Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe

Overview

General Information

Sample name:#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe
renamed because original name is a hash value
Original sample name:_uninstc.exe
Analysis ID:1520462
MD5:50c9853e37a18a5b5c2f5857ea1a5ab1
SHA1:079079af20c8d68e7ac999ee28961eee9b61f4c9
SHA256:31130b5f53f752897775b5a39ea3936e7afeff09dd3e381b15f1800efb68f2fb
Tags:exesilverfoxwinosuser-vm001cn
Infos:

Detection

Score:27
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Contain functionality to detect virtual machines
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Extensive use of GetProcAddress (often used to hide API calls)
Found evasive API chain (date check)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
Potential time zone aware malware
Program does not show much activity (idle)

Classification

  • System is w10x64
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90DE2B8 FindFirstFileExW,0_2_00007FF6F90DE2B8
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F9071A40 GetCurrentProcess,NtQueryObject,NtQueryObject,RtlNtStatusToDosError,_CxxThrowException,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_CxxThrowException,0_2_00007FF6F9071A40
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F9071F6D GetCurrentProcess,NtQueryObject,NtQueryObject,0_2_00007FF6F9071F6D
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F907BAC00_2_00007FF6F907BAC0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F9084CE00_2_00007FF6F9084CE0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90C80640_2_00007FF6F90C8064
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F909F1440_2_00007FF6F909F144
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D95800_2_00007FF6F90D9580
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90938760_2_00007FF6F9093876
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90C5A480_2_00007FF6F90C5A48
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F9090A400_2_00007FF6F9090A40
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F908FA780_2_00007FF6F908FA78
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90E7AA40_2_00007FF6F90E7AA4
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D0AE40_2_00007FF6F90D0AE4
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D7AE00_2_00007FF6F90D7AE0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90A0B140_2_00007FF6F90A0B14
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90CB9900_2_00007FF6F90CB990
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D09800_2_00007FF6F90D0980
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90829B00_2_00007FF6F90829B0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90959BC0_2_00007FF6F90959BC
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F908C9FC0_2_00007FF6F908C9FC
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90C8C880_2_00007FF6F90C8C88
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90DFC840_2_00007FF6F90DFC84
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90C5CE00_2_00007FF6F90C5CE0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90DAB3C0_2_00007FF6F90DAB3C
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F908DB640_2_00007FF6F908DB64
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F9092B780_2_00007FF6F9092B78
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F9099C1C0_2_00007FF6F9099C1C
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90CBEC40_2_00007FF6F90CBEC4
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F9075EC00_2_00007FF6F9075EC0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F909DD400_2_00007FF6F909DD40
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F9094D380_2_00007FF6F9094D38
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90CDD600_2_00007FF6F90CDD60
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D4DB80_2_00007FF6F90D4DB8
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D20700_2_00007FF6F90D2070
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F909B0640_2_00007FF6F909B064
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90DE0880_2_00007FF6F90DE088
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D509C0_2_00007FF6F90D509C
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90E10C80_2_00007FF6F90E10C8
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F909A0F40_2_00007FF6F909A0F4
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D0F7C0_2_00007FF6F90D0F7C
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D70200_2_00007FF6F90D7020
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D42B40_2_00007FF6F90D42B4
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F908D2B00_2_00007FF6F908D2B0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90CE44C0_2_00007FF6F90CE44C
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F907A4900_2_00007FF6F907A490
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90865200_2_00007FF6F9086520
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90C938C0_2_00007FF6F90C938C
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F908E37C0_2_00007FF6F908E37C
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90843AC0_2_00007FF6F90843AC
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90AE3C00_2_00007FF6F90AE3C0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90C83FC0_2_00007FF6F90C83FC
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90786900_2_00007FF6F9078690
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F908367C0_2_00007FF6F908367C
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D27280_2_00007FF6F90D2728
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F909A72C0_2_00007FF6F909A72C
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90945540_2_00007FF6F9094554
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D25880_2_00007FF6F90D2588
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D28C80_2_00007FF6F90D28C8
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90E29080_2_00007FF6F90E2908
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F909F9180_2_00007FF6F909F918
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90A17880_2_00007FF6F90A1788
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: String function: 00007FF6F90D9BEC appears 32 times
Source: classification engineClassification label: sus27.evad.winEXE@1/0@0/0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F9074350 FormatMessageA,LocalFree,std::ios_base::_Ios_base_dtor,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,GetLastError,_CxxThrowException,0_2_00007FF6F9074350
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F907BAC0 LoadLibraryW,GetProcAddress,IsDebuggerPresent,FreeLibrary,GetModuleHandleA,FindResourceA,LoadResource,SizeofResource,LockResource,CreateToolhelp32Snapshot,Process32First,CloseHandle,LoadLibraryA,GetProcAddress,allocator,allocator,_CxxThrowException,_invalid_parameter_noinfo_noreturn,_CxxThrowException,_CxxThrowException,_CxxThrowException,_CxxThrowException,_CxxThrowException,0_2_00007FF6F907BAC0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F907BAC0 LoadLibraryW,GetProcAddress,IsDebuggerPresent,FreeLibrary,GetModuleHandleA,FindResourceA,LoadResource,SizeofResource,LockResource,CreateToolhelp32Snapshot,Process32First,CloseHandle,LoadLibraryA,GetProcAddress,allocator,allocator,_CxxThrowException,_invalid_parameter_noinfo_noreturn,_CxxThrowException,_CxxThrowException,_CxxThrowException,_CxxThrowException,_CxxThrowException,0_2_00007FF6F907BAC0
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSection loaded: wintypes.dllJump to behavior
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F907BAC0 LoadLibraryW,GetProcAddress,IsDebuggerPresent,FreeLibrary,GetModuleHandleA,FindResourceA,LoadResource,SizeofResource,LockResource,CreateToolhelp32Snapshot,Process32First,CloseHandle,LoadLibraryA,GetProcAddress,allocator,allocator,_CxxThrowException,_invalid_parameter_noinfo_noreturn,_CxxThrowException,_CxxThrowException,_CxxThrowException,_CxxThrowException,_CxxThrowException,0_2_00007FF6F907BAC0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90B5C18 GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,0_2_00007FF6F90B5C18

Malware Analysis System Evasion

barindex
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: VBoxMouse.sys VBoxGuest.sys VBoxSF.sys 0_2_00007FF6F90789A0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: qemu qemu vbox vbox vbox 0_2_00007FF6F9079680
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeEvasive API call chain: GetSystemTimeAsFileTime,DecisionNodesgraph_0-45872
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeAPI coverage: 5.1 %
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe TID: 5976Thread sleep time: -50000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe TID: 5976Thread sleep time: -50000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeSystem information queried: CurrentTimeZoneInformationJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90DE2B8 FindFirstFileExW,0_2_00007FF6F90DE2B8
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeThread delayed: delay time: 50000Jump to behavior
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeThread delayed: delay time: 50000Jump to behavior
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeBinary or memory string: vmci.sys
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeBinary or memory string: vmhgfs.sys
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeBinary or memory string: VBoxMouse.sys
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeBinary or memory string: VBoxSF.sys
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeBinary or memory string: VBoxGuest.sys
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeBinary or memory string: vmmouse.sys
Source: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeBinary or memory string: vmmouse.sysvmhgfs.sysvm3dmp.sysvmu**mouse.sysvmx_svga.sysvmxnet.sysvmci.sysVBoxMouse.sysVBoxGuest.sysVBoxSF.sysFailed to find shellcode resourceFailed to load shellcode resourceShellcode resource size is 0Failed to lock shellcode resourceFailed to find lsass.exe processFailed to get RtlAdjustPrivilege addressGET
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F907BAC0 LoadLibraryW,GetProcAddress,IsDebuggerPresent,FreeLibrary,GetModuleHandleA,FindResourceA,LoadResource,SizeofResource,LockResource,CreateToolhelp32Snapshot,Process32First,CloseHandle,LoadLibraryA,GetProcAddress,allocator,allocator,_CxxThrowException,_invalid_parameter_noinfo_noreturn,_CxxThrowException,_CxxThrowException,_CxxThrowException,_CxxThrowException,_CxxThrowException,0_2_00007FF6F907BAC0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F907BAC0 LoadLibraryW,GetProcAddress,IsDebuggerPresent,FreeLibrary,GetModuleHandleA,FindResourceA,LoadResource,SizeofResource,LockResource,CreateToolhelp32Snapshot,Process32First,CloseHandle,LoadLibraryA,GetProcAddress,allocator,allocator,_CxxThrowException,_invalid_parameter_noinfo_noreturn,_CxxThrowException,_CxxThrowException,_CxxThrowException,_CxxThrowException,_CxxThrowException,0_2_00007FF6F907BAC0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90DF708 GetProcessHeap,0_2_00007FF6F90DF708
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90A3E20 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6F90A3E20
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90A4004 SetUnhandledExceptionFilter,0_2_00007FF6F90A4004
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90C4158 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF6F90C4158
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90A3694 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF6F90A3694
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90DDBA0 cpuid 0_2_00007FF6F90DDBA0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: GetLocaleInfoEx,__crtDownlevelLocaleNameToLCID,GetLocaleInfoW,0_2_00007FF6F90A2628
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: __crtGetLocaleInfoEx,0_2_00007FF6F90A2884
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: EnumSystemLocalesW,0_2_00007FF6F90E1A38
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: EnumSystemLocalesW,0_2_00007FF6F90E1B08
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: EnumSystemLocalesW,0_2_00007FF6F90D9B54
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF6F90E1BA4
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF6F90E1F30
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: GetLocaleInfoW,0_2_00007FF6F90E1DE4
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF6F90E210C
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: GetLocaleInfoW,0_2_00007FF6F90E1FE0
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: try_get_function,GetLocaleInfoW,0_2_00007FF6F90DA1BC
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,wcschr,wcschr,GetLocaleInfoW,0_2_00007FF6F90E1720
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F9086BAC GetSystemTimeAsFileTime,0_2_00007FF6F9086BAC
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90D9580 _get_daylight,_get_daylight,_get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,0_2_00007FF6F90D9580
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90AB290 GetVersionExW,Concurrency::details::platform::InitializeSystemFunctionPointers,Concurrency::details::WinRT::Initialize,_CxxThrowException,_CxxThrowException,0_2_00007FF6F90AB290
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90B94C8 Concurrency::details::SchedulerBase::GetInternalContext,Concurrency::details::WorkItem::ResolveToken,Concurrency::details::WorkItem::BindTo,Concurrency::details::SchedulerBase::ReleaseInternalContext,Concurrency::details::WorkItem::Bind,Concurrency::details::SchedulerBase::GetInternalContext,0_2_00007FF6F90B94C8
Source: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exeCode function: 0_2_00007FF6F90BA4F4 Concurrency::details::VirtualProcessor::ThrowVirtualProcessorEvent,Concurrency::details::InternalContextBase::SwitchOut,Concurrency::details::SchedulerBase::GetInternalContext,Concurrency::details::WorkItem::ResolveToken,Concurrency::details::WorkItem::BindTo,Concurrency::details::SchedulerBase::ReleaseInternalContext,Concurrency::details::InternalContextBase::SwitchTo,Concurrency::details::SchedulerBase::ReleaseInternalContext,Concurrency::details::WorkItem::Bind,0_2_00007FF6F90BA4F4
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Native API
1
DLL Side-Loading
1
DLL Side-Loading
112
Virtualization/Sandbox Evasion
OS Credential Dumping12
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Deobfuscate/Decode Files or Information
LSASS Memory121
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account Manager112
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
Process Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials23
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe8%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1520462
Start date and time:2024-09-27 11:23:28 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 2m 33s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:2
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe
renamed because original name is a hash value
Original Sample Name:_uninstc.exe
Detection:SUS
Classification:sus27.evad.winEXE@1/0@0/0
EGA Information:
  • Successful, ratio: 100%
HCA Information:
  • Successful, ratio: 96%
  • Number of executed functions: 28
  • Number of non-executed functions: 206
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Stop behavior analysis, all processes terminated
  • Exclude process from analysis (whitelisted): dllhost.exe
  • VT rate limit hit for: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe
TimeTypeDescription
05:24:36API Interceptor2x Sleep call for process: #U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe modified
No context
No context
No context
No context
No context
No created / dropped files found
File type:PE32+ executable (GUI) x86-64, for MS Windows
Entropy (8bit):6.532534399779066
TrID:
  • Win64 Executable GUI (202006/5) 92.65%
  • Win64 Executable (generic) (12005/4) 5.51%
  • Generic Win/DOS Executable (2004/3) 0.92%
  • DOS Executable Generic (2002/1) 0.92%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe
File size:887'808 bytes
MD5:50c9853e37a18a5b5c2f5857ea1a5ab1
SHA1:079079af20c8d68e7ac999ee28961eee9b61f4c9
SHA256:31130b5f53f752897775b5a39ea3936e7afeff09dd3e381b15f1800efb68f2fb
SHA512:af8c0cd6f960a2a98eca3a56496461260c56a2ef0500b5470266ffb568bc608ff8b224f7fdc5f0d40294188342de4b0baa7f257dc79c148674ae6d661fbb58a5
SSDEEP:12288:75wUl0+S9fNs974kg4B3ohHAbZioA2O4TmKBLf6:75wUl0+S9f8c8B3ohkZiEOmD
TLSH:AA158C16AAD445FCE0239336CB578567F7B274061A319B9F03AC066A1F272A14EFF721
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........v...%...%...%...$...%...$...%...$u..%...$...%...$...%...%|..%...$...%...$...%{..$...%{.x%...%...%...%{..$...%Rich...%.......
Icon Hash:00928e8e8686b000
Entrypoint:0x140033bec
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x140000000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x56EB4C6D [Fri Mar 18 00:31:41 2016 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:6
OS Version Minor:0
File Version Major:6
File Version Minor:0
Subsystem Version Major:6
Subsystem Version Minor:0
Import Hash:1d878e2886045880ff55ccfced8fd653
Instruction
dec eax
sub esp, 28h
call 00007F5515054A7Ch
dec eax
add esp, 28h
jmp 00007F551505449Fh
int3
int3
jmp 00007F5515053BC4h
int3
int3
int3
inc eax
push ebx
dec eax
sub esp, 20h
dec eax
mov ebx, ecx
dec eax
mov eax, edx
dec eax
lea ecx, dword ptr [00045A4Dh]
dec eax
mov dword ptr [ebx], ecx
dec eax
lea edx, dword ptr [ebx+08h]
xor ecx, ecx
dec eax
mov dword ptr [edx], ecx
dec eax
mov dword ptr [edx+08h], ecx
dec eax
lea ecx, dword ptr [eax+08h]
call 00007F5515071499h
dec eax
lea eax, dword ptr [0004E8CDh]
dec eax
mov dword ptr [ebx], eax
dec eax
mov eax, ebx
dec eax
add esp, 20h
pop ebx
ret
int3
dec eax
and dword ptr [ecx+10h], 00000000h
dec eax
lea eax, dword ptr [0004E8C4h]
dec eax
mov dword ptr [ecx+08h], eax
dec eax
lea eax, dword ptr [0004E8A9h]
dec eax
mov dword ptr [ecx], eax
dec eax
mov eax, ecx
ret
int3
int3
dec eax
sub esp, 48h
dec eax
lea ecx, dword ptr [esp+20h]
call 00007F55150545F7h
dec eax
lea edx, dword ptr [0006D9D3h]
dec eax
lea ecx, dword ptr [esp+20h]
call 00007F55150714FEh
int3
jmp 00007F5515075214h
int3
int3
int3
dec eax
mov dword ptr [esp+10h], ebx
dec eax
mov dword ptr [esp+18h], esi
push edi
dec eax
sub esp, 10h
xor eax, eax
mov dword ptr [0006F4C9h], 00000002h
xor ecx, ecx
mov dword ptr [0006F4B9h], 00000001h
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0xa1dac0x50.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0xb00000x2b580.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0xa90000x6138.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0xdc0000x165c.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x919b00x1c.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x919d00x100.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x790000x488.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x77e740x780005fc22c4fd8ce7fd6389e5fec6eaaac70False0.494903564453125data6.472719007713046IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x790000x29d5c0x29e009d081de1d188f689daedea7c0e9ed169False0.3739563899253731data4.735870485264002IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0xa30000x5b2c0x3a00b4c1acef0fb8e97fa77d58062b928ec1False0.16419719827586207data4.194091435024407IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.pdata0xa90000x61380x6200fe97fb6ad42f89bee1fc926d910dcf0fFalse0.4925063775510204data5.80549196958669IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.rsrc0xb00000x2b5800x2b60002a6e821f37f3fe0b12a318313864399False0.4194659582132565data5.245510363952572IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0xdc0000x165c0x18007bec397984cd14f99fb5a63c78f5caccFalse0.3336588541666667data5.318436076636775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_RCDATA0xb00a00x2b2acASCII text, with very long lines (65536), with no line terminatorsChineseChina0.4190043662194874
RT_MANIFEST0xdb3500x22fXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (499), with CRLF line terminatorsEnglishUnited States0.5295169946332737
DLLImport
ntdll.dllRtlNtStatusToDosError, RtlPcToFileHeader, RtlUnwindEx, TpAllocJobNotification, NtQueryObject, NtQueryInformationProcess, RtlUnwind
WINHTTP.dllWinHttpCrackUrl
KERNEL32.dllRtlVirtualUnwind, SetStdHandle, GetProcessHeap, SetEnvironmentVariableA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, GetCommandLineA, GetOEMCP, IsValidCodePage, FindNextFileW, FindFirstFileExW, WriteConsoleW, FindClose, HeapReAlloc, GetCurrentProcess, GetLastError, LocalFree, FormatMessageA, SearchPathA, CreateFileA, WriteFile, IsDebuggerPresent, CloseHandle, FreeLibrary, GetModuleHandleA, GetProcAddress, LoadResource, LockResource, SizeofResource, LoadLibraryA, LoadLibraryW, FindResourceA, CreateToolhelp32Snapshot, Process32First, Process32Next, CreateFileW, DuplicateHandle, SetEvent, CreateEventW, OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateJobObjectW, AssignProcessToJobObject, SetInformationJobObject, WideCharToMultiByte, WaitForSingleObjectEx, Sleep, SwitchToThread, GetCurrentThread, GetCurrentThreadId, GetExitCodeThread, QueryPerformanceCounter, EnterCriticalSection, LeaveCriticalSection, TryEnterCriticalSection, DeleteCriticalSection, MultiByteToWideChar, EncodePointer, DecodePointer, SetLastError, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetSystemTimeAsFileTime, GetTickCount, GetModuleHandleW, CompareStringW, LCMapStringW, GetLocaleInfoW, GetStringTypeW, GetCPInfo, RtlCaptureContext, RtlLookupFunctionEntry, SetFilePointerEx, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, GetStartupInfoW, GetCurrentProcessId, InitializeSListHead, CreateTimerQueue, SignalObjectAndWait, CreateThread, SetThreadPriority, GetThreadPriority, GetLogicalProcessorInformation, CreateTimerQueueTimer, ChangeTimerQueueTimer, DeleteTimerQueueTimer, GetNumaHighestNodeNumber, GetProcessAffinityMask, SetThreadAffinityMask, RegisterWaitForSingleObject, UnregisterWait, GetThreadTimes, FreeLibraryAndExitThread, GetModuleFileNameW, LoadLibraryExW, GetVersionExW, VirtualAlloc, VirtualProtect, VirtualFree, ReleaseSemaphore, InterlockedPopEntrySList, InterlockedPushEntrySList, InterlockedFlushSList, QueryDepthSList, UnregisterWaitEx, ReadConsoleW, ReadFile, GetConsoleMode, GetConsoleCP, RaiseException, ExitProcess, GetModuleHandleExW, ExitThread, GetStdHandle, GetACP, HeapAlloc, HeapFree, GetFileType, GetTimeZoneInformation, GetDateFormatW, GetTimeFormatW, IsValidLocale, GetUserDefaultLCID, EnumSystemLocalesW, FlushFileBuffers, HeapSize
Language of compilation systemCountry where language is spokenMap
ChineseChina
EnglishUnited States
No network behavior found

Click to jump to process

Click to jump to process

Target ID:0
Start time:05:24:36
Start date:27/09/2024
Path:C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe"
Imagebase:0x7ff6f9070000
File size:887'808 bytes
MD5 hash:50C9853E37A18A5B5C2F5857EA1A5AB1
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

