 5076->5078 5077 23e74408f2d 5080 23e74408f94 5077->5080 5106 23e7440888c 5077->5106 5081 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5078->5081 5079->5077 5082 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5079->5082 5084 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5080->5084 5081->5085 5082->5077 5084->5085 5085->5044 5087 23e74408fef Concurrency::details::SchedulerProxy::DeleteThis 5086->5087 5088 23e74408ff9 Concurrency::details::SchedulerProxy::DeleteThis 5087->5088 5090 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5087->5090 5089 23e74408d91 5088->5089 5091 23e74407390 RtlAllocateHeap 5088->5091 5094 23e74408a5c 5089->5094 5090->5088 5092 23e744090c0 5091->5092 5093 23e74408d5c RtlAllocateHeap 5092->5093 5093->5089 5118 23e744085a8 5094->5118 5096 23e74408a70 5096->5085 5097 23e74406ee4 5096->5097 5100 23e74406ef3 __std_exception_copy 5097->5100 5098 23e74407adc __std_exception_copy RtlAllocateHeap 5099 23e74406f2d 5098->5099 5099->5070 5099->5072 5100->5098 5100->5099 5102 23e74408a5c RtlAllocateHeap 5101->5102 5105 23e7440912d __scrt_get_show_window_mode 5102->5105 5103 23e74409283 _log10_special 5103->5074 5105->5103 5148 23e74408b74 5105->5148 5107 23e744088a8 Concurrency::details::SchedulerProxy::DeleteThis __scrt_get_show_window_mode 5106->5107 5108 23e74407adc __std_exception_copy RtlAllocateHeap 5107->5108 5111 23e744088d5 __scrt_get_show_window_mode 5107->5111 5109 23e74408944 5108->5109 5157 23e744079a0 5109->5157 5112 23e74407adc __std_exception_copy RtlAllocateHeap 5111->5112 5116 23e74408987 5111->5116 5113 23e744089e5 5112->5113 5114 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5113->5114 5114->5116 5115 23e74408a21 Concurrency::details::SchedulerProxy::DeleteThis 5115->5080 5116->5115 5117 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5116->5117 5117->5115 5119 23e744085c7 5118->5119 5120 23e744085cc 5118->5120 5119->5096 5120->5119 5124 23e744072bc 5120->5124 5122 23e744085e7 5135 23e7440b4b8 5122->5135 5125 23e744072d1 __std_exception_copy 5124->5125 5126 23e74407afc __std_exception_copy RtlAllocateHeap 5125->5126 5127 23e744072ed 5125->5127 5128 23e7440731e __std_exception_copy 5126->5128 5127->5122 5129 23e7440732c __std_exception_copy 5128->5129 5130 23e7440735a 5128->5130 5132 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5129->5132 5131 23e7440706c __std_exception_copy RtlAllocateHeap 5130->5131 5133 23e74407362 5131->5133 5132->5127 5134 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5133->5134 5134->5127 5136 23e7440b4e0 5135->5136 5137 23e7440b4cd 5135->5137 5136->5119 5137->5136 5139 23e7440a538 5137->5139 5140 23e744072bc RtlAllocateHeap 5139->5140 5141 23e7440a547 Concurrency::details::SchedulerProxy::DeleteThis 5140->5141 5143 23e7440a580 Concurrency::details::SchedulerProxy::DeleteThis 5141->5143 5144 23e7440a5a8 5141->5144 5143->5136 5145 23e7440a5c7 5144->5145 5146 23e7440a5ba Concurrency::details::SchedulerProxy::DeleteThis 5144->5146 5145->5143 5146->5145 5147 23e7440a290 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5146->5147 5147->5145 5149 23e74408bb1 5148->5149 5153 23e74408ca7 _log10_special 5148->5153 5149->5153 5154 23e7440c468 5149->5154 5151 23e74408c6e 5152 23e7440c468 RtlAllocateHeap 5151->5152 5152->5153 5153->5103 5155 23e744085a8 RtlAllocateHeap 5154->5155 5156 23e7440c48d 5155->5156 5156->5151 5160 23e74407838 5157->5160 5159 23e744079b9 5159->5111 5161 23e74407863 5160->5161 5164 23e744078d4 5161->5164 5163 23e7440788a 5163->5159 5170 23e7440761c 5164->5170 5166 23e7440790f 5166->5163 5167 23e744078fe _invalid_parameter_noinfo 5167->5166 5168 23e74407838 _invalid_parameter_noinfo RtlAllocateHeap 5167->5168 5169 23e744079b9 5168->5169 5169->5163 5171 23e74407663 5170->5171 5172 23e74407638 5170->5172 5171->5167 5174 23e744074fc 5172->5174 5175 23e7440751b __std_exception_copy 5174->5175 5176 23e74407528 5175->5176 5177 23e74407afc __std_exception_copy RtlAllocateHeap 5175->5177 5176->5171 5178 23e74407552 __std_exception_copy 5177->5178 5179 23e7440758e 5178->5179 5180 23e74407560 __std_exception_copy 5178->5180 5181 23e7440706c __std_exception_copy RtlAllocateHeap 5179->5181 5182 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5180->5182 5183 23e74407596 5181->5183 5182->5176 5184 23e74406ea8 __free_lconv_mon RtlAllocateHeap 5183->5184 5184->5176 5842 23e7440c764 5843 23e7440c7e9 5842->5843 5847 23e7440c800 5843->5847 5848 23e74406cf0 5843->5848 5845 23e7440b590 RtlAllocateHeap 5845->5847 5846 23e7440cb2c _log10_special 5847->5845 5847->5846 5849 23e74406d07 5848->5849 5852 23e7440b4ec 5849->5852 5851 23e74406d2f 5851->5847 5853 23e7440b505 5852->5853 5854 23e7440b518 5852->5854 5853->5854 5855 23e7440a538 RtlAllocateHeap 5853->5855 5854->5851 5855->5854 5523 23e7440f3a6 5524 23e7440f3be 5523->5524 5530 23e7440f429 5523->5530 5525 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5524->5525 5524->5530 5526 23e7440f40b 5525->5526 5527 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5526->5527 5528 23e7440f420 5527->5528 5529 23e74406b88 RtlAllocateHeap 5528->5529 5529->5530 5410 23e74404ee8 5413 23e744056c8 5410->5413 5414 23e744056e9 5413->5414 5418 23e74404f11 5413->5418 5415 23e7440571e 5414->5415 5414->5418 5419 23e74406bb4 5414->5419 5417 23e74405828 __std_exception_copy RtlAllocateHeap 5415->5417 5417->5418 5420 23e74406bc1 5419->5420 5421 23e74406bcb 5419->5421 5420->5421 5426 23e74406be6 5420->5426 5422 23e74407adc __std_exception_copy RtlAllocateHeap 5421->5422 5423 23e74406bd2 5422->5423 5424 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 5423->5424 5425 23e74406bde 5424->5425 5425->5415 5426->5425 5427 23e74407adc __std_exception_copy RtlAllocateHeap 5426->5427 5427->5423 5428 23e744029ec 5429 23e74406b88 RtlAllocateHeap 5428->5429 5430 23e744029f5 5429->5430 5998 23e7440652c 6001 23e744064b0 5998->6001 6000 23e74406555 6003 23e744064ce Concurrency::details::SchedulerProxy::DeleteThis 6001->6003 6002 23e74406507 Concurrency::details::SchedulerProxy::DeleteThis 6002->6000 6003->6002 6004 23e7440a5a8 RtlAllocateHeap 6003->6004 6004->6003 5856 23e7440f16c 5857 23e7440f1a8 5856->5857 5858 23e7440f1d4 5857->5858 5860 23e74403844 5857->5860 5861 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5860->5861 5862 23e7440386e 5861->5862 5863 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5862->5863 5864 23e7440387b 5863->5864 5865 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5864->5865 5866 23e74403884 5865->5866 5866->5858 5867 23e7440506e 5868 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5867->5868 5869 23e7440507b __CxxCallCatchBlock 5868->5869 5878 23e74403798 5869->5878 5871 23e74405117 __CxxCallCatchBlock 5872 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5871->5872 5873 23e7440512a 5872->5873 5874 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5873->5874 5876 23e74405133 5874->5876 5879 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5878->5879 5880 23e744037aa 5879->5880 5881 23e744037e5 5880->5881 5882 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5880->5882 5883 23e744037b5 5882->5883 5883->5881 5884 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5883->5884 5885 23e744037d6 5884->5885 5885->5871 5886 23e74402908 5885->5886 5887 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5886->5887 5888 23e74402916 5887->5888 5888->5871 6005 23e7440b730 6006 23e7440b75d 6005->6006 6007 23e74407adc __std_exception_copy RtlAllocateHeap 6006->6007 6010 23e7440b772 _log10_special 6006->6010 6008 23e7440b767 6007->6008 6009 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 6008->6009 6009->6010 6011 23e74404f30 6014 23e74405758 6011->6014 6013 23e74404f52 6015 23e7440576f 6014->6015 6016 23e74405767 6014->6016 6015->6013 6017 23e74405828 __std_exception_copy RtlAllocateHeap 6016->6017 6017->6015 5889 23e74404f74 5890 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5889->5890 5891 23e74404fa9 5890->5891 5892 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5891->5892 5893 23e74404fb7 __except_validate_context_record 5892->5893 5894 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5893->5894 5895 23e74404ffb 5894->5895 5896 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5895->5896 5897 23e74405004 5896->5897 5898 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5897->5898 5899 23e7440500d 5898->5899 5912 23e7440375c 5899->5912 5902 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5903 23e7440503d __CxxCallCatchBlock 5902->5903 5904 23e74403798 __CxxCallCatchBlock RtlAllocateHeap 5903->5904 5905 23e744050ee 5904->5905 5910 23e74402908 __CxxCallCatchBlock RtlAllocateHeap 5905->5910 5911 23e74405117 __CxxCallCatchBlock 5905->5911 5906 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5907 23e7440512a 5906->5907 5908 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5907->5908 5909 23e74405133 5908->5909 5910->5911 5911->5906 5913 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5912->5913 5914 23e7440376d 5913->5914 5915 23e74403778 5914->5915 5916 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5914->5916 5917 23e74402e5c __CxxCallCatchBlock RtlAllocateHeap 5915->5917 5916->5915 5918 23e74403789 5917->5918 5918->5902 5918->5903 5431 23e74405ff8 5432 23e74406008 5431->5432 5433 23e7440600d 5431->5433 5434 23e74405f98 RtlAllocateHeap 5432->5434 5434->5433 6018 23e7440ae39 6019 23e74407adc __std_exception_copy RtlAllocateHeap 6018->6019 6020 23e7440ae3e 6019->6020 6021 23e744079a0 _invalid_parameter_noinfo RtlAllocateHeap 6020->6021 6022 23e7440adf4 6021->6022 6023 23e74405c3a 6024 23e74405c3c 6023->6024 6025 23e74407afc __std_exception_copy RtlAllocateHeap 6024->6025 6028 23e74405c7c 6024->6028 6026 23e74405c72 6025->6026 6027 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6026->6027 6027->6028 5234 23e74407afc 5235 23e74407b0d __std_exception_copy 5234->5235 5236 23e74407b42 RtlAllocateHeap 5235->5236 5237 23e74407b5c __std_exception_copy 5235->5237 5236->5235 5236->5237 5531 23e744075bc 5532 23e744075cc 5531->5532 5533 23e74407434 __std_exception_copy RtlAllocateHeap 5532->5533 5534 23e744075d7 __vcrt_uninitialize_ptd 5532->5534 5533->5534 6029 23e7440713c 6030 23e74407141 6029->6030 6031 23e74407156 6029->6031 6035 23e7440715c 6030->6035 6034 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6034->6031 6036 23e7440719e 6035->6036 6037 23e744071a6 6035->6037 6038 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6036->6038 6039 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6037->6039 6038->6037 6040 23e744071b3 6039->6040 6041 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6040->6041 6042 23e744071c0 6041->6042 6043 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6042->6043 6044 23e744071cd 6043->6044 6045 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6044->6045 6046 23e744071da 6045->6046 6047 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6046->6047 6048 23e744071e7 6047->6048 6049 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6048->6049 6050 23e744071f4 6049->6050 6051 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6050->6051 6052 23e74407201 6051->6052 6053 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6052->6053 6054 23e74407211 6053->6054 6055 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6054->6055 6056 23e74407221 6055->6056 6061 23e7440700c 6056->6061 6058 23e74407236 6065 23e74406f84 6058->6065 6060 23e7440714e 6060->6034 6062 23e74407028 Concurrency::details::SchedulerProxy::DeleteThis 6061->6062 6063 23e74407058 Concurrency::details::SchedulerProxy::DeleteThis 6062->6063 6064 23e74406ea8 __free_lconv_mon RtlAllocateHeap 6062->6064 6063->6058 6064->6063 6066 23e74406fa0 Concurrency::details::SchedulerProxy::DeleteThis 6065->6066 6067 23e74407254 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6066->6067 6068 23e74406fae Concurrency::details::SchedulerProxy::DeleteThis 6067->6068 6068->6060 6069 23e74402e3c 6070 23e74402e56 6069->6070 6071 23e74402e45 6069->6071 6071->6070 6072 23e74405828 __std_exception_copy RtlAllocateHeap 6071->6072 6072->6070