Reset < >

    Execution Graph

    Execution Coverage:2.1%
    Dynamic/Decrypted Code Coverage:0%
    Signature Coverage:37.1%
    Total number of Nodes:1106
    Total number of Limit Nodes:24
    execution_graph 44354 7ff6f90c9874 44355 7ff6f90c9882 GetLastError ExitThread 44354->44355 44356 7ff6f90c9891 44354->44356 44367 7ff6f90d67d4 GetLastError 44356->44367 44358 7ff6f90c9896 44394 7ff6f90d8be4 44358->44394 44361 7ff6f90c98af 44398 7ff6f907aaf0 44361->44398 44363 7ff6f90c98c4 44405 7ff6f90c9a84 44363->44405 44368 7ff6f90d67f6 44367->44368 44369 7ff6f90d67f1 44367->44369 44376 7ff6f90d67fe 44368->44376 44410 7ff6f90da0b0 6 API calls try_get_function 44368->44410 44409 7ff6f90da068 6 API calls try_get_function 44369->44409 44372 7ff6f90d6891 SetLastError 44429 7ff6f90c96ec 35 API calls 2 library calls 44372->44429 44373 7ff6f90d6818 44373->44372 44411 7ff6f90d6a78 44373->44411 44375 7ff6f90d6804 44375->44372 44376->44372 44376->44375 44379 7ff6f90d687b SetLastError 44376->44379 44379->44358 44381 7ff6f90d6849 44426 7ff6f90da0b0 6 API calls try_get_function 44381->44426 44382 7ff6f90d6839 44420 7ff6f90da0b0 6 API calls try_get_function 44382->44420 44385 7ff6f90d6840 44421 7ff6f90d6af0 44385->44421 44386 7ff6f90d6851 44387 7ff6f90d6855 44386->44387 44388 7ff6f90d6867 44386->44388 44427 7ff6f90da0b0 6 API calls try_get_function 44387->44427 44428 7ff6f90d6584 14 API calls _Tolower 44388->44428 44392 7ff6f90d686f 44393 7ff6f90d6af0 Concurrency::details::SchedulerProxy::DeleteThis 14 API calls 44392->44393 44393->44376 44395 7ff6f90d8bf4 44394->44395 44396 7ff6f90c98a2 44394->44396 44395->44396 44441 7ff6f90d9e14 44395->44441 44396->44361 44408 7ff6f90da5f0 5 API calls try_get_function 44396->44408 44400 7ff6f907ab0f codecvt 44398->44400 44399 7ff6f907ab34 44399->44363 44400->44399 44454 7ff6f90c438c 44400->44454 44402 7ff6f907ab57 44404 7ff6f907ab70 46 API calls 44402->44404 44403 7ff6f907ab69 44403->44363 44404->44403 44465 7ff6f90c98dc 44405->44465 44408->44361 44410->44373 44412 7ff6f90d6a89 44411->44412 44419 7ff6f90d6a97 std::locale::_Locimp::_Makeushloc 44411->44419 44413 7ff6f90d6ada 44412->44413 44412->44419 44433 7ff6f90c932c 14 API calls _get_daylight 44413->44433 44414 7ff6f90d6abe HeapAlloc 44415 7ff6f90d6ad8 44414->44415 44414->44419 44417 7ff6f90d682b 44415->44417 44417->44381 44417->44382 44419->44413 44419->44414 44430 7ff6f90d380c 44419->44430 44420->44385 44422 7ff6f90d6af5 HeapFree 44421->44422 44423 7ff6f90d6b27 44421->44423 44422->44423 44424 7ff6f90d6b10 44422->44424 44423->44375 44440 7ff6f90c932c 14 API calls _get_daylight 44424->44440 44426->44386 44427->44385 44428->44392 44434 7ff6f90d383c 44430->44434 44433->44417 44439 7ff6f90c8a74 EnterCriticalSection 44434->44439 44440->44423 44444 7ff6f90d9bec 44441->44444 44445 7ff6f90d9c4d 44444->44445 44449 7ff6f90d9c48 try_get_function 44444->44449 44445->44396 44446 7ff6f90d9d30 44446->44445 44450 7ff6f90d9d3e GetProcAddress 44446->44450 44447 7ff6f90d9c7c LoadLibraryExW 44448 7ff6f90d9c9d GetLastError 44447->44448 44447->44449 44448->44449 44449->44445 44449->44446 44449->44447 44452 7ff6f90d9d15 FreeLibrary 44449->44452 44453 7ff6f90d9cd7 LoadLibraryExW 44449->44453 44451 7ff6f90d9d4f 44450->44451 44451->44445 44452->44449 44453->44449 44459 7ff6f90c42bc 31 API calls 3 library calls 44454->44459 44456 7ff6f90c43a5 44460 7ff6f90c43bc IsProcessorFeaturePresent 44456->44460 44459->44456 44461 7ff6f90c43cf 44460->44461 44464 7ff6f90c4158 14 API calls 3 library calls 44461->44464 44463 7ff6f90c43ea GetCurrentProcess TerminateProcess 44464->44463 44478 7ff6f90d6948 GetLastError 44465->44478 44468 7ff6f90c98f2 ExitThread 44469 7ff6f90c98fb 44470 7ff6f90c9907 ExitThread 44469->44470 44472 7ff6f90c9910 44469->44472 44471 7ff6f90c991b 44474 7ff6f90c992f 44471->44474 44475 7ff6f90c9929 CloseHandle 44471->44475 44472->44471 44504 7ff6f90da630 5 API calls try_get_function 44472->44504 44476 7ff6f90c993d FreeLibraryAndExitThread 44474->44476 44477 7ff6f90c9946 ExitThread 44474->44477 44475->44474 44476->44477 44479 7ff6f90d6965 44478->44479 44480 7ff6f90d696a 44478->44480 44505 7ff6f90da068 6 API calls try_get_function 44479->44505 44485 7ff6f90d6972 44480->44485 44506 7ff6f90da0b0 6 API calls try_get_function 44480->44506 44483 7ff6f90d697c SetLastError 44486 7ff6f90c98ed 44483->44486 44484 7ff6f90d69a3 44484->44483 44487 7ff6f90d6a78 _Thrd_start 11 API calls 44484->44487 44485->44483 44489 7ff6f90d6a0a SetLastError 44485->44489 44486->44468 44486->44469 44488 7ff6f90d69b6 44487->44488 44490 7ff6f90d69d4 44488->44490 44491 7ff6f90d69c4 44488->44491 44489->44486 44508 7ff6f90da0b0 6 API calls try_get_function 44490->44508 44507 7ff6f90da0b0 6 API calls try_get_function 44491->44507 44494 7ff6f90d69dc 44496 7ff6f90d69f2 44494->44496 44497 7ff6f90d69e0 44494->44497 44495 7ff6f90d69cb 44500 7ff6f90d6af0 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 44495->44500 44510 7ff6f90d6584 14 API calls _Tolower 44496->44510 44509 7ff6f90da0b0 6 API calls try_get_function 44497->44509 44502 7ff6f90d69d2 44500->44502 44501 7ff6f90d69fa 44503 7ff6f90d6af0 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 44501->44503 44502->44483 44503->44485 44504->44471 44506->44484 44507->44495 44508->44494 44509->44495 44510->44501 44511 7ff6f907f41b 44514 7ff6f907f4b0 44511->44514 44513 7ff6f907f42b 44515 7ff6f907f4cd 44514->44515 44516 7ff6f907f4d7 codecvt 44514->44516 44515->44516 44518 7ff6f90c487c 15 API calls _get_daylight 44515->44518 44516->44513 44518->44516 44519 7ff6f90c8064 44520 7ff6f90c8095 Concurrency::details::QuickBitSet::Grow 44519->44520 44521 7ff6f90c807a 44519->44521 44520->44521 44524 7ff6f90c80aa 44520->44524 44558 7ff6f90c932c 14 API calls _get_daylight 44521->44558 44523 7ff6f90c807f 44559 7ff6f90c436c 31 API calls _invalid_parameter_noinfo 44523->44559 44526 7ff6f90c80b0 44524->44526 44528 7ff6f90c80cd 44524->44528 44560 7ff6f90c932c 14 API calls _get_daylight 44526->44560 44550 7ff6f90d9ac0 44528->44550 44533 7ff6f90c8366 44534 7ff6f90c43bc __lc_wcstolc 17 API calls 44533->44534 44537 7ff6f90c837c 44534->44537 44538 7ff6f90c8350 44540 7ff6f90c43bc __lc_wcstolc 17 API calls 44538->44540 44540->44533 44542 7ff6f90c8111 44545 7ff6f90c818a 44542->44545 44546 7ff6f90c812a 44542->44546 44543 7ff6f90c833b 44544 7ff6f90c43bc __lc_wcstolc 17 API calls 44543->44544 44544->44538 44547 7ff6f90c808b 44545->44547 44580 7ff6f90d9afc 31 API calls _isindst 44545->44580 44546->44547 44579 7ff6f90d9afc 31 API calls _isindst 44546->44579 44551 7ff6f90d9ace 44550->44551 44552 7ff6f90c80d2 44550->44552 44581 7ff6f90c8a74 EnterCriticalSection 44551->44581 44561 7ff6f90d8d50 44552->44561 44554 7ff6f90d9ad6 44555 7ff6f90d9ae6 44554->44555 44556 7ff6f90d99b8 _Wcsftime 67 API calls 44554->44556 44557 7ff6f90c8ac8 _isindst LeaveCriticalSection 44555->44557 44556->44555 44557->44552 44558->44523 44559->44547 44560->44547 44562 7ff6f90c80e7 44561->44562 44563 7ff6f90d8d59 44561->44563 44562->44533 44567 7ff6f90d8d80 44562->44567 44582 7ff6f90c932c 14 API calls _get_daylight 44563->44582 44565 7ff6f90d8d5e 44583 7ff6f90c436c 31 API calls _invalid_parameter_noinfo 44565->44583 44568 7ff6f90c80f8 44567->44568 44569 7ff6f90d8d89 44567->44569 44568->44538 44573 7ff6f90d8db0 44568->44573 44584 7ff6f90c932c 14 API calls _get_daylight 44569->44584 44571 7ff6f90d8d8e 44585 7ff6f90c436c 31 API calls _invalid_parameter_noinfo 44571->44585 44574 7ff6f90d8db9 44573->44574 44576 7ff6f90c8109 44573->44576 44586 7ff6f90c932c 14 API calls _get_daylight 44574->44586 44576->44542 44576->44543 44577 7ff6f90d8dbe 44587 7ff6f90c436c 31 API calls _invalid_parameter_noinfo 44577->44587 44579->44547 44580->44547 44582->44565 44583->44562 44584->44571 44585->44568 44586->44577 44587->44576 44588 7ff6f9093876 44589 7ff6f909387f 44588->44589 44590 7ff6f9093941 44588->44590 44591 7ff6f90938bf 44589->44591 44851 7ff6f907eeac 44589->44851 44592 7ff6f9093981 44590->44592 44596 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44590->44596 44593 7ff6f90a3168 collate 4 API calls 44591->44593 44868 7ff6f90888f0 76 API calls 5 library calls 44592->44868 44597 7ff6f90938d0 44593->44597 44600 7ff6f9093958 44596->44600 44601 7ff6f909390b 44597->44601 44856 7ff6f907ef80 35 API calls 3 library calls 44597->44856 44598 7ff6f9093990 44602 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44598->44602 44599 7ff6f9093896 44855 7ff6f907ef2c LeaveCriticalSection 44599->44855 44867 7ff6f907ef2c LeaveCriticalSection 44600->44867 44609 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44601->44609 44605 7ff6f909393c 44602->44605 44608 7ff6f9093c40 44605->44608 44611 7ff6f9093b30 44605->44611 44612 7ff6f90939b8 44605->44612 44607 7ff6f90938f3 44857 7ff6f907f178 44607->44857 44809 7ff6f908b674 44608->44809 44609->44605 44614 7ff6f9093b69 44611->44614 44619 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44611->44619 44615 7ff6f90939f1 44612->44615 44620 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44612->44620 44874 7ff6f9089760 76 API calls 7 library calls 44614->44874 44618 7ff6f90a3168 collate 4 API calls 44615->44618 44625 7ff6f9093a02 44618->44625 44626 7ff6f9093b40 44619->44626 44627 7ff6f90939c8 44620->44627 44621 7ff6f9093e2e 44633 7ff6f90941d1 44621->44633 44637 7ff6f9094064 44621->44637 44638 7ff6f9093e48 44621->44638 44622 7ff6f9093c6a 44630 7ff6f9093caa 44622->44630 44640 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44622->44640 44623 7ff6f9093cfd 44632 7ff6f9093d3d 44623->44632 44635 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44623->44635 44624 7ff6f9093b78 44631 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44624->44631 44646 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44625->44646 44873 7ff6f907ef2c LeaveCriticalSection 44626->44873 44869 7ff6f907ef2c LeaveCriticalSection 44627->44869 44628 7ff6f9093d70 44648 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44628->44648 44700 7ff6f9093da9 44628->44700 44629 7ff6f9093dd8 44643 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44629->44643 44690 7ff6f9093e11 44629->44690 44642 7ff6f90a3168 collate 4 API calls 44630->44642 44641 7ff6f9093b86 44631->44641 44882 7ff6f9088688 76 API calls 5 library calls 44632->44882 44652 7ff6f90941e7 44633->44652 44653 7ff6f9094308 44633->44653 44644 7ff6f9093d14 44635->44644 44657 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44637->44657 44708 7ff6f909409d 44637->44708 44659 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44638->44659 44709 7ff6f9093e81 44638->44709 44649 7ff6f9093c81 44640->44649 44663 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44641->44663 44712 7ff6f9093bc6 44641->44712 44651 7ff6f9093cbb 44642->44651 44654 7ff6f9093de8 44643->44654 44881 7ff6f907ef2c LeaveCriticalSection 44644->44881 44656 7ff6f9093a2c 44646->44656 44647 7ff6f9093d4c 44658 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44647->44658 44661 7ff6f9093d80 44648->44661 44879 7ff6f907ef2c LeaveCriticalSection 44649->44879 44650 7ff6f90a3168 collate 4 API calls 44655 7ff6f9093dba 44650->44655 44685 7ff6f9093cde 44651->44685 44880 7ff6f90a2780 35 API calls 2 library calls 44651->44880 44677 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44652->44677 44714 7ff6f9094227 44652->44714 44665 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44653->44665 44716 7ff6f9094348 44653->44716 44884 7ff6f907ef2c LeaveCriticalSection 44654->44884 44668 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44655->44668 44680 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44656->44680 44726 7ff6f9093a6c 44656->44726 44670 7ff6f9094074 44657->44670 44689 7ff6f9093cf8 44658->44689 44671 7ff6f9093e58 44659->44671 44883 7ff6f907ef2c LeaveCriticalSection 44661->44883 44674 7ff6f9093b9d 44663->44674 44691 7ff6f909431f 44665->44691 44666 7ff6f90a3168 collate 4 API calls 44693 7ff6f9094238 44666->44693 44668->44621 44892 7ff6f907ef2c LeaveCriticalSection 44670->44892 44886 7ff6f907ef2c LeaveCriticalSection 44671->44886 44672 7ff6f90940ac 44683 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44672->44683 44875 7ff6f907ef2c LeaveCriticalSection 44674->44875 44676 7ff6f9093bd5 44686 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44676->44686 44688 7ff6f90941fe 44677->44688 44678 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44678->44689 44694 7ff6f9093a43 44680->44694 44681 7ff6f9094357 44695 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44681->44695 44682 7ff6f90a3168 collate 4 API calls 44698 7ff6f9093a7d 44682->44698 44699 7ff6f90940ba 44683->44699 44685->44678 44687 7ff6f9093be3 44686->44687 44703 7ff6f9093c23 44687->44703 44713 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44687->44713 44900 7ff6f907ef2c LeaveCriticalSection 44688->44900 44689->44621 44689->44628 44689->44629 44885 7ff6f9088b58 76 API calls 5 library calls 44690->44885 44905 7ff6f907ef2c LeaveCriticalSection 44691->44905 44692 7ff6f909425d 44717 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44692->44717 44693->44692 44901 7ff6f9092324 41 API calls 2 library calls 44693->44901 44870 7ff6f907ef2c LeaveCriticalSection 44694->44870 44707 7ff6f9094365 44695->44707 44728 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44698->44728 44710 7ff6f90940fa 44699->44710 44720 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44699->44720 44700->44650 44878 7ff6f9089c30 76 API calls 7 library calls 44703->44878 44719 7ff6f90943a5 44707->44719 44727 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44707->44727 44893 7ff6f9088dc0 76 API calls 5 library calls 44708->44893 44827 7ff6f90a3168 44709->44827 44895 7ff6f9089028 76 API calls 6 library calls 44710->44895 44876 7ff6f90899c8 76 API calls 7 library calls 44712->44876 44724 7ff6f9093bfa 44713->44724 44714->44666 44906 7ff6f9089e98 78 API calls 6 library calls 44716->44906 44725 7ff6f9094271 44717->44725 44908 7ff6f908a100 76 API calls 6 library calls 44719->44908 44730 7ff6f90940d1 44720->44730 44723 7ff6f9094109 44732 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44723->44732 44877 7ff6f907ef2c LeaveCriticalSection 44724->44877 44734 7ff6f90942b1 44725->44734 44742 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44725->44742 44726->44682 44735 7ff6f909437c 44727->44735 44736 7ff6f9093aa7 44728->44736 44894 7ff6f907ef2c LeaveCriticalSection 44730->44894 44731 7ff6f9093efc 44733 7ff6f90a3168 collate 4 API calls 44731->44733 44738 7ff6f9094117 44732->44738 44739 7ff6f9093f0d 44733->44739 44743 7ff6f90a3168 collate 4 API calls 44734->44743 44907 7ff6f907ef2c LeaveCriticalSection 44735->44907 44744 7ff6f9093ae7 44736->44744 44753 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44736->44753 44737 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44746 7ff6f9093ed3 44737->44746 44749 7ff6f9094157 44738->44749 44756 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44738->44756 44762 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44739->44762 44741 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44741->44608 44750 7ff6f9094288 44742->44750 44752 7ff6f90942c2 44743->44752 44747 7ff6f90a3168 collate 4 API calls 44744->44747 44887 7ff6f907ef2c LeaveCriticalSection 44746->44887 44755 7ff6f9093af8 44747->44755 44748 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44775 7ff6f9094303 44748->44775 44897 7ff6f90894f8 76 API calls 7 library calls 44749->44897 44902 7ff6f907ef2c LeaveCriticalSection 44750->44902 44758 7ff6f90942f0 44752->44758 44903 7ff6f90d28c8 36 API calls 5 library calls 44752->44903 44759 7ff6f9093abe 44753->44759 44760 7ff6f9093b20 44755->44760 44872 7ff6f90920f0 37 API calls 3 library calls 44755->44872 44761 7ff6f909412e 44756->44761 44758->44748 44871 7ff6f907ef2c LeaveCriticalSection 44759->44871 44760->44741 44896 7ff6f907ef2c LeaveCriticalSection 44761->44896 44767 7ff6f9093f37 44762->44767 44763 7ff6f9094166 44768 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44763->44768 44773 7ff6f9093f77 44767->44773 44777 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44767->44777 44774 7ff6f9094174 44768->44774 44769 7ff6f90944c7 44770 7ff6f90942e5 44904 7ff6f90c487c 15 API calls _get_daylight 44770->44904 44779 7ff6f90a3168 collate 4 API calls 44773->44779 44778 7ff6f90941b4 44774->44778 44783 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44774->44783 44775->44769 44780 7ff6f9094414 44775->44780 44786 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44775->44786 44782 7ff6f9093f4e 44777->44782 44899 7ff6f90893c4 76 API calls 7 library calls 44778->44899 44784 7ff6f9093f88 44779->44784 44781 7ff6f90a3168 collate 4 API calls 44780->44781 44787 7ff6f9094425 44781->44787 44888 7ff6f907ef2c LeaveCriticalSection 44782->44888 44788 7ff6f909418b 44783->44788 44789 7ff6f9093fb4 44784->44789 44889 7ff6f9091d24 37 API calls 3 library calls 44784->44889 44790 7ff6f90943eb 44786->44790 44791 7ff6f9094448 44787->44791 44796 7ff6f907f178 _Getcvt 35 API calls 44787->44796 44898 7ff6f907ef2c LeaveCriticalSection 44788->44898 44794 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44789->44794 44909 7ff6f907ef2c LeaveCriticalSection 44790->44909 44801 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44791->44801 44798 7ff6f9093fcd 44794->44798 44796->44791 44800 7ff6f909400d 44798->44800 44803 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44798->44803 44799 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 44799->44633 44802 7ff6f90a3168 collate 4 API calls 44800->44802 44801->44769 44804 7ff6f909401e 44802->44804 44805 7ff6f9093fe4 44803->44805 44806 7ff6f909404a 44804->44806 44891 7ff6f9091d24 37 API calls 3 library calls 44804->44891 44890 7ff6f907ef2c LeaveCriticalSection 44805->44890 44806->44799 44810 7ff6f908b6b5 44809->44810 44820 7ff6f908b781 44809->44820 44812 7ff6f90a3168 collate 4 API calls 44810->44812 44810->44820 44814 7ff6f908b6c6 44812->44814 44825 7ff6f908b720 44814->44825 44919 7ff6f909c120 34 API calls 3 library calls 44814->44919 44817 7ff6f908b741 44817->44820 44822 7ff6f908b7ae 44817->44822 44818 7ff6f908b6e3 44920 7ff6f90734b0 44818->44920 44910 7ff6f90a32c0 44820->44910 44824 7ff6f90c438c _invalid_parameter_noinfo_noreturn 31 API calls 44822->44824 44826 7ff6f908b7b3 44824->44826 44825->44817 44934 7ff6f9073b80 44825->44934 44828 7ff6f90a3173 44827->44828 44829 7ff6f9093e92 44828->44829 44830 7ff6f90d380c collate 2 API calls 44828->44830 44831 7ff6f90a3192 44828->44831 44836 7ff6f9084ad0 44829->44836 44830->44828 44832 7ff6f90a319d 44831->44832 44970 7ff6f907edf8 44831->44970 44974 7ff6f90a3c68 RtlPcToFileHeader RaiseException std::bad_alloc::bad_alloc _CxxThrowException 44832->44974 44837 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44836->44837 44838 7ff6f9084b01 44837->44838 44839 7ff6f9084bbc 44838->44839 44842 7ff6f9084b31 44838->44842 44841 7ff6f907edf8 Concurrency::cancel_current_task 2 API calls 44839->44841 44844 7ff6f9084bc1 44841->44844 44979 7ff6f907ef2c LeaveCriticalSection 44842->44979 44843 7ff6f9084ba6 44843->44731 44843->44737 44845 7ff6f90734b0 std::_Locinfo::_Locinfo 75 API calls 44844->44845 44846 7ff6f9084bff 44845->44846 44976 7ff6f9084ca4 44846->44976 44852 7ff6f907eebb 44851->44852 44853 7ff6f907eec0 44851->44853 45237 7ff6f90c8ae4 6 API calls std::_Locinfo::_Locinfo_ctor 44852->45237 44853->44599 44855->44591 44856->44607 44858 7ff6f907f190 Concurrency::details::QuickBitSet::Grow 44857->44858 45238 7ff6f90c8bc4 44858->45238 44863 7ff6f90c8c24 _Getdateorder 35 API calls 44865 7ff6f907f1a4 44863->44865 44864 7ff6f907f1bf 44864->44601 44865->44864 45248 7ff6f90c8b10 35 API calls _Tolower 44865->45248 44867->44592 44868->44598 44869->44615 44870->44726 44871->44744 44873->44614 44874->44624 44875->44712 44876->44676 44877->44703 44878->44760 44879->44630 44880->44685 44881->44632 44882->44647 44883->44700 44884->44690 44885->44655 44886->44709 44887->44731 44888->44773 44890->44800 44892->44708 44893->44672 44894->44710 44895->44723 44896->44749 44897->44763 44898->44778 44899->44806 44900->44714 44901->44692 44902->44734 44903->44770 44904->44758 44905->44716 44906->44681 44907->44719 44908->44758 44909->44780 44911 7ff6f90a32ca 44910->44911 44912 7ff6f908b79b 44911->44912 44913 7ff6f90a36c8 IsProcessorFeaturePresent 44911->44913 44912->44622 44912->44623 44912->44689 44914 7ff6f90a36df 44913->44914 44949 7ff6f90a38bc RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind 44914->44949 44916 7ff6f90a36f2 44950 7ff6f90a3694 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 44916->44950 44919->44818 44921 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44920->44921 44922 7ff6f90734d5 44921->44922 44923 7ff6f9073509 44922->44923 44924 7ff6f9073523 44922->44924 44951 7ff6f907f708 44923->44951 44958 7ff6f9071700 32 API calls 2 library calls 44924->44958 44928 7ff6f9073534 44959 7ff6f90c0b60 RtlPcToFileHeader RaiseException 44928->44959 44930 7ff6f9073545 44960 7ff6f90c0aa8 32 API calls 2 library calls 44930->44960 44932 7ff6f9073580 44933 7ff6f90a2780 35 API calls 2 library calls 44932->44933 44933->44825 44963 7ff6f907f774 71 API calls std::_Locinfo::_Locinfo_ctor 44934->44963 44936 7ff6f9073b9c 44937 7ff6f9073bab 44936->44937 44964 7ff6f90c487c 15 API calls _get_daylight 44936->44964 44939 7ff6f9073bc0 44937->44939 44965 7ff6f90c487c 15 API calls _get_daylight 44937->44965 44941 7ff6f9073bd3 44939->44941 44966 7ff6f90c487c 15 API calls _get_daylight 44939->44966 44943 7ff6f9073be6 44941->44943 44967 7ff6f90c487c 15 API calls _get_daylight 44941->44967 44944 7ff6f9073bf9 44943->44944 44968 7ff6f90c487c 15 API calls _get_daylight 44943->44968 44947 7ff6f9073c0c 44944->44947 44969 7ff6f90c487c 15 API calls _get_daylight 44944->44969 44949->44916 44961 7ff6f90c9654 71 API calls std::_Locinfo::_Locinfo_ctor 44951->44961 44953 7ff6f907f721 44954 7ff6f907f4b0 _Yarn 15 API calls 44953->44954 44955 7ff6f907f73b 44954->44955 44956 7ff6f907f74a 44955->44956 44962 7ff6f90c9654 71 API calls std::_Locinfo::_Locinfo_ctor 44955->44962 44958->44928 44959->44930 44960->44932 44961->44953 44962->44956 44963->44936 44964->44937 44965->44939 44966->44941 44967->44943 44968->44944 44969->44947 44971 7ff6f907ee06 std::bad_alloc::bad_alloc 44970->44971 44975 7ff6f90c0b60 RtlPcToFileHeader RaiseException 44971->44975 44973 7ff6f907ee17 44975->44973 44977 7ff6f9084ddf 44976->44977 44980 7ff6f909f144 44977->44980 44979->44843 45121 7ff6f909d134 44980->45121 44983 7ff6f909f232 44986 7ff6f909f36a 44983->44986 44987 7ff6f909f314 44983->44987 44988 7ff6f909f2ac 44983->44988 44984 7ff6f909f1a3 44989 7ff6f909f1e3 44984->44989 44993 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44984->44993 44985 7ff6f909f239 44990 7ff6f909f279 44985->44990 44994 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44985->44994 44991 7ff6f909f713 44986->44991 44997 7ff6f909f384 44986->44997 44998 7ff6f909f5a6 44986->44998 45000 7ff6f909f34d 44987->45000 45012 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44987->45012 44992 7ff6f909f2e5 44988->44992 45001 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44988->45001 44995 7ff6f90a3168 collate 4 API calls 44989->44995 45147 7ff6f909c5c8 76 API calls 7 library calls 44990->45147 44999 7ff6f909f8f9 44991->44999 45010 7ff6f909f83f 44991->45010 45011 7ff6f909f726 44991->45011 45005 7ff6f90a3168 collate 4 API calls 44992->45005 45002 7ff6f909f1ba 44993->45002 45003 7ff6f909f250 44994->45003 45006 7ff6f909f1f4 44995->45006 45009 7ff6f909f3bd 44997->45009 45023 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44997->45023 45007 7ff6f909f5df 44998->45007 45021 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 44998->45021 45150 7ff6f909c6fc 76 API calls 7 library calls 45000->45150 45013 7ff6f909f2bc 45001->45013 45144 7ff6f907ef2c LeaveCriticalSection 45002->45144 45146 7ff6f907ef2c LeaveCriticalSection 45003->45146 45016 7ff6f909f2f6 45005->45016 45017 7ff6f909f217 45006->45017 45145 7ff6f90a2780 35 API calls 2 library calls 45006->45145 45158 7ff6f909c830 76 API calls 7 library calls 45007->45158 45008 7ff6f909f288 45022 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45008->45022 45015 7ff6f90a3168 collate 4 API calls 45009->45015 45020 7ff6f909f87f 45010->45020 45029 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45010->45029 45018 7ff6f909f766 45011->45018 45028 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45011->45028 45019 7ff6f909f324 45012->45019 45148 7ff6f907ef2c LeaveCriticalSection 45013->45148 45025 7ff6f909f3ce 45015->45025 45032 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45016->45032 45038 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45017->45038 45030 7ff6f90a3168 collate 4 API calls 45018->45030 45149 7ff6f907ef2c LeaveCriticalSection 45019->45149 45170 7ff6f909cd00 78 API calls 7 library calls 45020->45170 45034 7ff6f909f5b6 45021->45034 45022->44983 45035 7ff6f909f394 45023->45035 45024 7ff6f909f5ee 45036 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45024->45036 45049 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45025->45049 45039 7ff6f909f73d 45028->45039 45041 7ff6f909f856 45029->45041 45042 7ff6f909f777 45030->45042 45032->44986 45157 7ff6f907ef2c LeaveCriticalSection 45034->45157 45151 7ff6f907ef2c LeaveCriticalSection 45035->45151 45046 7ff6f909f5fc 45036->45046 45038->44983 45165 7ff6f907ef2c LeaveCriticalSection 45039->45165 45169 7ff6f907ef2c LeaveCriticalSection 45041->45169 45047 7ff6f909f79c 45042->45047 45139 7ff6f909f108 45042->45139 45043 7ff6f909f88e 45048 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45043->45048 45054 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45046->45054 45079 7ff6f909f63c 45046->45079 45056 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45047->45056 45053 7ff6f909f89c 45048->45053 45060 7ff6f909f3f8 45049->45060 45063 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45053->45063 45081 7ff6f909f8dc 45053->45081 45058 7ff6f909f613 45054->45058 45062 7ff6f909f7b0 45056->45062 45159 7ff6f907ef2c LeaveCriticalSection 45058->45159 45059 7ff6f909f438 45066 7ff6f90a3168 collate 4 API calls 45059->45066 45060->45059 45064 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45060->45064 45061 7ff6f909f64b 45065 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45061->45065 45067 7ff6f909f7f0 45062->45067 45069 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45062->45069 45068 7ff6f909f8b3 45063->45068 45072 7ff6f909f40f 45064->45072 45073 7ff6f909f659 45065->45073 45074 7ff6f909f449 45066->45074 45070 7ff6f90a3168 collate 4 API calls 45067->45070 45171 7ff6f907ef2c LeaveCriticalSection 45068->45171 45075 7ff6f909f7c7 45069->45075 45078 7ff6f909f801 45070->45078 45152 7ff6f907ef2c LeaveCriticalSection 45072->45152 45080 7ff6f909f699 45073->45080 45084 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45073->45084 45089 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45074->45089 45166 7ff6f907ef2c LeaveCriticalSection 45075->45166 45077 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45077->44999 45082 7ff6f909f82f 45078->45082 45167 7ff6f90d0c58 36 API calls 5 library calls 45078->45167 45160 7ff6f909c964 76 API calls 7 library calls 45079->45160 45162 7ff6f909cbcc 78 API calls 7 library calls 45080->45162 45172 7ff6f909ce34 76 API calls 7 library calls 45081->45172 45082->45077 45088 7ff6f909f670 45084->45088 45161 7ff6f907ef2c LeaveCriticalSection 45088->45161 45092 7ff6f909f473 45089->45092 45090 7ff6f909f6a8 45093 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45090->45093 45091 7ff6f909f824 45168 7ff6f90c487c 15 API calls _get_daylight 45091->45168 45096 7ff6f909f4b3 45092->45096 45099 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45092->45099 45097 7ff6f909f6b6 45093->45097 45098 7ff6f90a3168 collate 4 API calls 45096->45098 45100 7ff6f909f6f6 45097->45100 45101 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45097->45101 45102 7ff6f909f4c4 45098->45102 45104 7ff6f909f48a 45099->45104 45164 7ff6f909ca98 78 API calls 7 library calls 45100->45164 45105 7ff6f909f6cd 45101->45105 45106 7ff6f909f4f0 45102->45106 45154 7ff6f909ef64 78 API calls 5 library calls 45102->45154 45153 7ff6f907ef2c LeaveCriticalSection 45104->45153 45163 7ff6f907ef2c LeaveCriticalSection 45105->45163 45110 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45106->45110 45112 7ff6f909f50e 45110->45112 45111 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45111->44991 45113 7ff6f909f54e 45112->45113 45114 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45112->45114 45115 7ff6f90a3168 collate 4 API calls 45113->45115 45116 7ff6f909f525 45114->45116 45117 7ff6f909f55f 45115->45117 45155 7ff6f907ef2c LeaveCriticalSection 45116->45155 45118 7ff6f909f58b 45117->45118 45156 7ff6f909ef64 78 API calls 5 library calls 45117->45156 45118->45111 45122 7ff6f909d175 45121->45122 45132 7ff6f909d241 45121->45132 45124 7ff6f90a3168 collate 4 API calls 45122->45124 45122->45132 45123 7ff6f90a32c0 collate 8 API calls 45125 7ff6f909d25b 45123->45125 45126 7ff6f909d186 45124->45126 45125->44983 45125->44984 45125->44985 45137 7ff6f909d1e0 45126->45137 45173 7ff6f909c120 34 API calls 3 library calls 45126->45173 45128 7ff6f9073b80 collate 72 API calls 45130 7ff6f909d201 45128->45130 45129 7ff6f909d1a3 45131 7ff6f90734b0 std::_Locinfo::_Locinfo 75 API calls 45129->45131 45130->45132 45134 7ff6f909d26e 45130->45134 45133 7ff6f909d1c3 45131->45133 45132->45123 45174 7ff6f90a2780 35 API calls 2 library calls 45133->45174 45136 7ff6f90c438c _invalid_parameter_noinfo_noreturn 31 API calls 45134->45136 45138 7ff6f909d273 45136->45138 45137->45128 45137->45130 45175 7ff6f909c444 45139->45175 45141 7ff6f909f136 45209 7ff6f90a2884 45141->45209 45144->44989 45145->45017 45146->44990 45147->45008 45148->44992 45149->45000 45150->45016 45151->45009 45152->45059 45153->45096 45154->45106 45155->45113 45156->45118 45157->45007 45158->45024 45159->45079 45160->45061 45161->45080 45162->45090 45163->45100 45164->45118 45165->45018 45166->45067 45167->45091 45168->45082 45169->45020 45170->45043 45171->45081 45172->45082 45173->45129 45174->45137 45176 7ff6f907f178 _Getcvt 35 API calls 45175->45176 45177 7ff6f909c46b 45176->45177 45214 7ff6f90d0980 36 API calls 5 library calls 45177->45214 45179 7ff6f909c493 45180 7ff6f907f4b0 _Yarn 15 API calls 45179->45180 45184 7ff6f909c4af 45179->45184 45181 7ff6f909c4a7 45180->45181 45215 7ff6f90c487c 15 API calls _get_daylight 45181->45215 45183 7ff6f907edf8 Concurrency::cancel_current_task 2 API calls 45185 7ff6f909c5c4 45183->45185 45196 7ff6f909c52a 45184->45196 45216 7ff6f90d0ae4 36 API calls 5 library calls 45184->45216 45188 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45185->45188 45187 7ff6f909c50e 45190 7ff6f907f4b0 _Yarn 15 API calls 45187->45190 45187->45196 45189 7ff6f909c5ed 45188->45189 45193 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45189->45193 45200 7ff6f909c63c _Getvals 45189->45200 45191 7ff6f909c522 45190->45191 45217 7ff6f90c487c 15 API calls _get_daylight 45191->45217 45194 7ff6f909c612 45193->45194 45218 7ff6f907ef2c LeaveCriticalSection 45194->45218 45195 7ff6f909c684 45220 7ff6f907ef2c LeaveCriticalSection 45195->45220 45196->45183 45201 7ff6f909c58e 45196->45201 45199 7ff6f909c6cf 45199->45141 45200->45195 45202 7ff6f909d134 collate 75 API calls 45200->45202 45201->45141 45203 7ff6f909c696 45202->45203 45204 7ff6f909c6df std::bad_alloc::bad_alloc 45203->45204 45205 7ff6f909c69c 45203->45205 45221 7ff6f90c0b60 RtlPcToFileHeader RaiseException 45204->45221 45219 7ff6f907f594 RtlPcToFileHeader RaiseException EnterCriticalSection LeaveCriticalSection collate 45205->45219 45208 7ff6f909c6fa 45222 7ff6f90c8c24 45209->45222 45214->45179 45215->45184 45216->45187 45217->45196 45218->45200 45219->45195 45220->45199 45221->45208 45223 7ff6f90d67d4 _Tolower 35 API calls 45222->45223 45224 7ff6f90c8c2d 45223->45224 45232 7ff6f90d7a78 45224->45232 45227 7ff6f90a2628 45228 7ff6f90a264f GetLocaleInfoEx 45227->45228 45229 7ff6f90a2657 __crtDownlevelLocaleNameToLCID 45227->45229 45230 7ff6f909f13b 45228->45230 45231 7ff6f90a265c GetLocaleInfoW 45229->45231 45230->45047 45231->45230 45233 7ff6f90a2894 45232->45233 45234 7ff6f90d7a8d 45232->45234 45233->45227 45234->45233 45236 7ff6f90e0ddc 35 API calls 3 library calls 45234->45236 45236->45233 45239 7ff6f90d67d4 _Tolower 35 API calls 45238->45239 45240 7ff6f90c8bcd 45239->45240 45241 7ff6f90d7a78 _Tolower 35 API calls 45240->45241 45242 7ff6f907f195 45241->45242 45243 7ff6f90c8c58 45242->45243 45244 7ff6f90d67d4 _Tolower 35 API calls 45243->45244 45245 7ff6f90c8c61 45244->45245 45246 7ff6f90d7a78 _Tolower 35 API calls 45245->45246 45247 7ff6f907f19c 45246->45247 45247->44863 45248->44864 45249 7ff6f907d8a4 45250 7ff6f907d8be Concurrency::details::QuickBitSet::Grow 45249->45250 45251 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45250->45251 45252 7ff6f907d8ca 45251->45252 45253 7ff6f907f708 std::_Locinfo::_Locinfo_ctor 72 API calls 45252->45253 45254 7ff6f907d939 45253->45254 45255 7ff6f907f178 _Getcvt 35 API calls 45254->45255 45256 7ff6f907d944 45255->45256 45257 7ff6f9073b80 collate 72 API calls 45256->45257 45258 7ff6f907d96d 45257->45258 45259 7ff6f907d9de 45258->45259 45260 7ff6f907eeac std::_Lockit::_Lockit 6 API calls 45258->45260 45267 7ff6f907da0d codecvt 45258->45267 45261 7ff6f9084ad0 std::locale::_Locimp::_Locimp_Addfac 78 API calls 45259->45261 45262 7ff6f907d9b2 45260->45262 45264 7ff6f907d9f0 45261->45264 45269 7ff6f907ef2c LeaveCriticalSection 45262->45269 45263 7ff6f90a32c0 collate 8 API calls 45265 7ff6f907daac 45263->45265 45264->45267 45270 7ff6f90c487c 15 API calls _get_daylight 45264->45270 45267->45263 45269->45259 45270->45267 45271 7ff6f90c7008 45272 7ff6f90c706f 45271->45272 45273 7ff6f90c7025 GetModuleHandleW 45271->45273 45281 7ff6f90c6eec 45272->45281 45273->45272 45275 7ff6f90c7032 45273->45275 45275->45272 45295 7ff6f90c7110 GetModuleHandleExW 45275->45295 45277 7ff6f90c70b1 45279 7ff6f90c70c3 45301 7ff6f90c8a74 EnterCriticalSection 45281->45301 45283 7ff6f90c6f08 45284 7ff6f90c6f24 34 API calls 45283->45284 45285 7ff6f90c6f11 45284->45285 45286 7ff6f90c8ac8 _isindst LeaveCriticalSection 45285->45286 45287 7ff6f90c6f19 45286->45287 45287->45277 45288 7ff6f90c70c4 45287->45288 45302 7ff6f90d8c38 45288->45302 45291 7ff6f90c70fe 45293 7ff6f90c7110 3 API calls 45291->45293 45292 7ff6f90c70ed GetCurrentProcess TerminateProcess 45292->45291 45294 7ff6f90c7105 ExitProcess 45293->45294 45296 7ff6f90c7155 45295->45296 45297 7ff6f90c7136 GetProcAddress 45295->45297 45299 7ff6f90c715f FreeLibrary 45296->45299 45300 7ff6f90c7165 45296->45300 45297->45296 45298 7ff6f90c714d 45297->45298 45298->45296 45299->45300 45300->45272 45303 7ff6f90c70d1 45302->45303 45304 7ff6f90d8c56 45302->45304 45303->45291 45303->45292 45306 7ff6f90d9dc4 5 API calls try_get_function 45304->45306 45306->45303 45307 7ff6f90a3a78 45330 7ff6f90a341c 45307->45330 45310 7ff6f90a3bc4 45553 7ff6f90a3e20 7 API calls 2 library calls 45310->45553 45311 7ff6f90a3a94 __scrt_acquire_startup_lock 45313 7ff6f90a3bce 45311->45313 45315 7ff6f90a3ab2 45311->45315 45554 7ff6f90a3e20 7 API calls 2 library calls 45313->45554 45316 7ff6f90a3ad7 45315->45316 45322 7ff6f90a3af4 __scrt_is_nonwritable_in_current_image __scrt_release_startup_lock 45315->45322 45336 7ff6f90d4908 45315->45336 45317 7ff6f90a3bd9 _purecall 45319 7ff6f90a3b5d 45340 7ff6f90a3f6c 45319->45340 45321 7ff6f90a3b62 45343 7ff6f907bac0 45321->45343 45322->45319 45550 7ff6f90c71a0 35 API calls Concurrency::SchedulerPolicy::_ValidPolicyValue 45322->45550 45327 7ff6f90a3b85 45327->45317 45552 7ff6f90a3600 8 API calls 2 library calls 45327->45552 45329 7ff6f90a3b9c 45329->45316 45331 7ff6f90a343e __scrt_initialize_crt 45330->45331 45555 7ff6f90c1d5c 45331->45555 45333 7ff6f90a3447 45333->45310 45333->45311 45334 7ff6f90a3443 __scrt_initialize_crt 45334->45333 45563 7ff6f90c1d90 8 API calls 3 library calls 45334->45563 45337 7ff6f90d4957 45336->45337 45338 7ff6f90d493d 45336->45338 45337->45322 45338->45337 45588 7ff6f9071082 45338->45588 45593 7ff6f90c16a0 45340->45593 45344 7ff6f907bb75 45343->45344 45344->45344 45595 7ff6f9072130 45344->45595 45346 7ff6f907bb97 45609 7ff6f9079230 45346->45609 45350 7ff6f907bcce 45351 7ff6f9072130 34 API calls 45350->45351 45352 7ff6f907bd0f 45351->45352 45353 7ff6f9079230 46 API calls 45352->45353 45354 7ff6f907bd1c 45353->45354 45355 7ff6f9072290 _Mpunct 34 API calls 45354->45355 45356 7ff6f907be5b 45355->45356 45632 7ff6f907b470 45356->45632 45358 7ff6f907be60 45660 7ff6f9079020 LoadLibraryW 45358->45660 45361 7ff6f907b470 53 API calls 45362 7ff6f907be6d 45361->45362 45363 7ff6f907cd34 45362->45363 45673 7ff6f90c87fc 45362->45673 45676 7ff6f90788e0 LoadLibraryExW 45363->45676 45366 7ff6f907cd5b 45692 7ff6f90717d0 31 API calls _invalid_parameter_noinfo_noreturn 45366->45692 45368 7ff6f907cd69 45372 7ff6f907cd82 45368->45372 45693 7ff6f90723b0 31 API calls _invalid_parameter_noinfo_noreturn 45368->45693 45371 7ff6f907be7c 45377 7ff6f907b470 53 API calls 45371->45377 45694 7ff6f90717d0 31 API calls _invalid_parameter_noinfo_noreturn 45372->45694 45373 7ff6f907cd97 45374 7ff6f907cdb3 45373->45374 45695 7ff6f90723b0 31 API calls _invalid_parameter_noinfo_noreturn 45373->45695 45376 7ff6f90a32c0 collate 8 API calls 45374->45376 45378 7ff6f907cdf4 45376->45378 45379 7ff6f907bf64 45377->45379 45551 7ff6f90a3fb0 GetModuleHandleW 45378->45551 45379->45363 45380 7ff6f907bf6c 45379->45380 45683 7ff6f9079680 53 API calls 4 library calls 45380->45683 45382 7ff6f907bf71 45383 7ff6f907cd2f 45382->45383 45684 7ff6f9079ee0 41 API calls 2 library calls 45382->45684 45385 7ff6f907b470 53 API calls 45383->45385 45385->45363 45386 7ff6f907bf7e 45386->45383 45685 7ff6f90789a0 35 API calls 3 library calls 45386->45685 45388 7ff6f907bf8b 45388->45383 45389 7ff6f907bf93 45388->45389 45390 7ff6f907b470 53 API calls 45389->45390 45391 7ff6f907bf98 LoadLibraryW 45390->45391 45392 7ff6f907c037 GetProcAddress IsDebuggerPresent 45391->45392 45393 7ff6f907c06e FreeLibrary 45392->45393 45394 7ff6f907b470 53 API calls 45393->45394 45395 7ff6f907c07e 45394->45395 45395->45363 45396 7ff6f907c086 45395->45396 45397 7ff6f9072130 34 API calls 45396->45397 45398 7ff6f907c0ce 45397->45398 45686 7ff6f9078cd0 38 API calls 2 library calls 45398->45686 45400 7ff6f907c0d7 45687 7ff6f9071770 31 API calls _invalid_parameter_noinfo_noreturn 45400->45687 45402 7ff6f907c0e3 45403 7ff6f907c0eb GetModuleHandleA FindResourceA 45402->45403 45404 7ff6f907cc32 45402->45404 45406 7ff6f907ce2b 45403->45406 45407 7ff6f907c114 LoadResource 45403->45407 45405 7ff6f907b470 53 API calls 45404->45405 45409 7ff6f907cd03 45405->45409 45698 7ff6f9071700 32 API calls 2 library calls 45406->45698 45410 7ff6f907c12c SizeofResource 45407->45410 45411 7ff6f907ce52 45407->45411 45413 7ff6f90788e0 12 API calls 45409->45413 45415 7ff6f907ce79 45410->45415 45416 7ff6f907c142 LockResource 45410->45416 45700 7ff6f9071700 32 API calls 2 library calls 45411->45700 45412 7ff6f907ce3f 45699 7ff6f90c0b60 RtlPcToFileHeader RaiseException 45412->45699 45419 7ff6f907cd2a 45413->45419 45702 7ff6f9071700 32 API calls 2 library calls 45415->45702 45421 7ff6f907c15b 45416->45421 45422 7ff6f907cea0 45416->45422 45419->45366 45420 7ff6f907ce66 45701 7ff6f90c0b60 RtlPcToFileHeader RaiseException 45420->45701 45688 7ff6f9077d30 34 API calls codecvt 45421->45688 45704 7ff6f9071700 32 API calls 2 library calls 45422->45704 45423 7ff6f907ce8d 45703 7ff6f90c0b60 RtlPcToFileHeader RaiseException 45423->45703 45428 7ff6f907cead 45705 7ff6f90c0b60 RtlPcToFileHeader RaiseException 45428->45705 45429 7ff6f907c17e 45689 7ff6f9077670 34 API calls 45429->45689 45432 7ff6f907cec0 45706 7ff6f9071700 32 API calls 2 library calls 45432->45706 45433 7ff6f907c1cd 45434 7ff6f907b470 53 API calls 45433->45434 45436 7ff6f907c1d2 45434->45436 45690 7ff6f90c7bfc 39 API calls _Wcsftime 45436->45690 45437 7ff6f907ced4 45707 7ff6f90c0b60 RtlPcToFileHeader RaiseException 45437->45707 45440 7ff6f907c1e2 45442 7ff6f907b470 53 API calls 45440->45442 45441 7ff6f907cee7 45708 7ff6f9075890 34 API calls 45441->45708 45444 7ff6f907c1e9 45442->45444 45447 7ff6f9079230 46 API calls 45444->45447 45449 7ff6f907c210 45447->45449 45450 7ff6f907b470 53 API calls 45449->45450 45451 7ff6f907c224 CreateToolhelp32Snapshot 45450->45451 45452 7ff6f907c25a Process32First 45451->45452 45453 7ff6f907cdff 45451->45453 45454 7ff6f907c2b3 CloseHandle 45452->45454 45696 7ff6f9071700 32 API calls 2 library calls 45453->45696 45454->45453 45457 7ff6f907c2c5 LoadLibraryA 45454->45457 45456 7ff6f907ce12 45697 7ff6f90c0b60 RtlPcToFileHeader RaiseException 45456->45697 45459 7ff6f907c369 GetProcAddress 45457->45459 45459->45432 45461 7ff6f907c37f 45459->45461 45460 7ff6f907ce25 45462 7ff6f90c438c _invalid_parameter_noinfo_noreturn 31 API calls 45460->45462 45463 7ff6f907b470 53 API calls 45461->45463 45462->45406 45464 7ff6f907c393 45463->45464 45465 7ff6f90a3168 collate 4 API calls 45464->45465 45466 7ff6f907c3ae 45465->45466 45691 7ff6f907ddd0 127 API calls 45466->45691 45550->45319 45551->45327 45552->45329 45553->45313 45554->45317 45556 7ff6f90c1d65 __vcrt_initialize_winapi_thunks __vcrt_initialize 45555->45556 45564 7ff6f90c3c4c 45556->45564 45560 7ff6f90c1d7c 45562 7ff6f90c1d73 45560->45562 45571 7ff6f90c3c94 DeleteCriticalSection 45560->45571 45562->45334 45563->45333 45566 7ff6f90c3c54 45564->45566 45567 7ff6f90c3c85 45566->45567 45568 7ff6f90c1d6f 45566->45568 45572 7ff6f90c3fd0 45566->45572 45577 7ff6f90c3c94 DeleteCriticalSection 45567->45577 45568->45562 45570 7ff6f90c2604 8 API calls 3 library calls 45568->45570 45570->45560 45571->45562 45578 7ff6f90c3ccc 45572->45578 45575 7ff6f90c401b InitializeCriticalSectionAndSpinCount 45576 7ff6f90c4010 45575->45576 45576->45566 45577->45568 45579 7ff6f90c3d2d 45578->45579 45586 7ff6f90c3d28 try_get_function 45578->45586 45579->45575 45579->45576 45580 7ff6f90c3e10 45580->45579 45583 7ff6f90c3e1e GetProcAddress 45580->45583 45581 7ff6f90c3d5c LoadLibraryExW 45582 7ff6f90c3d7d GetLastError 45581->45582 45581->45586 45582->45586 45584 7ff6f90c3e2f 45583->45584 45584->45579 45585 7ff6f90c3df5 FreeLibrary 45585->45586 45586->45579 45586->45580 45586->45581 45586->45585 45587 7ff6f90c3db7 LoadLibraryExW 45586->45587 45587->45586 45589 7ff6f90a367c 45588->45589 45592 7ff6f90a362c 34 API calls _onexit 45589->45592 45591 7ff6f90a3685 45591->45338 45592->45591 45594 7ff6f90a3f83 GetStartupInfoW 45593->45594 45594->45321 45596 7ff6f9072179 45595->45596 45602 7ff6f907214e codecvt 45595->45602 45597 7ff6f907218c 45596->45597 45598 7ff6f9072275 45596->45598 45600 7ff6f90721fd 45597->45600 45601 7ff6f90721d6 45597->45601 45709 7ff6f9072080 34 API calls _Mpunct 45598->45709 45604 7ff6f90a3168 collate 4 API calls 45600->45604 45607 7ff6f90721e6 codecvt 45600->45607 45603 7ff6f90a3168 collate 4 API calls 45601->45603 45602->45346 45603->45607 45604->45607 45605 7ff6f90c438c _invalid_parameter_noinfo_noreturn 31 API calls 45606 7ff6f9072280 45605->45606 45607->45605 45608 7ff6f9072256 45607->45608 45608->45346 45610 7ff6f907964e 45609->45610 45619 7ff6f9079291 _Stoullx 45609->45619 45611 7ff6f90a32c0 collate 8 API calls 45610->45611 45612 7ff6f907965d 45611->45612 45622 7ff6f9072290 45612->45622 45614 7ff6f90794af 45614->45610 45615 7ff6f9079675 45614->45615 45618 7ff6f90794d5 _Stoullx 45614->45618 45713 7ff6f90a379c 8 API calls __report_securityfailure 45615->45713 45617 7ff6f907967a 45618->45610 45712 7ff6f9077790 34 API calls 3 library calls 45618->45712 45619->45614 45710 7ff6f90c6b5c 39 API calls 2 library calls 45619->45710 45711 7ff6f9077790 34 API calls 3 library calls 45619->45711 45623 7ff6f90722dc 45622->45623 45631 7ff6f90722b2 codecvt 45622->45631 45624 7ff6f9072397 45623->45624 45625 7ff6f90722ef 45623->45625 45715 7ff6f9072080 34 API calls _Mpunct 45624->45715 45714 7ff6f90720c0 33 API calls 3 library calls 45625->45714 45628 7ff6f90c438c _invalid_parameter_noinfo_noreturn 31 API calls 45629 7ff6f90723a2 45628->45629 45630 7ff6f9072326 codecvt 45630->45628 45630->45631 45631->45350 45633 7ff6f907b47c __crtLCMapStringA 45632->45633 45634 7ff6f90c87fc 32 API calls 45633->45634 45635 7ff6f907b498 45634->45635 45636 7ff6f90a3168 collate 4 API calls 45635->45636 45637 7ff6f907b511 45636->45637 45716 7ff6f9077dc0 45637->45716 45639 7ff6f907b645 45729 7ff6f907ad40 45639->45729 45640 7ff6f907b570 45640->45639 45642 7ff6f907b66b 45640->45642 45645 7ff6f90c438c _invalid_parameter_noinfo_noreturn 31 API calls 45642->45645 45644 7ff6f90a32c0 collate 8 API calls 45646 7ff6f907b662 45644->45646 45647 7ff6f907b670 45645->45647 45646->45358 45650 7ff6f907b6ec 45647->45650 45749 7ff6f907b020 40 API calls _CxxThrowException 45647->45749 45649 7ff6f907b7ce 45751 7ff6f9076d40 40 API calls Concurrency::SchedulerPolicy::_ValidPolicyValue 45649->45751 45650->45649 45652 7ff6f907b78c 45650->45652 45653 7ff6f907b79d 45652->45653 45750 7ff6f9075790 40 API calls _CxxThrowException 45652->45750 45653->45358 45654 7ff6f907b7fe 45752 7ff6f9073640 34 API calls 2 library calls 45654->45752 45657 7ff6f907b80e 45753 7ff6f90c0b60 RtlPcToFileHeader RaiseException 45657->45753 45659 7ff6f907b81f 45661 7ff6f90790dd GetProcAddress GetProcAddress GetProcAddress 45660->45661 45662 7ff6f90791fc 45660->45662 45663 7ff6f90791f1 FreeLibrary 45661->45663 45664 7ff6f907912e 45661->45664 45665 7ff6f90a32c0 collate 8 API calls 45662->45665 45663->45662 45664->45663 45667 7ff6f9079140 45664->45667 45666 7ff6f9079220 45665->45666 45666->45361 45851 7ff6f90783f0 45667->45851 45670 7ff6f90783f0 10 API calls 45671 7ff6f9079197 FreeLibrary 45670->45671 45671->45662 45873 7ff6f90c8764 45673->45873 45677 7ff6f907895a GetProcAddress 45676->45677 45678 7ff6f9078985 45676->45678 45679 7ff6f907897c FreeLibrary 45677->45679 45680 7ff6f907896c MessageBoxW 45677->45680 45681 7ff6f90a32c0 collate 8 API calls 45678->45681 45679->45678 45680->45678 45682 7ff6f9078993 45681->45682 45682->45366 45683->45382 45684->45386 45685->45388 45686->45400 45687->45402 45688->45429 45689->45433 45690->45440 45692->45368 45693->45372 45694->45373 45695->45374 45696->45456 45697->45460 45698->45412 45699->45411 45700->45420 45701->45415 45702->45423 45703->45422 45704->45428 45705->45432 45706->45437 45707->45441 45710->45619 45711->45619 45712->45618 45713->45617 45714->45630 45717 7ff6f9077e05 45716->45717 45725 7ff6f9077e48 codecvt 45716->45725 45718 7ff6f9077e9c 45717->45718 45719 7ff6f9077e18 45717->45719 45754 7ff6f90720a0 34 API calls _Mpunct 45718->45754 45721 7ff6f9077e29 45719->45721 45722 7ff6f9077e56 45719->45722 45724 7ff6f90a3168 collate 4 API calls 45721->45724 45722->45725 45726 7ff6f90a3168 collate 4 API calls 45722->45726 45723 7ff6f9077e40 45723->45725 45727 7ff6f90c438c _invalid_parameter_noinfo_noreturn 31 API calls 45723->45727 45724->45723 45725->45640 45726->45725 45728 7ff6f9077ea7 45727->45728 45734 7ff6f907ad80 45729->45734 45730 7ff6f90a3168 collate 4 API calls 45730->45734 45733 7ff6f907adea 45736 7ff6f907adfa GetCurrentThreadId 45733->45736 45741 7ff6f907ae3f 45733->45741 45734->45730 45734->45733 45755 7ff6f9077920 45734->45755 45775 7ff6f9077bb0 45734->45775 45735 7ff6f907ae92 45737 7ff6f90a32c0 collate 8 API calls 45735->45737 45743 7ff6f907ae04 45736->45743 45740 7ff6f907aea7 45737->45740 45738 7ff6f907ae65 45738->45735 45745 7ff6f907aebe 45738->45745 45740->45644 45741->45735 45741->45738 45742 7ff6f907aeb9 45741->45742 45800 7ff6f90c6b08 45742->45800 45743->45733 45747 7ff6f9080ee8 40 API calls std::_Throw_Cpp_error 45743->45747 45799 7ff6f90803e4 WaitForSingleObjectEx GetExitCodeThread CloseHandle 45743->45799 45746 7ff6f90c438c _invalid_parameter_noinfo_noreturn 31 API calls 45745->45746 45748 7ff6f907aec4 45746->45748 45747->45743 45749->45650 45750->45653 45751->45654 45752->45657 45753->45659 45756 7ff6f9077b98 45755->45756 45760 7ff6f9077972 45755->45760 45805 7ff6f90720a0 34 API calls _Mpunct 45756->45805 45758 7ff6f9077b9e 45762 7ff6f90c438c _invalid_parameter_noinfo_noreturn 31 API calls 45758->45762 45759 7ff6f90779bb 45764 7ff6f90a3168 collate 4 API calls 45759->45764 45760->45759 45761 7ff6f9077a00 45760->45761 45765 7ff6f90779e7 45761->45765 45766 7ff6f90a3168 collate 4 API calls 45761->45766 45763 7ff6f9077ba4 45762->45763 45768 7ff6f90c6b08 Concurrency::SchedulerPolicy::_ValidPolicyValue 35 API calls 45763->45768 45764->45765 45765->45758 45767 7ff6f90a3168 collate 4 API calls 45765->45767 45766->45765 45769 7ff6f9077a3e 45767->45769 45770 7ff6f9077baa 45768->45770 45771 7ff6f9077bb0 46 API calls 45769->45771 45772 7ff6f9077a50 45771->45772 45772->45763 45773 7ff6f9077b4f 45772->45773 45774 7ff6f90c438c _invalid_parameter_noinfo_noreturn 31 API calls 45772->45774 45773->45734 45774->45756 45776 7ff6f9077c01 45775->45776 45777 7ff6f9077c0c 45776->45777 45813 7ff6f9080eac 40 API calls std::_Throw_Cpp_error 45776->45813 45806 7ff6f908093c 45777->45806 45782 7ff6f9077c5c 45810 7ff6f90804c0 45782->45810 45783 7ff6f9077c37 Concurrency::details::_CancellationTokenRegistration::_Invoke 45783->45782 45815 7ff6f9080eac 40 API calls std::_Throw_Cpp_error 45783->45815 45788 7ff6f9077c9d Concurrency::details::_CancellationTokenState::_DeregisterCallback 45789 7ff6f9077cc1 _Mtx_unlock 45788->45789 45817 7ff6f9080eac 40 API calls std::_Throw_Cpp_error 45788->45817 45791 7ff6f9077cf0 45789->45791 45818 7ff6f9080eac 40 API calls std::_Throw_Cpp_error 45789->45818 45819 7ff6f90808f4 15 API calls std::locale::_Locimp::_Locimp_dtor 45791->45819 45794 7ff6f9077cf8 45820 7ff6f9080c54 15 API calls std::locale::_Locimp::_Locimp_dtor 45794->45820 45796 7ff6f9077d00 45797 7ff6f90a32c0 collate 8 API calls 45796->45797 45798 7ff6f9077d0d 45797->45798 45798->45734 45799->45743 45801 7ff6f90d67d4 _Tolower 35 API calls 45800->45801 45804 7ff6f90c6b11 45801->45804 45850 7ff6f90c96ec 35 API calls 2 library calls 45804->45850 45807 7ff6f9080961 45806->45807 45808 7ff6f9077c2c 45807->45808 45821 7ff6f9080990 InitializeCriticalSectionAndSpinCount _Mtx_init_in_situ 45807->45821 45808->45783 45814 7ff6f9080eac 40 API calls std::_Throw_Cpp_error 45808->45814 45822 7ff6f90c99b0 45810->45822 45813->45777 45814->45783 45815->45782 45816 7ff6f9080eac 40 API calls std::_Throw_Cpp_error 45816->45788 45817->45788 45818->45791 45819->45794 45820->45796 45821->45808 45823 7ff6f90c99e0 45822->45823 45824 7ff6f90c99c9 45822->45824 45840 7ff6f90c9950 45823->45840 45847 7ff6f90c932c 14 API calls _get_daylight 45824->45847 45827 7ff6f90c99ce 45848 7ff6f90c436c 31 API calls _invalid_parameter_noinfo 45827->45848 45830 7ff6f90c99f3 CreateThread 45832 7ff6f90c9a23 GetLastError 45830->45832 45833 7ff6f90c9a30 45830->45833 45831 7ff6f9077c89 45831->45788 45831->45816 45849 7ff6f90c92bc 14 API calls 2 library calls 45832->45849 45833->45831 45835 7ff6f90c9a40 CloseHandle 45833->45835 45836 7ff6f90c9a46 45833->45836 45835->45836 45837 7ff6f90c9a55 45836->45837 45838 7ff6f90c9a4f FreeLibrary 45836->45838 45839 7ff6f90d6af0 Concurrency::details::SchedulerProxy::DeleteThis 14 API calls 45837->45839 45838->45837 45839->45831 45841 7ff6f90d6a78 _Thrd_start 14 API calls 45840->45841 45842 7ff6f90c9972 45841->45842 45843 7ff6f90d6af0 Concurrency::details::SchedulerProxy::DeleteThis 14 API calls 45842->45843 45844 7ff6f90c997c 45843->45844 45845 7ff6f90c9983 GetModuleHandleExW 45844->45845 45846 7ff6f90c999d 45844->45846 45845->45846 45846->45830 45846->45833 45847->45827 45848->45831 45849->45833 45852 7ff6f907841b 45851->45852 45853 7ff6f907840e 45851->45853 45867 7ff6f90805cc GetSystemTimeAsFileTime __crtFlsAlloc 45852->45867 45859 7ff6f908044c 45853->45859 45857 7ff6f90a32c0 collate 8 API calls 45858 7ff6f907847e 45857->45858 45858->45670 45868 7ff6f90805fc 45859->45868 45861 7ff6f9080473 _Xtime_diff_to_millis2 45862 7ff6f9080480 SleepEx 45861->45862 45864 7ff6f90804ac 45861->45864 45863 7ff6f90805fc xtime_get GetSystemTimeAsFileTime 45862->45863 45863->45861 45865 7ff6f90a32c0 collate 8 API calls 45864->45865 45866 7ff6f9078471 45865->45866 45866->45857 45867->45853 45869 7ff6f9080610 45868->45869 45871 7ff6f908061a 45868->45871 45869->45871 45872 7ff6f90805cc GetSystemTimeAsFileTime __crtFlsAlloc 45869->45872 45871->45861 45872->45871 45874 7ff6f90c8772 45873->45874 45875 7ff6f90c8786 45873->45875 45881 7ff6f90c932c 14 API calls _get_daylight 45874->45881 45876 7ff6f90c8782 45875->45876 45883 7ff6f90da240 6 API calls try_get_function 45875->45883 45876->45371 45879 7ff6f90c8777 45882 7ff6f90c436c 31 API calls _invalid_parameter_noinfo 45879->45882 45881->45879 45882->45876
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_$AddfacLocimp::_Locimp_std::locale::_$GetcvtMpunct$GetcollGetctypecollatenumpunct
    • String ID:
    • API String ID: 2498672018-0
    • Opcode ID: fb4a00f2c8653ac94c97500f7d9e0ea90b91f5ef66c12361f09c1cdd5456df5b
    • Instruction ID: f8b40413a1cbdd82e2d260fd3f99c12898aa67640a17689688bcf079d24be689
    • Opcode Fuzzy Hash: fb4a00f2c8653ac94c97500f7d9e0ea90b91f5ef66c12361f09c1cdd5456df5b
    • Instruction Fuzzy Hash: 06720B21E4AA1295E755DF21AC402B937A9AF65780F044139E92ED77EEFF3CE486C340

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 376 7ff6f907bac0-7ff6f907bb6e 377 7ff6f907bb75-7ff6f907bb7d 376->377 377->377 378 7ff6f907bb7f-7ff6f907bcf1 call 7ff6f9072130 call 7ff6f9079230 call 7ff6f9072290 377->378 387 7ff6f907bcf6-7ff6f907bcfd 378->387 387->387 388 7ff6f907bcff-7ff6f907be6f call 7ff6f9072130 call 7ff6f9079230 call 7ff6f9072290 call 7ff6f907b470 call 7ff6f9079020 call 7ff6f907b470 387->388 403 7ff6f907be75-7ff6f907bf5f call 7ff6f90c87fc call 7ff6f90c8380 call 7ff6f90c875c * 2 call 7ff6f907b470 388->403 404 7ff6f907cd34-7ff6f907cd56 call 7ff6f90788e0 388->404 431 7ff6f907bf64-7ff6f907bf66 403->431 408 7ff6f907cd5b 404->408 409 7ff6f907cd60-7ff6f907cd70 call 7ff6f90717d0 408->409 415 7ff6f907cd72-7ff6f907cd89 call 7ff6f90723b0 409->415 416 7ff6f907cd8e-7ff6f907cd9e call 7ff6f90717d0 409->416 415->416 424 7ff6f907cdb3-7ff6f907cdfe call 7ff6f90a32c0 416->424 425 7ff6f907cda0-7ff6f907cdae call 7ff6f90723b0 416->425 425->424 431->404 432 7ff6f907bf6c-7ff6f907bf73 call 7ff6f9079680 431->432 435 7ff6f907bf79-7ff6f907bf80 call 7ff6f9079ee0 432->435 436 7ff6f907cd2f call 7ff6f907b470 432->436 435->436 440 7ff6f907bf86-7ff6f907bf8d call 7ff6f90789a0 435->440 436->404 440->436 443 7ff6f907bf93-7ff6f907c080 call 7ff6f907b470 LoadLibraryW GetProcAddress IsDebuggerPresent FreeLibrary call 7ff6f907b470 440->443 443->404 450 7ff6f907c086-7ff6f907c0b1 443->450 451 7ff6f907c0b5-7ff6f907c0bc 450->451 451->451 452 7ff6f907c0be-7ff6f907c0e5 call 7ff6f9072130 call 7ff6f9078cd0 call 7ff6f9071770 451->452 459 7ff6f907c0eb-7ff6f907c10e GetModuleHandleA FindResourceA 452->459 460 7ff6f907ccfe-7ff6f907cd2d call 7ff6f907b470 call 7ff6f90788e0 452->460 462 7ff6f907ce2c-7ff6f907ce52 call 7ff6f9071700 call 7ff6f90c0b60 459->462 463 7ff6f907c114-7ff6f907c126 LoadResource 459->463 460->409 467 7ff6f907ce53-7ff6f907ce79 call 7ff6f9071700 call 7ff6f90c0b60 462->467 466 7ff6f907c12c-7ff6f907c13c SizeofResource 463->466 463->467 471 7ff6f907ce7a-7ff6f907cea0 call 7ff6f9071700 call 7ff6f90c0b60 466->471 472 7ff6f907c142-7ff6f907c155 LockResource 466->472 467->471 478 7ff6f907cea1-7ff6f907cec0 call 7ff6f9071700 call 7ff6f90c0b60 471->478 477 7ff6f907c15b-7ff6f907c254 call 7ff6f9077d30 call 7ff6f9077670 call 7ff6f907b470 call 7ff6f90c7bfc call 7ff6f907b470 call 7ff6f9079230 call 7ff6f907aa50 call 7ff6f907b470 CreateToolhelp32Snapshot 472->477 472->478 518 7ff6f907c25a-7ff6f907c2bf Process32First CloseHandle 477->518 519 7ff6f907cdff-7ff6f907ce2b call 7ff6f9071700 call 7ff6f90c0b60 call 7ff6f90c438c 477->519 494 7ff6f907cec1-7ff6f907cf07 call 7ff6f9071700 call 7ff6f90c0b60 call 7ff6f9075890 call 7ff6f907db00 478->494 511 7ff6f907cf09-7ff6f907cf11 call 7ff6f90a31a4 494->511 512 7ff6f907cf16-7ff6f907cf23 494->512 511->512 518->519 523 7ff6f907c2c5-7ff6f907c379 LoadLibraryA GetProcAddress 518->523 519->462 523->494 527 7ff6f907c37f-7ff6f907c75a call 7ff6f907b470 call 7ff6f90a3168 call 7ff6f907ddd0 call 7ff6f907b470 523->527 540 7ff6f907c760-7ff6f907c767 527->540 540->540 541 7ff6f907c769-7ff6f907c7ad call 7ff6f9072130 call 7ff6f9078e80 call 7ff6f9071770 540->541 548 7ff6f907c7b0-7ff6f907c7b7 541->548 548->548 549 7ff6f907c7b9-7ff6f907c811 call 7ff6f9072130 call 7ff6f9078e80 call 7ff6f907a8f0 call 7ff6f90717d0 call 7ff6f9071770 548->549 560 7ff6f907c814-7ff6f907c81b 549->560 560->560 561 7ff6f907c81d-7ff6f907c85e call 7ff6f9072130 call 7ff6f9078e80 call 7ff6f9071770 560->561 568 7ff6f907c861-7ff6f907c868 561->568 568->568 569 7ff6f907c86a-7ff6f907c8c2 call 7ff6f9072130 call 7ff6f9078e80 call 7ff6f907a8f0 call 7ff6f90717d0 call 7ff6f9071770 568->569 580 7ff6f907c8c5-7ff6f907c8cc 569->580 580->580 581 7ff6f907c8ce-7ff6f907c90d call 7ff6f9072130 call 7ff6f9078e80 call 7ff6f9071770 580->581 588 7ff6f907c910-7ff6f907c917 581->588 588->588 589 7ff6f907c919-7ff6f907c9ef call 7ff6f9072130 call 7ff6f9078e80 call 7ff6f907a8f0 call 7ff6f90717d0 call 7ff6f9071770 call 7ff6f907b470 call 7ff6f907a490 * 2 588->589 606 7ff6f907c9f0-7ff6f907c9f7 589->606 606->606 607 7ff6f907c9f9-7ff6f907ca2f call 7ff6f9072130 606->607 610 7ff6f907ca30-7ff6f907ca38 607->610 610->610 611 7ff6f907ca3a-7ff6f907cb6e call 7ff6f9072290 call 7ff6f907a490 call 7ff6f90717d0 call 7ff6f9071770 call 7ff6f907a280 call 7ff6f907b470 610->611 626 7ff6f907cb71-7ff6f907cb78 611->626 626->626 627 7ff6f907cb7a-7ff6f907cc39 call 7ff6f9072130 call 7ff6f907af20 call 7ff6f9071770 call 7ff6f907b470 call 7ff6f907b150 call 7ff6f907b470 call 7ff6f907b820 626->627 627->460
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID: 158$7YsC$7YsC$Failed to find lsass.exe process$Failed to find shellcode resource$Failed to get RtlAdjustPrivilege address$Failed to load shellcode resource$Failed to lock shellcode resource$Shellcode resource size is 0$YzsH$agxs$gerP$gj==$gj==$l.dl$ntdl$rese$wp9=
    • API String ID: 0-2991562347
    • Opcode ID: 977e809e7aae9650e66132d33d392e4e7de19001329471ffbb6c7019d6b61f18
    • Instruction ID: 4f9f81eb538102ba4541f44ee81944227f70963f0c61d252f97e2ba95b704ed6
    • Opcode Fuzzy Hash: 977e809e7aae9650e66132d33d392e4e7de19001329471ffbb6c7019d6b61f18
    • Instruction Fuzzy Hash: 36927E62D18BC689E761DF34DC412F92760FB99388F405239DA9C96A9EFF38D248C341

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Locimp::_Lockit::_Lockit::~_std::locale::_$AddfacLocimp_$GetctypeMakeushlocMakexlocYarn
    • String ID:
    • API String ID: 2183446013-0
    • Opcode ID: 4460336c54669a8e75083f648a9d816190a8b1f1dafdd6e4fd5649da36198e74
    • Instruction ID: 6229c22bbb3dffb9b5f12df35b2b503b73f57507814689fc00a52758a16bdb98
    • Opcode Fuzzy Hash: 4460336c54669a8e75083f648a9d816190a8b1f1dafdd6e4fd5649da36198e74
    • Instruction Fuzzy Hash: FDE10B61E09A0295EB5ADF15AC402B932A9EFA27D4F044039D96DC3BEDFF2DE495C340

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 702 7ff6f90d9580-7ff6f90d95ba call 7ff6f90d8d48 call 7ff6f90d8db0 707 7ff6f90d95c0-7ff6f90d95cb call 7ff6f90d8d50 702->707 708 7ff6f90d97cd-7ff6f90d980e call 7ff6f90c43bc call 7ff6f90d8d48 call 7ff6f90d8db0 702->708 714 7ff6f90d95d1-7ff6f90d95db 707->714 715 7ff6f90d97b8-7ff6f90d97cc call 7ff6f90c43bc 707->715 732 7ff6f90d99a3-7ff6f90d9a11 call 7ff6f90c43bc call 7ff6f90e3e44 708->732 733 7ff6f90d9814-7ff6f90d981f call 7ff6f90d8d50 708->733 718 7ff6f90d9603-7ff6f90d960c call 7ff6f90d6af0 714->718 719 7ff6f90d95dd-7ff6f90d95e3 714->719 715->708 729 7ff6f90d960f-7ff6f90d9616 718->729 723 7ff6f90d95e6-7ff6f90d95f1 719->723 724 7ff6f90d95f3-7ff6f90d95f9 723->724 725 7ff6f90d95fb-7ff6f90d95fd 723->725 724->723 724->725 725->718 728 7ff6f90d9762-7ff6f90d9778 725->728 729->729 731 7ff6f90d9618-7ff6f90d9638 call 7ff6f90d7704 call 7ff6f90d6af0 729->731 731->728 748 7ff6f90d963e-7ff6f90d9645 731->748 752 7ff6f90d9a13-7ff6f90d9a18 732->752 753 7ff6f90d9a1a-7ff6f90d9a1d 732->753 742 7ff6f90d9825-7ff6f90d9830 call 7ff6f90d8d80 733->742 743 7ff6f90d998e-7ff6f90d99a2 call 7ff6f90c43bc 733->743 754 7ff6f90d9836-7ff6f90d9859 call 7ff6f90d6af0 GetTimeZoneInformation 742->754 755 7ff6f90d9979-7ff6f90d998d call 7ff6f90c43bc 742->755 743->732 748->748 756 7ff6f90d9647-7ff6f90d9655 call 7ff6f90d6338 748->756 757 7ff6f90d9a68-7ff6f90d9a7a 752->757 759 7ff6f90d9a24-7ff6f90d9a34 call 7ff6f90d7704 753->759 760 7ff6f90d9a1f-7ff6f90d9a22 753->760 770 7ff6f90d9952-7ff6f90d9978 call 7ff6f90d8d40 call 7ff6f90d8d30 call 7ff6f90d8d38 754->770 771 7ff6f90d985f-7ff6f90d9881 754->771 755->743 774 7ff6f90d97a3-7ff6f90d97b7 call 7ff6f90c43bc 756->774 775 7ff6f90d965b-7ff6f90d9675 call 7ff6f90e3e4c 756->775 763 7ff6f90d9a8b call 7ff6f90d97e4 757->763 764 7ff6f90d9a7c-7ff6f90d9a7f 757->764 781 7ff6f90d9a3f-7ff6f90d9a5a call 7ff6f90e3e44 759->781 782 7ff6f90d9a36 759->782 760->757 783 7ff6f90d9a90-7ff6f90d9abc call 7ff6f90d6af0 call 7ff6f90a32c0 763->783 764->763 769 7ff6f90d9a81-7ff6f90d9a89 call 7ff6f90d9580 764->769 769->783 779 7ff6f90d9883-7ff6f90d9888 771->779 780 7ff6f90d988b-7ff6f90d9892 771->780 774->715 794 7ff6f90d978e-7ff6f90d97a2 call 7ff6f90c43bc 775->794 795 7ff6f90d967b-7ff6f90d967e 775->795 779->780 788 7ff6f90d9894-7ff6f90d989c 780->788 789 7ff6f90d98ac-7ff6f90d98af 780->789 809 7ff6f90d9a61-7ff6f90d9a63 call 7ff6f90d6af0 781->809 810 7ff6f90d9a5c-7ff6f90d9a5f 781->810 790 7ff6f90d9a38-7ff6f90d9a3d call 7ff6f90d6af0 782->790 788->789 797 7ff6f90d989e-7ff6f90d98aa 788->797 799 7ff6f90d98b2-7ff6f90d98ee call 7ff6f90c8bc4 WideCharToMultiByte 789->799 790->760 794->774 802 7ff6f90d9680-7ff6f90d9687 795->802 803 7ff6f90d9689-7ff6f90d96a9 call 7ff6f90c7bfc 795->803 797->799 819 7ff6f90d98fe-7ff6f90d9901 799->819 820 7ff6f90d98f0-7ff6f90d98f3 799->820 802->795 802->803 821 7ff6f90d96ac-7ff6f90d96af 803->821 809->757 810->790 823 7ff6f90d9904-7ff6f90d993a WideCharToMultiByte 819->823 820->819 822 7ff6f90d98f5-7ff6f90d98fc 820->822 826 7ff6f90d96b1-7ff6f90d96b8 821->826 827 7ff6f90d96ba-7ff6f90d96bd 821->827 822->823 824 7ff6f90d994b-7ff6f90d994f 823->824 825 7ff6f90d993c-7ff6f90d993f 823->825 824->770 825->824 828 7ff6f90d9941-7ff6f90d9949 825->828 826->827 829 7ff6f90d96bf-7ff6f90d96c2 826->829 827->821 828->770 830 7ff6f90d9712-7ff6f90d9716 829->830 831 7ff6f90d96c4-7ff6f90d96da call 7ff6f90c7bfc 829->831 832 7ff6f90d971d-7ff6f90d972b 830->832 833 7ff6f90d9718-7ff6f90d971a 830->833 840 7ff6f90d96e3-7ff6f90d96e8 831->840 835 7ff6f90d972d-7ff6f90d9743 call 7ff6f90e3e4c 832->835 836 7ff6f90d9747-7ff6f90d974b 832->836 833->832 838 7ff6f90d974e-7ff6f90d9760 call 7ff6f90d8d40 call 7ff6f90d8d30 835->838 847 7ff6f90d9745-7ff6f90d978d call 7ff6f90c43bc 835->847 836->838 838->728 842 7ff6f90d96ea-7ff6f90d96ed 840->842 843 7ff6f90d96dc-7ff6f90d96de 840->843 842->830 846 7ff6f90d96ef-7ff6f90d9702 call 7ff6f90c7bfc 842->846 843->842 848 7ff6f90d96e0 843->848 855 7ff6f90d970b-7ff6f90d9710 846->855 847->794 848->840 855->830 857 7ff6f90d9704-7ff6f90d9706 855->857 857->830 858 7ff6f90d9708 857->858 858->855
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _get_daylight$ByteCharMultiWide_invalid_parameter_noinfo$InformationTimeZone
    • String ID: ?$Eastern Standard Time$Eastern Summer Time
    • API String ID: 3440502458-688781733
    • Opcode ID: e056f1c026c43fca07be4a7889b5f158ef908aecc4012eb7e40475d80ec204aa
    • Instruction ID: a5f6a301fc4df20aff79b8c35aef081a6b61083228e78d2a954c863758eaec90
    • Opcode Fuzzy Hash: e056f1c026c43fca07be4a7889b5f158ef908aecc4012eb7e40475d80ec204aa
    • Instruction Fuzzy Hash: 26E1B032A0868286E764DF359C406A97B96FB94788F44513AEB7E83BDDEF3CD4418740