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: Open$Enum
                        • String ID:
                        • API String ID: 462099255-0
                        • Opcode ID: 2a02730be39cc75ee99e02b240c38d7de0b4f72d589f073dcba7369fd32cc831
                        • Instruction ID: de3d4758aca3cf4c16084ddb2ca82a40c8023e1a9589ae1236b2693d0edcdebe
                        • Opcode Fuzzy Hash: 2a02730be39cc75ee99e02b240c38d7de0b4f72d589f073dcba7369fd32cc831
                        • Instruction Fuzzy Hash: B3D15431618B888FEB65DF18DC896DAB7E1FF94304F00465EE44AD71A0EF349A55CB82
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ExceptionFilterUnhandled_invalid_parameter_noinfo
                        • String ID:
                        • API String ID: 59578552-0
                        • Opcode ID: f95e01fbf38a281d9255cdf92b69475522e65d4a66deb1467f342da968b848f1
                        • Instruction ID: 6aec0a9db2d8784e590509387ff1d882cc94a85cb697c8bcdc867a85c7399a41
                        • Opcode Fuzzy Hash: f95e01fbf38a281d9255cdf92b69475522e65d4a66deb1467f342da968b848f1
                        • Instruction Fuzzy Hash: CEE08630F155055AFD1B32B93C4E2ACB080BF15320F920295B412851F6F96D4EBC7E63
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: FileFindFirst
                        • String ID:
                        • API String ID: 1974802433-0
                        • Opcode ID: 81c7c7fd01d69da00775a62d13099b4ead950d999e7021fb467b756ffc4a194f
                        • Instruction ID: 4e1e1e3e254a9111b3c2134d41c1f3ebac822f345be21d4e5aaa30e495a74e45
                        • Opcode Fuzzy Hash: 81c7c7fd01d69da00775a62d13099b4ead950d999e7021fb467b756ffc4a194f
                        • Instruction Fuzzy Hash: 5BA1A731618A484BEB25EF24EC596EA73E1FF94301F11465AE44BD31E1EF389E198F81
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ComputerCreateMessageMutexName
                        • String ID:
                        • API String ID: 2342047096-0
                        • Opcode ID: bf0b7409f839259ce88bb476a521653d71adaaef5a7294aa3565bebdb25f1347
                        • Instruction ID: 9f77004288b2eee607d68843c466d522ed202f7b259a1cd2de01f79405e53001
                        • Opcode Fuzzy Hash: bf0b7409f839259ce88bb476a521653d71adaaef5a7294aa3565bebdb25f1347
                        • Instruction Fuzzy Hash: 2421C930618A448BE719EB34EC8D5AAB7F1FFD9305F45497DF08BC60A1FE7985058A41
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 157 23e74409c3c-23e74409c58 158 23e74409c5a-23e74409c83 157->158 159 23e74409c8f-23e74409c98 158->159 160 23e74409c85-23e74409c8a 158->160 162 23e74409cb0 159->162 163 23e74409c9a-23e74409c9d 159->163 161 23e74409d1a-23e74409d23 160->161 161->158 164 23e74409d29-23e74409d43 161->164 167 23e74409cb5-23e74409cc6 162->167 165 23e74409c9f-23e74409ca7 163->165 166 23e74409ca9-23e74409cae 163->166 165->167 166->167 169 23e74409cf5-23e74409d0d 167->169 170 23e74409cc8-23e74409cd3 GetFileType 167->170 169->161 172 23e74409d0f-23e74409d13 169->172 170->169 171 23e74409cd5-23e74409ce0 170->171 173 23e74409ce2-23e74409ce7 171->173 174 23e74409ce9-23e74409cec 171->174 172->161 173->161 174->161 175 23e74409cee-23e74409cf3 174->175 175->161
                        APIs
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: FileType
                        • String ID:
                        • API String ID: 3081899298-0
                        • Opcode ID: 39dc1a5228bf1e06e61612b5fff79bc4169a93c7aa8ff714042cd5f5cd4a771e
                        • Instruction ID: a46beccc6ea7d252a6377e1d517694b9d0ed0ce9402e9ba96b66e73af81ccdd2
                        • Opcode Fuzzy Hash: 39dc1a5228bf1e06e61612b5fff79bc4169a93c7aa8ff714042cd5f5cd4a771e
                        • Instruction Fuzzy Hash: 1631F631908E595FDBA69F2C9888660B6C0FF06320F210389E41AC71F4D638DDA5EB80
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: AllocateHeap
                        • String ID:
                        • API String ID: 1279760036-0
                        • Opcode ID: 30d4bf1e297d70a882b7f1add7ff9fded3996ca996f5e333fb51e94ed5290b56
                        • Instruction ID: cd90a9c2b81a5109d353a5afc8d016f5f7efdfc98a7a584ac98fa61c9e8d5842
                        • Opcode Fuzzy Hash: 30d4bf1e297d70a882b7f1add7ff9fded3996ca996f5e333fb51e94ed5290b56
                        • Instruction Fuzzy Hash: 8101A420B10E0A0FFF5A6BB9688D375B1D4FF68301F5640B56405C61F1FD5DCE68AA62
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ExitProcess
                        • String ID:
                        • API String ID: 621844428-0
                        • Opcode ID: 0c3185d8b51bac4eb50b0166e6d79b52d76e7ad81d5639061b00e529f1dc9730
                        • Instruction ID: 0658f419da243905a560682eda60c9ab19abe282b0dba0f49a48e21cc09d6628
                        • Opcode Fuzzy Hash: 0c3185d8b51bac4eb50b0166e6d79b52d76e7ad81d5639061b00e529f1dc9730
                        • Instruction Fuzzy Hash: 90D05E207012045BFF2CBBB0AD8D26D66528F44205F00186CA947CB6E7DD7D8C1E8B81
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 199 23e74404418-23e74404480 call 23e74405374 202 23e74404486-23e74404489 199->202 203 23e744048e7-23e744048ef call 23e74406c14 199->203 202->203 204 23e7440448f-23e74404495 202->204 206 23e74404564-23e74404576 204->206 207 23e7440449b-23e7440449f 204->207 209 23e74404837-23e7440483b 206->209 210 23e7440457c-23e74404580 206->210 207->206 211 23e744044a5-23e744044b0 207->211 214 23e74404874-23e7440487e call 23e74402e5c 209->214 215 23e7440483d-23e74404844 209->215 210->209 212 23e74404586-23e74404591 210->212 211->206 213 23e744044b6-23e744044bb 211->213 212->209 217 23e74404597-23e7440459e 212->217 213->206 218 23e744044c1-23e744044cb call 23e74402e5c 213->218 214->203 225 23e74404880-23e7440489f call 23e7440ee40 214->225 215->203 219 23e7440484a-23e7440486f call 23e744048f0 215->219 221 23e744045a4-23e744045db call 23e74403518 217->221 222 23e74404768-23e74404774 217->222 218->225 233 23e744044d1-23e744044fc call 23e74402e5c * 2 call 23e7440382c 218->233 219->214 221->222 237 23e744045e1-23e744045ea 221->237 222->214 226 23e7440477a-23e7440477e 222->226 230 23e7440478e-23e74404796 226->230 231 23e74404780-23e7440478c call 23e744037ec 226->231 230->214 236 23e7440479c-23e744047a9 call 23e744033bc 230->236 231->230 243 23e744047af-23e744047b7 231->243 267 23e744044fe-23e74404502 233->267 268 23e7440451c-23e74404526 call 23e74402e5c 233->268 236->214 236->243 241 23e744045ed-23e7440461f 237->241 245 23e74404625-23e74404630 241->245 246 23e7440475b-23e74404762 241->246 248 23e744048ca-23e744048e6 call 23e74402e5c * 2 call 23e74406b88 243->248 249 23e744047bd-23e744047c1 243->249 245->246 250 23e74404636-23e7440464f 245->250 246->222 246->241 248->203 254 23e744047c3-23e744047d2 call 23e744037ec 249->254 255 23e744047d4-23e744047d5 249->255 256 23e74404655-23e7440469a call 23e74403800 * 2 250->256 257 23e74404748-23e7440474d 250->257 263 23e744047d7-23e744047e1 call 23e7440540c 254->263 255->263 280 23e744046d8-23e744046de 256->280 281 23e7440469c-23e744046c2 call 23e74403800 call 23e74404b0c 256->281 260 23e74404758-23e74404759 257->260 260->246 263->214 278 23e744047e7-23e74404835 call 23e7440344c call 23e74403658 263->278 267->268 272 23e74404504-23e7440450f 267->272 268->206 284 23e74404528-23e74404548 call 23e74402e5c * 2 call 23e7440540c 268->284 272->268 277 23e74404511-23e74404516 272->277 277->203 277->268 278->214 288 23e7440474f-23e74404750 280->288 289 23e744046e0-23e744046e4 280->289 299 23e744046c4-23e744046d6 281->299 300 23e744046e9-23e74404746 call 23e74404344 281->300 305 23e7440455f-23e74404560 284->305 306 23e7440454a-23e74404554 call 23e744054fc 284->306 290 23e74404754-23e74404755 288->290 289->256 290->260 299->280 299->281 300->290 305->206 309 23e744048c4-23e744048c9 call 23e74406b88 306->309 310 23e7440455a-23e744048c3 call 23e74402894 call 23e74404ec8 call 23e74405780 306->310 309->248 310->309
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                        • String ID: csm$csm$csm
                        • API String ID: 849930591-393685449
                        • Opcode ID: 2ed4cc99f58428dff43d3f01cc5e852e5bb786ad8812c5a133ade536f624ce79
                        • Instruction ID: 600d82a612ddb50816f3332c61958366e95c0b0d3da3835875c150543bdccc75
                        • Opcode Fuzzy Hash: 2ed4cc99f58428dff43d3f01cc5e852e5bb786ad8812c5a133ade536f624ce79
                        • Instruction Fuzzy Hash: 14F1A330A18B088BEF65EF5894897A9B7E0FF55310F110699D449C32E2EB34DE95DB82
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 320 23e74402630-23e74402676 call 23e74402e04 323 23e74402758-23e7440275f 320->323 324 23e7440267c-23e74402682 320->324 326 23e744027fa-23e744027fe 323->326 325 23e74402686-23e74402688 324->325 328 23e74402804 325->328 329 23e7440268e-23e7440269a 325->329 327 23e74402764-23e74402770 326->327 326->328 333 23e74402776-23e7440277d 327->333 334 23e744027f8 327->334 330 23e74402809-23e74402826 328->330 331 23e744026a0-23e744026a7 329->331 332 23e7440274a-23e7440274c 329->332 331->332 336 23e744026ad-23e744026b2 331->336 332->325 333->334 335 23e7440277f-23e74402787 333->335 334->326 337 23e74402789-23e7440278e 335->337 338 23e744027cd-23e744027d3 335->338 336->332 339 23e744026b8-23e744026bd 336->339 340 23e74402790-23e7440279e 337->340 341 23e744027c8-23e744027cb 337->341 342 23e744027e1-23e744027f5 338->342 343 23e744027d5-23e744027d8 338->343 344 23e744026bf-23e744026d2 339->344 345 23e744026d6-23e744026dd 339->345 346 23e744027c0-23e744027c6 340->346 347 23e744027a0-23e744027a8 340->347 341->328 341->338 342->334 343->334 348 23e744027da-23e744027dd 343->348 359 23e74402751-23e74402753 344->359 360 23e744026d4 344->360 349 23e744026df-23e744026e7 345->349 350 23e74402707-23e74402745 call 23e74402dd0 call 23e74402e00 345->350 346->340 346->341 347->346 352 23e744027aa-23e744027b3 347->352 348->328 354 23e744027df 348->354 349->350 351 23e744026e9-23e744026f7 call 23e7440ed00 349->351 350->332 351->350 362 23e744026f9-23e744026ff 351->362 352->346 357 23e744027b5-23e744027be 352->357 354->334 357->341 357->346 359->330 360->332 360->345 362->350
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: CurrentImageNonwritable__except_validate_context_record
                        • String ID: csm$f
                        • API String ID: 3242871069-629598281
                        • Opcode ID: cbb6678aba45670b62180b90d032deeebbb74b39f1951d1e686324c8961a414a
                        • Instruction ID: 8a0ae7ae3f61cdac43a9df49b57c57a21490e03fb4e8819b834722079fcd058d
                        • Opcode Fuzzy Hash: cbb6678aba45670b62180b90d032deeebbb74b39f1951d1e686324c8961a414a
                        • Instruction Fuzzy Hash: 6561C530B18A058BEF69AF1CE889724B3D1FF54350F5141ADE84AC31E2F634EE659E85
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 365 23e74404c4c-23e74404c94 call 23e74402e04 call 23e74402e5c 370 23e74404cce-23e74404cd2 365->370 371 23e74404c96-23e74404c9c 365->371 372 23e74404d66-23e74404d6a 370->372 373 23e74404cd8-23e74404cdc 370->373 371->370 374 23e74404c9e-23e74404ca0 371->374 377 23e74404dae-23e74404db4 372->377 378 23e74404d6c-23e74404d78 372->378 375 23e74404ce2-23e74404cea 373->375 376 23e74404e5d 373->376 379 23e74404cb2-23e74404cb4 374->379 380 23e74404ca2-23e74404ca6 374->380 375->376 385 23e74404cf0-23e74404cf4 375->385 388 23e74404e62-23e74404e7c 376->388 383 23e74404e24-23e74404e58 call 23e74404418 377->383 384 23e74404db6-23e74404dba 377->384 386 23e74404d8e-23e74404d9a 378->386 387 23e74404d7a-23e74404d7e 378->387 379->370 381 23e74404cb6-23e74404cc2 379->381 380->381 382 23e74404ca8-23e74404cb0 380->382 381->370 390 23e74404cc4-23e74404cc8 381->390 382->370 382->379 383->376 384->383 389 23e74404dbc-23e74404dc3 384->389 391 23e74404d53-23e74404d61 call 23e744033e8 385->391 392 23e74404cf6-23e74404cf8 385->392 386->376 395 23e74404da0-23e74404da8 386->395 387->386 394 23e74404d80-23e74404d8c call 23e744037ec 387->394 389->383 396 23e74404dc5-23e74404dcd 389->396 390->370 390->376 391->376 398 23e74404d31-23e74404d33 392->398 399 23e74404cfa-23e74404d0c call 23e7440401c 392->399 394->377 394->386 395->376 395->377 396->383 402 23e74404dcf-23e74404de2 call 23e74403800 396->402 398->391 401 23e74404d35-23e74404d3d 398->401 407 23e74404e7d-23e74404e83 call 23e74406c14 399->407 412 23e74404d12-23e74404d15 399->412 406 23e74404d43-23e74404d47 401->406 401->407 402->383 416 23e74404de4-23e74404e22 402->416 406->407 410 23e74404d4d-23e74404d51 406->410 415 23e74404d21-23e74404d2c call 23e744051e8 410->415 412->407 417 23e74404d1b-23e74404d1f 412->417 415->376 416->388 417->415