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 1003 7ff6f90c8064-7ff6f90c8078 1004 7ff6f90c8095-7ff6f90c80a8 call 7ff6f90c16a0 1003->1004 1005 7ff6f90c807a-7ff6f90c8086 call 7ff6f90c932c call 7ff6f90c436c 1003->1005 1004->1005 1010 7ff6f90c80aa-7ff6f90c80ae 1004->1010 1014 7ff6f90c808b 1005->1014 1012 7ff6f90c80b0-7ff6f90c80bc call 7ff6f90c932c 1010->1012 1013 7ff6f90c80be-7ff6f90c80cb 1010->1013 1012->1014 1013->1012 1017 7ff6f90c80cd call 7ff6f90d9ac0 1013->1017 1015 7ff6f90c808d-7ff6f90c8094 1014->1015 1020 7ff6f90c80d2-7ff6f90c80e9 call 7ff6f90d8d50 1017->1020 1023 7ff6f90c80ef-7ff6f90c80fa call 7ff6f90d8d80 1020->1023 1024 7ff6f90c8367-7ff6f90c837f call 7ff6f90c43bc 1020->1024 1029 7ff6f90c8100-7ff6f90c810b call 7ff6f90d8db0 1023->1029 1030 7ff6f90c8351-7ff6f90c8366 call 7ff6f90c43bc 1023->1030 1035 7ff6f90c8111-7ff6f90c8128 1029->1035 1036 7ff6f90c833b-7ff6f90c8350 call 7ff6f90c43bc 1029->1036 1030->1024 1037 7ff6f90c818a-7ff6f90c8197 call 7ff6f90d9054 1035->1037 1038 7ff6f90c812a-7ff6f90c8143 call 7ff6f90d9054 1035->1038 1036->1030 1037->1015 1045 7ff6f90c819d-7ff6f90c81a3 1037->1045 1038->1015 1046 7ff6f90c8149-7ff6f90c814c 1038->1046 1047 7ff6f90c81c2 1045->1047 1048 7ff6f90c81a5-7ff6f90c81af call 7ff6f90d9afc 1045->1048 1049 7ff6f90c8152-7ff6f90c815c call 7ff6f90d9afc 1046->1049 1050 7ff6f90c82e7-7ff6f90c82e9 1046->1050 1052 7ff6f90c81c6-7ff6f90c81f3 1047->1052 1048->1047 1058 7ff6f90c81b1-7ff6f90c81c0 1048->1058 1049->1050 1061 7ff6f90c8162-7ff6f90c8178 call 7ff6f90d9054 1049->1061 1050->1015 1055 7ff6f90c81f5-7ff6f90c81fc 1052->1055 1056 7ff6f90c81fe-7ff6f90c823f 1052->1056 1055->1056 1059 7ff6f90c8241-7ff6f90c8248 1056->1059 1060 7ff6f90c824b-7ff6f90c8296 1056->1060 1058->1052 1059->1060 1063 7ff6f90c82a2-7ff6f90c82bc 1060->1063 1064 7ff6f90c8298-7ff6f90c829f 1060->1064 1061->1015 1070 7ff6f90c817e-7ff6f90c8185 1061->1070 1065 7ff6f90c82ee 1063->1065 1066 7ff6f90c82be-7ff6f90c82e0 1063->1066 1064->1063 1065->1050 1069 7ff6f90c82f0-7ff6f90c831d 1065->1069 1068 7ff6f90c82e3 1066->1068 1068->1050 1069->1068 1071 7ff6f90c831f-7ff6f90c8339 1069->1071 1070->1050 1071->1050
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _get_daylight$_isindst$_invalid_parameter_noinfo
    • String ID:
    • API String ID: 1405656091-0
    • Opcode ID: 980db3feaa98d670d0e2179d87a31a66d4ae0fee66c7df8ba197ac5009a55739
    • Instruction ID: 3b064435234f3f821561dd59db51a1fc968ae3111a21ce2bad5cdc5fc8de339c
    • Opcode Fuzzy Hash: 980db3feaa98d670d0e2179d87a31a66d4ae0fee66c7df8ba197ac5009a55739
    • Instruction Fuzzy Hash: 2881BFB2B046464BEB6C8E65CD05BA822A5EB54788F04903DEE1DCABCDFF3CE4018614

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AddressLibraryProc$Free$LoadThrd_sleepXtime_get_ticks
    • String ID: Coun$Freq$GetT$ickC$ount$ter$uenc
    • API String ID: 2031778473-2732439934
    • Opcode ID: 9d20d7a5e47f1f04f8d83ee82bee1d022dc6d366e3615be8b05c3e2c4efe27fc
    • Instruction ID: 4f0394729fd4a83db509006c4e2fd47b0ec46bae5d54006c7cd02ab2899171d7
    • Opcode Fuzzy Hash: 9d20d7a5e47f1f04f8d83ee82bee1d022dc6d366e3615be8b05c3e2c4efe27fc
    • Instruction Fuzzy Hash: FA518D22F04A8289E711DFB0E8503AD73B5EF58788F05413ACE1E67A88EF38D156C704

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 859 7ff6f90d97e4-7ff6f90d980e call 7ff6f90d8d48 call 7ff6f90d8db0 864 7ff6f90d99a3-7ff6f90d9a11 call 7ff6f90c43bc call 7ff6f90e3e44 859->864 865 7ff6f90d9814-7ff6f90d981f call 7ff6f90d8d50 859->865 879 7ff6f90d9a13-7ff6f90d9a18 864->879 880 7ff6f90d9a1a-7ff6f90d9a1d 864->880 871 7ff6f90d9825-7ff6f90d9830 call 7ff6f90d8d80 865->871 872 7ff6f90d998e-7ff6f90d99a2 call 7ff6f90c43bc 865->872 881 7ff6f90d9836-7ff6f90d9859 call 7ff6f90d6af0 GetTimeZoneInformation 871->881 882 7ff6f90d9979-7ff6f90d998d call 7ff6f90c43bc 871->882 872->864 883 7ff6f90d9a68-7ff6f90d9a7a 879->883 885 7ff6f90d9a24-7ff6f90d9a34 call 7ff6f90d7704 880->885 886 7ff6f90d9a1f-7ff6f90d9a22 880->886 894 7ff6f90d9952-7ff6f90d9978 call 7ff6f90d8d40 call 7ff6f90d8d30 call 7ff6f90d8d38 881->894 895 7ff6f90d985f-7ff6f90d9881 881->895 882->872 888 7ff6f90d9a8b call 7ff6f90d97e4 883->888 889 7ff6f90d9a7c-7ff6f90d9a7f 883->889 902 7ff6f90d9a3f-7ff6f90d9a5a call 7ff6f90e3e44 885->902 903 7ff6f90d9a36 885->903 886->883 904 7ff6f90d9a90-7ff6f90d9abc call 7ff6f90d6af0 call 7ff6f90a32c0 888->904 889->888 893 7ff6f90d9a81-7ff6f90d9a89 call 7ff6f90d9580 889->893 893->904 900 7ff6f90d9883-7ff6f90d9888 895->900 901 7ff6f90d988b-7ff6f90d9892 895->901 900->901 907 7ff6f90d9894-7ff6f90d989c 901->907 908 7ff6f90d98ac-7ff6f90d98af 901->908 922 7ff6f90d9a61-7ff6f90d9a63 call 7ff6f90d6af0 902->922 923 7ff6f90d9a5c-7ff6f90d9a5f 902->923 909 7ff6f90d9a38-7ff6f90d9a3d call 7ff6f90d6af0 903->909 907->908 913 7ff6f90d989e-7ff6f90d98aa 907->913 915 7ff6f90d98b2-7ff6f90d98ee call 7ff6f90c8bc4 WideCharToMultiByte 908->915 909->886 913->915 929 7ff6f90d98fe-7ff6f90d9901 915->929 930 7ff6f90d98f0-7ff6f90d98f3 915->930 922->883 923->909 932 7ff6f90d9904-7ff6f90d993a WideCharToMultiByte 929->932 930->929 931 7ff6f90d98f5-7ff6f90d98fc 930->931 931->932 933 7ff6f90d994b-7ff6f90d994f 932->933 934 7ff6f90d993c-7ff6f90d993f 932->934 933->894 934->933 935 7ff6f90d9941-7ff6f90d9949 934->935 935->894
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _get_daylight_invalid_parameter_noinfo$ByteCharMultiWide$FreeHeapInformationTimeZone
    • String ID: ?$Eastern Standard Time$Eastern Summer Time
    • API String ID: 2401661991-688781733
    • Opcode ID: 90b8dfbf901003e42658c5151d9198e74a5229eedeac75c91a888f9b87f65051
    • Instruction ID: 666bc6050a01a32c5098018b52d3fd7894fc48636186e54a1bdcc5779be2ac47
    • Opcode Fuzzy Hash: 90b8dfbf901003e42658c5151d9198e74a5229eedeac75c91a888f9b87f65051
    • Instruction Fuzzy Hash: 9A619B32A186428AE764DF25EC801A977A5FF84794F84413AEA6D827DDFF3CE581C740

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: __scrt_fastfail__scrt_is_nonwritable_in_current_image$__scrt_acquire_startup_lock__scrt_get_show_window_mode__scrt_initialize_crt__scrt_is_managed_app__scrt_release_startup_lock__scrt_uninitialize_crt__vcrt_initialize
    • String ID:
    • API String ID: 1664584033-0
    • Opcode ID: 55bc8d2aca4288ef9c140cd2ccc4de8dbba448ad7001838a59fca08c757d4f52
    • Instruction ID: 0f13f2777bbadda3fe7d2d88f462521c1c1b9ba01227b974e393a271da94ace4
    • Opcode Fuzzy Hash: 55bc8d2aca4288ef9c140cd2ccc4de8dbba448ad7001838a59fca08c757d4f52
    • Instruction Fuzzy Hash: B2312A21E1C20345FB15AF65DC513BA6692AF51744F44403DEA7ECB6DFFE2CE8458290

    Control-flow Graph

    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Library$AddressFreeLoadMessageProc
    • String ID: Mess$ageB$oxW
    • API String ID: 2780580303-3069161946
    • Opcode ID: 4bc8adc1b78907f513fc786450d80eda5fc97488af26e0ef22ab6344f0554d06
    • Instruction ID: f68a6d0ce47383922797cfad8da60263b28b6e43cc9f186b343ec8843fa133d4
    • Opcode Fuzzy Hash: 4bc8adc1b78907f513fc786450d80eda5fc97488af26e0ef22ab6344f0554d06
    • Instruction Fuzzy Hash: 24117C62B156519DFB01CFA2AC446BC3AB06B09BE8F484438CE2D97B48EF38C5858711

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_$AddfacGetcvtLocimp::_Locimp_Locinfo::_Locinfo_ctorLockit::~_Yarnstd::locale::_
    • String ID:
    • API String ID: 3597945955-0
    • Opcode ID: 517802372387ccde4f7721f051ca2a997f446734f4bc9ce07f05ac2489fa750e
    • Instruction ID: b16d4bacd03ce2a3feeb1e9a2ca81aa5c0ea4e256a939da3059ba70240707ac1
    • Opcode Fuzzy Hash: 517802372387ccde4f7721f051ca2a997f446734f4bc9ce07f05ac2489fa750e
    • Instruction Fuzzy Hash: 4151A732A0CB8592EB21DF25E8502B973A4FB95B90F484139D79D83B99EF3CE485C705

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 1122 7ff6f907ad40-7ff6f907ad7d 1123 7ff6f907ad80-7ff6f907ad8a 1122->1123 1124 7ff6f907adcd-7ff6f907adda call 7ff6f9077920 1123->1124 1125 7ff6f907ad8c-7ff6f907adb1 call 7ff6f90a3168 call 7ff6f9077bb0 1123->1125 1129 7ff6f907addf 1124->1129 1134 7ff6f907adbd-7ff6f907adcb 1125->1134 1135 7ff6f907adb3-7ff6f907adb8 call 7ff6f90a31a4 1125->1135 1131 7ff6f907ade4-7ff6f907ade8 1129->1131 1131->1123 1133 7ff6f907adea-7ff6f907adf2 1131->1133 1136 7ff6f907ae49-7ff6f907ae4c 1133->1136 1137 7ff6f907adf4-7ff6f907adf8 1133->1137 1134->1131 1135->1134 1139 7ff6f907ae9a-7ff6f907aeb8 call 7ff6f90a32c0 1136->1139 1140 7ff6f907ae4e-7ff6f907ae54 1136->1140 1141 7ff6f907adfa-7ff6f907ae02 GetCurrentThreadId 1137->1141 1142 7ff6f907ae36-7ff6f907ae3d 1137->1142 1145 7ff6f907ae56-7ff6f907ae5a 1140->1145 1146 7ff6f907ae65-7ff6f907ae7b 1140->1146 1147 7ff6f907ae04-7ff6f907ae09 call 7ff6f9080ee8 1141->1147 1148 7ff6f907ae0e-7ff6f907ae24 call 7ff6f90803e4 1141->1148 1142->1137 1144 7ff6f907ae3f-7ff6f907ae44 1142->1144 1144->1136 1151 7ff6f907ae5c-7ff6f907ae63 1145->1151 1152 7ff6f907aeb9-7ff6f907aebe call 7ff6f90c6b08 1145->1152 1153 7ff6f907ae7d-7ff6f907ae90 1146->1153 1154 7ff6f907ae92-7ff6f907ae95 call 7ff6f90a31a4 1146->1154 1147->1148 1160 7ff6f907ae26-7ff6f907ae2b call 7ff6f9080ee8 1148->1160 1161 7ff6f907ae30-7ff6f907ae33 1148->1161 1151->1145 1151->1146 1158 7ff6f907aebf-7ff6f907aec4 call 7ff6f90c438c 1152->1158 1153->1154 1153->1158 1154->1139 1160->1161 1161->1142
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Cpp_errorThrow_std::_$Cnd_destroyCurrentMtx_destroyMtx_initMtx_unlockThrd_joinThrd_startThread_invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 4061800114-0
    • Opcode ID: d214aeb6ccc95a562b8402ab828d4bd30d0fe96f4a953e3290569f0e53d15e30
    • Instruction ID: 6391fe09e7584a5c006789d047ea8e97d3f2a7076feb8039cfa5d2f55b298bf8
    • Opcode Fuzzy Hash: d214aeb6ccc95a562b8402ab828d4bd30d0fe96f4a953e3290569f0e53d15e30
    • Instruction Fuzzy Hash: 4C41A222B1868182EB509F65D9442AEA361EF847F0F144639EBBD47BCDEF7CE4808701

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Cnd_destroyMtx_destroyMtx_initMtx_unlockThrd_start
    • String ID:
    • API String ID: 2938124238-0
    • Opcode ID: f1868420eb924195e895775748ceeaedc62e5277740351bb7f5fc450f9ca8990
    • Instruction ID: 3f0ff5aed7290c3b68fb7f180ea7cfd66d5e10e7a2dc00328f6372b39531e38f
    • Opcode Fuzzy Hash: f1868420eb924195e895775748ceeaedc62e5277740351bb7f5fc450f9ca8990
    • Instruction Fuzzy Hash: CC412722F09B5288FB549BB19C513ED26B5AB487A8F040139DE6DD7BCEEF38E4408745

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: CloseCreateErrorFreeHandleLastLibraryThread_invalid_parameter_noinfo
    • String ID:
    • API String ID: 2067211477-0
    • Opcode ID: 08ed1d4c42050ec392658845bfe524db88aa4d3b07c01d7ba851e1dce114c3a8
    • Instruction ID: c3df5d89eddcd2f149e68fd82fbfd0dea00590a1bbc47f47359ea095d7ffeeb8
    • Opcode Fuzzy Hash: 08ed1d4c42050ec392658845bfe524db88aa4d3b07c01d7ba851e1dce114c3a8
    • Instruction Fuzzy Hash: 9F214225B0974286EF15DF66985017963A0AF84B80F084539EF7E837DDFE3CE400C660

    Control-flow Graph

    APIs
      • Part of subcall function 00007FF6F90D6948: GetLastError.KERNEL32(?,?,8000000000000000,00007FF6F90C9335,?,?,?,?,00007FF6F90D6B15), ref: 00007FF6F90D6952
      • Part of subcall function 00007FF6F90D6948: SetLastError.KERNEL32(?,?,8000000000000000,00007FF6F90C9335,?,?,?,?,00007FF6F90D6B15), ref: 00007FF6F90D697E
    • ExitThread.KERNEL32 ref: 00007FF6F90C98F4
    • ExitThread.KERNEL32 ref: 00007FF6F90C9909
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorExitLastThread
    • String ID:
    • API String ID: 1611280651-0
    • Opcode ID: 59c4a6963072dc2200774ba5c96d922b26b8fb9d4c7ee41bf7ea5306705dfb46
    • Instruction ID: 6af7fb97e736304bca4423a88e4476e3c0232a16d4fd52a1b008deb4f4920d40
    • Opcode Fuzzy Hash: 59c4a6963072dc2200774ba5c96d922b26b8fb9d4c7ee41bf7ea5306705dfb46
    • Instruction Fuzzy Hash: 0E012821B08A8292EB056F748D8423C62A5EF40B74F14173DD73E827E9FF2CE8598350

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Process$CurrentExitTerminate
    • String ID:
    • API String ID: 1703294689-0
    • Opcode ID: 53077afccc69a4dd1a010a808ad812dcf372d9b3d2230ae3ee0c212679bdc2ff
    • Instruction ID: eec04d50a4a736bbef98ed184cd6a0dc71880ff33015c51839d08b3e6083e56b
    • Opcode Fuzzy Hash: 53077afccc69a4dd1a010a808ad812dcf372d9b3d2230ae3ee0c212679bdc2ff
    • Instruction Fuzzy Hash: 5DE04F20B0830686FB687F759C952B92256AF84741F20543CC92E863DEED3DE8488310

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 1257 7ff6f907b470-7ff6f907b4ac call 7ff6f90a3940 call 7ff6f90c87fc 1262 7ff6f907b4b0-7ff6f907b4d3 1257->1262 1262->1262 1263 7ff6f907b4d5-7ff6f907b516 call 7ff6f9078690 call 7ff6f90a3168 1262->1263 1268 7ff6f907b518-7ff6f907b51e 1263->1268 1269 7ff6f907b520 1263->1269 1270 7ff6f907b523-7ff6f907b594 call 7ff6f90a31a4 call 7ff6f9077dc0 1268->1270 1269->1270 1275 7ff6f907b596-7ff6f907b59a 1270->1275 1276 7ff6f907b613-7ff6f907b616 1270->1276 1279 7ff6f907b59c-7ff6f907b5a7 1275->1279 1280 7ff6f907b5f3-7ff6f907b5f6 1275->1280 1277 7ff6f907b64d call 7ff6f907ad40 1276->1277 1278 7ff6f907b618-7ff6f907b62e 1276->1278 1288 7ff6f907b652-7ff6f907b66a call 7ff6f90a32c0 1277->1288 1281 7ff6f907b645-7ff6f907b648 call 7ff6f90a31a4 1278->1281 1282 7ff6f907b630-7ff6f907b643 1278->1282 1284 7ff6f907b5b0-7ff6f907b5f1 1279->1284 1280->1276 1285 7ff6f907b5f8 1280->1285 1281->1277 1282->1281 1286 7ff6f907b66b-7ff6f907b6bf call 7ff6f90c438c 1282->1286 1284->1280 1284->1284 1289 7ff6f907b600-7ff6f907b611 1285->1289 1295 7ff6f907b6ca-7ff6f907b6d6 1286->1295 1296 7ff6f907b6c1-7ff6f907b6c7 1286->1296 1289->1276 1289->1289 1297 7ff6f907b6d8-7ff6f907b6e0 1295->1297 1298 7ff6f907b6ef-7ff6f907b700 1295->1298 1296->1295 1297->1298 1299 7ff6f907b6e2-7ff6f907b6e5 1297->1299 1300 7ff6f907b709-7ff6f907b716 1298->1300 1301 7ff6f907b702-7ff6f907b707 1298->1301 1299->1298 1303 7ff6f907b6e7-7ff6f907b6ec call 7ff6f907b020 1299->1303 1305 7ff6f907b73d-7ff6f907b741 1300->1305 1306 7ff6f907b718-7ff6f907b720 1300->1306 1304 7ff6f907b763-7ff6f907b78a 1301->1304 1303->1298 1308 7ff6f907b78c-7ff6f907b793 call 7ff6f907ef78 1304->1308 1309 7ff6f907b7ce-7ff6f907b7d0 1304->1309 1315 7ff6f907b747-7ff6f907b758 1305->1315 1306->1305 1310 7ff6f907b722-7ff6f907b73b 1306->1310 1319 7ff6f907b795-7ff6f907b79d call 7ff6f9075790 1308->1319 1320 7ff6f907b79e-7ff6f907b7ad 1308->1320 1312 7ff6f907b7db-7ff6f907b7eb 1309->1312 1313 7ff6f907b7d2-7ff6f907b7d9 1309->1313 1310->1315 1316 7ff6f907b7ef-7ff6f907b81f call 7ff6f9076d40 call 7ff6f9073640 call 7ff6f90c0b60 1312->1316 1313->1316 1315->1304 1319->1320 1321 7ff6f907b7b6-7ff6f907b7cd 1320->1321 1322 7ff6f907b7af-7ff6f907b7b5 1320->1322 1322->1321
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 3668304517-3916222277
    • Opcode ID: 34b7a81319f3a570114e4e6290e8e85e272063c0dc67f372ae795c383e11763f
    • Instruction ID: 77540769cce22b686bedb5ae88b37507be7e97d2013a755a2e52d40c2944efe9
    • Opcode Fuzzy Hash: 34b7a81319f3a570114e4e6290e8e85e272063c0dc67f372ae795c383e11763f
    • Instruction Fuzzy Hash: 50818572A15B8182EB148F29D8513B9A760FB85BA4F14833ADB6D877D9EF3CD481C701
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: try_get_function
    • String ID: AppPolicyGetThreadInitializationType
    • API String ID: 2742660187-3350320272
    • Opcode ID: ce75949736fbde21343834cb8b50f4a006a4a1040df50360689b242f64e1e7b6
    • Instruction ID: 7803894a7781b48e984d3247dcebff8091a6260997087fc60ac284618d737b77
    • Opcode Fuzzy Hash: ce75949736fbde21343834cb8b50f4a006a4a1040df50360689b242f64e1e7b6
    • Instruction Fuzzy Hash: 8FE04F91E0950AD1FF455F91AC001B01211DF087BCE48033AEA3C863D8FE2CEA99D304
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 3668304517-0
    • Opcode ID: c44ed366d8de4c662e0f08cb95b8fa742348f4d5b0e0f82980a6293a64fa6d62
    • Instruction ID: c2b7da164ad758b39d7bf86c4290950a3aa30a7e8ea0f1111b878d45f2d436e4
    • Opcode Fuzzy Hash: c44ed366d8de4c662e0f08cb95b8fa742348f4d5b0e0f82980a6293a64fa6d62
    • Instruction Fuzzy Hash: 91718D62B09A8581EF148F29E80427966A5EB84BF4F558739DE7D43BD9EF3CE481C301
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Cnd_do_broadcast_at_thread_exitMtx_unlock
    • String ID:
    • API String ID: 3664743064-0
    • Opcode ID: 83e0adefe17ca9ad8f5b03030cf6eb1a18c82bd3fef7bf9ec5c94f197ceba56b
    • Instruction ID: 4296dd6d2f1f469601b09d6eeeff2e94b82d7ca86298a1d45fa5e1d384225c93
    • Opcode Fuzzy Hash: 83e0adefe17ca9ad8f5b03030cf6eb1a18c82bd3fef7bf9ec5c94f197ceba56b
    • Instruction Fuzzy Hash: 81217531F0864182EB549F25D84127A62A5FF84754F540139EAADC7BDEEF3CE4928B04
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Thrd_sleepXtime_get_ticks
    • String ID:
    • API String ID: 2736526484-0
    • Opcode ID: ad8e22bb93492d7c1794e8284a8eab5c434cdef3aa11ebb6d7be5d99d615c568
    • Instruction ID: 4f899f0818758d3c59d3163bb5669ac07faaecbc1882f0ea90bf3a37124ecbec
    • Opcode Fuzzy Hash: ad8e22bb93492d7c1794e8284a8eab5c434cdef3aa11ebb6d7be5d99d615c568
    • Instruction Fuzzy Hash: AF01B9A2B1978942EB648F24A851369A3D4FB8C3C8F445135EADE86789FF2CD1414B04
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorExitLastThread
    • String ID:
    • API String ID: 1611280651-0
    • Opcode ID: 60b4ac61bffc80a819f642a658f2081e26c96e24864ec600703ed24e0d73b1e5
    • Instruction ID: 0022dcb5550f5d7e3355fbb53406be5b163cbf0158ac3cfd8cf67aabeff7f1df
    • Opcode Fuzzy Hash: 60b4ac61bffc80a819f642a658f2081e26c96e24864ec600703ed24e0d73b1e5
    • Instruction Fuzzy Hash: 9EF03A66E0964286EF19AFB59C155BC12A1AF94B14F041039EA39C33DAFE2CE944C210
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Concurrency::cancel_current_task$ExceptionThrowstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 2386360001-0
    • Opcode ID: 23f425f8a334c2b16384e28a3fa6a9e2980a0f072a9231f595175fb2069c4236
    • Instruction ID: 6315a40245ea76870e434193a8541a40f7510a96834a84c64ca07ffc225dee7a
    • Opcode Fuzzy Hash: 23f425f8a334c2b16384e28a3fa6a9e2980a0f072a9231f595175fb2069c4236
    • Instruction Fuzzy Hash: 95E0EC40E0920751FB697E629C1617401440F25370E1C1B39E97EC82CFFD1CE5558291
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Yarn$GetcvtGetdateorderGetvalsInfoLocale__crt
    • String ID:
    • API String ID: 228185232-0
    • Opcode ID: 9bd1aeecd99623c410cbf8d4a302e2f0fb334ace1778b8932efd3ba5b1ef268a
    • Instruction ID: 1c5564a348419144ac1c386be68f7b60e3c71b721f4c4771b9d1d21322f7d817
    • Opcode Fuzzy Hash: 9bd1aeecd99623c410cbf8d4a302e2f0fb334ace1778b8932efd3ba5b1ef268a
    • Instruction Fuzzy Hash: 1EE08673915B4286D7189B78A80116972E4E7487747304738DAFC893E9EF38C1638780
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: HandleModule$AddressFreeLibraryProc
    • String ID:
    • API String ID: 3947729631-0
    • Opcode ID: a400e2c35ec8908003dcc9e2bd86db1e572eab0855f1136fcd494bcdbee10d9d
    • Instruction ID: f8a239b2d006ca0573e9d3ff6559e4a7ee4250432a8b638bbd4441eb45ee8fd9
    • Opcode Fuzzy Hash: a400e2c35ec8908003dcc9e2bd86db1e572eab0855f1136fcd494bcdbee10d9d
    • Instruction Fuzzy Hash: 78214C32E14741CAEF159F64C8542EC37A4EB44708F54453AEA2D82BCAEF39D594CBA0
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 3668304517-0
    • Opcode ID: e993fabd9ee2871ea03103400a04aa23078cd60f1600e9e8e69424d7a1892393
    • Instruction ID: 679895317aeda9e713936942c8b71c3e9eca03fd17b3cdd5d09fc20a1644667d
    • Opcode Fuzzy Hash: e993fabd9ee2871ea03103400a04aa23078cd60f1600e9e8e69424d7a1892393
    • Instruction Fuzzy Hash: E0F0C262B0468581EF049F62E8843AD6321EB48FC8F584035DB2D4BB8ADE2CC4D18300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Locimp::_LocinfoLocinfo::_MakelocYarnstd::_std::locale::_
    • String ID:
    • API String ID: 1170983839-0
    • Opcode ID: bc804f9a403f99231c964db1dbc11832e4a21dda8f36c0b1ad1263aac2b511c3
    • Instruction ID: 37449f1bf7c6c79be92d8c8443304991188fb9d1969aa158d07ffae6aa3606bc
    • Opcode Fuzzy Hash: bc804f9a403f99231c964db1dbc11832e4a21dda8f36c0b1ad1263aac2b511c3
    • Instruction Fuzzy Hash: 62D0A92270A30082DA009F3EE980419A315AB82BC8768A030CF1C0379BDD2CD0B18204
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _onexit
    • String ID:
    • API String ID: 572287377-0
    • Opcode ID: f53fe8b83b4cf940d88fb519a97dba29c9c636b0e1b6b6c3e345df8328d18f50
    • Instruction ID: 50635b45e105d947b894d373a8ac8f488ad19fbe2998281efdf0cb8693a89f92
    • Opcode Fuzzy Hash: f53fe8b83b4cf940d88fb519a97dba29c9c636b0e1b6b6c3e345df8328d18f50
    • Instruction Fuzzy Hash: B5C04C51E6940FC5E71C7F75CC8647401505B69704FD1463AC52DC13D5EC4CD1E64641
    APIs
    • HeapAlloc.KERNEL32(?,?,?,00007FF6F90DDAF5,?,?,00000000,00007FF6F90DF6CF,?,?,?,00007FF6F90D4379,?,?,?,00007FF6F90D429D), ref: 00007FF6F90D7742
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AllocHeap
    • String ID:
    • API String ID: 4292702814-0
    • Opcode ID: 96d74318c8102fb9f3c7f8e035594f168e2d973853a897eca0e36dd17639f2e5
    • Instruction ID: 29471d53f9f4f7cc8bdb2f1c25d4f1123a7cbbdb986a878aacc3e2c57b6c604a
    • Opcode Fuzzy Hash: 96d74318c8102fb9f3c7f8e035594f168e2d973853a897eca0e36dd17639f2e5
    • Instruction Fuzzy Hash: 0CF0F895A1D20645FF646FB15D412B522D65F847A0F585A3ADE3EC53CAFE2CE4809120
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AddressConcurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorErrorExceptionHandleLastModuleProcThrow
    • String ID: CreateRemoteThreadEx$CreateUmsCompletionList$CreateUmsThreadContext$DeleteProcThreadAttributeList$DeleteUmsCompletionList$DeleteUmsThreadContext$DequeueUmsCompletionListItems$EnterUmsSchedulingMode$ExecuteUmsThread$GetCurrentUmsThread$GetNextUmsListItem$GetUmsCompletionListEvent$InitializeProcThreadAttributeList$QueryUmsThreadInformation$SetUmsThreadInformation$UmsThreadYield$UpdateProcThreadAttribute$kernel32.dll
    • API String ID: 1942842289-2643937717
    • Opcode ID: a32647a2585ad13fa15972578e42c76dba6805246e239683fc8797d020c1c341
    • Instruction ID: b49a689b4a18d079d137b145d6f29ac8e6cf6e8c3d0dce3df808425b790546b6
    • Opcode Fuzzy Hash: a32647a2585ad13fa15972578e42c76dba6805246e239683fc8797d020c1c341
    • Instruction Fuzzy Hash: 3D020960E09A0395FF19EF61EC592B922A5BF84B54F404439E96EC62EDFE3CE548C344
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AddressProc$EncodeHandleModulePointer
    • String ID: AcquireSRWLockExclusive$CloseThreadpoolTimer$CloseThreadpoolWait$CloseThreadpoolWork$CompareStringEx$CreateEventExW$CreateSemaphoreExW$CreateSemaphoreW$CreateSymbolicLinkW$CreateThreadpoolTimer$CreateThreadpoolWait$CreateThreadpoolWork$FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$FlushProcessWriteBuffers$FreeLibraryWhenCallbackReturns$GetCurrentPackageId$GetCurrentProcessorNumber$GetFileInformationByHandleEx$GetLocaleInfoEx$GetSystemTimePreciseAsFileTime$GetTickCount64$InitOnceExecuteOnce$InitializeConditionVariable$InitializeCriticalSectionEx$InitializeSRWLock$LCMapStringEx$ReleaseSRWLockExclusive$SetFileInformationByHandle$SetThreadpoolTimer$SetThreadpoolWait$SleepConditionVariableCS$SleepConditionVariableSRW$SubmitThreadpoolWork$TryAcquireSRWLockExclusive$WaitForThreadpoolTimerCallbacks$WakeAllConditionVariable$WakeConditionVariable$kernel32.dll
    • API String ID: 73157160-295688737
    • Opcode ID: cae96f76881c60b9b48b9cd7771779038fb8d5d0b045166fafa3d84d0d47c3e7
    • Instruction ID: 515b58c75edd8dcded931f27ea90f7a2a07cae1141669ab0f937676c5a75e9c2
    • Opcode Fuzzy Hash: cae96f76881c60b9b48b9cd7771779038fb8d5d0b045166fafa3d84d0d47c3e7
    • Instruction Fuzzy Hash: A6E15D64E19B47A1EB08EF50FC9816523A9BF5A744B841439C97E863BCFE3CE189C300
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Library$Free$AddressProc_invalid_parameter_noinfo_noreturn$Load
    • String ID: .dll$.dll$GetS$are$avas$avg$bitd$box$cuck$der$efen$el32$gsA$gues$ice$iphl$kern$mInf$malw$papi$qemu$sand$serv$trin$ual$ualb$usEx$vbox$vbox$vbox$virt$virt$vmwa$yste
    • API String ID: 13129336-110364904
    • Opcode ID: 926e3a317a4876145a7f7000ee2f48dbbeeec46091013ed1cb7c4727af655c68
    • Instruction ID: f020b6ea7b04fb1b0336ec930be01b413ae71507fd38145fcf7e5d7ebd17f78b
    • Opcode Fuzzy Hash: 926e3a317a4876145a7f7000ee2f48dbbeeec46091013ed1cb7c4727af655c68
    • Instruction Fuzzy Hash: A0224662A19BC28AEB208F25D8443E93761FB457A8F504239DA7D4BBDCEF78D644C701
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AddressLibraryLoadProc$File$CloseCrackCreateHandleHttpWrite
    • String ID: GET$WinH$WinH$dll$h$onne$pen$spon$ttp.$ttpC$ttpO$winh
    • API String ID: 1374871504-1302821344
    • Opcode ID: 0cef8fc70c4840044f696872ced4eea2a2330069dfb2d0534f483a879132f51a
    • Instruction ID: 128c88a37677b3bb17ebce76db3e5894dd38ffaefc49c7d61e02b24e93208483
    • Opcode Fuzzy Hash: 0cef8fc70c4840044f696872ced4eea2a2330069dfb2d0534f483a879132f51a
    • Instruction Fuzzy Hash: F5C16E72A097828AEB60DF61E8447AD37B0FB48788F844139EA5D47B98EF3CD605C741
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: memcpy_s$_invalid_parameter_noinfo
    • String ID:
    • API String ID: 2880407647-0
    • Opcode ID: 8063efdc9de485ee38816a67eff462435e340b8218a1daf9c0f97be6f423fd99
    • Instruction ID: e8e838cb3260c0ef275f5688d2c79e2471557871e7dc870881bfa95754b2c666
    • Opcode Fuzzy Hash: 8063efdc9de485ee38816a67eff462435e340b8218a1daf9c0f97be6f423fd99
    • Instruction Fuzzy Hash: D003A372A081D28BD7758E25D840BF937A5FB8478CF401139DA1AA7B9DEF38E944CB50
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Lockitstd::_$Lockit::_Lockit::~_
    • String ID: $0123456789-
    • API String ID: 3469846696-700845222
    • Opcode ID: 218e53bb72e9e0f6f2464561835006351a3cffe6a85929c02ad2d2bb034f6a30
    • Instruction ID: c7245b6bd4bcfaa742aed03338062fe6f4a1336517daa92ba178c08d47834f6c
    • Opcode Fuzzy Hash: 218e53bb72e9e0f6f2464561835006351a3cffe6a85929c02ad2d2bb034f6a30
    • Instruction Fuzzy Hash: 7BC2AC62B08A8685FB058F65C8943BD2761BB85B98F54413ADE6E877DDEF3CE845C300
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: CurrentDuplicateExceptionHandleObjectProcessQueryThrow
    • String ID: 3$Failed to hijack object handle$NtQueryInformationProcess$NtQueryObject
    • API String ID: 2506526296-3432217144
    • Opcode ID: bdc0d6f03d999707b1706eac007eb8bcff8f77c28476bb6890dfaee55542d95f
    • Instruction ID: c972eeb3e13b379fdd41ad0cdd5d9c0f7ad900bbcf1c56a29022865ef6d21941
    • Opcode Fuzzy Hash: bdc0d6f03d999707b1706eac007eb8bcff8f77c28476bb6890dfaee55542d95f
    • Instruction Fuzzy Hash: 5FF18572A1878681EB60DF15E8443AE7365FB85BA0F14423ADAAD877D9EF3CD485C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
    • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
    • API String ID: 808467561-2761157908
    • Opcode ID: ebf695d740cf9b684e7ef851c7b95ff5751eb3b0c0db158049e32c2b887eacab
    • Instruction ID: 5f17b1241c333b72eb4a6150067260ea65e2d63e3970d5c2a87e2ad037632928
    • Opcode Fuzzy Hash: ebf695d740cf9b684e7ef851c7b95ff5751eb3b0c0db158049e32c2b887eacab
    • Instruction Fuzzy Hash: 0DB2F872E081928AE7759E699C406FD3B95FB84788F40513DDA2AD7BCCEF39E5408B40
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$PathSearch
    • String ID: VBoxGuest.sys$VBoxMouse.sys$VBoxSF.sys$vm3dmp.sys$vmci.sys$vmhgfs.sys$vmmouse.sys$vmu**mouse.sys$vmx_svga.sys$vmxnet.sys
    • API String ID: 828134698-2441281973
    • Opcode ID: 3473c4336cfb70c788b506f784a42a88fedf4026b6987b3718f2866aafcf0a69
    • Instruction ID: 505642f459a25f93b8f61342745e859c9a7c51c74fd578c5d884db02848e0f03
    • Opcode Fuzzy Hash: 3473c4336cfb70c788b506f784a42a88fedf4026b6987b3718f2866aafcf0a69
    • Instruction Fuzzy Hash: 39919322A18BC289EB10DF38DC417E96760FB95758F405239DAAC97ADDEF6CD644C340
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Lockitstd::_$Lockit::_Lockit::~_
    • String ID: $0123456789-
    • API String ID: 3469846696-700845222
    • Opcode ID: 15ce30c2212c6f06e5edbfa142deb670f3ac7c0d19db035e79cfa460bae040cf
    • Instruction ID: 7938ef340c7ca9c7e037a2a46d915cedf088c0c86fd4036e259b8ef270f56e34
    • Opcode Fuzzy Hash: 15ce30c2212c6f06e5edbfa142deb670f3ac7c0d19db035e79cfa460bae040cf
    • Instruction Fuzzy Hash: A3A29C62B08A8285EB50DF65D8401AD67B1FB85B94F444139EE6E97BEDEF3CE485C300
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$LockitLockit::_std::_
    • String ID: $0123456789-
    • API String ID: 2793160773-700845222
    • Opcode ID: 038d15bf6612fc9aa228cb0d1058634f8596754a6de6c4b57b85ec738651ce16
    • Instruction ID: 3026918eb5db9dfc92015bedafd1564443c0307a166220867923c62298f4e465
    • Opcode Fuzzy Hash: 038d15bf6612fc9aa228cb0d1058634f8596754a6de6c4b57b85ec738651ce16
    • Instruction Fuzzy Hash: D5A2BC22B09A8285EB449F66D8401BD67B1FB85B94F444139EE6E97BDDEF3CE481C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$ErrorExceptionFormatFreeIos_base_dtorLastLocalMessageThrowstd::ios_base::_
    • String ID: failed: $FormatMessageA failed:
    • API String ID: 1499771356-1331817580
    • Opcode ID: e7243b5f99f5f77f2b2ec79b7d6c0f808e915cfb64451c21881e69f4f4339de5
    • Instruction ID: e1692471f51f972e1f75df5f65821bd6b2bb9103cd30f3b3bf9f3e630a9c7848
    • Opcode Fuzzy Hash: e7243b5f99f5f77f2b2ec79b7d6c0f808e915cfb64451c21881e69f4f4339de5
    • Instruction Fuzzy Hash: D2915862B14B8689EB10DF64D8443ED3762FB84BA8F50423ADA6D97ADDEF38D441C341
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Lockitstd::_$Lockit::_Lockit::~_
    • String ID: !%x$%.0Lf$0123456789-
    • API String ID: 3469846696-778084515
    • Opcode ID: 7193d8051715aa0c45b371c397311df4a68ec5840703d6c70ff1fab96844a15f
    • Instruction ID: 98a94df6bcb367488644e67c4a8d5ff3279976ac67de96274d59cc9b32e4b51d
    • Opcode Fuzzy Hash: 7193d8051715aa0c45b371c397311df4a68ec5840703d6c70ff1fab96844a15f
    • Instruction Fuzzy Hash: 8412AD22B08B8599EB10CF65D8403AD6761EB89BA8F04423ADE6D57BDDEF38D145C380
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_
    • String ID:
    • API String ID: 593203224-0
    • Opcode ID: 79b529a21420bb1d95d23f7bfbb35f8bc13078b797c853a695b558ebcb7ed740
    • Instruction ID: cf5d3bdebe7e24472eeba7b7b899ef0faef85687d82fcd0cff0243e47d8412cc
    • Opcode Fuzzy Hash: 79b529a21420bb1d95d23f7bfbb35f8bc13078b797c853a695b558ebcb7ed740
    • Instruction Fuzzy Hash: 2E52AC62B18A9685FB118F6AD8441AD6B71FB59B98F044135DFAD83BDDEF38D881C300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorLastNameTranslatewcschr$CodePageValid
    • String ID:
    • API String ID: 4034593509-0
    • Opcode ID: be655004c0dd4ea7d75b64525a0fb309909eb3b7571d9666ab2fe5d424677240
    • Instruction ID: 9044491755195e1da3a2a8a2d1b8e5ef9c7937a47a75d43786dfebee7fa99452
    • Opcode Fuzzy Hash: be655004c0dd4ea7d75b64525a0fb309909eb3b7571d9666ab2fe5d424677240
    • Instruction Fuzzy Hash: 43817032B0878285EBB4AF21DC512B923A5EB84B84F454139DA6D877C9EF3CE995C740
    APIs
      • Part of subcall function 00007FF6F90D67D4: GetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D67DE
      • Part of subcall function 00007FF6F90D67D4: SetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D6893
    • GetUserDefaultLCID.KERNEL32(?,?,?,00000000), ref: 00007FF6F90E227C
      • Part of subcall function 00007FF6F90D67D4: SetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D687D
    • EnumSystemLocalesW.KERNEL32(?,?,?,00000000,00000001,00000000,?,00007FF6F90D5241), ref: 00007FF6F90E2263
    • ProcessCodePage.LIBCMT ref: 00007FF6F90E22A6
    • IsValidCodePage.KERNEL32 ref: 00007FF6F90E22C7
    • IsValidLocale.KERNEL32 ref: 00007FF6F90E22DD
    • GetLocaleInfoW.KERNEL32 ref: 00007FF6F90E2339
    • GetLocaleInfoW.KERNEL32 ref: 00007FF6F90E2355
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorLastLocale$CodeInfoPageValid$DefaultEnumLocalesProcessSystemUser
    • String ID:
    • API String ID: 2187550130-0
    • Opcode ID: 9789a35afcd32da5a1f841fd6f1c50f3075dbd0776c0b463e5a1a7728d490b4b
    • Instruction ID: 862925f521f02857b77ca17273ec9e9ad0ec683bf8a212783d2b04546ec1e523
    • Opcode Fuzzy Hash: 9789a35afcd32da5a1f841fd6f1c50f3075dbd0776c0b463e5a1a7728d490b4b
    • Instruction Fuzzy Hash: 6A716762F086039AEB55AF68DC506BD33A0AF48748F44453ACA2D936D9FF3CE985C750
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
    • String ID:
    • API String ID: 1239891234-0
    • Opcode ID: d71fd12e5e487183928d2d7f5b32ebd81a83957dfd7d479d62cecfdd9694a98d
    • Instruction ID: e93739efa4f8f197f254d0707839f1fa8f8913faa2dd2cef79129dbe717d5653
    • Opcode Fuzzy Hash: d71fd12e5e487183928d2d7f5b32ebd81a83957dfd7d479d62cecfdd9694a98d
    • Instruction Fuzzy Hash: CA317336608B8185DB64DF65EC402AE73A4FB88758F54013AEAAD83BD9EF3CC555CB00
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Stoulx
    • String ID:
    • API String ID: 4138948651-0
    • Opcode ID: 880db0e2458fae6dd4bf6cf23656f5417a6f540675da826ecc3f7676cd842955
    • Instruction ID: 99fb9a22a8d3d9d9a9b804f5fae1396c6a72173bbf0ada0da282dc59e48f9831
    • Opcode Fuzzy Hash: 880db0e2458fae6dd4bf6cf23656f5417a6f540675da826ecc3f7676cd842955
    • Instruction Fuzzy Hash: B3128062B18B4589EB10CF66D8442AD6361FB49BE4F504235EE6D87BDDEF38E486C700
    APIs
    • _invalid_parameter_noinfo.LIBCMT ref: 00007FF6F90DE0C8
      • Part of subcall function 00007FF6F90C43BC: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF6F90C4369), ref: 00007FF6F90C43C5
      • Part of subcall function 00007FF6F90C43BC: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF6F90C4369), ref: 00007FF6F90C43EA
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: CurrentFeaturePresentProcessProcessor_invalid_parameter_noinfo
    • String ID: *$.$.
    • API String ID: 4036615347-2112782162
    • Opcode ID: a6d757489066476fcc46afb15dd7695ea2c54c907a3e814965bdc3569c4a7e37
    • Instruction ID: 8b8fecc671a47b4392afb219da1352b4a6ac8e991fe42a93204c617d8a56eaae
    • Opcode Fuzzy Hash: a6d757489066476fcc46afb15dd7695ea2c54c907a3e814965bdc3569c4a7e37
    • Instruction Fuzzy Hash: 7B51E072F14A5585FB11DFA69C402BD67A5BB84BC8F14853ADE6D97BC9EE38D0428300
    APIs
      • Part of subcall function 00007FF6F9073150: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9073190
      • Part of subcall function 00007FF6F9073150: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F90731B3
      • Part of subcall function 00007FF6F9073150: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F90731E0
      • Part of subcall function 00007FF6F9073150: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F90732FA
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F908439D
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F90843A3
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~__invalid_parameter_noinfo_noreturn
    • String ID: 0123456789ABCDEFabcdef-+XxPp
    • API String ID: 4156930308-3606100449
    • Opcode ID: 3633239660b73ed081228dc85ef6291688b3ac6d91e8ced24a93fb3393aeaf9d
    • Instruction ID: e1a5098fe77bb535402d097e202d56d148f8c9bb9afff391765079213c546126
    • Opcode Fuzzy Hash: 3633239660b73ed081228dc85ef6291688b3ac6d91e8ced24a93fb3393aeaf9d
    • Instruction Fuzzy Hash: 2692B162B0C68285EB188F25C95027D3BA1BF91B84F588439DEBD877DAEF2DE455C300
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID: 0123456789-+Ee
    • API String ID: 0-1347306980
    • Opcode ID: 9767abdae08f1cb72ae322cb19fbee991ab45f555d6599d034a6d20d9305e107
    • Instruction ID: 58cb1bac2e8e70a5ad005dc9ea9f8d58332eaa65b7824abb4c7adda957e25d07
    • Opcode Fuzzy Hash: 9767abdae08f1cb72ae322cb19fbee991ab45f555d6599d034a6d20d9305e107
    • Instruction Fuzzy Hash: BB92C422B0D68286EB198F29C95027D3BA1BF91B84F588139DE7D877D9EF2DE455C300
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID: 0123456789-+Ee
    • API String ID: 0-1347306980
    • Opcode ID: 1ecac08825bed5d0864dd42242ff2fd273c294098825da341b59f7a68b7ed73e
    • Instruction ID: 8564dfed4b0c05a833533b9c0d7e47e7cf21f48a4ebf812b7251ed33355e51c2
    • Opcode Fuzzy Hash: 1ecac08825bed5d0864dd42242ff2fd273c294098825da341b59f7a68b7ed73e
    • Instruction Fuzzy Hash: 9742B222B0D65295EF599F2599502BD27A1BF51B88F404039DE6E87BDEEF3CE44AC300
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID: 0123456789-+Ee
    • API String ID: 0-1347306980
    • Opcode ID: 1914edf34c204729da52728933ba711342b689c81a02235e78f222bd4673cf17
    • Instruction ID: e89a6dfc6fde6101b86853dd560b234f300c880a609d716ed6e68c126c2217d5
    • Opcode Fuzzy Hash: 1914edf34c204729da52728933ba711342b689c81a02235e78f222bd4673cf17
    • Instruction Fuzzy Hash: 2D42C262B0D64285EB589F2599502BD27A1BB51B88F404139DE6E87BDEFF7CE44EC300
    APIs
      • Part of subcall function 00007FF6F9089AFC: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9089B1C
      • Part of subcall function 00007FF6F9089AFC: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9089B41
      • Part of subcall function 00007FF6F9089AFC: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9089B6B
      • Part of subcall function 00007FF6F9089AFC: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9089BFE
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F908E370
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F908E376
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~__invalid_parameter_noinfo_noreturn
    • String ID: 0123456789ABCDEFabcdef-+XxPp
    • API String ID: 4156930308-3606100449
    • Opcode ID: 607a296d5e7dfd75b5dc0ed7497f3229c8378f6c26fa29b403a558ab07fa1522
    • Instruction ID: 77afab554e716c14b16ee071676da1a564396d89f149f86262418ff23bf407b8
    • Opcode Fuzzy Hash: 607a296d5e7dfd75b5dc0ed7497f3229c8378f6c26fa29b403a558ab07fa1522
    • Instruction Fuzzy Hash: 01329222B0C64285EF59AF2599502BD6761BF95B84F404139DE6E87BDEEF3CE44AC300
    APIs
      • Part of subcall function 00007FF6F9089C30: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9089C50
      • Part of subcall function 00007FF6F9089C30: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9089C75
      • Part of subcall function 00007FF6F9089C30: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9089C9F
      • Part of subcall function 00007FF6F9089C30: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9089D32
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F908EB88
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F908EB8E
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~__invalid_parameter_noinfo_noreturn
    • String ID: 0123456789ABCDEFabcdef-+XxPp
    • API String ID: 4156930308-3606100449
    • Opcode ID: 6108c203123dee2b6d8b0ba2902f8ccf347d79332082c6713db5a326c5305ef1
    • Instruction ID: 13b0df1f9bcc6a5bbd354247bfb79cc0a275a68980e278e82e9dd4bb7533dd08
    • Opcode Fuzzy Hash: 6108c203123dee2b6d8b0ba2902f8ccf347d79332082c6713db5a326c5305ef1
    • Instruction Fuzzy Hash: 94327162B0C65285EF59AF2599502BD2762BF95B84F404439DE6E87BDEEF3CE442C300
    APIs
      • Part of subcall function 00007FF6F9073150: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9073190
      • Part of subcall function 00007FF6F9073150: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F90731B3
      • Part of subcall function 00007FF6F9073150: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F90731E0
      • Part of subcall function 00007FF6F9073150: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F90732FA
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F9084A58
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F9084A5E
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~__invalid_parameter_noinfo_noreturn
    • String ID: 0123456789ABCDEFabcdef-+Xx
    • API String ID: 4156930308-2799312399
    • Opcode ID: 3f51415d3456d7500b8b1a663bf33415d654550858592d87f938501d504091f0
    • Instruction ID: b0be1413ed9a0fdf528120ec1fd1a2a9bc15e24d421c9ea1815f8bead82218ac
    • Opcode Fuzzy Hash: 3f51415d3456d7500b8b1a663bf33415d654550858592d87f938501d504091f0
    • Instruction Fuzzy Hash: BF22B162B0C69285FB19CF65C85027D3BA1AB81B98F545139CE6E9B7DEEF2CD446C300
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::__invalid_parameter_noinfo_noreturnstd::_
    • String ID: %.0Lf$0123456789-
    • API String ID: 3145298356-3094241602
    • Opcode ID: 1e8dfe5823d39aca4df6c52db93dcd819832284230f8f6049cc36ed5c2aa593c
    • Instruction ID: 6dd52fe300923380cb38b917d986e28c3151db42e4fe4a455760dd0ee5f10d13
    • Opcode Fuzzy Hash: 1e8dfe5823d39aca4df6c52db93dcd819832284230f8f6049cc36ed5c2aa593c
    • Instruction Fuzzy Hash: 74E17D22B09B858AEB11CF65D8402AD6371FB94B88F50413ADE6DA7BADEF38D445C340
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::__invalid_parameter_noinfo_noreturnstd::_
    • String ID: %.0Lf$0123456789-
    • API String ID: 3145298356-3094241602
    • Opcode ID: 76a8486d43a9fd38dca75a486efcc2a1624efcc32a55aba72adab17a63d7fc4a
    • Instruction ID: f6f47db5467989fdbe761e0c76c1b07faa90607aceb8fd18e4664097645772f0
    • Opcode Fuzzy Hash: 76a8486d43a9fd38dca75a486efcc2a1624efcc32a55aba72adab17a63d7fc4a
    • Instruction Fuzzy Hash: 67E16D22B08B8595EB11CF65D8502AD7371FB84B98F40413ADE6DA7BADEF38D455C340
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _get_daylight$_invalid_parameter_noinfo
    • String ID:
    • API String ID: 1286766494-0
    • Opcode ID: d21bfbbfdd8519a0b8afb1af7b3b50d6130fb840f8323c99a1e2a18ec3cf5119
    • Instruction ID: d3c5120e62c83811305ace82fec12f77b3bbd98bf8f2e04cf167f91db7c1fad8
    • Opcode Fuzzy Hash: d21bfbbfdd8519a0b8afb1af7b3b50d6130fb840f8323c99a1e2a18ec3cf5119
    • Instruction Fuzzy Hash: 28A25C72A0868286E7B88F28D9501B937A2FF55B88B14413ADB9D87BDDEF3DD5118700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: gfffffff
    • API String ID: 3215553584-1523873471
    • Opcode ID: 55e31a2a53492d449e3f7d6c0a8c789c62ac8188ad68ceeeb8b97270eb7f7bb5
    • Instruction ID: d4f4e88ab9e066466f5fda456a329529ef61a9a5029716056b42d5f8defe06f4
    • Opcode Fuzzy Hash: 55e31a2a53492d449e3f7d6c0a8c789c62ac8188ad68ceeeb8b97270eb7f7bb5
    • Instruction Fuzzy Hash: 61913AA3B097C686EB118F2598003BDB7A6AB55784F05903BCE6D877D9EE3DE506C301
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$ExceptionThrow$CurrentDuplicateErrorHandleObjectProcessQueryStatus
    • String ID: NtQueryObject
    • API String ID: 3024610690-1504830893
    • Opcode ID: 9e4e735f7a1f6e367f68973d3c9e99cef007dba3a5fc152fa8b7dfcfac9b97db
    • Instruction ID: 66c243a159272c775e0d95ed9b5bb781522ab3629c79b9720bbb33c0612cc406
    • Opcode Fuzzy Hash: 9e4e735f7a1f6e367f68973d3c9e99cef007dba3a5fc152fa8b7dfcfac9b97db
    • Instruction Fuzzy Hash: F8514F76608B8186D760DF15E88439EB7A4F789B90F148126DB8DC3799EF3CD485CB41
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: InfoLocaletry_get_function
    • String ID: GetLocaleInfoEx
    • API String ID: 2200034068-2904428671
    • Opcode ID: 5c644f459f267c95513bb6b31a8f7d728b38b0c72f1211787eb50d6fa98e0d31
    • Instruction ID: f862d5e701066f76a4c53c3fcc976f85a9f8517aa9f6675729d0a60641618af6
    • Opcode Fuzzy Hash: 5c644f459f267c95513bb6b31a8f7d728b38b0c72f1211787eb50d6fa98e0d31
    • Instruction Fuzzy Hash: B6016225B0CB4182EB809F56B9404BAA761FF85BC4F58403AEE6C87B9DEE3CD9018744