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
                        • String ID: csm$csm
                        • API String ID: 3896166516-3733052814
                        • Opcode ID: 179d466ca7e911971df6fec40f864e8670ee48de26d9b50b7fdfc5552c99cf0b
                        • Instruction ID: 5be523eaa13b5c78e7e1f61555636035a90755f1a1d8ab7bb81fe9b9b4280a84
                        • Opcode Fuzzy Hash: 179d466ca7e911971df6fec40f864e8670ee48de26d9b50b7fdfc5552c99cf0b
                        • Instruction Fuzzy Hash: 8371C030B54A048FEFA99B189088764B3D0FF54311F16469AD449C76F2EB389DA8DB82
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_initialize_crt__scrt_release_startup_lock
                        • String ID:
                        • API String ID: 1452418845-0
                        • Opcode ID: 02bd2f8f1202d19f588490249a19570c034d6b83775ef71651d1b56b0c06cdeb
                        • Instruction ID: b7b2ae1d30f5d94b2c93b8c79fb690bd498079225ed35077708972a1574ef83f
                        • Opcode Fuzzy Hash: 02bd2f8f1202d19f588490249a19570c034d6b83775ef71651d1b56b0c06cdeb
                        • Instruction Fuzzy Hash: 8041B320F002044AFF5AA774B45D3E9B2E1AF55304F0645A9A546872F3FE2E5F2CAE41
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000004.00000002.389783943.0000023E74401000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000023E74401000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_4_2_23e74401000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: CallTranslator
                        • String ID: MOC$RCC
                        • API String ID: 3163161869-2084237596
                        • Opcode ID: 837fe712d1c841b9689310fb0e3b5e3a97da388e70ee50221832e68052b7cfc4
                        • Instruction ID: 822f80332b5d4f6feab5aecb2d9ebca9d4db58e707d42be5f189512b25cc7340
                        • Opcode Fuzzy Hash: 837fe712d1c841b9689310fb0e3b5e3a97da388e70ee50221832e68052b7cfc4
                        • Instruction Fuzzy Hash: 25718F30A18B0C8FEB55EF98E4457A9B7E0FF58300F11029EE445D31A2E778EA55CB82
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Execution Graph

                        Execution Coverage:2.7%
                        Dynamic/Decrypted Code Coverage:100%
                        Signature Coverage:0%
                        Total number of Nodes:1217
                        Total number of Limit Nodes:17
                        execution_graph 6454 17fe20a652c 6457 17fe20a64b0 6454->6457 6456 17fe20a6555 6459 17fe20a64ce Concurrency::details::SchedulerProxy::DeleteThis 6457->6459 6458 17fe20a6507 Concurrency::details::SchedulerProxy::DeleteThis 6458->6456 6459->6458 6460 17fe20aa5a8 _invalid_parameter_noinfo RtlAllocateHeap 6459->6460 6460->6459 6461 17fe20ab322 6462 17fe20ab34e 6461->6462 6463 17fe20a7afc _invalid_parameter_noinfo RtlAllocateHeap 6462->6463 6464 17fe20ab36d 6463->6464 6465 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6464->6465 6466 17fe20ab37b 6465->6466 6467 17fe20ab3a5 6466->6467 6468 17fe20a7afc _invalid_parameter_noinfo RtlAllocateHeap 6466->6468 6469 17fe20ab397 6468->6469 6470 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6469->6470 6470->6467 5699 17fe20af5a0 5704 17fe20a2e5c 5699->5704 5702 17fe20af5b9 5703 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 5703->5702 5710 17fe20a2e78 5704->5710 5707 17fe20a2e6a 5707->5702 5707->5703 5708 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 5709 17fe20a2e74 5708->5709 5711 17fe20a2e65 5710->5711 5712 17fe20a2e97 _CreateFrameInfo __vcrt_FlsSetValue 5710->5712 5711->5707 5711->5708 5712->5711 5713 17fe20a5828 __std_exception_destroy RtlAllocateHeap 5712->5713 5713->5711 5714 17fe20af3a6 5715 17fe20af3be 5714->5715 5721 17fe20af429 5714->5721 5716 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 5715->5716 5715->5721 5717 17fe20af40b 5716->5717 5718 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 5717->5718 5719 17fe20af420 5718->5719 5720 17fe20a6b88 RtlAllocateHeap 5719->5720 5720->5721 5506 17fe20a1ca4 5523 17fe20a1e68 5506->5523 5508 17fe20a1d03 5509 17fe20a1cb8 __scrt_get_show_window_mode __scrt_acquire_startup_lock __scrt_release_startup_lock 5509->5506 5509->5508 5512 17fe20a1ae0 5509->5512 5527 17fe20a6060 5509->5527 5532 17fe20a2a30 5512->5532 5515 17fe20a1b6b CreateMutexExA 5517 17fe20a1b80 5515->5517 5516 17fe20a1b27 5516->5515 5516->5516 5518 17fe20a1baa 5517->5518 5534 17fe20a1770 5517->5534 5518->5509 5520 17fe20a1b8c 5549 17fe20a12c0 RegOpenKeyExA 5520->5549 5522 17fe20a1b91 MessageBoxA 5522->5518 5573 17fe20a246c 5523->5573 5526 17fe20a1e93 __scrt_initialize_crt 5526->5509 5575 17fe20a9084 5527->5575 5529 17fe20a60b5 5529->5509 5530 17fe20a606f 5530->5529 5581 17fe20a9434 5530->5581 5533 17fe20a1aff GetComputerNameA 5532->5533 5533->5516 5535 17fe20a1794 __scrt_get_show_window_mode 5534->5535 5536 17fe20a17fc FindFirstFileA 5535->5536 5538 17fe20a181a __scrt_get_show_window_mode 5536->5538 5540 17fe20a1aa9 5536->5540 5537 17fe20a18e2 5537->5520 5538->5537 5541 17fe20a1992 5538->5541 5561 17fe20a5828 5538->5561 5540->5520 5542 17fe20a5828 __std_exception_destroy RtlAllocateHeap 5541->5542 5543 17fe20a1a29 5541->5543 5542->5543 5543->5540 5544 17fe20a5828 __std_exception_destroy RtlAllocateHeap 5543->5544 5545 17fe20a1a95 5544->5545 5546 17fe20a5828 __std_exception_destroy RtlAllocateHeap 5545->5546 5547 17fe20a1a9d 5546->5547 5565 17fe20a1240 5547->5565 5556 17fe20a173e 5549->5556 5560 17fe20a1300 __scrt_get_show_window_mode 5549->5560 5550 17fe20a1351 5550->5522 5551 17fe20a171a 5553 17fe20a1736 5551->5553 5554 17fe20a1240 RtlAllocateHeap 5551->5554 5552 17fe20a13d4 RegEnumKeyExA 5552->5560 5555 17fe20a5828 __std_exception_destroy RtlAllocateHeap 5553->5555 5554->5553 5555->5556 5556->5522 5557 17fe20a1451 RegOpenKeyExA 5557->5556 5557->5560 5558 17fe20a1701 RegCloseKey 5558->5560 5559 17fe20a154d RegEnumValueA 5559->5560 5560->5550 5560->5551 5560->5552 5560->5557 5560->5558 5560->5559 5563 17fe20a6ea8 __free_lconv_num 5561->5563 5562 17fe20a6ede 5562->5541 5563->5562 5564 17fe20a7adc __std_exception_copy RtlAllocateHeap 5563->5564 5564->5562 5566 17fe20a1260 5565->5566 5568 17fe20a1297 5566->5568 5569 17fe20a1000 5566->5569 5568->5540 5571 17fe20a1048 5569->5571 5570 17fe20a11b4 5570->5566 5571->5570 5572 17fe20a5828 __std_exception_destroy RtlAllocateHeap 5571->5572 5572->5570 5574 17fe20a1e8a __scrt_dllmain_crt_thread_attach 5573->5574 5574->5526 5576 17fe20a90d6 5575->5576 5577 17fe20a9091 5575->5577 5576->5530 5585 17fe20a7390 5577->5585 5582 17fe20a93c0 5581->5582 5583 17fe20a85a8 RtlAllocateHeap 5582->5583 5584 17fe20a93e4 5583->5584 5584->5530 5586 17fe20a73a1 _invalid_parameter_noinfo 5585->5586 5587 17fe20a73ae 5586->5587 5589 17fe20a7afc _invalid_parameter_noinfo RtlAllocateHeap 5586->5589 5588 17fe20a73b4 5587->5588 5590 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 5587->5590 5599 17fe20a8d5c 5588->5599 5592 17fe20a73d8 _invalid_parameter_noinfo 5589->5592 5591 17fe20a7431 5590->5591 5593 17fe20a7414 5592->5593 5594 17fe20a73e6 _invalid_parameter_noinfo 5592->5594 5595 17fe20a706c _invalid_parameter_noinfo RtlAllocateHeap 5593->5595 5596 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5594->5596 5597 17fe20a741c 5595->5597 5596->5587 5598 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5597->5598 5598->5588 5622 17fe20a8fcc 5599->5622 5601 17fe20a8d91 5633 17fe20a8a5c 5601->5633 5606 17fe20a8dc7 5607 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5606->5607 5620 17fe20a8dae 5607->5620 5608 17fe20a8dd6 5608->5608 5642 17fe20a9100 5608->5642 5610 17fe20a8ec9 5611 17fe20a8eec 5610->5611 5612 17fe20a8ed2 5610->5612 5615 17fe20a8f2d 5611->5615 5617 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5611->5617 5613 17fe20a7adc __std_exception_copy RtlAllocateHeap 5612->5613 5614 17fe20a8ed7 5613->5614 5616 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5614->5616 5621 17fe20a8f94 5615->5621 5647 17fe20a888c 5615->5647 5616->5620 5617->5615 5619 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5619->5620 5620->5576 5621->5619 5627 17fe20a8fef Concurrency::details::SchedulerProxy::DeleteThis 5622->5627 5623 17fe20a906b 5623->5601 5624 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 5626 17fe20a9083 5624->5626 5625 17fe20a8ff9 Concurrency::details::SchedulerProxy::DeleteThis 5625->5623 5625->5624 5628 17fe20a90d6 5626->5628 5630 17fe20a7390 RtlAllocateHeap 5626->5630 5627->5625 5629 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5627->5629 5628->5601 5629->5625 5631 17fe20a90c0 5630->5631 5632 17fe20a8d5c 2 API calls 5631->5632 5632->5628 5659 17fe20a85a8 5633->5659 5635 17fe20a8a70 5635->5620 5636 17fe20a6ee4 5635->5636 5637 17fe20a6f2f 5636->5637 5641 17fe20a6ef3 _invalid_parameter_noinfo 5636->5641 5639 17fe20a7adc __std_exception_copy RtlAllocateHeap 5637->5639 5638 17fe20a6f16 RtlAllocateHeap 5640 17fe20a6f2d 5638->5640 5638->5641 5639->5640 5640->5606 5640->5608 5641->5637 5641->5638 5643 17fe20a8a5c RtlAllocateHeap 5642->5643 5646 17fe20a912d __scrt_get_show_window_mode 5643->5646 5645 17fe20a9283 _log10_special 5645->5610 5646->5645 5669 17fe20a8b74 5646->5669 5649 17fe20a88a8 Concurrency::details::SchedulerProxy::DeleteThis __scrt_get_show_window_mode 5647->5649 5648 17fe20a7adc __std_exception_copy RtlAllocateHeap 5650 17fe20a8944 5648->5650 5649->5648 5652 17fe20a88d5 __scrt_get_show_window_mode 5649->5652 5651 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 5650->5651 5651->5652 5653 17fe20a7adc __std_exception_copy RtlAllocateHeap 5652->5653 5657 17fe20a8987 5652->5657 5654 17fe20a89e5 5653->5654 5655 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 5654->5655 5655->5657 5656 17fe20a8a21 Concurrency::details::SchedulerProxy::DeleteThis 5656->5621 5657->5656 5658 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5657->5658 5658->5656 5660 17fe20a85cc 5659->5660 5664 17fe20a85c7 5659->5664 5661 17fe20a72bc __CxxCallCatchBlock RtlAllocateHeap 5660->5661 5660->5664 5662 17fe20a85e7 5661->5662 5665 17fe20ab4b8 5662->5665 5664->5635 5666 17fe20ab4cd 5665->5666 5667 17fe20ab4e0 5665->5667 5666->5667 5668 17fe20aa538 _invalid_parameter_noinfo RtlAllocateHeap 5666->5668 5667->5664 5668->5667 5673 17fe20a8bb1 5669->5673 5676 17fe20a8ca7 _log10_special 5669->5676 5671 17fe20a8c3b 5684 17fe20ac468 5671->5684 5673->5676 5677 17fe20aa074 5673->5677 5675 17fe20ac468 RtlAllocateHeap 5675->5676 5676->5645 5678 17fe20a85a8 RtlAllocateHeap 5677->5678 5679 17fe20aa0b6 5678->5679 5680 17fe20a6ee4 2 API calls 5679->5680 5681 17fe20aa0f3 _log10_special 5679->5681 5683 17fe20aa11c __scrt_get_show_window_mode 5679->5683 5680->5683 5681->5671 5682 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5682->5681 5683->5681 5683->5682 5685 17fe20a85a8 RtlAllocateHeap 5684->5685 5686 17fe20ac48d 5685->5686 5689 17fe20ac134 5686->5689 5688 17fe20a8c6e 5688->5675 5691 17fe20ac175 5689->5691 5690 17fe20ac43d _log10_special 5690->5688 5691->5690 5692 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5691->5692 5692->5690 5930 17fe20a5c3a 5932 17fe20a5c3c 5930->5932 5931 17fe20a5c7c 5932->5931 5933 17fe20a7afc _invalid_parameter_noinfo