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: memcpy_s
    • String ID:
    • API String ID: 1502251526-0
    • Opcode ID: f5d40666c0f671f225113b7e5c3b0db6b340d98f509cddb77ea7f59479a0c1cc
    • Instruction ID: 79abff3a5d23a652acdc0f575153318ca2d79f9665fbe39ca3e31bbbeadca5e7
    • Opcode Fuzzy Hash: f5d40666c0f671f225113b7e5c3b0db6b340d98f509cddb77ea7f59479a0c1cc
    • Instruction Fuzzy Hash: F3C10572B1868587D734CF15E44866AB7A1FB94784F148139DB5E93B88EF3CE845CB40
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _get_daylight$_invalid_parameter_noinfo
    • String ID:
    • API String ID: 1286766494-0
    • Opcode ID: 6a917a330a65a9d1bbd685c2f67503f1e4b9e650ec2cf0748861dad91b55190e
    • Instruction ID: b9f893d4043367c2f10334253c90a68d4c4b70156621a61ef45d63c152b96fd1
    • Opcode Fuzzy Hash: 6a917a330a65a9d1bbd685c2f67503f1e4b9e650ec2cf0748861dad91b55190e
    • Instruction Fuzzy Hash: E5A17A66B0961286FF1DCE64D960AB923B0AF54788F00453EDE2EC66D9FF79F5028314
    APIs
      • Part of subcall function 00007FF6F90D67D4: GetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D67DE
      • Part of subcall function 00007FF6F90D67D4: SetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D6893
    • GetLocaleInfoW.KERNEL32 ref: 00007FF6F90E1C11
    • GetLocaleInfoW.KERNEL32 ref: 00007FF6F90E1C63
    • GetLocaleInfoW.KERNEL32 ref: 00007FF6F90E1D22
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: InfoLocale$ErrorLast
    • String ID:
    • API String ID: 661929714-0
    • Opcode ID: a95e9a3af592e11b89632737c661631c55e9aeaedbdcc31dcb240e94767d76cf
    • Instruction ID: 2c716200e4dc835ab71207838d15d66cde0357963e5f2e6b1b51d11988560fef
    • Opcode Fuzzy Hash: a95e9a3af592e11b89632737c661631c55e9aeaedbdcc31dcb240e94767d76cf
    • Instruction Fuzzy Hash: B1614E72A0854286EBB4EF25D9802BD73A6FB94744F008139DB6EC76D9EF3CE5558700
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID: .
    • API String ID: 0-248832578
    • Opcode ID: a6be5fa504fde9f4d0ebe0174f8db6fad87117daa0e9344f4536ee8ed2d017bc
    • Instruction ID: 37d480bac58ecb09fcb829163a621496a085e4d40ba90a7cb7d65a3745d447e4
    • Opcode Fuzzy Hash: a6be5fa504fde9f4d0ebe0174f8db6fad87117daa0e9344f4536ee8ed2d017bc
    • Instruction Fuzzy Hash: 2A310862F1469149E7609F62AC046BA7791FB85BE4F44863AEE7D87BCCEE3CD4018700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 3668304517-0
    • Opcode ID: 38ed7583e5665c8963f21477d1b7db81941ea29b8d3edf18cde8fdf9913d15f5
    • Instruction ID: 7c7768d72f277c0e0ec639b547d27c4b354c92ae9a881a2daa8d1b0168ef9725
    • Opcode Fuzzy Hash: 38ed7583e5665c8963f21477d1b7db81941ea29b8d3edf18cde8fdf9913d15f5
    • Instruction Fuzzy Hash: 41021412F08A8589FB24CF65D8503ED2761AB487A8F044639EE6E97BCDEE3CD445C342
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 3668304517-0
    • Opcode ID: fba4dfd50f8ee03b1c2a605ba8e61a494a64ca1d8c70f50af349776d5520e385
    • Instruction ID: 6abc20aad73a9b30eee00072b46504c3288e0858da93493a8e1a0f960a2d007b
    • Opcode Fuzzy Hash: fba4dfd50f8ee03b1c2a605ba8e61a494a64ca1d8c70f50af349776d5520e385
    • Instruction Fuzzy Hash: AAC1B262B14A848AFB10CFA5E8017AD6361FB49B98F404636EE5D67BDDEF38D446C340
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 3668304517-0
    • Opcode ID: 9c8b913d795b83a487dd84b8f31e81fe796e7b63a77d071d3dc75286b90031ae
    • Instruction ID: 763be0e1a54d1617d0cc5ac849b07682f82842c11aca51ce40343715cf845242
    • Opcode Fuzzy Hash: 9c8b913d795b83a487dd84b8f31e81fe796e7b63a77d071d3dc75286b90031ae
    • Instruction Fuzzy Hash: D1C1D462B18A848AFB10DFA5E8017AD6361EB497A8F404635EE6D67BDCEF38D4458340
    APIs
    • __lc_wcstolc.LIBCMT ref: 00007FF6F90D521C
      • Part of subcall function 00007FF6F90E1720: TranslateName.LIBCMT ref: 00007FF6F90E178A
      • Part of subcall function 00007FF6F90E1720: TranslateName.LIBCMT ref: 00007FF6F90E17C5
      • Part of subcall function 00007FF6F90E1720: GetACP.KERNEL32(?,?,?,?,?,00007FF6F90D5248), ref: 00007FF6F90E1824
      • Part of subcall function 00007FF6F90E1720: IsValidCodePage.KERNEL32(?,?,?,?,?,00007FF6F90D5248), ref: 00007FF6F90E1835
      • Part of subcall function 00007FF6F90DA3FC: try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA41F
      • Part of subcall function 00007FF6F90DA1BC: try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA1F5
    • GetACP.KERNEL32 ref: 00007FF6F90D52DB
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: NameTranslatetry_get_function$CodePageValid__lc_wcstolc
    • String ID:
    • API String ID: 1314065171-0
    • Opcode ID: fd7f6c7a82a4e92604cf90730bfb4a3ef9ffd3fb8a2967312237a13ccd6ea120
    • Instruction ID: b1c872e338ce03dcdd43d1b89d8a8a57ee1aba0da4e2290110c164ed02c2af16
    • Opcode Fuzzy Hash: fd7f6c7a82a4e92604cf90730bfb4a3ef9ffd3fb8a2967312237a13ccd6ea120
    • Instruction Fuzzy Hash: 19B1A426A1878242EB649F669D117BA6292FFD57C8F10403EEE6D87BCDEF3DD5018600
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionRaise_clrfp
    • String ID:
    • API String ID: 15204871-0
    • Opcode ID: b1f77e4dbea57c49a0da3710d827af29517322e94797f121fcdc4ae307bcfe3f
    • Instruction ID: e9730fce620b4ab8e7a24e0c417c8e3f982f3d2f1b287498d8314f187966ff4f
    • Opcode Fuzzy Hash: b1f77e4dbea57c49a0da3710d827af29517322e94797f121fcdc4ae307bcfe3f
    • Instruction Fuzzy Hash: 72B15CB7605B858BEB15CF29C84636C7BA1F784B48F188926DB6D837A8DF39D451C700
    APIs
    • _Wcsftime.LIBCMT ref: 00007FF6F90C93DF
      • Part of subcall function 00007FF6F90D5500: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6F90D552B
      • Part of subcall function 00007FF6F90D7704: HeapAlloc.KERNEL32(?,?,?,00007FF6F90DDAF5,?,?,00000000,00007FF6F90DF6CF,?,?,?,00007FF6F90D4379,?,?,?,00007FF6F90D429D), ref: 00007FF6F90D7742
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AllocHeapWcsftime_invalid_parameter_noinfo
    • String ID:
    • API String ID: 3834302206-0
    • Opcode ID: ab943573138329c4fa326bd78fd5cb6832f1f729ee0c53977e0d8d1ca3eb2000
    • Instruction ID: 8761372169e99bbecdc3a39bfc53865e9d26a86309f3a80681e3658e7bfd54b2
    • Opcode Fuzzy Hash: ab943573138329c4fa326bd78fd5cb6832f1f729ee0c53977e0d8d1ca3eb2000
    • Instruction Fuzzy Hash: FB91A072A04A5186EB608E65D89177D23A1FB84B98F10863AEF7EC77DDEF38D0418310
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID: a/p$am/pm
    • API String ID: 0-3206640213
    • Opcode ID: 5b017f1334bb343455c8fc1f177543630685a7b9a25ac512998af95de81a46d2
    • Instruction ID: 4fb218c3cd9b3285a992235b8688fc697ec02ef04ea7913ed562d8b881b189a3
    • Opcode Fuzzy Hash: 5b017f1334bb343455c8fc1f177543630685a7b9a25ac512998af95de81a46d2
    • Instruction Fuzzy Hash: 1AE1BD22A0864381EB648F2C89546B923A6FF55784F54813BEA6E877DCFF3CE951D300
    APIs
      • Part of subcall function 00007FF6F90893C4: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F90893E4
      • Part of subcall function 00007FF6F90893C4: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9089409
      • Part of subcall function 00007FF6F90893C4: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9089433
      • Part of subcall function 00007FF6F90893C4: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F90894C6
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F9095515
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_$_invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 533778753-0
    • Opcode ID: 0d0f552eed7cb280ce7abd8355b168796df7f44f2c8157a778b7e075f0eba648
    • Instruction ID: 1e500590330293dd4d71ccf4b30bdf698360b3258194cd246a11ed257a666971
    • Opcode Fuzzy Hash: 0d0f552eed7cb280ce7abd8355b168796df7f44f2c8157a778b7e075f0eba648
    • Instruction Fuzzy Hash: 8F327E22F18A9585EB118F6AD8441BD63B0FB99B88F454135EEAD93BDDEF38D581C300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::__invalid_parameter_noinfo_noreturnstd::_
    • String ID:
    • API String ID: 3145298356-0
    • Opcode ID: 7288ccf1f75c163a8ae776ddd85e95c011243fb121527eb75be87c8daad37c91
    • Instruction ID: 86e2b916262fae0d19aa038c2f85a7117f771a2f56063ffdf356b83975d9b1bc
    • Opcode Fuzzy Hash: 7288ccf1f75c163a8ae776ddd85e95c011243fb121527eb75be87c8daad37c91
    • Instruction Fuzzy Hash: B0328C22F08AA585EB118F69D8441BD73B1FB98B88F455135DEAD93BADEF38D581C300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ByteCharInfoMultiWide
    • String ID:
    • API String ID: 2366317374-0
    • Opcode ID: 970bf0923c1d13ea3cbc42fb022d988f21b10d21fc08255e680184457e09c24d
    • Instruction ID: 33a565707c97dc1881293a9a4f31f163542e2afd0325340a972e4e0ce51e641a
    • Opcode Fuzzy Hash: 970bf0923c1d13ea3cbc42fb022d988f21b10d21fc08255e680184457e09c24d
    • Instruction Fuzzy Hash: BD02AD22E08BC186E751CF3898456F973A4FB58748F459239EFAC87696EF78E191C700
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 55c7793efff6e1a7b457cea5cf84b6998e37ec664203431fd890545ffcf507ad
    • Instruction ID: 15af6373e884a5ef71a97d31296819965d4fb01d056e6644a4ffe3692d7b5778
    • Opcode Fuzzy Hash: 55c7793efff6e1a7b457cea5cf84b6998e37ec664203431fd890545ffcf507ad
    • Instruction Fuzzy Hash: 52E17032A08B8185E710DF61E8406FE27A6FB59784F418636DFAD9779AEF38D245C700
    APIs
      • Part of subcall function 00007FF6F90D67D4: GetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D67DE
      • Part of subcall function 00007FF6F90D67D4: SetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D6893
    • GetLocaleInfoW.KERNEL32 ref: 00007FF6F90E1E4D
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorLast$InfoLocale
    • String ID:
    • API String ID: 3736152602-0
    • Opcode ID: e0cf389e8eb778650d8237c4c940b8ea085efe1e87aa576b1d9d210fa1ab4da1
    • Instruction ID: 25d6608d954f11d938df898d047ea40f0a1800a1c31db8ca0f3bed5d910b4911
    • Opcode Fuzzy Hash: e0cf389e8eb778650d8237c4c940b8ea085efe1e87aa576b1d9d210fa1ab4da1
    • Instruction Fuzzy Hash: C7217132A08642C6EB74DF25E8416A972A1FB94780F408139EB6DC37D9EF3CE555C740
    APIs
      • Part of subcall function 00007FF6F90D67D4: GetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D67DE
      • Part of subcall function 00007FF6F90D67D4: SetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D6893
    • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF6F90E220F,?,?,?,00000000,00000001,00000000,?,00007FF6F90D5241), ref: 00007FF6F90E1AD6
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorLast$EnumLocalesSystem
    • String ID:
    • API String ID: 2417226690-0
    • Opcode ID: 06b9d6f5964766a179f0f3cfb44b17b74a26384d3fd05f017e55ff37fbfe4f28
    • Instruction ID: 22972edce414cbf839d2f7d26ca8e3ee12912aa2b63dc20f28fb59574bd7e3d6
    • Opcode Fuzzy Hash: 06b9d6f5964766a179f0f3cfb44b17b74a26384d3fd05f017e55ff37fbfe4f28
    • Instruction Fuzzy Hash: 4411D667E18645CAEB649F15D8806B877A1FB90FA0F488139D63D873C8EE78D5D1C740
    APIs
      • Part of subcall function 00007FF6F90D67D4: GetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D67DE
      • Part of subcall function 00007FF6F90D67D4: SetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D6893
    • GetLocaleInfoW.KERNEL32(?,?,?,00007FF6F90E1D9E), ref: 00007FF6F90E2017
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorLast$InfoLocale
    • String ID:
    • API String ID: 3736152602-0
    • Opcode ID: 738b8bdd37ae94de1e87c2eeacf389ecfd379fc0f8903fdc7b35fff345786fc4
    • Instruction ID: dd7bb2d45ab130ed166348be7c1e1c8a97e620ddb18525f5876c8c11cce1f55a
    • Opcode Fuzzy Hash: 738b8bdd37ae94de1e87c2eeacf389ecfd379fc0f8903fdc7b35fff345786fc4
    • Instruction Fuzzy Hash: 81110A22E1C19782EB64BF16D4446792291EB40764F10553ADB3E876DEEE3DEC81C740
    APIs
      • Part of subcall function 00007FF6F90D67D4: GetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D67DE
      • Part of subcall function 00007FF6F90D67D4: SetLastError.KERNEL32(?,?,?,00007FF6F90DC4DE,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90DC3B9), ref: 00007FF6F90D6893
    • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF6F90E21CB,?,?,?,00000000,00000001,00000000,?,00007FF6F90D5241), ref: 00007FF6F90E1B8A
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorLast$EnumLocalesSystem
    • String ID:
    • API String ID: 2417226690-0
    • Opcode ID: 18e4a387b4a2991d5e80ac9927e0b74267005d752bada3651eb45c3a41e952f7
    • Instruction ID: 3383d47bc2ae2264e1ee0fbbf63cb6ac0becde65308bcab69f317da45dc4c192
    • Opcode Fuzzy Hash: 18e4a387b4a2991d5e80ac9927e0b74267005d752bada3651eb45c3a41e952f7
    • Instruction Fuzzy Hash: 1701D666E082818AE7606F16E8407B976D2EB50764F448336D638876D8FF68D480C700
    APIs
    • EnumSystemLocalesW.KERNEL32(?,?,00000000,00007FF6F90D9FC5,?,?,?,?,?,?,?,?,00000000,00007FF6F90E1000), ref: 00007FF6F90D9BA8
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: EnumLocalesSystem
    • String ID:
    • API String ID: 2099609381-0
    • Opcode ID: 5dbcfa246fc451c4969a4a479fe0dd4d3197f93e36e857ab14c75e33123e5648
    • Instruction ID: ec8ccf62bcde4cd15254f1c7c0f191093e3eb9ce01e227dc52efdd396bd7f679
    • Opcode Fuzzy Hash: 5dbcfa246fc451c4969a4a479fe0dd4d3197f93e36e857ab14c75e33123e5648
    • Instruction Fuzzy Hash: 13018472B14B4183E708DF25EC404A97366E799B80B04C13ADE69977ACEF3CD4958340
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: 0
    • API String ID: 3215553584-4108050209
    • Opcode ID: 6c5f29fb049f8c23788bf49bec50a2971d683713d9a1a86d3abeb24b3c4c7e14
    • Instruction ID: f59da649d1f3a1f02c43402f43585f5b11b6a7a2fe3fe8967582599d16991b55
    • Opcode Fuzzy Hash: 6c5f29fb049f8c23788bf49bec50a2971d683713d9a1a86d3abeb24b3c4c7e14
    • Instruction Fuzzy Hash: 73712629A0C24646EB788E19888037D6B92AF41B44F54053DDD6DCB6DDEF2FE845C721
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: 0
    • API String ID: 3215553584-4108050209
    • Opcode ID: 6254dfefb1850aee79c5b533ea55ea327a7645dd020de98c594c08c9c8e1ed2b
    • Instruction ID: 785ca58a069f1fcc5d2d006179c8760a53b6e2466b10cd18d26553d4187a049f
    • Opcode Fuzzy Hash: 6254dfefb1850aee79c5b533ea55ea327a7645dd020de98c594c08c9c8e1ed2b
    • Instruction Fuzzy Hash: 7A713829A1C34246FB788E1988482BD2390AF41748F58063DDD6DCB7DDEE2FE8469721
    APIs
    • GetLastError.KERNEL32 ref: 00007FF6F90DABE1
      • Part of subcall function 00007FF6F90D6A78: HeapAlloc.KERNEL32(?,?,00000000,00007FF6F90D69B6,?,?,8000000000000000,00007FF6F90C9335,?,?,?,?,00007FF6F90D6B15), ref: 00007FF6F90D6ACD
      • Part of subcall function 00007FF6F90D6AF0: HeapFree.KERNEL32 ref: 00007FF6F90D6B06
      • Part of subcall function 00007FF6F90E3E4C: _invalid_parameter_noinfo.LIBCMT ref: 00007FF6F90E3E77
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Heap$AllocErrorFreeLast_invalid_parameter_noinfo
    • String ID:
    • API String ID: 3361962657-0
    • Opcode ID: 2c31ddf1c833a7717effb875131b6cb155bee2f4f5ed9fb6d94a3e1702af6623
    • Instruction ID: 55467c42ba7122b06a09c480368fbcff2e89bab82e526b932eea471f5b1a1917
    • Opcode Fuzzy Hash: 2c31ddf1c833a7717effb875131b6cb155bee2f4f5ed9fb6d94a3e1702af6623
    • Instruction Fuzzy Hash: 6641C721F0964342FBB05E266C5177AA296AF957E0F44553EEE6DC77C9FE3CE4018600
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: HeapProcess
    • String ID:
    • API String ID: 54951025-0
    • Opcode ID: ac0caae950e66478979915d12c06c86b826de5dfe6479bdecca7230833496965
    • Instruction ID: 63d60665dd4d5b416bc4d630c64fb07c95356a995baf5172f30a6b4333a0b8b8
    • Opcode Fuzzy Hash: ac0caae950e66478979915d12c06c86b826de5dfe6479bdecca7230833496965
    • Instruction Fuzzy Hash: B7B09224E07A06C6EB08BF226C4221422A87F98700F858078C26C81364EF2C25A69B01
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AllocHeap_invalid_parameter_noinfo
    • String ID:
    • API String ID: 2314373116-0
    • Opcode ID: c5199ffe8d08066759e8e2a21b71ae925e4799fcb8dd42fa0fe0f250b762205e
    • Instruction ID: 1d20b29e2b6efb6f88dbbb23f78268b7dd12f317710a2430f12628bd85310e96
    • Opcode Fuzzy Hash: c5199ffe8d08066759e8e2a21b71ae925e4799fcb8dd42fa0fe0f250b762205e
    • Instruction Fuzzy Hash: 69221571F14A9742EB64DE299D142AA6392FB947A8F14523ACF7E877DCEF2DD4018300
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_$Stollx
    • String ID:
    • API String ID: 568052979-0
    • Opcode ID: fb2f00c43c33c9158ea7a8aa29b3d87ac7ca452d07932dd4f240cc50cd01c606
    • Instruction ID: f708eb0c5944ee09050d229128e786d592187817396e35914467c71dc48dcd8f
    • Opcode Fuzzy Hash: fb2f00c43c33c9158ea7a8aa29b3d87ac7ca452d07932dd4f240cc50cd01c606
    • Instruction Fuzzy Hash: EA42CF62A08A8685EB648F26C98027D3771FB85B88F048239DF6D877D9EF3CE455C744
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 1b4645939430158448760eafff18a4533f5fe2984b39d2026c67a5a4cf993723
    • Instruction ID: 42823004401942e1d57af170dbec0c57c27cf084ef174d7c253826857e8a7baa
    • Opcode Fuzzy Hash: 1b4645939430158448760eafff18a4533f5fe2984b39d2026c67a5a4cf993723
    • Instruction Fuzzy Hash: 32424026D29E4685E7538F35AC115752328FF5138CF00973BE82EB66D9FF2CE6468209
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorLast$try_get_function
    • String ID:
    • API String ID: 762735579-0
    • Opcode ID: cd1af57cbec9541ec63f2d745ac25408d7a1eda785b0fcdb2962e55478490840
    • Instruction ID: ae4396fa53f5b2f93f359035271bbb6e3f25de52b590eccdad6863043598e15e
    • Opcode Fuzzy Hash: cd1af57cbec9541ec63f2d745ac25408d7a1eda785b0fcdb2962e55478490840
    • Instruction Fuzzy Hash: 39C1C562A1868682EBB4AF71DC116BA3391FB84B88F444139DE69C3ACDEF3CD555C740
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 8e520398f4660cb9380e41c43c5202e2ae4ff50d1c8c851b26be1c2eb8a750aa
    • Instruction ID: 15c2cae3e55719da4b8fc208e83393e4e1222ffcc0d3c4d1b1de28f42c2c251c
    • Opcode Fuzzy Hash: 8e520398f4660cb9380e41c43c5202e2ae4ff50d1c8c851b26be1c2eb8a750aa
    • Instruction Fuzzy Hash: D7A12623A086624AFB288E2598913B922D0BF50758F14063DDA7EC77DDFE6CE509D720
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: f592e73326d3148f9e44476cd46fc395a78076866fb379bc7f5fd125498cd0bb
    • Instruction ID: af8744726b3fa4f8869d98387bac983aaeb69cd8f1e0cb2498bcf36e962c7feb
    • Opcode Fuzzy Hash: f592e73326d3148f9e44476cd46fc395a78076866fb379bc7f5fd125498cd0bb
    • Instruction Fuzzy Hash: 18518F337155918BE348CF2AC854AAD77A6F7C8750F49C23ADA1983789EF36D905CB40
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: ca5663d3315edfa89b2372b8c74f5c88b694e85a9d54ad7857828c788f29c833
    • Instruction ID: b297cd1b2b988fd923295f67cb9fa75db89ed5717e35ea63467175ea9224e050
    • Opcode Fuzzy Hash: ca5663d3315edfa89b2372b8c74f5c88b694e85a9d54ad7857828c788f29c833
    • Instruction Fuzzy Hash: 0241A562B14B5482EF04CF2AD9241A9B796AB49FD4B499037DE1ED7B9CEE3CD4468300
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 13600dbca5ff03b695715bb408f94d6037378f6f3352864caf0a704fe4c8565b
    • Instruction ID: bf8aca3ee32cd418209dfc97aba5638a4ebb1ca6d5096099946a8a9e47df70ec
    • Opcode Fuzzy Hash: 13600dbca5ff03b695715bb408f94d6037378f6f3352864caf0a704fe4c8565b
    • Instruction Fuzzy Hash: 6E410762B2475A81EF10DF2AD90466963A6FB84FD8F14453ADE6E477E8EE3CD442C300
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: d3ca32a3791865b6b7188888d186ad1617919cebf05d269dfce1ac40cee68598
    • Instruction ID: 9570d71a50b049f415916441cb3702b7e9a41a881ad9eebe54ac2b30725a5ab6
    • Opcode Fuzzy Hash: d3ca32a3791865b6b7188888d186ad1617919cebf05d269dfce1ac40cee68598
    • Instruction Fuzzy Hash: FF410562B2475A81EF109F29D80466D62A6FB84FD8F14453ADE6D477E8EE3CD442C300
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: CurrentFeaturePresentProcessProcessor
    • String ID:
    • API String ID: 1010374628-0
    • Opcode ID: 2a8c941fff02a8b033ff8e71c6bdb45d23515a846cef4ac911cf9aa7ea2450bf
    • Instruction ID: 4bbf5e6dc54b1948db4f9e65316b4d110fbe9a8082413f2a029cbca5aeb992cb
    • Opcode Fuzzy Hash: 2a8c941fff02a8b033ff8e71c6bdb45d23515a846cef4ac911cf9aa7ea2450bf
    • Instruction Fuzzy Hash: 5A412662F1868945FB119F359C087697BA2EB45BE8F44823ADE6E477C9EE3CD402C704
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: CurrentFeaturePresentProcessProcessor
    • String ID:
    • API String ID: 1010374628-0
    • Opcode ID: 1f054c1d9e7c0c7af088510d46025ee51d9a770e6be353259681b1da38aa552a
    • Instruction ID: 411325f7a5a80703a78ebbb2bb7d0046a36f4173908c9ac1dcadd18723335e10
    • Opcode Fuzzy Hash: 1f054c1d9e7c0c7af088510d46025ee51d9a770e6be353259681b1da38aa552a
    • Instruction Fuzzy Hash: 8A412962F1468945FB659F25980836D67A2EB45BD0F08823FDE6E8B7C9EE3CD442C704
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: db000112929a43aa55be0a0b8687f1710b62cb56d2ba30bcdf18646c8374d5fa
    • Instruction ID: 52921299b27027f4f093eaa41c8af7c1559ff4969d6f265fef77b1dc1390fb76
    • Opcode Fuzzy Hash: db000112929a43aa55be0a0b8687f1710b62cb56d2ba30bcdf18646c8374d5fa
    • Instruction Fuzzy Hash: B8F0C271B192958ADBA8CF28A84262977D4F758380F90C07DD69CC3B48EA3C91A09F44
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: fcdf9a7923ffcd36fa13054744af46b831ea375b7f997aaa7f90ff56d6ffd0fd
    • Instruction ID: cf32f3573aea95fe7f5de1f7d8e9b2a9050d5ed478c1d81c579ec2f638328cf1
    • Opcode Fuzzy Hash: fcdf9a7923ffcd36fa13054744af46b831ea375b7f997aaa7f90ff56d6ffd0fd
    • Instruction Fuzzy Hash: 2DA0012590880290EB189F54ED904B03220AB90300B51027AC22E910B8EE3CE540A255
    APIs
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA6FF
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA71E
      • Part of subcall function 00007FF6F90D9BEC: GetProcAddress.KERNEL32(?,?,0000000100000005,00007FF6F90DA0DE,?,?,8000000000000000,00007FF6F90D69A3,?,?,8000000000000000,00007FF6F90C9335), ref: 00007FF6F90D9D44
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA73D
      • Part of subcall function 00007FF6F90D9BEC: LoadLibraryExW.KERNELBASE(?,?,0000000100000005,00007FF6F90DA0DE,?,?,8000000000000000,00007FF6F90D69A3,?,?,8000000000000000,00007FF6F90C9335), ref: 00007FF6F90D9C8F
      • Part of subcall function 00007FF6F90D9BEC: GetLastError.KERNEL32(?,?,0000000100000005,00007FF6F90DA0DE,?,?,8000000000000000,00007FF6F90D69A3,?,?,8000000000000000,00007FF6F90C9335), ref: 00007FF6F90D9C9D
      • Part of subcall function 00007FF6F90D9BEC: LoadLibraryExW.KERNEL32(?,?,0000000100000005,00007FF6F90DA0DE,?,?,8000000000000000,00007FF6F90D69A3,?,?,8000000000000000,00007FF6F90C9335), ref: 00007FF6F90D9CDF
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA75C
      • Part of subcall function 00007FF6F90D9BEC: FreeLibrary.KERNEL32(?,?,0000000100000005,00007FF6F90DA0DE,?,?,8000000000000000,00007FF6F90D69A3,?,?,8000000000000000,00007FF6F90C9335), ref: 00007FF6F90D9D18
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA77B
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA79A
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA7B9
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA7D8
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA7F7
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA816
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: try_get_function$Library$Load$AddressErrorFreeLastProc
    • String ID: AreFileApisANSI$CompareStringEx$EnumSystemLocalesEx$GetDateFormatEx$GetLocaleInfoEx$GetTimeFormatEx$GetUserDefaultLocaleName$IsValidLocaleName$LCIDToLocaleName$LCMapStringEx$LocaleNameToLCID
    • API String ID: 3255926029-3252031757
    • Opcode ID: d9a017a2f42a4a8a0d4d7784366a78a826f99904011b822b84b5e2bbea456847
    • Instruction ID: f687496baca3f933c6ac9dd90a3030b6f3e186926b13f9230e27dd016b9fd22d
    • Opcode Fuzzy Hash: d9a017a2f42a4a8a0d4d7784366a78a826f99904011b822b84b5e2bbea456847
    • Instruction Fuzzy Hash: C8314260A0DA47A1EB84DF54ED516F0232AEB4435CF81403BE52D822E9FE7DE749D348
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrow
    • String ID: 158$7YsC$7YsC$Failed to find shellcode resource$Failed to get RtlAdjustPrivilege address$Failed to load shellcode resource$Failed to lock shellcode resource$Shellcode resource size is 0$dll$gerP$gj==$gj==$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set$l.dl$l32.$p$rese$runa$shel$wp9=
    • API String ID: 432778473-29599500
    • Opcode ID: 1467987442ddf86f021a06e3839a386a85251c636058390d01c8d2cfda5f13a7
    • Instruction ID: 8f2fe83ac8a471915a0e80f3ae515ceaf5aa7fd7d505f764bef6b0eaabbcfc8e
    • Opcode Fuzzy Hash: 1467987442ddf86f021a06e3839a386a85251c636058390d01c8d2cfda5f13a7
    • Instruction Fuzzy Hash: 38516D72609A4192EF148F19D89037967A0FB84FA4F54813ADA6EC37E8EF3DD885C341
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Library$Free$_invalid_parameter_noinfo_noreturn$AddressProc$Load
    • String ID: .dll$C:\$VM$VMwa$Virt$el32$kern$tion$ual
    • API String ID: 1437614955-3798700775
    • Opcode ID: 54476f12b3d7411ff82bd32d19affdec9b623e19e5a37a04263ca3be26910e3a
    • Instruction ID: 75b00cca890eecbb41a5abcd6b2c561eab0d636ced7ae4d8437ba41064a6648d
    • Opcode Fuzzy Hash: 54476f12b3d7411ff82bd32d19affdec9b623e19e5a37a04263ca3be26910e3a
    • Instruction Fuzzy Hash: 36A18C62A18A8189FB40CF68D8403AD6BA0FB857B4F501239DABD46BEDEF3CD545C701
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AddressProc$HandleModule
    • String ID: .dll$File$GetP$Libr$Load$Move$aryA$ddre$el32$kern$rocA
    • API String ID: 667068680-126220184
    • Opcode ID: 4454fb24077ff5455a89e90f9902d5b7fe5697f4b894a93879f4a8ce81e0cae1
    • Instruction ID: 7a4a36b5ec166965d31b8233fc66902e8832c5204939c17279dee20c4cf0d9df
    • Opcode Fuzzy Hash: 4454fb24077ff5455a89e90f9902d5b7fe5697f4b894a93879f4a8ce81e0cae1
    • Instruction Fuzzy Hash: A7515461E19A0299FB04EF68EC943A837B1AF44788F444039DE2D8A6EDFE7DE544C341
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowcodecvtstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3742870595-0
    • Opcode ID: df2e4a7e4f07289f7e4a08e44b43e456a4844c0e1e2ce282e63d166bc0f429f4
    • Instruction ID: 51e38c541672d2556664e3f5ea2efe086d2c9684fcaeaed8ab7820a557734cc7
    • Opcode Fuzzy Hash: df2e4a7e4f07289f7e4a08e44b43e456a4844c0e1e2ce282e63d166bc0f429f4
    • Instruction Fuzzy Hash: B7513D22F0DA4291EB19DF15EC404B96764FB94BA4F184239EA7D876EDEF2CE481C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: -$0$0$0
    • API String ID: 3215553584-3524293751
    • Opcode ID: ccb662a9822b5dcfd1cdd1cf4ac0bd3c5a7645ba60182f379fe4881fa860732a
    • Instruction ID: 60488f0062cd4c285ab104ccb92b8f67b4cd7db2e90dbefeba61fef660cc0a2e
    • Opcode Fuzzy Hash: ccb662a9822b5dcfd1cdd1cf4ac0bd3c5a7645ba60182f379fe4881fa860732a
    • Instruction Fuzzy Hash: 97F1F732A0D6A685E7608F2598502BC3795EB51B84F94803ACB7DC77DAEF3DE415D320
    APIs
    • GetLogicalProcessorInformation.KERNEL32(?,?,?,?,?,?,00000000,00007FF6F90A95CB,?,?,?,?,00007FF6F90A9D0E), ref: 00007FF6F90A64A2
    • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FF6F90A95CB,?,?,?,?,00007FF6F90A9D0E), ref: 00007FF6F90A64A8
    • GetLogicalProcessorInformation.KERNEL32(?,?,?,?,?,?,00000000,00007FF6F90A95CB,?,?,?,?,00007FF6F90A9D0E), ref: 00007FF6F90A64C8
    • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FF6F90A95CB,?,?,?,?,00007FF6F90A9D0E), ref: 00007FF6F90A64E0
    • Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error.LIBCONCRT ref: 00007FF6F90A64F9
    • _CxxThrowException.LIBVCRUNTIME ref: 00007FF6F90A650A
    • std::bad_alloc::bad_alloc.LIBCMT ref: 00007FF6F90A6515
    • _CxxThrowException.LIBVCRUNTIME ref: 00007FF6F90A6526
    • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FF6F90A95CB,?,?,?,?,00007FF6F90A9D0E), ref: 00007FF6F90A652C
    • Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error.LIBCONCRT ref: 00007FF6F90A6545
    • _CxxThrowException.LIBVCRUNTIME ref: 00007FF6F90A6556
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorExceptionLastThrow$Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorInformationLogicalProcessor$std::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 503786641-0
    • Opcode ID: 788b10bfa82d8fc6f87998b6076669e9f4836150f6e12274fd37ebb58a4c5beb
    • Instruction ID: a0dc032f75d9433522a3b76e6e0fb1d33f6e1d5b804550c462542ec5e6df21e5
    • Opcode Fuzzy Hash: 788b10bfa82d8fc6f87998b6076669e9f4836150f6e12274fd37ebb58a4c5beb
    • Instruction Fuzzy Hash: DA114261E0864792FF25EF21EC551BA62B1BF84B84F404439E66DC65EDFE2DD904C740
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Library$Free$AddressLoadProc_invalid_parameter_noinfo_noreturn
    • String ID: .dll$eA$el32$kern
    • API String ID: 519604945-407738492
    • Opcode ID: 76036b64e29c11404c7f97a55c5f22fbb22b18237d3b65f8baa8a4ee13aca0da
    • Instruction ID: 07d16de1bf8cb5cec56ee18d8dff2c5e89ef90fa1a82e7bdd5862a598502c9e2
    • Opcode Fuzzy Hash: 76036b64e29c11404c7f97a55c5f22fbb22b18237d3b65f8baa8a4ee13aca0da
    • Instruction Fuzzy Hash: 3F416632718B8186EB149F25E8447A96760FB89BA4F441239DABD47BCDEF7CD544C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: INF$NAN$NAN(IND)$NAN(SNAN)$inf$nan$nan(ind)$nan(snan)
    • API String ID: 3215553584-2617248754
    • Opcode ID: 5e02269aa9dbdbd6a54443a9696c2d26be7ea865e5a5fc89706890d50da2ae7f
    • Instruction ID: f47d5160fefeead4bf97ff0c8cf2923ab16a9de2bd7f3e1b9dff1cce15bf9f98
    • Opcode Fuzzy Hash: 5e02269aa9dbdbd6a54443a9696c2d26be7ea865e5a5fc89706890d50da2ae7f
    • Instruction Fuzzy Hash: 78415A32A09B4189E714CF65E8507AD33A5FB54398F40413AEE6C87B9DEE3CE525C344
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: b0946c3906f0796d99b4d5727145a69f8d3ffbcea19c82acd1799f6f778c7601
    • Instruction ID: 7f65f78a179600de392c9512cda5c3fc47f6bb2af2deccfa80c7576d1e79d719
    • Opcode Fuzzy Hash: b0946c3906f0796d99b4d5727145a69f8d3ffbcea19c82acd1799f6f778c7601
    • Instruction Fuzzy Hash: C841C162A09A0296EB14AF21DC413AD2360FB82794F504238DB7C87BDAFF3DE565C740
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrowstd::invalid_argument::invalid_argument$AffinitizeConcurrency::details::FreeObjectProcessorRoot::SignalVirtualWait
    • String ID: pContext$switchState
    • API String ID: 2956575298-2660820399
    • Opcode ID: f744664efa757ad388f7271cce7dd11baf795997056589853306e0b810f0b018
    • Instruction ID: ab4ac6466360781ac5beeee68184ebe47abd00ccf2e5dc223ccb7d8d32cca8e6
    • Opcode Fuzzy Hash: f744664efa757ad388f7271cce7dd11baf795997056589853306e0b810f0b018
    • Instruction Fuzzy Hash: 23319D73E08A0685EB22DF06DC401696371FF94B88F54413AEA6DC77E8EE3CE5458380
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AcquireConcurrency::details::_CriticalLock::_ReentrantValue
    • String ID: proc
    • API String ID: 2079939915-735085620
    • Opcode ID: ac0a681821c8f0057a54e597328bf8f6a09aa78352c52e4ff03553feb9cf0bea
    • Instruction ID: 6a1b8eee1207cf2b4b6671ceda9965582d866ff7a65a26e58bd81268a73c7fec
    • Opcode Fuzzy Hash: ac0a681821c8f0057a54e597328bf8f6a09aa78352c52e4ff03553feb9cf0bea
    • Instruction Fuzzy Hash: A2616972A08B4696EB249F1AD8402A977B0FB88F94F144139DB6D877E9EF38E451C740
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Concurrency::cancel_current_task$Getcvt$ExceptionThrowstd::bad_alloc::bad_alloc
    • String ID: false$true
    • API String ID: 846290698-2658103896
    • Opcode ID: d10fad1a80be36852cb8ce69145a44fc32a021828c63bf4e50dcd109f12b1c21
    • Instruction ID: 13801bd2024870e9dc0b880880aad01c3d3a5abf4f39c83e0c9176d28c65889b
    • Opcode Fuzzy Hash: d10fad1a80be36852cb8ce69145a44fc32a021828c63bf4e50dcd109f12b1c21
    • Instruction Fuzzy Hash: C641B022709B8681DB25DF25A8502BD77A2AB85BB0F584239DA7D473D9EF3CE511C301
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: CurrentThread$Xtime_diff_to_millis2xtime_get
    • String ID:
    • API String ID: 3218647749-0
    • Opcode ID: e64e5a5447870c834285efcfb5828636cb2d9b04f6c682d295efe35556a715bc
    • Instruction ID: 726a33426511fe7f84c2d4777aeec2b80e5245b6b5327be29ee5dda2e54c3dbf
    • Opcode Fuzzy Hash: e64e5a5447870c834285efcfb5828636cb2d9b04f6c682d295efe35556a715bc
    • Instruction Fuzzy Hash: BB41DB32E0D646C6EB649F15D8442AA7370EB44B44F504039DBAE826E8EF3DE8C6CB44
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmoneypunctstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 1374409470-0
    • Opcode ID: 3b7485f7c00ff1d19314a4d5ecedfc3cba27b288fb54ced7f76bf4c99f727a4d
    • Instruction ID: 5358e8a3a5e8d55082145d98e422ede9845f95515e683d2b1baf6e80a3db6c2a
    • Opcode Fuzzy Hash: 3b7485f7c00ff1d19314a4d5ecedfc3cba27b288fb54ced7f76bf4c99f727a4d
    • Instruction Fuzzy Hash: F0314D21E48B42A5EB15DF15EC400B97365EB94BA4F184239EA7E877EDEF2CE485C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrownumpunctstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3444589844-0
    • Opcode ID: 10688b1269fd84e81cccb73df0bb7d4e167434d17e8e98487df4bbe4a2e07745
    • Instruction ID: db86bd1fe2dd68e58a8b5d2e00b640bd27dbb6a1008bda762ecfdcccf93dd27c
    • Opcode Fuzzy Hash: 10688b1269fd84e81cccb73df0bb7d4e167434d17e8e98487df4bbe4a2e07745
    • Instruction Fuzzy Hash: E4312121B0DA4291EB15DF15ED400796365EB947A4F18423AEB7D877EDEF2CE485C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmessagesstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3381189198-0
    • Opcode ID: 8564da937ee4bb52c3f21f8f14370469168e64e98a0d0afab44b17aa5a83a80b
    • Instruction ID: d39edcfead9608fe9cb063694a637f53ea805d9830316c1b553bec957ec57752
    • Opcode Fuzzy Hash: 8564da937ee4bb52c3f21f8f14370469168e64e98a0d0afab44b17aa5a83a80b
    • Instruction Fuzzy Hash: 49315D22E48B4291EB11DF19EC400B96764EB95BA4F184239EA7D877EDFF2CE585C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmessagesstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3381189198-0
    • Opcode ID: d102ee66f869b1f4d530f8e8e65fec3da162bfb0f6312889922cb4a8ea9a7b80
    • Instruction ID: 3a4535ff434d4165f2f54696f6f1cc6b1e8c95ba41bcba754d678b95ac6e7c5c
    • Opcode Fuzzy Hash: d102ee66f869b1f4d530f8e8e65fec3da162bfb0f6312889922cb4a8ea9a7b80
    • Instruction Fuzzy Hash: 38317B25B0DA02A1EB15EF65EC400B96360FB947A4F080639EB7D877EDEF2CE4468740
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmoneypunctstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 1374409470-0
    • Opcode ID: 3cb086bca6b3932f25bd418e78416ea28e76308afd68103b3908442e50c2bea3
    • Instruction ID: 3b965c1c688bc1e24a3e3ec860f16f066081022ef5804b7c2233241395a014bd
    • Opcode Fuzzy Hash: 3cb086bca6b3932f25bd418e78416ea28e76308afd68103b3908442e50c2bea3
    • Instruction Fuzzy Hash: 13317B62E08A4295EB15DF25EC400B96760FB95BA0F080239EA7D837EDFF2CE445C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrownumpunctstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3444589844-0
    • Opcode ID: 9a14a6e17cdb2768e5a339c65fab37816b8eeff472eb2a6330f2d5078aa8c804
    • Instruction ID: 06560c1b6e3fcb65c9a43c348b0fe40dc49a3caa9d05163a4ba00ba7e0617306
    • Opcode Fuzzy Hash: 9a14a6e17cdb2768e5a339c65fab37816b8eeff472eb2a6330f2d5078aa8c804
    • Instruction Fuzzy Hash: 64312C21A4DA4291EB15EF15EC400B967A4FB947A4F184239EB7D877EDEE2CE486C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmessagesstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3381189198-0
    • Opcode ID: 96cc5ed84c0ad44b3912cf8a647946ed8e13329890bd03cab1b3d0fd541989ec
    • Instruction ID: e927012cf802df5b76f5ffca49e42e7876984bfd0b61aae1754c6377b9940edf
    • Opcode Fuzzy Hash: 96cc5ed84c0ad44b3912cf8a647946ed8e13329890bd03cab1b3d0fd541989ec
    • Instruction Fuzzy Hash: D0313A22E0DA4291EB65DF15EC400B96368AF95BA4F184239DA7D876EDEE2CE485C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmoneypunctstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 1374409470-0
    • Opcode ID: 459d7b77116365acc94093b7e405309e730f83908df264e21d4b44966fa83f43
    • Instruction ID: 13e58b4fbf049d6e94343a879dbd218b75136528c7201a7aefb0f968c980145c
    • Opcode Fuzzy Hash: 459d7b77116365acc94093b7e405309e730f83908df264e21d4b44966fa83f43
    • Instruction Fuzzy Hash: 97310E21B0DA4291EB15EF55EC400B96365EB94BA4F184239EB7D876EDFF2CE445C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmoneypunctstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 1374409470-0
    • Opcode ID: 2f632cc1c20a26362cdab046b27027203a2c4e262fdf1182743a93095fba4e61
    • Instruction ID: a93f0c0a911f9bc303a4d4336a7be7b6e56351ac7307e4304620e6c5a955e4c4
    • Opcode Fuzzy Hash: 2f632cc1c20a26362cdab046b27027203a2c4e262fdf1182743a93095fba4e61
    • Instruction Fuzzy Hash: 75310E21A0DA4291EB15EF15EC400B96365EB95BA4F184235EB7DC77EDEF2CE4868700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmoneypunctstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 1374409470-0
    • Opcode ID: 4d85737bd72922c63ffee81f12e5edae82289409f64832017a782d7f22625acf
    • Instruction ID: 645d640520f8b5ce096ea3e4e7b856b780883199fd072a0d136a7c155e7e31cc
    • Opcode Fuzzy Hash: 4d85737bd72922c63ffee81f12e5edae82289409f64832017a782d7f22625acf
    • Instruction Fuzzy Hash: B5315C21A0DA0291EB15EF15EC404B96364EF947A4F181235EB7E837EDEF2CE486C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmessagesstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3381189198-0
    • Opcode ID: cc986269916903b1f4ca633500454660843ea81379766bb38ac0f126560e9fd9
    • Instruction ID: c45f2d2eacc09095935ddff8efb9ff7a8a1714711a5ea68b0cddf2934157513b
    • Opcode Fuzzy Hash: cc986269916903b1f4ca633500454660843ea81379766bb38ac0f126560e9fd9
    • Instruction Fuzzy Hash: 2D314C25B0CB4291EB15DF1AEC400B96364EB95BE4F180639DA7D876EDEF2CE496C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmessagesstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3381189198-0
    • Opcode ID: 9a012c7a3332397a21073f42406b88680b884ee24ab4b75df02fa1f39f591b39
    • Instruction ID: 06173d1205ddcda05021844de1ac559b509fcc431838a630afff7e4973ea2571
    • Opcode Fuzzy Hash: 9a012c7a3332397a21073f42406b88680b884ee24ab4b75df02fa1f39f591b39
    • Instruction Fuzzy Hash: E3313E21E58B42A1EB15DF25EC400B96364EB94BA4F18423ADA7D877EDFF2CE585C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmessagesstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3381189198-0
    • Opcode ID: 787ef293c19ed1666d925d887057f502cfe4918e344ca5f519e98c96513b0932
    • Instruction ID: a21eb2adab37833f148ec3c02f39b5edd20b3b3f92069a997754ea6b7108e8bb
    • Opcode Fuzzy Hash: 787ef293c19ed1666d925d887057f502cfe4918e344ca5f519e98c96513b0932
    • Instruction Fuzzy Hash: D6313D61B0DA4291EB15EF15EC400B96364AB94BA4F180235EB7E877EDEE2CE496C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmessagesstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3381189198-0
    • Opcode ID: 4cfd44ccc9993a6baebe831ef451af701858d4ebc743b38aab345ce5a672cfe3
    • Instruction ID: c87863432791dcc24d21b4ac09c5d772c058e576139da440b4da069474cf0c6d
    • Opcode Fuzzy Hash: 4cfd44ccc9993a6baebe831ef451af701858d4ebc743b38aab345ce5a672cfe3
    • Instruction Fuzzy Hash: E8312122B0DA4291EB15DF19EC4007967A4EB957A4F180635EBBD877EDEF2CE446C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmessagesstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3381189198-0
    • Opcode ID: bd6c7f70aa7a086b9df065dfff25bfaef2899a811436cf7bad175b024ae4f0d7
    • Instruction ID: 1e711a043400892ed98ee506137bf561f38c019f19aaac0d3f72b73f21799a25
    • Opcode Fuzzy Hash: bd6c7f70aa7a086b9df065dfff25bfaef2899a811436cf7bad175b024ae4f0d7
    • Instruction Fuzzy Hash: FE314F22A0DA4291EB15EF15EC400796365EB95BA4F184239EB7D877EDEF2CE486C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowmessagesstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 3381189198-0
    • Opcode ID: 1e557ae58a6be1c1c89c2f8c13843b85a31bedc3d0174689acf4afa9ce3eb672
    • Instruction ID: 27348a2a49c98c079c3904fb3a272e8c6183629389d2eea36fd06d72c7fe5aa3
    • Opcode Fuzzy Hash: 1e557ae58a6be1c1c89c2f8c13843b85a31bedc3d0174689acf4afa9ce3eb672
    • Instruction Fuzzy Hash: 90313D22E08A42A1EB15DF19EC400B96364FB95BA4F184239EA7D877EDFF2CE445C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 388f10cd296e545faa9b3c947cf95eb3c133e808b1fc39d2b8799aa3514dc878
    • Instruction ID: 6bbb392df6c737f7cbf20602e660030c9051254d0b1af8d5d0fddc352d2597aa
    • Opcode Fuzzy Hash: 388f10cd296e545faa9b3c947cf95eb3c133e808b1fc39d2b8799aa3514dc878
    • Instruction Fuzzy Hash: 9CC1D862A0878245E7659F259C002BD2B92BF80B80F45513EEA6E87BDDFF3CE549C711
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: .exe$0123$4567$89$WXYZ
    • API String ID: 3668304517-3065352625
    • Opcode ID: 090fc058a325bb5840cfb1d1aeee143479e0404b3b7d232949cd0abe2971d524
    • Instruction ID: 70e8a39db8e512f6720b97736f7f963e77e6c65ea3f31e76b1f47752d6eb49b1
    • Opcode Fuzzy Hash: 090fc058a325bb5840cfb1d1aeee143479e0404b3b7d232949cd0abe2971d524
    • Instruction Fuzzy Hash: E281B032B18B8189EB20CF65E8443AD67A1FB457A4F540239EA6D87FD9EF38D181C701
    APIs
    • _invalid_parameter_noinfo.LIBCMT ref: 00007FF6F90D0CE8
    • MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF6F90D0C79), ref: 00007FF6F90D0D06
    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF6F90D0C79), ref: 00007FF6F90D0D13
    • MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF6F90D0C79), ref: 00007FF6F90D0D4E
    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF6F90D0C79), ref: 00007FF6F90D0D58
    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90D0C79), ref: 00007FF6F90D0DFC
    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF6F90D0C79), ref: 00007FF6F90D0E06
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ByteCharErrorLastMultiWide$_invalid_parameter_noinfo
    • String ID:
    • API String ID: 351348912-0
    • Opcode ID: 5867f64a99bd49bd0d8054cd6f6ffac70b4abd963a733690479a945ad6c9b596
    • Instruction ID: e2198019e18a90dbc63f02c818f549cb47768a46fac47f64fdf03608a53467db
    • Opcode Fuzzy Hash: 5867f64a99bd49bd0d8054cd6f6ffac70b4abd963a733690479a945ad6c9b596
    • Instruction Fuzzy Hash: 4C418162B08B4681EB659F26AC04379A6A5BF84B94F04413EEE6D837D9FF3CE401C704
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::locale::_$Lockitstd::_$AddstdExceptionInitLocimpLocimp::_Lockit::_Lockit::~_New_SetgloballocaleThrowYarnstd::ios_base::_
    • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
    • API String ID: 2033144875-1866435925
    • Opcode ID: 83824d63f6dd518ec7a716ce279713dc2d1319dcb7a74af62807e9dfe8645359
    • Instruction ID: 87a5ffed36ab7de1d05dee94768e17391d6cba970acf0e4557dbbaf910e189a7
    • Opcode Fuzzy Hash: 83824d63f6dd518ec7a716ce279713dc2d1319dcb7a74af62807e9dfe8645359
    • Instruction Fuzzy Hash: 6E41C632A04B4186EB14DF15E8802AD37A4FB44FA4F544139EB6E977E9EF39E452C341
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_GetctypeLocinfoLocinfo::_Register
    • String ID:
    • API String ID: 1048444095-0
    • Opcode ID: 1117332309c7cbc8d21ddff4dd82d100fbe68fa51b7b9168f0fddeace453fcd6
    • Instruction ID: dee9daadff9a03c3a63ec9e38355925f0bdb30ccb6f6ed1319c33f4b5d5e0f83
    • Opcode Fuzzy Hash: 1117332309c7cbc8d21ddff4dd82d100fbe68fa51b7b9168f0fddeace453fcd6
    • Instruction Fuzzy Hash: 9C516B21A09B4281EB21DF19EC403B973A4FB94BA4F058139DA6D833E9EF3CE485C301
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: FindInstanceTargetType$FileHeader
    • String ID: Bad dynamic_cast!
    • API String ID: 1429038817-2956939130
    • Opcode ID: d4fad69649a260f20efbd95d980eae0fe95562dbdae86f46c21a25584120a0be
    • Instruction ID: 8100206c461abc828d22c18d1872c80d34b76033f07ce695e09e71635ebef57b
    • Opcode Fuzzy Hash: d4fad69649a260f20efbd95d980eae0fe95562dbdae86f46c21a25584120a0be
    • Instruction Fuzzy Hash: BE41B222B19A8793EB64CF65DC806796390BF44B94F004539DE6D83B88EF3CE045C710
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 4235596951-0
    • Opcode ID: cce80c1528d2971b2fc71faaa615b8cd69dc9224225962b24e8b0fd87f9db37b
    • Instruction ID: 7a08a2045342f0e9dc283a822a981662e4bc2274a6c116b9260071947a5631a5
    • Opcode Fuzzy Hash: cce80c1528d2971b2fc71faaa615b8cd69dc9224225962b24e8b0fd87f9db37b
    • Instruction Fuzzy Hash: 01314D21A0DA4291EB19EF25EC400B96365FB957A4F084235EB7D877EEEF2CE445C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 4235596951-0
    • Opcode ID: f67a88f065306ac4569016a9ccd68073b067aeabf4232f1473efa7adb572a843
    • Instruction ID: dfff6e52e10f3aedef8584aac22289d8badc85cc9d0eaf942d0520389565c7a6
    • Opcode Fuzzy Hash: f67a88f065306ac4569016a9ccd68073b067aeabf4232f1473efa7adb572a843
    • Instruction Fuzzy Hash: 3C317321E0DB4291EB15DF15EC400B96364EB95BA4F180235EA7E837EDEF2CE485C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 4235596951-0
    • Opcode ID: ad43b0b21893440a6b5cfa61db75e69c0fd79c7b1a4809ae3aa0d9c3a333083a
    • Instruction ID: 3f7090bbf8755222fbb0f30ef28f5dc3327c595080e657eeb0c2ef2865747208
    • Opcode Fuzzy Hash: ad43b0b21893440a6b5cfa61db75e69c0fd79c7b1a4809ae3aa0d9c3a333083a
    • Instruction Fuzzy Hash: 44313021B0DA4291EB56DF15EC400B96365EB94BA4F184235EA7D87BEDEF2CE486C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$ExceptionFacet_RegisterThrowstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 4235596951-0
    • Opcode ID: 7d968b1df914a71798d3e0a9f5744b92dbdcf9654c340ff1752623abb446fda4
    • Instruction ID: 5f60bb60212854d507e1a549a83d0d4c27d4bfec0b1acdbaab5e3ef1f00ca061
    • Opcode Fuzzy Hash: 7d968b1df914a71798d3e0a9f5744b92dbdcf9654c340ff1752623abb446fda4
    • Instruction Fuzzy Hash: F7314121A1EA4291EB55DF15EC400796364EB947A4F184235EA7D87BEDFF2CE446C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_
    • String ID:
    • API String ID: 593203224-0
    • Opcode ID: f30e898e6549f00571e8546b7cce91e437940e85354038f9996e2233ca21565c
    • Instruction ID: dd6667ea90125610782648cb5b1c34805eccca916122d12deee629398e06b093
    • Opcode Fuzzy Hash: f30e898e6549f00571e8546b7cce91e437940e85354038f9996e2233ca21565c
    • Instruction Fuzzy Hash: 95310B22A0DA4291EB15EF15EC400B96764EB95BA4F184235EB7D87BEDEF2CE445C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_
    • String ID:
    • API String ID: 593203224-0
    • Opcode ID: 0ab486d89b916da3138881fe39bba0c11599e7c2e34847b66f0bc9008059230e
    • Instruction ID: 9a7eb49405a0a75dd06087ef5d1312eaf5bb1da6e799e5c81ae51fcf197ab324
    • Opcode Fuzzy Hash: 0ab486d89b916da3138881fe39bba0c11599e7c2e34847b66f0bc9008059230e
    • Instruction Fuzzy Hash: C9316022E09A4295EB11DF15EC400B96764FB94BA4F08423AEA7E877EDEF2CE445C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AllocErrorExceptionLastThrowVirtual
    • String ID: Virt$lloc$ualA
    • API String ID: 907125667-1619206022
    • Opcode ID: 0096d44dffaf4607507c0c90516fdef95b6fb7c5494e70a4045b5ae478b51b74
    • Instruction ID: 6ed1e5ab97975d3f2ffedc0008e2619121c573227e0e9c4dc6daf915cf670a7c
    • Opcode Fuzzy Hash: 0096d44dffaf4607507c0c90516fdef95b6fb7c5494e70a4045b5ae478b51b74
    • Instruction Fuzzy Hash: BA11C1A1B1868191EB20DF25E8453AA7760AB867A0F044139DABC8B7EDFF3DD5458B00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
    • String ID: CONOUT$
    • API String ID: 3230265001-3130406586
    • Opcode ID: e08065fa919532bd172bc3d0274e671b7715f678acaef7576f04e0797315584c
    • Instruction ID: 095da8d0eef68b091e9d21efd068a2e50d63bf580b11fbc982c94a0a63b21968
    • Opcode Fuzzy Hash: e08065fa919532bd172bc3d0274e671b7715f678acaef7576f04e0797315584c
    • Instruction Fuzzy Hash: AF118162B18A4186E750AF46EC5432976B4FB98BE4F440238EA7DC77E8EF3CD9548740
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrowstd::invalid_argument::invalid_argument
    • String ID: pScheduler$version
    • API String ID: 1079095653-3154422776
    • Opcode ID: 72ef138237fec66464d4bb8e9962ed5c05b4bf87a9061cac3b4de145a4568324
    • Instruction ID: 89a224c54492f6891aa4be55ab03eab9a4cc14c280eb6268b37160bd3edc739e
    • Opcode Fuzzy Hash: 72ef138237fec66464d4bb8e9962ed5c05b4bf87a9061cac3b4de145a4568324
    • Instruction Fuzzy Hash: 77F067A2E1850BA4EF25DF00EC400A46362FB60388FA0043AE17D868EDFF2CE249C705
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_LocinfoLocinfo::_Register
    • String ID:
    • API String ID: 1750885376-0
    • Opcode ID: 42cb51d2101887a47301346b431fa299c0f77afd89874528af20c3fe4dd02fa1
    • Instruction ID: 965a697104de2ca594f18c374950370e3ab185dd6c9436d03c5a74dfa954e716
    • Opcode Fuzzy Hash: 42cb51d2101887a47301346b431fa299c0f77afd89874528af20c3fe4dd02fa1
    • Instruction Fuzzy Hash: DF514A32A09B4284EB65DF25E8403A973A4FB59BA4F544139DA6D833D9EF3CE446C341
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$Lockit$Lockit::_Lockit::~_$Facet_LocinfoLocinfo::_Register
    • String ID:
    • API String ID: 1750885376-0
    • Opcode ID: e13b4916b3d0b7b1f29c18ef919b3000c1c4477abb046fe9e9ce4f3ea682de5f
    • Instruction ID: 21a15c5ff143e1953cf3de82307867c9884ae9ebee7c6235c95894735df589db
    • Opcode Fuzzy Hash: e13b4916b3d0b7b1f29c18ef919b3000c1c4477abb046fe9e9ce4f3ea682de5f
    • Instruction Fuzzy Hash: 88416861A09B4290FB25DF15EC503B963A4EB55BA0F09413ACA6D833DDEF3DE885C342
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: dc51cb4e30d41db8caa03f08c5183aca40d5ea447b0cedc8d4ebb7de1ab473f0
    • Instruction ID: 92b0d37cfedc0ef53c8d87412c0b45984dcadc025e87ceb6588be7a349577624
    • Opcode Fuzzy Hash: dc51cb4e30d41db8caa03f08c5183aca40d5ea447b0cedc8d4ebb7de1ab473f0
    • Instruction Fuzzy Hash: BB21A422E08B4291EB15DF29EC000796364EB94BA4F181235EBBD877EDEF2CE446C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: GetcvtGetvals
    • String ID: ,$false$true
    • API String ID: 1915861045-760133229
    • Opcode ID: 5a6db18cb9aaf7a7c40cd0816283021d5bfb6c8945b8ccbb6c2466d079df25f8
    • Instruction ID: 45e6cfe97b3c6f1f635e91450fe805beba8a40766d101987280584405212f3f0
    • Opcode Fuzzy Hash: 5a6db18cb9aaf7a7c40cd0816283021d5bfb6c8945b8ccbb6c2466d079df25f8
    • Instruction Fuzzy Hash: BE41512661CAC182E761CF24E4401EAB7A0FB853A4F445226EB9E4369DEF3CD185CB00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
    • API String ID: 3668304517-1866435925
    • Opcode ID: ce5efb31be3d80cf0ce667bb522ec130d027e30b745915f044dcf0a40c8a15f9
    • Instruction ID: a95a79cc7295686db55d56f21d6f96425ccda0e6ba60b7046e9bd517d44535e9
    • Opcode Fuzzy Hash: ce5efb31be3d80cf0ce667bb522ec130d027e30b745915f044dcf0a40c8a15f9
    • Instruction Fuzzy Hash: C7318562A18B8651FB109F68E8053AAA311FB957B4F405335E6BD827DDFF6CD180C741
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _ctrlfp_set_errno_from_matherr
    • String ID: exp
    • API String ID: 4230380726-113136155
    • Opcode ID: 4a0b32c48e246b9a52872eedfe415e23741a1b697d816cba6a4ef9322b349a1b
    • Instruction ID: 2ecda8f18cf7e974b4119b25ec31168f2e08d3c5b54e992db81cd29525c6f018
    • Opcode Fuzzy Hash: 4a0b32c48e246b9a52872eedfe415e23741a1b697d816cba6a4ef9322b349a1b
    • Instruction Fuzzy Hash: 9E211076A186858BD760CF28E84016E76A1FF88740F50513AFAADC2B9DEF3CD5049F00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrow$Valuestd::invalid_argument::invalid_argument
    • String ID: pScheduler
    • API String ID: 1003427811-923244539
    • Opcode ID: 23c3d0de890831ee0a9add91377922055746caf07640ccc199c89593e127323f
    • Instruction ID: 494c45827073b167bee82e709768ff7b7b9f494bb6c6e5c065c1c9fb76d6f7e4
    • Opcode Fuzzy Hash: 23c3d0de890831ee0a9add91377922055746caf07640ccc199c89593e127323f
    • Instruction Fuzzy Hash: FC014FA2A1894652EF25EF05D8500B96371FF94788FA04035E6ADC69FEFE2CE549C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrow$std::invalid_argument::invalid_argument
    • String ID: pContext
    • API String ID: 3084224051-2046700901
    • Opcode ID: c13d226b9dfa8510147f47651518070281f47e175b8fb78a2b9b51c3fc1173e0
    • Instruction ID: 176a9ae259875553757d5b1574a5fea27a48801cd6b7af5368f34cf368b73fbc
    • Opcode Fuzzy Hash: c13d226b9dfa8510147f47651518070281f47e175b8fb78a2b9b51c3fc1173e0
    • Instruction Fuzzy Hash: 56115A62A1894A91EF15EF15DC500B96361FF90B88F905035EA7EC66F9FE2CE549C300
    APIs
    Strings
    • :Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December, xrefs: 00007FF6F908749B
    • :AM:am:PM:pm, xrefs: 00007FF6F90874BA
    • :Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday, xrefs: 00007FF6F908745B
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Yarn
    • String ID: :AM:am:PM:pm$:Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December$:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday
    • API String ID: 1767336200-35662545
    • Opcode ID: 79e69241a29a73c47b507ba0a4561c25bb9ca2756b70f31496cc51e7068838eb
    • Instruction ID: f9d9203bf0fa0e987d9fafbe702354d8c388bb48c91cc10c18354f58d150e304
    • Opcode Fuzzy Hash: 79e69241a29a73c47b507ba0a4561c25bb9ca2756b70f31496cc51e7068838eb
    • Instruction Fuzzy Hash: D7013C26A08B8281EB04EF22D8553B923A1EF88BD8F444139DA1C877CEEF3CD545C390
    APIs
    • Concurrency::details::VirtualProcessorRoot::ResetSubscriptionLevel.LIBCONCRT ref: 00007FF6F90BE00C
      • Part of subcall function 00007FF6F90BE064: Concurrency::details::SchedulerProxy::DecrementCoreSubscription.LIBCONCRT ref: 00007FF6F90BE07D
    • std::invalid_argument::invalid_argument.LIBCONCRT ref: 00007FF6F90BE02E
    • _CxxThrowException.LIBVCRUNTIME ref: 00007FF6F90BE03F
    • _CxxThrowException.LIBVCRUNTIME ref: 00007FF6F90BE05B
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Concurrency::details::ExceptionSubscriptionThrow$CoreDecrementLevelProcessorProxy::ResetRoot::SchedulerVirtualstd::invalid_argument::invalid_argument
    • String ID: pScheduler
    • API String ID: 3788913018-923244539
    • Opcode ID: b1dafd2b5d159991c940216b2016126b22ffd41fa414ac92279b832134687d83
    • Instruction ID: 1d3e5876de3227fedb2f60ca523b09e959b5930142bf5612203a2a80b40ebedd
    • Opcode Fuzzy Hash: b1dafd2b5d159991c940216b2016126b22ffd41fa414ac92279b832134687d83
    • Instruction Fuzzy Hash: 34F08CA2A2894B91EF25EF04D8500B85371FF50788F905435DA7DCAAEDFE2CE649C701
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AddressFreeHandleLibraryModuleProc
    • String ID: CorExitProcess$mscoree.dll
    • API String ID: 4061214504-1276376045
    • Opcode ID: 0f34e98f4a7d712abe554ed76f4c7fc3e1878c79dc3be099c6deeab263af7b68
    • Instruction ID: c7173b16f438b89afc354c612887c1ba36dd77ecc89f548940e902e40888613f
    • Opcode Fuzzy Hash: 0f34e98f4a7d712abe554ed76f4c7fc3e1878c79dc3be099c6deeab263af7b68
    • Instruction Fuzzy Hash: 6DF05EA1B1964282EF485F60EC843752365EF88744F44103DDA3FC66E8EE2CD588C310
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: a52775d09e562e435926eb87e210c581af98815a0a3b8116f756561f35ed8cbe
    • Instruction ID: 31c58f06c0ef98a2b9ffa5c8107832fbf07e0a25b339bb6e3d3b9d2297fa3326
    • Opcode Fuzzy Hash: a52775d09e562e435926eb87e210c581af98815a0a3b8116f756561f35ed8cbe
    • Instruction Fuzzy Hash: 08A1C462B0978246FF616F1189603BA66D2AF40BA4F584A39DA7D977CDFF3DE4448300
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 2e2aae7eef73db643bb20f643d42d83acb24b7cea38b6c5a1ff1f306df41f32c
    • Instruction ID: b7db02cd82d9489b6ba59305e05086396f29976c7b435881b2c4c9b2431e2390
    • Opcode Fuzzy Hash: 2e2aae7eef73db643bb20f643d42d83acb24b7cea38b6c5a1ff1f306df41f32c
    • Instruction Fuzzy Hash: 8D91B022E18A22A5EB559F659C406BD2762BF54B84F00513ADE2E977DDEF38E442C310
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 71d07e8bc5b4c40419a36865c1dc6e598739140e3669d3ce770438e2d6ad1965
    • Instruction ID: 63522b335d16a904e919c94d0a7fb776b1c66c290d8f64e0e0967b8f57c8af67
    • Opcode Fuzzy Hash: 71d07e8bc5b4c40419a36865c1dc6e598739140e3669d3ce770438e2d6ad1965
    • Instruction Fuzzy Hash: 2191A522A0964286EB618F119C806BD66A5BF44BA4F544639EE7D877DDFF3CD842C320
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _set_statfp
    • String ID:
    • API String ID: 1156100317-0
    • Opcode ID: 5b39ec1b62ef9cb3d82bf92e2da72284b7f70405199098550c91011f644fc3f4
    • Instruction ID: b4e6b3dea8d0d9eabfa5926f80a68b04a1b342965f73c70c8132a79b5183598b
    • Opcode Fuzzy Hash: 5b39ec1b62ef9cb3d82bf92e2da72284b7f70405199098550c91011f644fc3f4
    • Instruction Fuzzy Hash: E851A512E18E4A85E7229F28DC5037AA352BF45754F40863EFA7D967D8FF3CE4818600
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: FileWrite$ByteCharConsoleErrorLastMultiWide
    • String ID:
    • API String ID: 3659116390-0
    • Opcode ID: 02fd73176117bd439747371dae0259dd7f702533b3b1dd400b979c524323b8e3
    • Instruction ID: 1892625a267cb9fb2d6d515a1fd832f80a123c8a888936382022c3cd430640e0
    • Opcode Fuzzy Hash: 02fd73176117bd439747371dae0259dd7f702533b3b1dd400b979c524323b8e3
    • Instruction Fuzzy Hash: 51517E72F14A5289E710CF65E8402AD3BB1FB08798F44853ADE6E877D8EE38D545C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 95add7e9165ed8ea0344261a7692415332c02a2bd4c4ab729b10abc044ca4d0f
    • Instruction ID: 290ee7b7af3694f03db09cd6819ebe9fb2b006d7734b4d61573df83540f5d38c
    • Opcode Fuzzy Hash: 95add7e9165ed8ea0344261a7692415332c02a2bd4c4ab729b10abc044ca4d0f
    • Instruction Fuzzy Hash: A251956290D69685EB518F24D8503BC3BA1AB85F44F588079D7ACC73CEEF2DE416C722
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrow
    • String ID: $ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
    • API String ID: 432778473-3951162480
    • Opcode ID: 72ea5f8c44b095c2b341faa189da0af77ec9eaa9c2887ec51d0280da01b0b587
    • Instruction ID: d3012a76bdcc38ece8018156b4f365b23cc6481e8933ea91f144b361725be0d5
    • Opcode Fuzzy Hash: 72ea5f8c44b095c2b341faa189da0af77ec9eaa9c2887ec51d0280da01b0b587
    • Instruction Fuzzy Hash: 01316D72604A0581EF14DF19C89027967A0EF40FA5F548639DA3E873E8EF2DD846C342
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ThrowVirtual$Event$Concurrency::details::ExceptionProcessorProcessor::
    • String ID:
    • API String ID: 2357715348-0
    • Opcode ID: c3ee152ca42d32e24890e8de32dc4a01bdf930be7a2fdba1709aaad9126b0b61
    • Instruction ID: be7d31cb12ff96daf29cc7d442d10b2ac1ac08823434d7c542f9d63edb76b2e2
    • Opcode Fuzzy Hash: c3ee152ca42d32e24890e8de32dc4a01bdf930be7a2fdba1709aaad9126b0b61
    • Instruction Fuzzy Hash: 6731AFA1E1894692EB24DF25EC501B963B5EF94B48F141039DA7EC73E9FE2DE488C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Xtime_diff_to_millis2xtime_get$Mtx_reset_owner
    • String ID:
    • API String ID: 638720424-0
    • Opcode ID: 44aa5243e6c6a4e6666a266b2b6eac0e1bc7a671ce2fcd92bd286f589ebaefcc
    • Instruction ID: ac16d39b31b68758299dd511a2955530ea6623c1427310d4aa2332205ff690ce
    • Opcode Fuzzy Hash: 44aa5243e6c6a4e6666a266b2b6eac0e1bc7a671ce2fcd92bd286f589ebaefcc
    • Instruction Fuzzy Hash: 5F212F52B0C54286EB18EF16EC511BA63A1BF88FC4F454035ED5D877DAEE3CD5468B08
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _set_statfp
    • String ID:
    • API String ID: 1156100317-0
    • Opcode ID: e85e589465e8c342b262a1cd7525f310e6f4d00c3f542fea3a454d13f6af990b
    • Instruction ID: 0ec741aa7fc214a4654e2b082e7769c4807876b68c733f1297d5b6719e05ae08
    • Opcode Fuzzy Hash: e85e589465e8c342b262a1cd7525f310e6f4d00c3f542fea3a454d13f6af990b
    • Instruction Fuzzy Hash: B3118C63E18A0346F7683D2CEE6637910526F58370F494A3DE97EC66EEFE2CE8414200
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: a65d5929713a9101d83c6602be6fa7d320eb173ec439c386c1f6c77a5349f831
    • Instruction ID: b94fcf3e6a2414e60724fbec55e0e682073582def7d0cc5856ee3d43cf96b7ab
    • Opcode Fuzzy Hash: a65d5929713a9101d83c6602be6fa7d320eb173ec439c386c1f6c77a5349f831
    • Instruction Fuzzy Hash: 0B119322B0DA0251FF299F25DC404756755AB907B4F180335EA7D866EDFF2CE886C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: 4546943baa67c76c94b2eb76d64478b3f0c4262e27f41adb309958f97f0364ef
    • Instruction ID: cddc8a48034c974b6f04ff314ed65a8cad51945cfa75be35df67b415a4ffc55e
    • Opcode Fuzzy Hash: 4546943baa67c76c94b2eb76d64478b3f0c4262e27f41adb309958f97f0364ef
    • Instruction Fuzzy Hash: 02116622B0DB4251EB299F25DC004B56755ABA07B4F184735EA7D876EDFE2CE886C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: eb127ad6b9ab837b3096df53b011fb5a61d8475777e4108075ed068c02301838
    • Instruction ID: 1960b47d1ef043568a8dbd400d704f960fed7646f26084d259ded7c15afeee86
    • Opcode Fuzzy Hash: eb127ad6b9ab837b3096df53b011fb5a61d8475777e4108075ed068c02301838
    • Instruction Fuzzy Hash: F4119622B0DA0251FB29DF15DC404796664AB947F4F580335EA7D866EDFF2CE486C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: b0e83be9bf6aaba18d94be4d62a9e6211a41dc93530d30c93cfd5e869af1e46a
    • Instruction ID: 7944d78abb8270473bf2d19250f8a4e54d01bb5b9c7270c6fcbda92dd5897850
    • Opcode Fuzzy Hash: b0e83be9bf6aaba18d94be4d62a9e6211a41dc93530d30c93cfd5e869af1e46a
    • Instruction Fuzzy Hash: E0115122B0DA0251EB299F25DC404796755AB947B4F580335FB7D866EEFE2CE4868700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: 30dfa2ff92dbeee43e214081317e0c56dbbc9cb540c905661b8ecafb66fddc8d
    • Instruction ID: 54c92e78e751eca7ae3cdaf6ae528c97e38965238ef2a9d9e3caabd08dc9a6bb
    • Opcode Fuzzy Hash: 30dfa2ff92dbeee43e214081317e0c56dbbc9cb540c905661b8ecafb66fddc8d
    • Instruction Fuzzy Hash: 42119322B0DA0191EB29DF24DC400796650AB907B4F580335EA7D87AEDFF2CE8868700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: a322557ed60a39c747e9ebdbe2a12675070c8fbcc01f407c5ac2aaeae2414e80
    • Instruction ID: d0f433f44d444694d27c152c5fa77485a03cfba5c91feec28dc3a773f882af04