RtlAllocateHeap 5932->5933 5934 17fe20a5c72 5933->5934 5935 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5934->5935 5935->5931 5722 17fe20a75bc 5723 17fe20a75cc 5722->5723 5724 17fe20a7434 __std_exception_copy RtlAllocateHeap 5723->5724 5725 17fe20a75d7 __vcrt_uninitialize_ptd 5723->5725 5724->5725 5945 17fe20a2e3c 5946 17fe20a2e45 5945->5946 5947 17fe20a2e56 5945->5947 5946->5947 5948 17fe20a5828 __std_exception_destroy RtlAllocateHeap 5946->5948 5948->5947 6474 17fe20a713c 6475 17fe20a7141 6474->6475 6479 17fe20a7156 6474->6479 6480 17fe20a715c 6475->6480 6478 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6478->6479 6481 17fe20a71a6 6480->6481 6482 17fe20a719e 6480->6482 6484 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6481->6484 6483 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6482->6483 6483->6481 6485 17fe20a71b3 6484->6485 6486 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6485->6486 6487 17fe20a71c0 6486->6487 6488 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6487->6488 6489 17fe20a71cd 6488->6489 6490 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6489->6490 6491 17fe20a71da 6490->6491 6492 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6491->6492 6493 17fe20a71e7 6492->6493 6494 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6493->6494 6495 17fe20a71f4 6494->6495 6496 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6495->6496 6497 17fe20a7201 6496->6497 6498 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6497->6498 6499 17fe20a7211 6498->6499 6500 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6499->6500 6501 17fe20a7221 6500->6501 6506 17fe20a700c 6501->6506 6503 17fe20a7236 6510 17fe20a6f84 6503->6510 6505 17fe20a714e 6505->6478 6507 17fe20a7028 Concurrency::details::SchedulerProxy::DeleteThis 6506->6507 6508 17fe20a7058 Concurrency::details::SchedulerProxy::DeleteThis 6507->6508 6509 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6507->6509 6508->6503 6509->6508 6511 17fe20a6fa0 Concurrency::details::SchedulerProxy::DeleteThis 6510->6511 6512 17fe20a7254 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 6511->6512 6513 17fe20a6fae Concurrency::details::SchedulerProxy::DeleteThis 6512->6513 6513->6505 6514 17fe20a4f30 6517 17fe20a5758 6514->6517 6516 17fe20a4f52 6518 17fe20a5767 6517->6518 6519 17fe20a576f 6517->6519 6520 17fe20a5828 __std_exception_destroy RtlAllocateHeap 6518->6520 6519->6516 6520->6519 6521 17fe20ab730 6522 17fe20ab75d 6521->6522 6523 17fe20a7adc __std_exception_copy RtlAllocateHeap 6522->6523 6526 17fe20ab772 _log10_special 6522->6526 6524 17fe20ab767 6523->6524 6525 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 6524->6525 6525->6526 5949 17fe20a4c4c 5950 17fe20a4c79 __except_validate_context_record 5949->5950 5951 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 5950->5951 5952 17fe20a4c7e 5951->5952 5954 17fe20a4cd8 5952->5954 5956 17fe20a4d66 5952->5956 5971 17fe20a4d2c 5952->5971 5953 17fe20a4d85 5967 17fe20a4dd4 5953->5967 5953->5971 6008 17fe20a3800 5953->6008 5955 17fe20a4d53 5954->5955 5959 17fe20a4cfa 5954->5959 5960 17fe20a4d31 5954->5960 5954->5971 5996 17fe20a33e8 5955->5996 5956->5953 6005 17fe20a37ec 5956->6005 5972 17fe20a401c 5959->5972 5960->5955 5964 17fe20a4d09 5960->5964 5963 17fe20a4e7d 5968 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 5963->5968 5964->5963 5966 17fe20a4d1b 5964->5966 5977 17fe20a51e8 5966->5977 5967->5971 6011 17fe20a4418 5967->6011 5969 17fe20a4e82 5968->5969 5973 17fe20a402a 5972->5973 5974 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 5973->5974 5976 17fe20a403b 5973->5976 5975 17fe20a4081 5974->5975 5976->5964 5978 17fe20a37ec Is_bad_exception_allowed RtlAllocateHeap 5977->5978 5979 17fe20a5217 5978->5979 6066 17fe20a3f78 5979->6066 5982 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 5994 17fe20a5234 __CxxCallCatchBlock __FrameHandler3::GetHandlerSearchState 5982->5994 5983 17fe20a532b 5984 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 5983->5984 5985 17fe20a5330 5984->5985 5988 17fe20a533b 5985->5988 5989 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 5985->5989 5986 17fe20a5366 5987 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 5986->5987 5987->5988 5990 17fe20a5348 __FrameHandler3::GetHandlerSearchState 5988->5990 5991 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 5988->5991 5989->5988 5990->5971 5992 17fe20a5371 5991->5992 5993 17fe20a37ec RtlAllocateHeap Is_bad_exception_allowed 5993->5994 5994->5983 5994->5986 5994->5993 6070 17fe20a3814 5994->6070 6073 17fe20a344c 5996->6073 6003 17fe20a51e8 __FrameHandler3::FrameUnwindToEmptyState RtlAllocateHeap 6004 17fe20a343c 6003->6004 6004->5971 6006 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6005->6006 6007 17fe20a37f5 6006->6007 6007->5953 6009 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6008->6009 6010 17fe20a3809 6009->6010 6010->5967 6085 17fe20a5374 6011->6085 6013 17fe20a4879 6014 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 6013->6014 6024 17fe20a4880 _log10_special 6013->6024 6016 17fe20a48ec 6014->6016 6015 17fe20a455f 6017 17fe20a4837 6015->6017 6019 17fe20a4597 6015->6019 6017->6013 6051 17fe20a47f9 6017->6051 6143 17fe20a48f0 6017->6143 6018 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6018->6013 6022 17fe20a4768 6019->6022 6113 17fe20a3518 6019->6113 6027 17fe20a4785 6022->6027 6028 17fe20a37ec Is_bad_exception_allowed RtlAllocateHeap 6022->6028 6022->6051 6023 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6026 17fe20a44c6 6023->6026 6024->5971 6026->6024 6029 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6026->6029 6033 17fe20a47a7 6027->6033 6027->6051 6138 17fe20a33bc 6027->6138 6028->6027 6030 17fe20a44d6 6029->6030 6032 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6030->6032 6035 17fe20a44df 6032->6035 6034 17fe20a47bd 6033->6034 6033->6051 6064 17fe20a48c9 6033->6064 6036 17fe20a47c8 6034->6036 6039 17fe20a37ec Is_bad_exception_allowed RtlAllocateHeap 6034->6039 6097 17fe20a382c 6035->6097 6043 17fe20a540c RtlAllocateHeap 6036->6043 6037 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6040 17fe20a48cf 6037->6040 6039->6036 6042 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6040->6042 6044 17fe20a48d8 6042->6044 6045 17fe20a47df 6043->6045 6047 17fe20a6b88 RtlAllocateHeap 6044->6047 6049 17fe20a344c __FrameHandler3::GetHandlerSearchState RtlAllocateHeap 6045->6049 6045->6051 6046 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6048 17fe20a4521 6046->6048 6047->6013 6048->6015 6052 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6048->6052 6049->6051 6050 17fe20a3800 RtlAllocateHeap 6058 17fe20a45c6 6050->6058 6051->6018 6053 17fe20a452d 6052->6053 6055 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6053->6055 6056 17fe20a4536 6055->6056 6100 17fe20a540c 6056->6100 6058->6022 6058->6050 6119 17fe20a4b0c 6058->6119 6133 17fe20a4344 6058->6133 6061 17fe20a454a 6109 17fe20a54fc 6061->6109 6063 17fe20a6b88 RtlAllocateHeap 6063->6064 6064->6037 6065 17fe20a4552 __CxxCallCatchBlock std::bad_alloc::bad_alloc 6065->6063 6067 17fe20a3f9a 6066->6067 6068 17fe20a3f8f 6066->6068 6067->5982 6069 17fe20a401c __GetCurrentState RtlAllocateHeap 6068->6069 6069->6067 6071 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6070->6071 6072 17fe20a3822 6071->6072 6072->5994 6074 17fe20a4014 __FrameHandler3::GetHandlerSearchState RtlAllocateHeap 6073->6074 6075 17fe20a3407 6074->6075 6076 17fe20a4014 6075->6076 6077 17fe20a401c 6076->6077 6078 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 6077->6078 6080 17fe20a3415 6077->6080 6079 17fe20a4081 6078->6079 6081 17fe20a3358 6080->6081 6084 17fe20a3376 6081->6084 6082 17fe20a33a3 6082->6003 6083 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6083->6084 6084->6082 6084->6083 6086 17fe20a4014 __FrameHandler3::GetHandlerSearchState RtlAllocateHeap 6085->6086 6087 17fe20a5399 6086->6087 6088 17fe20a344c __FrameHandler3::GetHandlerSearchState RtlAllocateHeap 6087->6088 6089 17fe20a53ae 6088->6089 6160 17fe20a3fa0 6089->6160 6092 17fe20a53c0 __FrameHandler3::GetHandlerSearchState 6163 17fe20a3fd8 6092->6163 6093 17fe20a53e3 6094 17fe20a3fa0 __GetUnwindTryBlock RtlAllocateHeap 6093->6094 6095 17fe20a447a 6094->6095 6095->6013 6095->6015 6095->6023 6098 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6097->6098 6099 17fe20a383a 6098->6099 6099->6013 6099->6046 6101 17fe20a54f3 6100->6101 6106 17fe20a5437 6100->6106 6103 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 6101->6103 6102 17fe20a4546 6102->6015 6102->6061 6105 17fe20a54f8 6103->6105 6104 17fe20a3800 RtlAllocateHeap 6104->6106 6106->6102 6106->6104 6107 17fe20a37ec Is_bad_exception_allowed RtlAllocateHeap 6106->6107 6108 17fe20a4b0c RtlAllocateHeap 6106->6108 6107->6106 6108->6106 6110 17fe20a5519 Is_bad_exception_allowed 6109->6110 6112 17fe20a5569 6109->6112 6111 17fe20a37ec RtlAllocateHeap Is_bad_exception_allowed 6110->6111 6110->6112 6111->6110 6112->6065 6114 17fe20a4014 __FrameHandler3::GetHandlerSearchState RtlAllocateHeap 6113->6114 6115 17fe20a3557 6114->6115 6116 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 6115->6116 6118 17fe20a3565 6115->6118 6117 17fe20a3655 6116->6117 6118->6058 6120 17fe20a4bc8 6119->6120 6121 17fe20a4b39 6119->6121 6120->6058 6122 17fe20a37ec Is_bad_exception_allowed RtlAllocateHeap 6121->6122 6123 17fe20a4b42 6122->6123 6123->6120 6124 17fe20a37ec Is_bad_exception_allowed RtlAllocateHeap 6123->6124 6125 17fe20a4b5b 6123->6125 6124->6125 6125->6120 6126 17fe20a4b87 6125->6126 6127 17fe20a37ec Is_bad_exception_allowed RtlAllocateHeap 6125->6127 6128 17fe20a3800 RtlAllocateHeap 6126->6128 6127->6126 6129 17fe20a4b9b 6128->6129 6129->6120 6130 17fe20a4bb4 6129->6130 6131 17fe20a37ec Is_bad_exception_allowed RtlAllocateHeap 6129->6131 6132 17fe20a3800 RtlAllocateHeap 6130->6132 6131->6130 6132->6120 6134 17fe20a344c __FrameHandler3::GetHandlerSearchState RtlAllocateHeap 6133->6134 6135 17fe20a4381 6134->6135 6136 17fe20a37ec Is_bad_exception_allowed RtlAllocateHeap 6135->6136 6137 17fe20a43b9 6136->6137 6137->6058 6139 17fe20a4014 __FrameHandler3::GetHandlerSearchState RtlAllocateHeap 6138->6139 6140 17fe20a33d0 6139->6140 6141 17fe20a3358 __FrameHandler3::FrameUnwindToEmptyState RtlAllocateHeap 6140->6141 6142 17fe20a33da 6141->6142 6142->6033 6144 17fe20a4926 6143->6144 6145 17fe20a4994 6143->6145 6146 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6144->6146 6145->6051 6147 17fe20a492b 6146->6147 6150 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6147->6150 6157 17fe20a4990 6147->6157 6148 17fe20a49c9 6152 17fe20a3518 RtlAllocateHeap 6148->6152 6149 17fe20a4b03 6151 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 6149->6151 6155 17fe20a494a 6150->6155 6153 17fe20a4b08 6151->6153 6154 17fe20a49e6 6152->6154 6154->6145 6158 17fe20a37ec RtlAllocateHeap Is_bad_exception_allowed 6154->6158 6159 17fe20a4344 RtlAllocateHeap 6154->6159 6155->6157 6166 17fe20a3304 6155->6166 6157->6145 6157->6148 6157->6149 6158->6154 6159->6154 6161 17fe20a344c __FrameHandler3::GetHandlerSearchState RtlAllocateHeap 6160->6161 6162 17fe20a3fb3 6161->6162 6162->6092 6162->6093 6164 17fe20a344c __FrameHandler3::GetHandlerSearchState RtlAllocateHeap 6163->6164 6165 17fe20a3ff2 6164->6165 6165->6095 6167 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6166->6167 6168 17fe20a3330 6167->6168 6168->6157 5726 17fe20a1bc0 5727 17fe20a1bd0 5726->5727 5736 17fe20a6470 5727->5736 5729 17fe20a1bdc _RTC_Initialize 5735 17fe20a1c49 5729->5735 5742 17fe20a2064 5729->5742 5731 17fe20a1c09 5745 17fe20a5c8c 5731->5745 5733 17fe20a1c15 5733->5735 5774 17fe20a655c 5733->5774 5737 17fe20a6481 5736->5737 5738 17fe20a6489 5737->5738 5739 17fe20a7adc __std_exception_copy RtlAllocateHeap 5737->5739 5738->5729 5740 17fe20a6498 5739->5740 5741 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 5740->5741 5741->5738 5781 17fe20a2028 5742->5781 5744 17fe20a206d 5744->5731 5746 17fe20a5cac 5745->5746 5747 17fe20a5cc3 5745->5747 5748 17fe20a5cca 5746->5748 5749 17fe20a5cb4 5746->5749 5747->5733 5750 17fe20a9084 2 API calls 5748->5750 5751 17fe20a7adc __std_exception_copy RtlAllocateHeap 5749->5751 5752 17fe20a5ccf 5750->5752 5753 17fe20a5cb9 5751->5753 5827 17fe20a8768 5752->5827 5755 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 5753->5755 5755->5747 5756 17fe20a5ce6 5836 17fe20a5a64 5756->5836 5758 17fe20a5d23 5759 17fe20a5d59 5758->5759 5760 17fe20a5d41 5758->5760 5761 17fe20a5a64 RtlAllocateHeap 5759->5761 5762 17fe20a7adc __std_exception_copy RtlAllocateHeap 5760->5762 5767 17fe20a5d75 5761->5767 5763 17fe20a5d46 5762->5763 5764 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5763->5764 5764->5747 5765 17fe20a5d7b 5766 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5765->5766 5766->5747 5767->5765 5768 17fe20a5da7 5767->5768 5769 17fe20a5dc0 5767->5769 5770 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5768->5770 5771 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5769->5771 5772 17fe20a5db0 5770->5772 5771->5765 5773 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5772->5773 5773->5747 5775 17fe20a72bc __CxxCallCatchBlock RtlAllocateHeap 5774->5775 5776 17fe20a6569 5775->5776 5777 17fe20a659d 5776->5777 5778 17fe20a7adc __std_exception_copy RtlAllocateHeap 5776->5778 5777->5735 5779 17fe20a6592 5778->5779 5780 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 5779->5780 5780->5777 5782 17fe20a2042 5781->5782 5784 17fe20a203b 5781->5784 5785 17fe20a69c8 5782->5785 5784->5744 5788 17fe20a6604 5785->5788 5787 17fe20a6a0a 5787->5784 5789 17fe20a6620 Concurrency::details::SchedulerProxy::DeleteThis 5788->5789 5792 17fe20a667c 5789->5792 5791 17fe20a6629 Concurrency::details::SchedulerProxy::DeleteThis 5791->5787 5793 17fe20a66a8 5792->5793 5801 17fe20a673d 5792->5801 5800 17fe20a6719 5793->5800 5793->5801 5802 17fe20aaaac 5793->5802 5794 17fe20aaaac 2 API calls 5797 17fe20a6733 5794->5797 5796 17fe20a670f 5798 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5796->5798 5799 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5797->5799 5798->5800 5799->5801 5800->5794 5800->5801 5801->5791 5803 17fe20aaace 5802->5803 5804 17fe20aaaeb 5802->5804 5803->5804 5805 17fe20aaadc 5803->5805 5808 17fe20aaaf5 5804->5808 5811 17fe20ac608 5804->5811 5807 17fe20a7adc __std_exception_copy RtlAllocateHeap 5805->5807 5810 17fe20aaae1 __scrt_get_show_window_mode 5807->5810 5818 17fe20a6e2c 5808->5818 5810->5796 5812 17fe20ac62a 5811->5812 5813 17fe20ac611 5811->5813 5814 17fe20a7adc __std_exception_copy RtlAllocateHeap 5813->5814 5815 17fe20ac616 5814->5815 5816 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 5815->5816 5817 17fe20ac621 5816->5817 5817->5808 5819 17fe20a6e4b 5818->5819 5820 17fe20a6e41 5818->5820 5822 17fe20a6e50 5819->5822 5826 17fe20a6e57 _invalid_parameter_noinfo 5819->5826 5821 17fe20a6ee4 2 API calls 5820->5821 5825 17fe20a6e49 5821->5825 5823 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5822->5823 5823->5825 5824 17fe20a7adc __std_exception_copy RtlAllocateHeap 5824->5825 5825->5810 5826->5824 5826->5825 5828 17fe20a87a9 5827->5828 5829 17fe20a87ad 5828->5829 5830 17fe20a87c1 5828->5830 5842 17fe20a7a50 5829->5842 5831 17fe20a85a8 RtlAllocateHeap 5830->5831 5832 17fe20a87ef 5831->5832 5847 17fe20a864c 5832->5847 5834 17fe20a87ba _log10_special 5834->5756 5838 17fe20a5aa2 5836->5838 5837 17fe20a9434 RtlAllocateHeap 5837->5838 5838->5837 5840 17fe20a5b0e 5838->5840 5839 17fe20a5bff 5839->5758 5840->5839 5841 17fe20a9434 RtlAllocateHeap 5840->5841 5841->5840 5843 17fe20a7434 __std_exception_copy RtlAllocateHeap 5842->5843 5844 17fe20a7a5d __free_lconv_num 5843->5844 5845 17fe20a7434 __std_exception_copy RtlAllocateHeap 5844->5845 5846 17fe20a7a7f 5845->5846 5846->5834 5848 17fe20a868b 5847->5848 5849 17fe20a8670 5847->5849 5850 17fe20a86ee 5848->5850 5852 17fe20a8690 5848->5852 5849->5834 5850->5849 5853 17fe20a7a50 RtlAllocateHeap 5850->5853 5851 17fe20a7adc __std_exception_copy RtlAllocateHeap 5851->5849 5852->5849 5852->5851 5854 17fe20a86fb 5853->5854 5855 17fe20a7adc __std_exception_copy RtlAllocateHeap 5854->5855 5855->5849 6527 17fe20abb40 6530 17fe20abb5d 6527->6530 6528 17fe20abb62 6529 17fe20a7adc __std_exception_copy RtlAllocateHeap 6528->6529 6533 17fe20abb78 6528->6533 6535 17fe20abb6c 6529->6535 6530->6528 6532 17fe20abbac 6530->6532 6530->6533 6531 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 6531->6533 6532->6533 6534 17fe20a7adc __std_exception_copy RtlAllocateHeap 6532->6534 6534->6535 6535->6531 6169 17fe20ab444 6170 17fe20ab44f 6169->6170 6177 17fe20ad394 6170->6177 6173 17fe20ab454 6174 17fe20ab485 6173->6174 6182 17fe20ad448 6173->6182 6175 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6174->6175 6176 17fe20ab491 6175->6176 6180 17fe20ad3ad Concurrency::details::SchedulerProxy::DeleteThis 6177->6180 6178 17fe20ad42d Concurrency::details::SchedulerProxy::DeleteThis 6178->6173 6180->6178 6181 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6180->6181 6186 17fe20ad900 6180->6186 6181->6180 6183 17fe20ad45c 6182->6183 6185 17fe20ad470 6182->6185 6184 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6183->6184 6183->6185 6184->6185 6185->6173 6187 17fe20ad930 6186->6187 6194 17fe20ad7dc 6187->6194 6189 17fe20ad949 6190 17fe20a6c80 _invalid_parameter_noinfo RtlAllocateHeap 6189->6190 6191 17fe20ad96e 6189->6191 6190->6191 6192 17fe20a6c80 _invalid_parameter_noinfo RtlAllocateHeap 6191->6192 6193 17fe20ad983 6191->6193 6192->6193 6193->6180 6195 17fe20ad7f7 6194->6195 6197 17fe20ad825 6194->6197 6196 17fe20a78d4 _invalid_parameter_noinfo RtlAllocateHeap 6195->6196 6199 17fe20ad817 6196->6199 6197->6199 6200 17fe20ad858 6197->6200 6199->6189 6201 17fe20ad898 6200->6201 6202 17fe20ad873 6200->6202 6212 17fe20ad893 6201->6212 6214 17fe20ab1bc 6201->6214 6203 17fe20a78d4 _invalid_parameter_noinfo RtlAllocateHeap 6202->6203 6203->6212 6206 17fe20ad448 RtlAllocateHeap 6207 17fe20ad8b5 6206->6207 6220 17fe20ab708 6207->6220 6212->6199 6213 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6213->6212 6215 17fe20ab1e2 6214->6215 6216 17fe20ab213 6214->6216 6215->6216 6217 17fe20ab708 RtlAllocateHeap 6215->6217 6216->6206 6218 17fe20ab203 6217->6218 6233 17fe20acf6c 6218->6233 6221 17fe20ab711 6220->6221 6225 17fe20ab721 6220->6225 6222 17fe20a7adc __std_exception_copy RtlAllocateHeap 6221->6222 6223 17fe20ab716 6222->6223 6224 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 6223->6224 6224->6225 6226 17fe20ae2ec 6225->6226 6227 17fe20ae318 6226->6227 6228 17fe20ad8c7 6226->6228 6229 17fe20ae37c 6227->6229 6231 17fe20ae348 6227->6231 6228->6212 6228->6213 6230 17fe20a78d4 _invalid_parameter_noinfo RtlAllocateHeap 6229->6230 6230->6228 6276 17fe20ae274 6231->6276 6234 17fe20acfc2 6233->6234 6239 17fe20acf95 6233->6239 6235 17fe20acfdb 6234->6235 6237 17fe20ad032 6234->6237 6236 17fe20a78d4 _invalid_parameter_noinfo RtlAllocateHeap 6235->6236 6236->6239 6237->6239 6240 17fe20ad08c 6237->6240 6239->6216 6241 17fe20ad0b7 6240->6241 6248 17fe20ad0eb 6240->6248 6242 17fe20ad0bc 6241->6242 6244 17fe20ad12a 6241->6244 6243 17fe20a78d4 _invalid_parameter_noinfo RtlAllocateHeap 6242->6243 6243->6248 6245 17fe20ad140 6244->6245 6249 17fe20ad798 6244->6249 6253 17fe20ad48c 6245->6253 6248->6239 6250 17fe20ad6ec 6249->6250 6261 17fe20a9ab8 6250->6261 6252 17fe20ad713 6252->6245 6254 17fe20ad4a2 6253->6254 6255 17fe20ad495 6253->6255 6257 17fe20ad49a 6254->6257 6258 17fe20a7adc __std_exception_copy RtlAllocateHeap 6254->6258 6256 17fe20a7adc __std_exception_copy RtlAllocateHeap 6255->6256 6256->6257 6257->6248 6259 17fe20ad4d9 6258->6259 6260 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 6259->6260 6260->6257 6262 17fe20a9ac1 6261->6262 6263 17fe20a9ad6 6261->6263 6273 17fe20a7abc 6262->6273 6265 17fe20a7abc RtlAllocateHeap 6263->6265 6267 17fe20a9ace 6263->6267 6268 17fe20a9b11 6265->6268 6267->6252 6270 17fe20a7adc __std_exception_copy RtlAllocateHeap 6268->6270 6269 17fe20a7adc __std_exception_copy RtlAllocateHeap 6269->6267 6271 17fe20a9b19 6270->6271 6272 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 6271->6272 6272->6267 6274 17fe20a7434 __std_exception_copy RtlAllocateHeap 6273->6274 6275 17fe20a7ac5 6274->6275 6275->6269 6277 17fe20ae290 6276->6277 6278 17fe20ae2c5 6277->6278 6280 17fe20ae3b0 6277->6280 6278->6228 6281 17fe20a9ab8 RtlAllocateHeap 6280->6281 6282 17fe20ae3cc 6281->6282 6285 17fe20a9ab8 RtlAllocateHeap 6282->6285 6289 17fe20ae40f 6282->6289 6290 17fe20ae3d2 6282->6290 6284 17fe20ae437 6284->6278 6287 17fe20ae402 6285->6287 6286 17fe20a9ab8 RtlAllocateHeap 6286->6290 6288 17fe20a9ab8 RtlAllocateHeap 6287->6288 6288->6289 6289->6286 6289->6290 6291 17fe20a99fc 6290->6291 6292 17fe20a9a18 6291->6292 6293 17fe20a7adc __std_exception_copy RtlAllocateHeap 6292->6293 6296 17fe20a9a4b 6292->6296 6294 17fe20a9a8f 6293->6294 6295 17fe20a7abc RtlAllocateHeap 6294->6295 6295->6296 6296->6284 6536 17fe20a9d44 6537 17fe20a9d54 Concurrency::details::SchedulerProxy::DeleteThis 6536->6537 6542 17fe20a9904 6537->6542 6539 17fe20a9d5d 6541 17fe20a9d66 Concurrency::details::SchedulerProxy::DeleteThis 6539->6541 6550 17fe20a9b4c 6539->6550 6543 17fe20a994c Concurrency::details::SchedulerProxy::DeleteThis 6542->6543 6544 17fe20a9923 6542->6544 6548 17fe20a9934 Concurrency::details::SchedulerProxy::DeleteThis 6543->6548 6554 17fe20a980c 6543->6554 6545 17fe20a7adc __std_exception_copy RtlAllocateHeap 6544->6545 6546 17fe20a9928 6545->6546 6547 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 6546->6547 6547->6548 6548->6539 6551 17fe20a9b72 6550->6551 6552 17fe20a9904 RtlAllocateHeap 6551->6552 6553 17fe20a9baa 6551->6553 6552->6553 6553->6541 6555 17fe20a7afc _invalid_parameter_noinfo RtlAllocateHeap 6554->6555 6558 17fe20a982d 6555->6558 6556 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6557 17fe20a9899 6556->6557 6557->6543 6558->6556 5238 17fe20a6259 5246 17fe20a6b88 5238->5246 5240 17fe20a625e 5241 17fe20a615c RtlAllocateHeap 5240->5241 5242 17fe20a630b 5241->5242 5243 17fe20a6312 5242->5243 5244 17fe20a6328 ExitProcess 5242->5244 5245 17fe20a6324 5244->5245 5251 17fe20a72bc 5246->5251 5252 17fe20a72d1 _invalid_parameter_noinfo 5251->5252 5254 17fe20a72ed 5252->5254 5269 17fe20a7afc 5252->5269 5255 17fe20a6b91 5254->5255 5256 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 5254->5256 5265 17fe20a6c14 5255->5265 5258 17fe20a738e 5256->5258 5257 17fe20a731e _invalid_parameter_noinfo 5259 17fe20a735a 5257->5259 5260 17fe20a732c _invalid_parameter_noinfo 5257->5260 5277 17fe20a706c 5259->5277 5273 17fe20a6ea8 5260->5273 5264 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5264->5254 5266 17fe20a6c1d __CxxCallCatchBlock 5265->5266 5268 17fe20a6c2c __CxxCallCatchBlock 5266->5268 5415 17fe20aad60 5266->5415 5272 17fe20a7b0d _invalid_parameter_noinfo 5269->5272 5270 17fe20a7b42 RtlAllocateHeap 5271 17fe20a7b5c __std_exception_copy 5270->5271 5270->5272 5271->5257 5272->5270 5272->5271 5274 17fe20a6ede 5273->5274 5275 17fe20a6ead __free_lconv_num 5273->5275 5274->5254 5275->5274 5281 17fe20a7adc 5275->5281 5278 17fe20a711e _invalid_parameter_noinfo 5277->5278 5295 17fe20a6fc4 5278->5295 5280 17fe20a7133 5280->5264 5284 17fe20a7434 5281->5284 5285 17fe20a7449 _invalid_parameter_noinfo 5284->5285 5286 17fe20a7465 5285->5286 5287 17fe20a7afc _invalid_parameter_noinfo RtlAllocateHeap 5285->5287 5286->5274 5288 17fe20a7496 _invalid_parameter_noinfo 5287->5288 5289 17fe20a74d2 5288->5289 5290 17fe20a74a4 _invalid_parameter_noinfo 5288->5290 5291 17fe20a706c _invalid_parameter_noinfo RtlAllocateHeap 5289->5291 5292 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5290->5292 5293 17fe20a74da 5291->5293 5292->5286 5294 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5293->5294 5294->5286 5296 17fe20a6fe0 Concurrency::details::SchedulerProxy::DeleteThis 5295->5296 5299 17fe20a7254 5296->5299 5298 17fe20a6ff6 Concurrency::details::SchedulerProxy::DeleteThis 5298->5280 5300 17fe20a729c Concurrency::details::SchedulerProxy::DeleteThis 5299->5300 5301 17fe20a7270 Concurrency::details::SchedulerProxy::DeleteThis 5299->5301 5300->5298 5301->5300 5303 17fe20aa290 5301->5303 5304 17fe20aa32c 5303->5304 5307 17fe20aa2b3 5303->5307 5305 17fe20aa37f 5304->5305 5308 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5304->5308 5369 17fe20aa430 5305->5369 5307->5304 5309 17fe20aa2f2 5307->5309 5314 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5307->5314 5310 17fe20aa350 5308->5310 5312 17fe20aa314 5309->5312 5320 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5309->5320 5311 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5310->5311 5315 17fe20aa364 5311->5315 5316 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5312->5316 5313 17fe20aa38b 5321 17fe20aa3ea 5313->5321 5323 17fe20a6ea8 RtlAllocateHeap __free_lconv_num 5313->5323 5318 17fe20aa2e6 5314->5318 5319 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5315->5319 5317 17fe20aa320 5316->5317 5322 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5317->5322 5329 17fe20a9dc0 5318->5329 5325 17fe20aa373 5319->5325 5326 17fe20aa308 5320->5326 5322->5304 5323->5313 5327 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5325->5327 5357 17fe20a9ecc 5326->5357 5327->5305 5330 17fe20a9dc9 5329->5330 5354 17fe20a9ec4 5329->5354 5331 17fe20a9de3 5330->5331 5332 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5330->5332 5333 17fe20a9df5 5331->5333 5334 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5331->5334 5332->5331 5335 17fe20a9e07 5333->5335 5336 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5333->5336 5334->5333 5337 17fe20a9e19 5335->5337 5338 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5335->5338 5336->5335 5339 17fe20a9e2b 5337->5339 5340 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5337->5340 5338->5337 5341 17fe20a9e3d 5339->5341 5342 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5339->5342 5340->5339 5343 17fe20a9e4f 5341->5343 5345 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5341->5345 5342->5341 5344 17fe20a9e61 5343->5344 5346 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5343->5346 5347 17fe20a9e73 5344->5347 5348 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5344->5348 5345->5343 5346->5344 5349 17fe20a9e85 5347->5349 5350 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5347->5350 5348->5347 5351 17fe20a9e9a 5349->5351 5352 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5349->5352 5350->5349 5353 17fe20a9eaf 5351->5353 5355 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5351->5355 5352->5351 5353->5354 5356 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5353->5356 5354->5309 5355->5353 5356->5354 5358 17fe20a9ed1 5357->5358 5367 17fe20a9f32 5357->5367 5359 17fe20a9eea 5358->5359 5360 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5358->5360 5361 17fe20a9efc 5359->5361 5362 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5359->5362 5360->5359 5363 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5361->5363 5364 17fe20a9f0e 5361->5364 5362->5361 5363->5364 5365 17fe20a9f20 5364->5365 5366 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5364->5366 5365->5367 5368 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5365->5368 5366->5365 5367->5312 5368->5367 5370 17fe20aa435 5369->5370 5371 17fe20aa461 5369->5371 5370->5371 5375 17fe20a9f6c 5370->5375 5371->5313 5374 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5374->5371 5376 17fe20a9f75 5375->5376 5377 17fe20aa064 5375->5377 5411 17fe20a9f38 5376->5411 5377->5374 5380 17fe20a9f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5381 17fe20a9f9e 5380->5381 5382 17fe20a9f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5381->5382 5383 17fe20a9fac 5382->5383 5384 17fe20a9f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5383->5384 5385 17fe20a9fba 5384->5385 5386 17fe20a9f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5385->5386 5387 17fe20a9fc9 5386->5387 5388 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5387->5388 5389 17fe20a9fd5 5388->5389 5390 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5389->5390 5391 17fe20a9fe1 5390->5391 5392 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5391->5392 5393 17fe20a9fed 5392->5393 5394 17fe20a9f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5393->5394 5395 17fe20a9ffb 5394->5395 5396 17fe20a9f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5395->5396 5397 17fe20aa009 5396->5397 5398 17fe20a9f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5397->5398 5399 17fe20aa017 5398->5399 5400 17fe20a9f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5399->5400 5401 17fe20aa025 5400->5401 5402 17fe20a9f38 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5401->5402 5403 17fe20aa034 5402->5403 5404 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5403->5404 5405 17fe20aa040 5404->5405 5406 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5405->5406 5407 17fe20aa04c 5406->5407 5408 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5407->5408 5409 17fe20aa058 5408->5409 5410 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5409->5410 5410->5377 5412 17fe20a9f5f 5411->5412 5414 17fe20a9f4e 5411->5414 5412->5380 5413 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5413->5414 5414->5412 5414->5413 5416 17fe20aad90 5415->5416 5422 17fe20aadb7 Concurrency::details::SchedulerProxy::DeleteThis 5415->5422 5417 17fe20a7434 __std_exception_copy RtlAllocateHeap 5416->5417 5418 17fe20aada4 5416->5418 5416->5422 5417->5418 5419 17fe20aae39 5418->5419 5418->5422 5428 17fe20aadf4 5418->5428 5420 17fe20a7adc __std_exception_copy RtlAllocateHeap 5419->5420 5421 17fe20aae3e 5420->5421 5434 17fe20a79a0 5421->5434 5423 17fe20aaef3 Concurrency::details::SchedulerProxy::DeleteThis 5422->5423 5424 17fe20aafc0 Concurrency::details::SchedulerProxy::DeleteThis 5422->5424 5426 17fe20a72bc __CxxCallCatchBlock RtlAllocateHeap 5422->5426 5427 17fe20a72bc __CxxCallCatchBlock RtlAllocateHeap 5423->5427 5430 17fe20aaf68 5423->5430 5433 17fe20aaf57 5423->5433 5429 17fe20aaee3 5426->5429 5427->5430 5428->5268 5431 17fe20a72bc __CxxCallCatchBlock RtlAllocateHeap 5429->5431 5432 17fe20a72bc __CxxCallCatchBlock RtlAllocateHeap 5430->5432 5430->5433 5431->5423 5432->5433 5433->5268 5437 17fe20a7838 5434->5437 5438 17fe20a7863 5437->5438 5445 17fe20a78d4 5438->5445 5440 17fe20a788a 5441 17fe20a78ad 5440->5441 5451 17fe20a6c80 5440->5451 5442 17fe20a78c2 5441->5442 5444 17fe20a6c80 _invalid_parameter_noinfo RtlAllocateHeap 5441->5444 5442->5428 5444->5442 5462 17fe20a761c 5445->5462 5447 17fe20a790f 5447->5440 5448 17fe20a78fe _invalid_parameter_noinfo 5448->5447 5449 17fe20a7838 _invalid_parameter_noinfo RtlAllocateHeap 5448->5449 5450 17fe20a79b9 5449->5450 5450->5440 5452 17fe20a6cd8 5451->5452 5453 17fe20a6c8f 5451->5453 5452->5441 5454 17fe20a74fc _invalid_parameter_noinfo RtlAllocateHeap 5453->5454 5455 17fe20a6cbe 5454->5455 5455->5452 5456 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 5455->5456 5457 17fe20a6ce6 5456->5457 5458 17fe20a6c80 _invalid_parameter_noinfo RtlAllocateHeap 5457->5458 5459 17fe20a6d07 5458->5459 5477 17fe20ab4ec 5459->5477 5461 17fe20a6d2f _invalid_parameter_noinfo 5461->5441 5463 17fe20a7638 5462->5463 5465 17fe20a7663 5462->5465 5466 17fe20a74fc 5463->5466 5465->5448 5467 17fe20a751b _invalid_parameter_noinfo 5466->5467 5468 17fe20a7afc _invalid_parameter_noinfo RtlAllocateHeap 5467->5468 5475 17fe20a7528 5467->5475 5469 17fe20a7552 _invalid_parameter_noinfo 5468->5469 5470 17fe20a758e 5469->5470 5471 17fe20a7560 _invalid_parameter_noinfo 5469->5471 5472 17fe20a706c _invalid_parameter_noinfo RtlAllocateHeap 5470->5472 5473 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5471->5473 5474 17fe20a7596 5472->5474 5473->5475 5476 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5474->5476 5475->5465 5476->5475 5478 17fe20ab505 5477->5478 5480 17fe20ab518 5477->5480 5478->5480 5481 17fe20aa538 5478->5481 5480->5461 5482 17fe20a72bc __CxxCallCatchBlock RtlAllocateHeap 5481->5482 5484 17fe20aa547 Concurrency::details::SchedulerProxy::DeleteThis 5482->5484 5483 17fe20aa592 5483->5480 5484->5483 5489 17fe20aa5a8 5484->5489 5486 17fe20aa580 Concurrency::details::SchedulerProxy::DeleteThis 5486->5483 5487 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 5486->5487 5488 17fe20aa5a5 5487->5488 5490 17fe20aa5ba Concurrency::details::SchedulerProxy::DeleteThis 5489->5490 5492 17fe20aa5c7 5489->5492 5491 17fe20aa290 Concurrency::details::SchedulerProxy::DeleteThis RtlAllocateHeap 5490->5491 5490->5492 5491->5492 5492->5486 6392 17fe20af2d8 6394 17fe20af2ed 6392->6394 6393 17fe20af300 6394->6393 6395 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6394->6395 6396 17fe20af310 6395->6396 6397 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6396->6397 6398 17fe20af319 6397->6398 6399 17fe20a6b88 RtlAllocateHeap 6398->6399 6400 17fe20af322 6399->6400 6297 17fe20a8258 6298 17fe20a82ba 6297->6298 6299 17fe20a85a8 RtlAllocateHeap 6298->6299 6300 17fe20a833a 6299->6300 6307 17fe20a7b88 6300->6307 6303 17fe20a85a8 RtlAllocateHeap 6304 17fe20a8431 6303->6304 6324 17fe20a7d04 6304->6324 6306 17fe20a849d 6308 17fe20a7bb2 6307->6308 6309 17fe20a7bd6 6307->6309 6311 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6308->6311 6322 17fe20a7bc1 6308->6322 6310 17fe20a7bdb 6309->6310 6315 17fe20a7c30 6309->6315 6312 17fe20a7bf0 6310->6312 6313 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6310->6313 6310->6322 6311->6322 6314 17fe20a6ee4 2 API calls 6312->6314 6313->6312 6314->6322 6316 17fe20a7c81 6315->6316 6318 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6315->6318 6321 17fe20a7c53 6315->6321 6319 17fe20a6ee4 2 API calls 6316->6319 6317 17fe20a7a50 RtlAllocateHeap 6320 17fe20a7c60 6317->6320 6318->6316 6319->6321 6323 17fe20a7adc __std_exception_copy RtlAllocateHeap 6320->6323 6321->6317 6321->6322 6322->6303 6323->6322 6325 17fe20a7d2e 6324->6325 6326 17fe20a7d52 6324->6326 6329 17fe20a7d3d 6325->6329 6330 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6325->6330 6327 17fe20a7d58 6326->6327 6328 17fe20a7dac 6326->6328 6327->6329 6331 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6327->6331 6333 17fe20a7d6d 6327->6333 6334 17fe20a7dd7 6328->6334 6335 17fe20a7e08 6328->6335 6337 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6328->6337 6329->6306 6330->6329 6331->6333 6332 17fe20a6ee4 2 API calls 6332->6329 6333->6332 6334->6329 6336 17fe20a7a50 RtlAllocateHeap 6334->6336 6338 17fe20a6ee4 2 API calls 6335->6338 6339 17fe20a7de4 6336->6339 6337->6335 6338->6334 6340 17fe20a7adc __std_exception_copy RtlAllocateHeap 6339->6340 6340->6329 5856 17fe20a5fdc 5857 17fe20a5fec 5856->5857 5858 17fe20a5ff1 5856->5858 5860 17fe20a5f98 5857->5860 5861 17fe20a5f9d 5860->5861 5865 17fe20a5fce 5860->5865 5862 17fe20a5fc6 5861->5862 5863 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5861->5863 5864 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5862->5864 5863->5861 5864->5865 5865->5858 6341 17fe20a506e 6342 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6341->6342 6343 17fe20a507b __CxxCallCatchBlock 6342->6343 6352 17fe20a3798 6343->6352 6345 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6347 17fe20a512a 6345->6347 6348 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6347->6348 6350 17fe20a5133 6348->6350 6351 17fe20a5117 __CxxCallCatchBlock 6351->6345 6353 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6352->6353 6354 17fe20a37aa 6353->6354 6355 17fe20a37e5 6354->6355 6357 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6354->6357 6356 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 6355->6356 6358 17fe20a37ea 6356->6358 6359 17fe20a37b5 6357->6359 6359->6355 6360 17fe20a37d1 6359->6360 6361 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6360->6361 6362 17fe20a37d6 6361->6362 6362->6351 6363 17fe20a2908 6362->6363 6364 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6363->6364 6365 17fe20a2916 6364->6365 6365->6351 5866 17fe20a29ec 5867 17fe20a6b88 RtlAllocateHeap 5866->5867 5868 17fe20a29f5 5867->5868 6559 17fe20ae760 6562 17fe20ae780 6559->6562 6563 17fe20ae79a 6562->6563 6564 17fe20ae77b 6563->6564 6566 17fe20ae5c0 6563->6566 6567 17fe20ae600 _raise_exc _log10_special 6566->6567 6568 17fe20ae6a9 6567->6568 6569 17fe20ae679 6567->6569 6577 17fe20aebb0 6568->6577 6573 17fe20ae49c 6569->6573 6572 17fe20ae6a7 _log10_special 6572->6564 6574 17fe20ae4e0 _log10_special 6573->6574 6575 17fe20ae4f5 6574->6575 6576 17fe20aebb0 _log10_special RtlAllocateHeap 6574->6576 6575->6572 6576->6575 6578 17fe20aebb9 6577->6578 6579 17fe20aebd0 6577->6579 6581 17fe20aebc8 6578->6581 6582 17fe20a7adc __std_exception_copy RtlAllocateHeap 6578->6582 6580 17fe20a7adc __std_exception_copy RtlAllocateHeap 6579->6580 6580->6581 6581->6572 6582->6581 6404 17fe20af4df 6407 17fe20a5160 6404->6407 6408 17fe20a51d0 6407->6408 6409 17fe20a517f 6407->6409 6409->6408 6410 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6409->6410 6410->6408 6411 17fe20a6ae0 6412 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6411->6412 6413 17fe20a6af0 6412->6413 6414 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6413->6414 6415 17fe20a6b04 6414->6415 6416 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6415->6416 6417 17fe20a6b18 6416->6417 6418 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6417->6418 6419 17fe20a6b2c 6418->6419 5693 17fe20a6ee4 5694 17fe20a6f2f 5693->5694 5698 17fe20a6ef3 _invalid_parameter_noinfo 5693->5698 5696 17fe20a7adc __std_exception_copy RtlAllocateHeap 5694->5696 5695 17fe20a6f16 RtlAllocateHeap 5697 17fe20a6f2d 5695->5697 5695->5698 5696->5697 5698->5694 5698->5695 5869 17fe20a5ff8 5870 17fe20a6008 5869->5870 5871 17fe20a600d 5869->5871 5872 17fe20a5f98 RtlAllocateHeap 5870->5872 5872->5871 5502 17fe20a7afc 5505 17fe20a7b0d _invalid_parameter_noinfo 5502->5505 5503 17fe20a7b42 RtlAllocateHeap 5504 17fe20a7b5c __std_exception_copy 5503->5504 5503->5505 5505->5503 5505->5504 6583 17fe20af170 6584 17fe20af1a8 6583->6584 6585 17fe20af1d4 6584->6585 6587 17fe20a3844 6584->6587 6588 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6587->6588 6589 17fe20a386e 6588->6589 6590 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6589->6590 6591 17fe20a387b 6590->6591 6592 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6591->6592 6593 17fe20a3884 6592->6593 6593->6585 6594 17fe20a4f74 6595 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6594->6595 6596 17fe20a4fa9 6595->6596 6597 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6596->6597 6598 17fe20a4fb7 __except_validate_context_record 6597->6598 6599 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6598->6599 6600 17fe20a4ffb 6599->6600 6601 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6600->6601 6602 17fe20a5004 6601->6602 6603 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6602->6603 6604 17fe20a500d 6603->6604 6617 17fe20a375c 6604->6617 6607 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6608 17fe20a503d __CxxCallCatchBlock 6607->6608 6609 17fe20a3798 __CxxCallCatchBlock RtlAllocateHeap 6608->6609 6613 17fe20a50ee 6609->6613 6610 17fe20a5117 __CxxCallCatchBlock 6611 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6610->6611 6612 17fe20a512a 6611->6612 6614 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6612->6614 6613->6610 6615 17fe20a2908 __CxxCallCatchBlock RtlAllocateHeap 6613->6615 6616 17fe20a5133 6614->6616 6615->6610 6618 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6617->6618 6619 17fe20a376d 6618->6619 6620 17fe20a3778 6619->6620 6621 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6619->6621 6622 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6620->6622 6621->6620 6623 17fe20a3789 6622->6623 6623->6607 6623->6608 6624 17fe20af58a 6627 17fe20a295c 6624->6627 6628 17fe20a2986 6627->6628 6629 17fe20a2974 6627->6629 6630 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6628->6630 6629->6628 6631 17fe20a297c 6629->6631 6633 17fe20a298b 6630->6633 6632 17fe20a2984 6631->6632 6634 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6631->6634 6633->6632 6635 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6633->6635 6636 17fe20a29ab 6634->6636 6635->6632 6637 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6636->6637 6638 17fe20a29b8 6637->6638 6639 17fe20a6b88 RtlAllocateHeap 6638->6639 6640 17fe20a29c1 6639->6640 5493 17fe20a1c88 5501 17fe20a2388 5493->5501 6366 17fe20a4e8c 6369 17fe20a56c8 6366->6369 6370 17fe20a56e9 6369->6370 6374 17fe20a4eb5 6369->6374 6371 17fe20a6bb4 __std_exception_copy RtlAllocateHeap 6370->6371 6373 17fe20a571e 6370->6373 6370->6374 6371->6373 6372 17fe20a5828 __std_exception_destroy RtlAllocateHeap 6372->6374 6373->6372 6420 17fe20ac500 6421 17fe20a9084 2 API calls 6420->6421 6422 17fe20ac509 6421->6422 6641 17fe20a9d80 6644 17fe20a9d8c 6641->6644 6643 17fe20a9db3 6644->6643 6645 17fe20a98b4 6644->6645 6646 17fe20a98b9 6645->6646 6648 17fe20a98f4 6645->6648 6647 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 6646->6647 6647->6648 6648->6644 6423 17fe20af504 6424 17fe20a3798 __CxxCallCatchBlock RtlAllocateHeap 6423->6424 6426 17fe20af517 6424->6426 6425 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6427 17fe20af56a 6425->6427 6429 17fe20a2908 __CxxCallCatchBlock RtlAllocateHeap 6426->6429 6431 17fe20af556 __CxxCallCatchBlock 6426->6431 6428 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6427->6428 6430 17fe20af57a 6428->6430 6429->6431 6431->6425 6432 17fe20a5304 6441 17fe20a5237 __CxxCallCatchBlock __FrameHandler3::GetHandlerSearchState 6432->6441 6433 17fe20a532b 6434 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6433->6434 6435 17fe20a5330 6434->6435 6438 17fe20a533b 6435->6438 6439 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6435->6439 6436 17fe20a5366 6437 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 6436->6437 6437->6438 6440 17fe20a5348 __FrameHandler3::GetHandlerSearchState 6438->6440 6442 17fe20a6c14 __CxxCallCatchBlock RtlAllocateHeap 6438->6442 6439->6438 6441->6433 6441->6436 6444 17fe20a37ec RtlAllocateHeap Is_bad_exception_allowed 6441->6444 6445 17fe20a3814 __FrameHandler3::FrameUnwindToEmptyState RtlAllocateHeap 6441->6445 6443 17fe20a5371 6442->6443 6444->6441 6445->6441 5873 17fe20ac418 5874 17fe20ac43d _log10_special 5873->5874 5875 17fe20ac42c 5873->5875 5875->5874 5876 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5875->5876 5876->5874 6375 17fe20ac098 6376 17fe20ac0a0 6375->6376 6377 17fe20ac0b5 6376->6377 6379 17fe20ac0ce 6376->6379 6378 17fe20a7adc __std_exception_copy RtlAllocateHeap 6377->6378 6380 17fe20ac0ba 6378->6380 6382 17fe20a85a8 RtlAllocateHeap 6379->6382 6383 17fe20ac0c5 6379->6383 6381 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 6380->6381 6381->6383 6382->6383 6649 17fe20a2398 6650 17fe20a23cc 6649->6650 6651 17fe20a23b0 6649->6651 6651->6650 6658 17fe20a29c4 6651->6658 6656 17fe20a6b88 RtlAllocateHeap 6657 17fe20a23f2 6656->6657 6659 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6658->6659 6660 17fe20a23de 6659->6660 6661 17fe20a29d8 6660->6661 6662 17fe20a2e5c _CreateFrameInfo RtlAllocateHeap 6661->6662 6663 17fe20a23ea 6662->6663 6663->6656 6446 17fe20a4f1c 6447 17fe20a5758 6446->6447 6448 17fe20a576f 6447->6448 6449 17fe20a5828 __std_exception_destroy RtlAllocateHeap 6447->6449 6449->6448 5877 17fe20a5e14 5878 17fe20a5e2d 5877->5878 5891 17fe20a5e29 5877->5891 5879 17fe20a9084 2 API calls 5878->5879 5880 17fe20a5e32 5879->5880 5892 17fe20a95e0 5880->5892 5883 17fe20a5e4b 5904 17fe20a5e88 5883->5904 5884 17fe20a5e3f 5886 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5884->5886 5886->5891 5888 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5889 17fe20a5e72 5888->5889 5890 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5889->5890 5890->5891 5894 17fe20a95ff 5892->5894 5893 17fe20a5e37 5893->5883 5893->5884 5894->5893 5895 17fe20a6ee4 2 API calls 5894->5895 5896 17fe20a967b 5895->5896 5897 17fe20a968c 5896->5897 5898 17fe20a9683 5896->5898 5900 17fe20a96bd 5897->5900 5901 17fe20a96b3 5897->5901 5899 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5898->5899 5899->5893 5903 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5900->5903 5902 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5901->5902 5902->5893 5903->5893 5905 17fe20a5ead 5904->5905 5906 17fe20a7afc _invalid_parameter_noinfo RtlAllocateHeap 5905->5906 5917 17fe20a5ee3 5906->5917 5907 17fe20a5eeb 5908 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5907->5908 5909 17fe20a5e53 5908->5909 5909->5888 5910 17fe20a5f5e 5911 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5910->5911 5911->5909 5912 17fe20a7afc _invalid_parameter_noinfo RtlAllocateHeap 5912->5917 5913 17fe20a5f4d 5915 17fe20a5f98 RtlAllocateHeap 5913->5915 5916 17fe20a5f55 5915->5916 5919 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5916->5919 5917->5907 5917->5910 5917->5912 5917->5913 5918 17fe20a5f83 _invalid_parameter_noinfo 5917->5918 5920 17fe20a6ea8 __free_lconv_num RtlAllocateHeap 5917->5920 5921 17fe20a6bb4 5917->5921 5919->5907 5920->5917 5922 17fe20a6bcb 5921->5922 5923 17fe20a6bc1 5921->5923 5924 17fe20a7adc __std_exception_copy RtlAllocateHeap 5922->5924 5923->5922 5928 17fe20a6be6 5923->5928 5925 17fe20a6bd2 5924->5925 5926 17fe20a79a0 _invalid_parameter_noinfo RtlAllocateHeap 5925->5926 5927 17fe20a6bde 5926->5927 5927->5917 5928->5927 5929 17fe20a7adc __std_exception_copy RtlAllocateHeap 5928->5929 5929->5925

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: Open$Enum
                        • String ID:
                        • API String ID: 462099255-0
                        • Opcode ID: 2a02730be39cc75ee99e02b240c38d7de0b4f72d589f073dcba7369fd32cc831
                        • Instruction ID: 1650cd3d390e8e7035f6f10f2e980de524e5cb151bb46ce795e2d47ddd19235f
                        • Opcode Fuzzy Hash: 2a02730be39cc75ee99e02b240c38d7de0b4f72d589f073dcba7369fd32cc831
                        • Instruction Fuzzy Hash: 1BD1607551CB888FEB65DF18D8846DAB7F1FB98304F440A2EE54AD71A0EF349641CB82
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ExceptionFilterUnhandled_invalid_parameter_noinfo
                        • String ID:
                        • API String ID: 59578552-0
                        • Opcode ID: f95e01fbf38a281d9255cdf92b69475522e65d4a66deb1467f342da968b848f1
                        • Instruction ID: 6572cfa8874fb3a77c6edb6255f64c7cf0398ffde2039b02a1f6e3f29b4cff45
                        • Opcode Fuzzy Hash: f95e01fbf38a281d9255cdf92b69475522e65d4a66deb1467f342da968b848f1
                        • Instruction Fuzzy Hash: A8E086BA81DD054DEE1932B90C462EE21B0AB45310FD2023EB71D851F6FD5900934353
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: FileFindFirst
                        • String ID:
                        • API String ID: 1974802433-0
                        • Opcode ID: 81c7c7fd01d69da00775a62d13099b4ead950d999e7021fb467b756ffc4a194f
                        • Instruction ID: 6569fdba2705a4124a08383941aba246e3b510c0e48607633bb89f4ced615e0e
                        • Opcode Fuzzy Hash: 81c7c7fd01d69da00775a62d13099b4ead950d999e7021fb467b756ffc4a194f
                        • Instruction Fuzzy Hash: 7CA1B33560CE484FEB29EF24DC596EA73E1FBA4300F45462ED54BD71A1EF3499068B81
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ComputerCreateMessageMutexName
                        • String ID:
                        • API String ID: 2342047096-0
                        • Opcode ID: bf0b7409f839259ce88bb476a521653d71adaaef5a7294aa3565bebdb25f1347
                        • Instruction ID: f18c293d85774e1aceabed22703f4ffbc1c4273379d17f09c823fcc400833fc1
                        • Opcode Fuzzy Hash: bf0b7409f839259ce88bb476a521653d71adaaef5a7294aa3565bebdb25f1347
                        • Instruction Fuzzy Hash: 4021D73121CA448FE719DB24DC895EAB3F1FBD9305F84497DE18BC60A1EE3881068A41
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: AllocateHeap
                        • String ID:
                        • API String ID: 1279760036-0
                        • Opcode ID: 30d4bf1e297d70a882b7f1add7ff9fded3996ca996f5e333fb51e94ed5290b56
                        • Instruction ID: a704109736c16e79124bdb5f81691e8fef33bd4145f9813a13c2983128dfeafe
                        • Opcode Fuzzy Hash: 30d4bf1e297d70a882b7f1add7ff9fded3996ca996f5e333fb51e94ed5290b56
                        • Instruction Fuzzy Hash: A1016DF632EE0A4EFB6A6BB948993AB31F4DB68301F95803D560AC61F2FD15C8464251
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: AllocateHeap
                        • String ID:
                        • API String ID: 1279760036-0
                        • Opcode ID: c29eb4a6d2c213a181199b5d01373da4079d59e2d89cd9e4ad03217af82161b8
                        • Instruction ID: e61765dc0f73711e3868e3033218e2ba56d76872504ba0ec92578473f8336edc
                        • Opcode Fuzzy Hash: c29eb4a6d2c213a181199b5d01373da4079d59e2d89cd9e4ad03217af82161b8
                        • Instruction Fuzzy Hash: C0F030BA22CE054EFF68A77908A53F726B0EB58751FC2413C660EC21F1FE18C8428511
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: ExitProcess
                        • String ID:
                        • API String ID: 621844428-0
                        • Opcode ID: 0c3185d8b51bac4eb50b0166e6d79b52d76e7ad81d5639061b00e529f1dc9730
                        • Instruction ID: 2e5c48bfd54b69ac723a0b0f95c19481c9cd2d957bf106c4e7bf7a1a5e1ed4b5
                        • Opcode Fuzzy Hash: 0c3185d8b51bac4eb50b0166e6d79b52d76e7ad81d5639061b00e529f1dc9730
                        • Instruction Fuzzy Hash: 47D012753095044FFF18BB7099CD2AA27718744305F40183C665BCB6E7DD798C064741
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 194 17fe20a4418-17fe20a4480 call 17fe20a5374 197 17fe20a48e7-17fe20a48ef call 17fe20a6c14 194->197 198 17fe20a4486-17fe20a4489 194->198 198->197 199 17fe20a448f-17fe20a4495 198->199 201 17fe20a449b-17fe20a449f 199->201 202 17fe20a4564-17fe20a4576 199->202 201->202 206 17fe20a44a5-17fe20a44b0 201->206 204 17fe20a4837-17fe20a483b 202->204 205 17fe20a457c-17fe20a4580 202->205 209 17fe20a483d-17fe20a4844 204->209 210 17fe20a4874-17fe20a487e call 17fe20a2e5c 204->210 205->204 207 17fe20a4586-17fe20a4591 205->207 206->202 208 17fe20a44b6-17fe20a44bb 206->208 207->204 213 17fe20a4597-17fe20a459e 207->213 208->202 214 17fe20a44c1-17fe20a44cb call 17fe20a2e5c 208->214 209->197 211 17fe20a484a-17fe20a486f call 17fe20a48f0 209->211 210->197 220 17fe20a4880-17fe20a489f call 17fe20aee40 210->220 211->210 217 17fe20a4768-17fe20a4774 213->217 218 17fe20a45a4-17fe20a45db call 17fe20a3518 213->218 214->220 228 17fe20a44d1-17fe20a44fc call 17fe20a2e5c * 2 call 17fe20a382c 214->228 217->210 221 17fe20a477a-17fe20a477e 217->221 218->217 232 17fe20a45e1-17fe20a45ea 218->232 225 17fe20a478e-17fe20a4796 221->225 226 17fe20a4780-17fe20a478c call 17fe20a37ec 221->226 225->210 231 17fe20a479c-17fe20a47a9 call 17fe20a33bc 225->231 226->225 241 17fe20a47af-17fe20a47b7 226->241 262 17fe20a44fe-17fe20a4502 228->262 263 17fe20a451c-17fe20a4526 call 17fe20a2e5c 228->263 231->210 231->241 237 17fe20a45ed-17fe20a461f 232->237 238 17fe20a475b-17fe20a4762 237->238 239 17fe20a4625-17fe20a4630 237->239 238->217 238->237 239->238 243 17fe20a4636-17fe20a464f 239->243 244 17fe20a48ca-17fe20a48e6 call 17fe20a2e5c * 2 call 17fe20a6b88 241->244 245 17fe20a47bd-17fe20a47c1 241->245 247 17fe20a4748-17fe20a474d 243->247 248 17fe20a4655-17fe20a469a call 17fe20a3800 * 2 243->248 244->197 249 17fe20a47c3-17fe20a47d2 call 17fe20a37ec 245->249 250 17fe20a47d4-17fe20a47d5 245->250 253 17fe20a4758-17fe20a4759 247->253 275 17fe20a46d8-17fe20a46de 248->275 276 17fe20a469c-17fe20a46c2 call 17fe20a3800 call 17fe20a4b0c 248->276 258 17fe20a47d7-17fe20a47e1 call 17fe20a540c 249->258 250->258 253->238 258->210 273 17fe20a47e7-17fe20a4835 call 17fe20a344c call 17fe20a3658 258->273 262->263 267 17fe20a4504-17fe20a450f 262->267 263->202 279 17fe20a4528-17fe20a4548 call 17fe20a2e5c * 2 call 17fe20a540c 263->279 267->263 272 17fe20a4511-17fe20a4516 267->272 272->197 272->263 273->210 283 17fe20a474f-17fe20a4750 275->283 284 17fe20a46e0-17fe20a46e4 275->284 295 17fe20a46e9-17fe20a4746 call 17fe20a4344 276->295 296 17fe20a46c4-17fe20a46d6 276->296 300 17fe20a454a-17fe20a4554 call 17fe20a54fc 279->300 301 17fe20a455f-17fe20a4560 279->301 285 17fe20a4754-17fe20a4755 283->285 284->248 285->253 295->285 296->275 296->276 304 17fe20a455a-17fe20a48c3 call 17fe20a2894 call 17fe20a4ec8 call 17fe20a5780 300->304 305 17fe20a48c4-17fe20a48c9 call 17fe20a6b88 300->305 301->202 304->305 305->244
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                        • String ID: csm$csm$csm
                        • API String ID: 849930591-393685449
                        • Opcode ID: 2ed4cc99f58428dff43d3f01cc5e852e5bb786ad8812c5a133ade536f624ce79
                        • Instruction ID: ae170397396fb04f6deabf8d3fad83d4c2a6cd633ea3a5462b11b35de2024571
                        • Opcode Fuzzy Hash: 2ed4cc99f58428dff43d3f01cc5e852e5bb786ad8812c5a133ade536f624ce79
                        • Instruction Fuzzy Hash: B1F14F7951CE488FEB54EB5884817EAB7F0FB55710F91066DE549C72A2EF30D882C782
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 315 17fe20a2630-17fe20a2676 call 17fe20a2e04 318 17fe20a2758-17fe20a275f 315->318 319 17fe20a267c-17fe20a2682 315->319 320 17fe20a27fa-17fe20a27fe 318->320 321 17fe20a2686-17fe20a2688 319->321 322 17fe20a2764-17fe20a2770 320->322 323 17fe20a2804 320->323 321->323 324 17fe20a268e-17fe20a269a 321->324 325 17fe20a27f8 322->325 326 17fe20a2776-17fe20a277d 322->326 327 17fe20a2809-17fe20a2826 323->327 328 17fe20a274a-17fe20a274c 324->328 329 17fe20a26a0-17fe20a26a7 324->329 325->320 326->325 330 17fe20a277f-17fe20a2787 326->330 328->321 329->328 331 17fe20a26ad-17fe20a26b2 329->331 332 17fe20a2789-17fe20a278e 330->332 333 17fe20a27cd-17fe20a27d3 330->333 331->328 334 17fe20a26b8-17fe20a26bd 331->334 335 17fe20a27c8-17fe20a27cb 332->335 336 17fe20a2790-17fe20a279e 332->336 337 17fe20a27e1-17fe20a27f5 333->337 338 17fe20a27d5-17fe20a27d8 333->338 339 17fe20a26bf-17fe20a26d2 334->339 340 17fe20a26d6-17fe20a26dd 334->340 335->323 335->333 343 17fe20a27c0-17fe20a27c6 336->343 344 17fe20a27a0-17fe20a27a8 336->344 337->325 338->325 345 17fe20a27da-17fe20a27dd 338->345 351 17fe20a2751-17fe20a2753 339->351 352 17fe20a26d4 339->352 341 17fe20a2707-17fe20a2745 call 17fe20a2dd0 call 17fe20a2e00 340->341 342 17fe20a26df-17fe20a26e7 340->342 341->328 342->341 347 17fe20a26e9-17fe20a26f7 call 17fe20aed00 342->347 343->335 343->336 344->343 348 17fe20a27aa-17fe20a27b3 344->348 345->323 350 17fe20a27df 345->350 347->341 357 17fe20a26f9-17fe20a26ff 347->357 348->343 354 17fe20a27b5-17fe20a27be 348->354 350->325 351->327 352->328 352->340 354->335 354->343 357->341
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: CurrentImageNonwritable__except_validate_context_record
                        • String ID: csm$f
                        • API String ID: 3242871069-629598281
                        • Opcode ID: cbb6678aba45670b62180b90d032deeebbb74b39f1951d1e686324c8961a414a
                        • Instruction ID: 3ba9174a26c3736a8e62b2abe72b3a7f03946c74cb5a7914321de1ac7a0310d4
                        • Opcode Fuzzy Hash: cbb6678aba45670b62180b90d032deeebbb74b39f1951d1e686324c8961a414a
                        • Instruction Fuzzy Hash: 2461B27660CE048FEB68AF1CD8857AA73E1F754350F91417DE94AC36E2EE30ED428685
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 360 17fe20a4c4c-17fe20a4c94 call 17fe20a2e04 call 17fe20a2e5c 365 17fe20a4cce-17fe20a4cd2 360->365 366 17fe20a4c96-17fe20a4c9c 360->366 367 17fe20a4cd8-17fe20a4cdc 365->367 368 17fe20a4d66-17fe20a4d6a 365->368 366->365 369 17fe20a4c9e-17fe20a4ca0 366->369 370 17fe20a4e5d 367->370 371 17fe20a4ce2-17fe20a4cea 367->371 372 17fe20a4dae-17fe20a4db4 368->372 373 17fe20a4d6c-17fe20a4d78 368->373 374 17fe20a4cb2-17fe20a4cb4 369->374 375 17fe20a4ca2-17fe20a4ca6 369->375 380 17fe20a4e62-17fe20a4e7c 370->380 371->370 377 17fe20a4cf0-17fe20a4cf4 371->377 382 17fe20a4db6-17fe20a4dba 372->382 383 17fe20a4e24-17fe20a4e58 call 17fe20a4418 372->383 378 17fe20a4d7a-17fe20a4d7e 373->378 379 17fe20a4d8e-17fe20a4d9a 373->379 374->365 376 17fe20a4cb6-17fe20a4cc2 374->376 375->376 381 17fe20a4ca8-17fe20a4cb0 375->381 376->365 385 17fe20a4cc4-17fe20a4cc8 376->385 386 17fe20a4cf6-17fe20a4cf8 377->386 387 17fe20a4d53-17fe20a4d61 call 17fe20a33e8 377->387 378->379 388 17fe20a4d80-17fe20a4d8c call 17fe20a37ec 378->388 379->370 390 17fe20a4da0-17fe20a4da8 379->390 381->365 381->374 382->383 384 17fe20a4dbc-17fe20a4dc3 382->384 383->370 384->383 391 17fe20a4dc5-17fe20a4dcd 384->391 385->365 385->370 393 17fe20a4cfa-17fe20a4d0c call 17fe20a401c 386->393 394 17fe20a4d31-17fe20a4d33 386->394 387->370 388->372 388->379 390->370 390->372 391->383 397 17fe20a4dcf-17fe20a4de2 call 17fe20a3800 391->397 401 17fe20a4e7d-17fe20a4e83 call 17fe20a6c14 393->401 407 17fe20a4d12-17fe20a4d15 393->407 394->387 396 17fe20a4d35-17fe20a4d3d 394->396 396->401 402 17fe20a4d43-17fe20a4d47 396->402 397->383 410 17fe20a4de4-17fe20a4e22 397->410 402->401 405 17fe20a4d4d-17fe20a4d51 402->405 409 17fe20a4d21-17fe20a4d2c call 17fe20a51e8 405->409 407->401 411 17fe20a4d1b-17fe20a4d1f 407->411 409->370 410->380 411->409
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
                        • String ID: csm$csm
                        • API String ID: 3896166516-3733052814
                        • Opcode ID: 179d466ca7e911971df6fec40f864e8670ee48de26d9b50b7fdfc5552c99cf0b
                        • Instruction ID: 343430ed44d61f442571e92259ec0e336acdca74ddeccbe3499baebf7ef9b054
                        • Opcode Fuzzy Hash: 179d466ca7e911971df6fec40f864e8670ee48de26d9b50b7fdfc5552c99cf0b
                        • Instruction Fuzzy Hash: 7E71807A11CE048FEBA8DB1880847A673E0FB54325FA5466ED55DC76F2EF309882C742
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_initialize_crt__scrt_release_startup_lock
                        • String ID:
                        • API String ID: 1452418845-0
                        • Opcode ID: 02bd2f8f1202d19f588490249a19570c034d6b83775ef71651d1b56b0c06cdeb
                        • Instruction ID: 96a50d855ca8ffb394238b778b3e7155d75672598e88626b535b21dd2c65a41b
                        • Opcode Fuzzy Hash: 02bd2f8f1202d19f588490249a19570c034d6b83775ef71651d1b56b0c06cdeb
                        • Instruction Fuzzy Hash: 984180BA60CE444EFB58A77894553EB73B1AB55340F8A493CA74E872F7EE6848078241
                        Uniqueness

                        Uniqueness Score: -1.00%

                        Control-flow Graph

                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000005.00000002.401725916.0000017FE20A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000017FE20A1000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_5_2_17fe20a1000_rundll32.jbxd
                        Yara matches
                        Similarity
                        • API ID: CallTranslator
                        • String ID: MOC$RCC
                        • API String ID: 3163161869-2084237596
                        • Opcode ID: 837fe712d1c841b9689310fb0e3b5e3a97da388e70ee50221832e68052b7cfc4
                        • Instruction ID: 289aa48ca244c2d061e61f2fb14d675c65377b47aa0420ec229f835381221ba6
                        • Opcode Fuzzy Hash: 837fe712d1c841b9689310fb0e3b5e3a97da388e70ee50221832e68052b7cfc4
                        • Instruction Fuzzy Hash: 50716D7551CA0C8FEB54EF58D4427EAB7F0FB58310F51026DE54AD31A2EB74E9828B82
                        Uniqueness

                        Uniqueness Score: -1.00%