    • Opcode Fuzzy Hash: a322557ed60a39c747e9ebdbe2a12675070c8fbcc01f407c5ac2aaeae2414e80
    • Instruction Fuzzy Hash: 93115122B0DA4255FB25EF65EC400B96664AB907B4F584335EB7C866EDFE2CE486C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: f489f292a9c3c9113bbd77258b93de16be446b0022f2ecf1b8e72f75ee2b235f
    • Instruction ID: b8b4eca188aa9b8c7db3966d4dc3640cf5574d839af0a4a1eccfe6595aeb574e
    • Opcode Fuzzy Hash: f489f292a9c3c9113bbd77258b93de16be446b0022f2ecf1b8e72f75ee2b235f
    • Instruction Fuzzy Hash: 69116622B0DA4251FB29DF65EC004756664AB907F4F584335EA7C876EDFF2CE8868704
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: 1d1f7928f3e674a7a175fd1c19f71502ba8d9de63a0b3a9e2c17927bfa910516
    • Instruction ID: de9607c5a40aafe0d1e7cf927a91cbe9de6a2bfd2ddfddced55d3d79f4ca811c
    • Opcode Fuzzy Hash: 1d1f7928f3e674a7a175fd1c19f71502ba8d9de63a0b3a9e2c17927bfa910516
    • Instruction Fuzzy Hash: FA119362B0DA0251EB29DF24DC004B56660AB907B4F180339EA7C876EDFF2CE496C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: 3f9aad18514c2f48e749fa0293bed2deb02b0ab3f5a1de1b3968120941640670
    • Instruction ID: 63222e13b864ca98a0497fe87f4c052031f0479fcded4adc6faaa29d6b860e1b
    • Opcode Fuzzy Hash: 3f9aad18514c2f48e749fa0293bed2deb02b0ab3f5a1de1b3968120941640670
    • Instruction Fuzzy Hash: B911B422B0DA0151EB29DF15DC000756654AB907B4F084635EBBD876EDFE2CE446C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: LockitLockit::_std::_
    • String ID:
    • API String ID: 3382485803-0
    • Opcode ID: 3714b395d732a18ebcfbeeec4bad1795663fdbde3c5f02f36dd8f0aaab1c9233
    • Instruction ID: baa07f3e4231b3eb9c7d6c8747740abd238af605b81ebdc9e556444137503938
    • Opcode Fuzzy Hash: 3714b395d732a18ebcfbeeec4bad1795663fdbde3c5f02f36dd8f0aaab1c9233
    • Instruction Fuzzy Hash: 16118422B0CA0291FB299F15DC004B56660AB907B4F180335EA7C866EDFE2CE882C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorErrorExceptionLastObjectRegisterSingleThrowWait
    • String ID:
    • API String ID: 733098319-0
    • Opcode ID: b578473ef8cb21ad8029f682bcf977bd624714aab27c3c4b37ac5aa09f5a84c4
    • Instruction ID: e7b7988b7f1d62f29b5f4b06964f43991b85dc4fd6695f9a0e05bf8bbbbd59f5
    • Opcode Fuzzy Hash: b578473ef8cb21ad8029f682bcf977bd624714aab27c3c4b37ac5aa09f5a84c4
    • Instruction Fuzzy Hash: 9511C161E18A4282FB15AF22EC441BA6361FF85FC4F504135EA6DC3AEDEE2CD1458B00
    APIs
    • Concurrency::details::_CriticalNonReentrantLock::_Acquire.LIBCMT ref: 00007FF6F90ACEA8
      • Part of subcall function 00007FF6F90A6C94: _SpinWait.LIBCONCRT ref: 00007FF6F90A6CC3
    • Concurrency::details::SchedulerBase::UpdatePendingVersion.LIBCMT ref: 00007FF6F90ACEB0
      • Part of subcall function 00007FF6F90B060C: Concurrency::details::SchedulerBase::ComputeSafePointCommitVersion.LIBCONCRT ref: 00007FF6F90B0615
    • Concurrency::details::SchedulerBase::CommitToVersion.LIBCONCRT ref: 00007FF6F90ACEBC
    • Concurrency::details::_CriticalNonReentrantLock::_Acquire.LIBCMT ref: 00007FF6F90ACEC4
    • Concurrency::details::SchedulerBase::UpdateCommitVersion.LIBCMT ref: 00007FF6F90ACECE
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Base::Concurrency::details::SchedulerVersion$Commit$AcquireConcurrency::details::_CriticalLock::_ReentrantUpdate$ComputePendingPointSafeSpinWait
    • String ID:
    • API String ID: 4127798528-0
    • Opcode ID: 0c175fac23acd3e12448dc2c9f29d3f88a8089771e904cc33543f5b42713ed3c
    • Instruction ID: ce06491b72f54568f9bbbde1e7d5facb8a88413aee915a50aaf0bff423fe8763
    • Opcode Fuzzy Hash: 0c175fac23acd3e12448dc2c9f29d3f88a8089771e904cc33543f5b42713ed3c
    • Instruction Fuzzy Hash: CFF05411F5C29281EB14EF16A94107952649F84FC0F159435FD6A97BCEEE2CE44187C0
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID: -$e+000$gfff
    • API String ID: 3215553584-2620144452
    • Opcode ID: a3901d1a71b9ef73cf6801bac217ad80bc7d722183ce59e9fbcbd7962e656b91
    • Instruction ID: 809f57627eb3b6411c24c2f62289a5a85a608abd7970aea41c15369a3650bfa3
    • Opcode Fuzzy Hash: a3901d1a71b9ef73cf6801bac217ad80bc7d722183ce59e9fbcbd7962e656b91
    • Instruction Fuzzy Hash: 49511A62B187C546E7658F359C417697B92E780B90F08923ADBBC87BDAEE2DD444C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ByteCharErrorFileLastMultiWideWrite
    • String ID: U
    • API String ID: 2456169464-4171548499
    • Opcode ID: 5c2f8853b9d007c8ba63f8057913248889664fd97ede8168115dee2e5209a9ec
    • Instruction ID: c45d44931cc3921bbb0518afe7c024a14c1e13ca67a1ebbc9f8365c3eeac2ded
    • Opcode Fuzzy Hash: 5c2f8853b9d007c8ba63f8057913248889664fd97ede8168115dee2e5209a9ec
    • Instruction Fuzzy Hash: 3F41B432B1869192E720CF65E8443B96761FB99B94F844035EE5EC7798EF3CD442CB40
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Getvals
    • String ID: $+xv$$+xv$+v$x+v$xv$+xv+$xv$+x+$vx+$vx$v+x+$vx$+vx+v $+v $v $+v +$v $++$ v+$ v$ v++$ v$+ v+xv$+ v$v$ +v+ $v$ ++x$v+ $v$v ++ $v$ +v
    • API String ID: 1336808981-3573081731
    • Opcode ID: 3a9987d22390b8fa3125d11084598a66408c4ac617ee6a49d9ec7c966cc0c5ab
    • Instruction ID: a5f9b5aa2453d7ab70c3eb9648a5182be330c52ced0361ee375ad2e4c7467307
    • Opcode Fuzzy Hash: 3a9987d22390b8fa3125d11084598a66408c4ac617ee6a49d9ec7c966cc0c5ab
    • Instruction Fuzzy Hash: 4531E676B086954AEBBACF2098D057D7BA1EF01B81748013ACA6EC378DEE7DE505C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Getvals
    • String ID: $+xv$$+xv$+v$x+v$xv$+xv+$xv$+x+$vx+$vx$v+x+$vx$+vx+v $+v $v $+v +$v $++$ v+$ v$ v++$ v$+ v+xv$+ v$v$ +v+ $v$ ++x$v+ $v$v ++ $v$ +v
    • API String ID: 1336808981-3573081731
    • Opcode ID: df15b07e090aeb4a7218bf1cd50486f1aff17c383b34efdae4bc86ca9a501db9
    • Instruction ID: af73f0475e297f2d683f1c5c6ea52fb1947e97bd04433c47dc3a3ae6fd5af634
    • Opcode Fuzzy Hash: df15b07e090aeb4a7218bf1cd50486f1aff17c383b34efdae4bc86ca9a501db9
    • Instruction Fuzzy Hash: EE31A836B086968AE7B5CF20989057D7BA5EB45B81B44013ACA6EC37CCEF7DE546C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Getcvt
    • String ID: ,$false$true
    • API String ID: 1921796781-760133229
    • Opcode ID: acce9e0a9a7ec6fa05143ac08c4826acdc95091abb3cc2d945c59aeb4dda9af2
    • Instruction ID: 85355fc4d6e74940c6541d98d0e139dfa07c4041a2083f77fe0130d6a41ba8d2
    • Opcode Fuzzy Hash: acce9e0a9a7ec6fa05143ac08c4826acdc95091abb3cc2d945c59aeb4dda9af2
    • Instruction Fuzzy Hash: 03314D26618BC181DB61DF25F8402AEB3A4FB84794F44112AEBAE477A9EF3CD145C740
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: OpenProcess
    • String ID: Open$Proc$ess
    • API String ID: 3743895883-633399097
    • Opcode ID: fc99a96c7583fcbc373fda103b06ff0073ab04cf23c5f454a5b4ddd3765f98fe
    • Instruction ID: c2fcfd75ca54742066ff8f192e55c116ad9977617048a0eb3aefc8d2c1f4855b
    • Opcode Fuzzy Hash: fc99a96c7583fcbc373fda103b06ff0073ab04cf23c5f454a5b4ddd3765f98fe
    • Instruction Fuzzy Hash: D411C362A0968045EB109F55FC4136ABBA0EB897F4F544238EAAD477E9EF3CD445CB40
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 3668304517-0
    • Opcode ID: 3d14564acb495c5a417a5bbc5b66ff28801d34afeed0559c2efc26276102e641
    • Instruction ID: a4213d1f2025e0b339eef95c5cfd5b740245a4229c96df38aec4ebabe19f84d3
    • Opcode Fuzzy Hash: 3d14564acb495c5a417a5bbc5b66ff28801d34afeed0559c2efc26276102e641
    • Instruction Fuzzy Hash: 10E1C262708A4691EF189F16E9045AAB366FB48FD4F544136DE6C8BBDDEE7CE081C304
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 1b9790ddae54c4fae710acab6649481434d4fd9c84749f52d8544fd790fc6e8d
    • Instruction ID: 864d46da73216c02d4d1c4b3d430ac8233799ecc90a54c805ca4e476672c9376
    • Opcode Fuzzy Hash: 1b9790ddae54c4fae710acab6649481434d4fd9c84749f52d8544fd790fc6e8d
    • Instruction Fuzzy Hash: 17B1F462708A4191EB08DF26E9441A9B356FB44FC4F48453ADF6D87B9DEE7CE091C304
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$_invalid_parameter_noinfo_noreturn$Lockit::_Lockit::~_$Stollx
    • String ID:
    • API String ID: 2178053848-0
    • Opcode ID: 0bf66218f0c70f9e50c2a319838f8f9f4a2a75dc4ce4537f8c6bb8daffc975e3
    • Instruction ID: c65757fa8205427da46e1b8f9e7de441f0d2d399599e7a725e11bf713265f472
    • Opcode Fuzzy Hash: 0bf66218f0c70f9e50c2a319838f8f9f4a2a75dc4ce4537f8c6bb8daffc975e3
    • Instruction Fuzzy Hash: E1A1AD62B18B468AFB04CFA5D8441AD2771FB85B98B41413ADE2D97BEDEF38D445C340
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$ExceptionThrow
    • String ID:
    • API String ID: 912942878-0
    • Opcode ID: 1beca4280fc7a8cee08e259ee377d055c7d21d729b25eaf46f5b86b0a78c62e5
    • Instruction ID: ede2a9cac572cdcf7b586f11c8e6990b5be37c5a9bfe827d84fdd058e91f2cfe
    • Opcode Fuzzy Hash: 1beca4280fc7a8cee08e259ee377d055c7d21d729b25eaf46f5b86b0a78c62e5
    • Instruction Fuzzy Hash: DA81A162B09A8181EB60DF25E8442BD63A5BB84BE4F544639DA7D87BD9EF3CD452C300
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrow
    • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
    • API String ID: 432778473-1866435925
    • Opcode ID: 2d7ad143d1a076f5ee7fe952836cba1d552d21dbf52fa5c5d6611a7c311318a5
    • Instruction ID: 17cfee90441715d62bc85bc5cdd9946c40b7eda494fcf4a5b1362d9b946962b3
    • Opcode Fuzzy Hash: 2d7ad143d1a076f5ee7fe952836cba1d552d21dbf52fa5c5d6611a7c311318a5
    • Instruction Fuzzy Hash: 06714172608A4281EB608F1DD99036C67A1FB44FA5F548135DA6EC77E8EF3DD895C301
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrow
    • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
    • API String ID: 432778473-1866435925
    • Opcode ID: 33be099b1b17043a85ff60158e8f68dd7db81d29badbfa963d5871934304ce98
    • Instruction ID: e9376ccbab023c8fc25fe6b2863c46768c56a25e8833b886c818451a1d78062f
    • Opcode Fuzzy Hash: 33be099b1b17043a85ff60158e8f68dd7db81d29badbfa963d5871934304ce98
    • Instruction Fuzzy Hash: DF715272609A4291EB608F1DD980379A7A1FB44FA4F548136DA5EC77E8EF3ED885C301
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: 3e12b3072926e37bbd89c5050a97d5adf74274eee81cea212d77db79ff21c1e7
    • Instruction ID: 1e06166e26646795251fad650f4adfd5045999015f17a298f646ced5bec1c343
    • Opcode Fuzzy Hash: 3e12b3072926e37bbd89c5050a97d5adf74274eee81cea212d77db79ff21c1e7
    • Instruction Fuzzy Hash: 3D51A622A0978285EB605F15A88017D7A95FF84BA0F19533BEA79877D9EF3CE441E700
    APIs
      • Part of subcall function 00007FF6F9072F90: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9072FD3
      • Part of subcall function 00007FF6F9072F90: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9072FF6
      • Part of subcall function 00007FF6F9072F90: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9073023
      • Part of subcall function 00007FF6F9072F90: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9073112
    • _CxxThrowException.LIBVCRUNTIME ref: 00007FF6F9073EBA
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~_$ExceptionThrow
    • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
    • API String ID: 4074540200-1866435925
    • Opcode ID: 097f471ae75fa6c1eaecd4d4248b39634aa2c18d3683b0c09e9b3e202bc4b258
    • Instruction ID: 0455f2520b41e2d7fe02efd0e98863d27eee6fae36672ad60517cc9f8e71702a
    • Opcode Fuzzy Hash: 097f471ae75fa6c1eaecd4d4248b39634aa2c18d3683b0c09e9b3e202bc4b258
    • Instruction Fuzzy Hash: D45198726086C582EB10DF19E4803A9B7A0FB84B94F44413AEB6D83BD8EF7CD445C701
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Concurrency::event::waitConcurrency::event::wait_for_multipleExceptionThrowstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 482297304-0
    • Opcode ID: 33c45967bdb5639e42c1e8442a502087a9e64da037af6c1f6d2b59d351ba53ff
    • Instruction ID: 09756547cb2b743c5251c0e63152085f0a99aac8faea1a3b06823ae569808d75
    • Opcode Fuzzy Hash: 33c45967bdb5639e42c1e8442a502087a9e64da037af6c1f6d2b59d351ba53ff
    • Instruction Fuzzy Hash: AE416C72A15B8689EB149F24CC502AC63A5FF14BA8F544639EA3D87BDCEF38E4558340
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo$ByteCharErrorLastMultiWide
    • String ID:
    • API String ID: 4141327611-0
    • Opcode ID: a11e567576d705eda2d6a3eccd788de22924937d1bfeb7fb7984bbce765a91ac
    • Instruction ID: 1b622bb081ca9aebb262d41e325ec59aaa8ac8bb5482bf920387a78f218e677f
    • Opcode Fuzzy Hash: a11e567576d705eda2d6a3eccd788de22924937d1bfeb7fb7984bbce765a91ac
    • Instruction Fuzzy Hash: 6341B5A2A0C74286FB619F14984037DA2D2AF80794F54513ADBBD86BDEEF3CD9418701
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-0
    • Opcode ID: a0042ae1c7ee5d34df169b3ba048cd34896f17ff076d8b3e6c1fe45d86097910
    • Instruction ID: 51ffeac011521130a549d65159c74f422c92a86a3bb2439107e8cfee274a250e
    • Opcode Fuzzy Hash: a0042ae1c7ee5d34df169b3ba048cd34896f17ff076d8b3e6c1fe45d86097910
    • Instruction Fuzzy Hash: BB413C2290CA95D5EB52CF64C8102BC3BA0BB85F44F598076DAAC873CEEE3DD445D325
    APIs
    • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF6F90D3D9B,?,?,?,00007FF6F90D41E2), ref: 00007FF6F90DF0C9
    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,00007FF6F90D3D9B,?,?,?,00007FF6F90D41E2), ref: 00007FF6F90DF12B
    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,00007FF6F90D3D9B,?,?,?,00007FF6F90D41E2), ref: 00007FF6F90DF165
    • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF6F90D3D9B,?,?,?,00007FF6F90D41E2), ref: 00007FF6F90DF18F
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ByteCharEnvironmentMultiStringsWide$Free
    • String ID:
    • API String ID: 1557788787-0
    • Opcode ID: c7ed8db65c11c1bad54623ef608c877b64869ca86de7bae7657bd33c7a6a0948
    • Instruction ID: 4b080185c4aa0dd4277286e0c9a672477034c5bcabd543300f6b63c45f7d05f4
    • Opcode Fuzzy Hash: c7ed8db65c11c1bad54623ef608c877b64869ca86de7bae7657bd33c7a6a0948
    • Instruction Fuzzy Hash: 9B217525F1879181E7209F12AC0002966A9FF58BD0B488139DFAEA3BE8EF3CD452C700
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Exception$Throw$FileHeaderRaiseallocator
    • String ID:
    • API String ID: 2585430457-0
    • Opcode ID: f6b3750b338bd07d8d6b7b36dcc48045d36917ec134f0d48251f88cd9fd53527
    • Instruction ID: ae7fd65e27c4200a5430aace4083dcc5c00cd231e0269fe0d9164a9bbc85fb09
    • Opcode Fuzzy Hash: f6b3750b338bd07d8d6b7b36dcc48045d36917ec134f0d48251f88cd9fd53527
    • Instruction Fuzzy Hash: 5B0184A2615A8489D71CEE73DC510FE1362FB88BD8F04943AFE5D8769EDF24D4418740
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrow
    • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
    • API String ID: 432778473-1866435925
    • Opcode ID: 4d1243f049a73087c7bff65184d901dbebf975780722cfe4b39578402451a5bf
    • Instruction ID: 280f4b78302f2750c26f1a1c952e930b7cc30c94cfc249349013bb628df2d891
    • Opcode Fuzzy Hash: 4d1243f049a73087c7bff65184d901dbebf975780722cfe4b39578402451a5bf
    • Instruction Fuzzy Hash: D011D662A04A4585EF10CF14D8822E86761FB40BB4F544239EA3ECB6E9EF3DD586C301
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrow
    • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
    • API String ID: 432778473-1866435925
    • Opcode ID: c50d87df547d8f479af870e3b8962347b50d3372f7b60b3851f4a5ce6c88b7db
    • Instruction ID: 09b670ef99bce353494e53b39b78e391979fe3d28027abee9c56d93c3af27120
    • Opcode Fuzzy Hash: c50d87df547d8f479af870e3b8962347b50d3372f7b60b3851f4a5ce6c88b7db
    • Instruction Fuzzy Hash: 98018F72A1868691EF14DF00DC411E96365FB40B88FD84039E66D87A99FF3CE511C741
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: CreateExceptionQueueThrowTimerstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 49178901-0
    • Opcode ID: 4a28ce72633afb586a3a1fd4c97582b96378884681afbf312a7af73c3ad2f2da
    • Instruction ID: f2a1919cb69b8d432b9614d6cbb56c529fd5f43dfac0e8f9cff1c1982a9f60ff
    • Opcode Fuzzy Hash: 4a28ce72633afb586a3a1fd4c97582b96378884681afbf312a7af73c3ad2f2da
    • Instruction Fuzzy Hash: 1B112371E0A60B95EB10DF44EC8017826A8BF66754F000539D93DC63EAFF2DE4888781
    APIs
    • EnterCriticalSection.KERNEL32 ref: 00007FF6F90AB989
    • Concurrency::details::SchedulerProxy::ReferenceCurrentThreadExecutionResource.LIBCONCRT ref: 00007FF6F90AB992
      • Part of subcall function 00007FF6F90B5828: TlsGetValue.KERNEL32 ref: 00007FF6F90B5844
      • Part of subcall function 00007FF6F90B5828: Concurrency::details::ExecutionResource::IncrementUseCounts.LIBCONCRT ref: 00007FF6F90B587E
      • Part of subcall function 00007FF6F90B5828: Concurrency::details::SchedulerProxy::GetResourceForNewSubscription.LIBCONCRT ref: 00007FF6F90B58DB
    • Concurrency::details::ResourceManager::PerformAllocation.LIBCONCRT ref: 00007FF6F90AB9AB
      • Part of subcall function 00007FF6F90A9E84: Concurrency::details::ResourceManager::CreateAllocatedNodeData.LIBCONCRT ref: 00007FF6F90A9EAB
      • Part of subcall function 00007FF6F90A9E84: Concurrency::details::ResourceManager::SetupStaticAllocationData.LIBCONCRT ref: 00007FF6F90A9F8F
      • Part of subcall function 00007FF6F90A9E84: Concurrency::details::ResourceManager::PreProcessStaticAllocationData.LIBCMT ref: 00007FF6F90A9F97
      • Part of subcall function 00007FF6F90A9E84: Concurrency::details::ResourceManager::ReserveCores.LIBCONCRT ref: 00007FF6F90A9FA8
      • Part of subcall function 00007FF6F90A9E84: Concurrency::details::ResourceManager::ReleaseCoresOnExistingSchedulers.LIBCONCRT ref: 00007FF6F90A9FD6
      • Part of subcall function 00007FF6F90A9E84: Concurrency::details::ResourceManager::RedistributeCoresAmongAll.LIBCONCRT ref: 00007FF6F90A9FFC
    • LeaveCriticalSection.KERNEL32 ref: 00007FF6F90AB9B6
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Concurrency::details::$Resource$Manager::$AllocationCoresData$CriticalExecutionProxy::SchedulerSectionStatic$AllocatedAmongCountsCreateCurrentEnterExistingIncrementLeaveNodePerformProcessRedistributeReferenceReleaseReserveResource::SchedulersSetupSubscriptionThreadValue
    • String ID:
    • API String ID: 2825417320-0
    • Opcode ID: 049d89592681e53489fe974ef302e7e8360a3b61bb890fa22b0cc8ae9562ebaf
    • Instruction ID: b842692c82dca1a39dbcb249785c1bcf078472fed54db2f617d04bfc1243ddce
    • Opcode Fuzzy Hash: 049d89592681e53489fe974ef302e7e8360a3b61bb890fa22b0cc8ae9562ebaf
    • Instruction Fuzzy Hash: 7BF0C221B09B9185EB44DF16E80016DA760EB85FE0B585234EF7D47BDAEE38D0028780
    APIs
    • Concurrency::details::LoadLibraryAndCreateThread.LIBCMT ref: 00007FF6F90A7931
      • Part of subcall function 00007FF6F90A6A3C: CreateThread.KERNEL32 ref: 00007FF6F90A6A54
      • Part of subcall function 00007FF6F90A6A3C: Concurrency::details::ReferenceLoadLibrary.LIBCONCRT ref: 00007FF6F90A6A75
    • GetLastError.KERNEL32 ref: 00007FF6F90A7951
    • Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error.LIBCONCRT ref: 00007FF6F90A796A
    • _CxxThrowException.LIBVCRUNTIME ref: 00007FF6F90A797B
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Concurrency::details::CreateLibraryLoadThread$Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorErrorExceptionLastReferenceThrow
    • String ID:
    • API String ID: 2629157235-0
    • Opcode ID: e73ce0fa291804275a6de18c66b4691d0968cc8faa617b2008bbf2ebab0b7332
    • Instruction ID: 19106f761e533b55e3d9885581b0a267adc3c63ab12ba4233dd7f1e1fad04c91
    • Opcode Fuzzy Hash: e73ce0fa291804275a6de18c66b4691d0968cc8faa617b2008bbf2ebab0b7332
    • Instruction Fuzzy Hash: 70F0C221E1860682FB259B60EC153B522A1EB84B44F504539F66DCAACDFF3CD545C680
    APIs
    • Concurrency::details::SchedulerBase::FastCurrentScheduler.LIBCMT ref: 00007FF6F90AC9E1
      • Part of subcall function 00007FF6F90AD39C: TlsGetValue.KERNEL32(?,?,?,?,00007FF6F90AC9E6), ref: 00007FF6F90AD3A6
    • Concurrency::details::SchedulerBase::AttachExternalContext.LIBCONCRT ref: 00007FF6F90AC9F0
      • Part of subcall function 00007FF6F90ACA40: Concurrency::details::InternalContextBase::LeaveScheduler.LIBCONCRT ref: 00007FF6F90ACA7B
      • Part of subcall function 00007FF6F90ACA40: Concurrency::details::SchedulerBase::GetExternalContext.LIBCMT ref: 00007FF6F90ACAA5
    • Concurrency::details::SchedulerBase::ThrowSchedulerEvent.LIBCONCRT ref: 00007FF6F90ACA17
      • Part of subcall function 00007FF6F90B0490: Concurrency::details::Etw::Trace.LIBCONCRT ref: 00007FF6F90B0501
    • _CxxThrowException.LIBVCRUNTIME ref: 00007FF6F90ACA38
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Scheduler$Concurrency::details::$Base::$Context$ExternalThrow$AttachCurrentEtw::EventExceptionFastInternalLeaveTraceValue
    • String ID:
    • API String ID: 2625748029-0
    • Opcode ID: b13647bbccd46cf25b37e5fc7274d483705db42ff0fe46224583dae303edc2a1
    • Instruction ID: a16a83fa7919f72305ee5607cd625d31a051fcc1675f7aa2b7817d499e4efd5f
    • Opcode Fuzzy Hash: b13647bbccd46cf25b37e5fc7274d483705db42ff0fe46224583dae303edc2a1
    • Instruction Fuzzy Hash: FDF03AA1E1819795EB24EF10DC511F42321AF6134CF480038D9BDCB6EAFE2DF4898748
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrowstd::invalid_argument::invalid_argument
    • String ID:
    • API String ID: 1079095653-0
    • Opcode ID: 96c5f273c176d705afa000d38c0e5ca79654b11e737a8d6021a3a0f7f32d0f8c
    • Instruction ID: ad5fd8c327baa0ce371970b5222b63f29dc5b66e4d3cb543840cb3d57a658421
    • Opcode Fuzzy Hash: 96c5f273c176d705afa000d38c0e5ca79654b11e737a8d6021a3a0f7f32d0f8c
    • Instruction Fuzzy Hash: 6EF04F62A1844691EB24EF14D8552A96371FF90784F904139E26CC66EAFE2CE544C740
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: std::_$ExceptionFacet_LockitLockit::~_RegisterThrowstd::bad_alloc::bad_alloc
    • String ID:
    • API String ID: 1786031634-0
    • Opcode ID: d3f255f332f2a5b63e5776209d7872b2a3c23c35e7cb4416977c398b47104de7
    • Instruction ID: c3103b58a0b9a4f315a84fc54142f782882650c378781e1c77590ae5d6651725
    • Opcode Fuzzy Hash: d3f255f332f2a5b63e5776209d7872b2a3c23c35e7cb4416977c398b47104de7
    • Instruction Fuzzy Hash: 96F0FF26A08A0691EB15DF59E8500A96324BB847B8F480235EB7D827FAEF3CE595C704
    APIs
    • _CxxThrowException.LIBVCRUNTIME ref: 00007FF6F90C2480
      • Part of subcall function 00007FF6F90C0B60: RtlPcToFileHeader.NTDLL ref: 00007FF6F90C0BD5
      • Part of subcall function 00007FF6F90C0B60: RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF6F907EE3A), ref: 00007FF6F90C0C07
    • _CxxThrowException.LIBVCRUNTIME ref: 00007FF6F90C24A3
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Exception$Throw$FileHeaderRaise
    • String ID: Access violation - no RTTI data!$Bad dynamic_cast!
    • API String ID: 3102897148-3176238549
    • Opcode ID: 32d14d53810e6e10d26a95acb230c1802583cd312274b1cf9ecce54dc8fd8f26
    • Instruction ID: 63bb2dfb507d02eac440598a7fc6a94d136ed3a91138d2f64ed927a6aa11ec41
    • Opcode Fuzzy Hash: 32d14d53810e6e10d26a95acb230c1802583cd312274b1cf9ecce54dc8fd8f26
    • Instruction Fuzzy Hash: F0F01D51E2A507A1EF04EF54DC910B82321FF91704F805435E12E869EEFF6CE549C724
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AllocConcurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorErrorExceptionLastThrow
    • String ID:
    • API String ID: 1741573935-0
    • Opcode ID: 887054bd17b7c21e1673a4a65352cd3f7c6998ef4f2318afbda64b7d44bec155
    • Instruction ID: 1817c0679913dee461383cad3ed8906703fb9394ba145bdbf9163e276b2cbe19
    • Opcode Fuzzy Hash: 887054bd17b7c21e1673a4a65352cd3f7c6998ef4f2318afbda64b7d44bec155
    • Instruction Fuzzy Hash: A8E09265E0864696E724AF24DC451B522A1BF90314F900635D27DC26ECFF3CE149C600
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorErrorExceptionHighestLastNodeNumaNumberThrow
    • String ID:
    • API String ID: 2755226096-0
    • Opcode ID: e2b6f529b5f13b6efadea9c7a50f79f421ab5a9f2a279a381b6ef5a6ebe2241d
    • Instruction ID: bff563ebb739ba5bd8a3d6f56afd355fbeab19a3f749a1154145290f0ff8a6de
    • Opcode Fuzzy Hash: e2b6f529b5f13b6efadea9c7a50f79f421ab5a9f2a279a381b6ef5a6ebe2241d
    • Instruction Fuzzy Hash: 83E06D61E0854296EB10EF20DC411B663B1BF80700F804035E2ADC25ECFE6CD509C740
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorErrorExceptionLastThrowValue
    • String ID:
    • API String ID: 1894548659-0
    • Opcode ID: 1623d7455d6e5692fccac301e55d87f12ee9a5e2f9c20dc68d39f39fa042617a
    • Instruction ID: de7ba7e519899e2c6b8bb2e3643ec318d2030fbd12e1466b6d70275939f201c7
    • Opcode Fuzzy Hash: 1623d7455d6e5692fccac301e55d87f12ee9a5e2f9c20dc68d39f39fa042617a
    • Instruction Fuzzy Hash: 82E04661E0864696FB24AF21DC562B622A1BF90B44F805139E2ADC25ECFE2DE609C650
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorErrorExceptionLastPriorityThreadThrow
    • String ID:
    • API String ID: 152467346-0
    • Opcode ID: 850e2196c4765034904f65ce08261fb0d0b214f5dfc86e83cae4623598e52235
    • Instruction ID: 80cefb0e2a56abc7dd66d7244b148e05ff0641018ca8dd23fa9cdf032081ea5b
    • Opcode Fuzzy Hash: 850e2196c4765034904f65ce08261fb0d0b214f5dfc86e83cae4623598e52235
    • Instruction Fuzzy Hash: C6E04F61E0864796FB24AF21DC552B962A1BF90B44F805139E26DC65DCFE2CD509C650
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AllocConcurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_errorErrorExceptionLastThrow
    • String ID:
    • API String ID: 1741573935-0
    • Opcode ID: 5e4bf07b4cc18031c2b4b66f154d1205326e4510a187a6d650e950e69b0539c1
    • Instruction ID: 1130ab4d16d749e235006f7deba846c7bfb1830327957659a2bf6ce01b134703
    • Opcode Fuzzy Hash: 5e4bf07b4cc18031c2b4b66f154d1205326e4510a187a6d650e950e69b0539c1
    • Instruction Fuzzy Hash: 74E04F61E0854696E714AB24DC451B922A1BF90714F905235E17DC15ECFF3DD5198640
    APIs
      • Part of subcall function 00007FF6F9089AFC: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9089B1C
      • Part of subcall function 00007FF6F9089AFC: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9089B41
      • Part of subcall function 00007FF6F9089AFC: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9089B6B
      • Part of subcall function 00007FF6F9089AFC: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9089BFE
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F908F3F6
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F908F3FC
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~__invalid_parameter_noinfo_noreturn
    • String ID: 0123456789ABCDEFabcdef-+Xx
    • API String ID: 4156930308-2799312399
    • Opcode ID: 7cae201fb6047541e79a5767e4e613e0f74ef01a0ebb7330a8c5ea5e7a91fbfc
    • Instruction ID: 9698db1444f23067da76a811942354cd8b38f2491c800e45656dfef980f9410d
    • Opcode Fuzzy Hash: 7cae201fb6047541e79a5767e4e613e0f74ef01a0ebb7330a8c5ea5e7a91fbfc
    • Instruction Fuzzy Hash: D6D1C022B0C68289EB58DF76D8402BD2761AB95B94F805139DF6E977CDEE3CE446C340
    APIs
      • Part of subcall function 00007FF6F9089C30: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9089C50
      • Part of subcall function 00007FF6F9089C30: std::_Lockit::_Lockit.LIBCPMT ref: 00007FF6F9089C75
      • Part of subcall function 00007FF6F9089C30: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9089C9F
      • Part of subcall function 00007FF6F9089C30: std::_Lockit::~_Lockit.LIBCPMT ref: 00007FF6F9089D32
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F908F89E
    • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF6F908F8A4
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Lockitstd::_$Lockit::_Lockit::~__invalid_parameter_noinfo_noreturn
    • String ID: 0123456789ABCDEFabcdef-+Xx
    • API String ID: 4156930308-2799312399
    • Opcode ID: 1dc00d8fcada3d7558fa675a16d402792629313f86a7bcd271e1ac8adf3e27d7
    • Instruction ID: 8a56f73f056f2dd1f0ce1611472335b140e8b14ea265a9d898e3e3cf9f01ad60
    • Opcode Fuzzy Hash: 1dc00d8fcada3d7558fa675a16d402792629313f86a7bcd271e1ac8adf3e27d7
    • Instruction Fuzzy Hash: EAD1DF22B0C68289FB58DF7699402BD2761AB85B94F404139DF6E977CDEE7CE446C380
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-3916222277
    • Opcode ID: 429754e866dc2bbcd6181d576b0bfde65bde3842853cc3fda8aa79a5a0fa78f0
    • Instruction ID: 758ebeb0fb45cab85108e9cc46f596d8305b4c0e54c54a3c7a3bff27ac559111
    • Opcode Fuzzy Hash: 429754e866dc2bbcd6181d576b0bfde65bde3842853cc3fda8aa79a5a0fa78f0
    • Instruction Fuzzy Hash: 4D61C57A90C21296E7648F28985417C37A0FF05B1DF64123ED66EC62DDEF2AE441DB20
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo
    • String ID:
    • API String ID: 3215553584-3916222277
    • Opcode ID: 6279f47928a1544ff9292a4a9be30ab0fb741c67cfe6d46b6919420d111a3257
    • Instruction ID: e94328dd96cac9f9a6b688a98f27082444cac157f87debd8a43efbffe4a3f507
    • Opcode Fuzzy Hash: 6279f47928a1544ff9292a4a9be30ab0fb741c67cfe6d46b6919420d111a3257
    • Instruction Fuzzy Hash: 1461963A90C60286F7648E28884837C37E4FB57B18F54113DDA6AC62DEEF2EE445D721
    APIs
    Strings
    • C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe, xrefs: 00007FF6F90D3C32
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: FileFreeHeapModuleName_invalid_parameter_noinfo
    • String ID: C:\Users\user\Desktop\#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.exe
    • API String ID: 13503096-2733368497
    • Opcode ID: b776ba6da8c3556491d25e101a6681b806031bc3f622bdbfc6dee3235063a310
    • Instruction ID: 49f699c10fcee0dd6e5f4385beef008de4f8b4bfa15534028015d769c6591085
    • Opcode Fuzzy Hash: b776ba6da8c3556491d25e101a6681b806031bc3f622bdbfc6dee3235063a310
    • Instruction Fuzzy Hash: 64418332E08B5685EB14DF25AC410B9B795FF45798B54403AEA6E83BD9EF3CE4818700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _handle_errorf
    • String ID: "$powf
    • API String ID: 2315412904-603753351
    • Opcode ID: 1f7ec3c1cad5386b290e1b080345c1ec0e852f4a9f94ffcf34dcaea9eb7656d7
    • Instruction ID: 461155f435eefcfa3400f1980b32716ebcca13f0b74438bb76c1d5f97ad25289
    • Opcode Fuzzy Hash: 1f7ec3c1cad5386b290e1b080345c1ec0e852f4a9f94ffcf34dcaea9eb7656d7
    • Instruction Fuzzy Hash: 20416273D28681DAD370DF22E4807AAB6A0F7A9348F11232AF74942ED8DF7DD5549B00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: FileHandleType
    • String ID: @
    • API String ID: 3000768030-2766056989
    • Opcode ID: d429798f18a8b69d17c8251e41d55c6f7bd7bd8a02af226ff63664266fb2709a
    • Instruction ID: 6da5f8840ad294f767cd70d716e413a2b07e6ea0b30d77428d7cf79c95314ab7
    • Opcode Fuzzy Hash: d429798f18a8b69d17c8251e41d55c6f7bd7bd8a02af226ff63664266fb2709a
    • Instruction Fuzzy Hash: 9D219A22A0874241FB688F289C905386696FB45774F28133ADBBE877DCEE39D881D301
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _handle_error
    • String ID: "$pow
    • API String ID: 1757819995-713443511
    • Opcode ID: 83fa541469f52ee94b3bbb6fca9bb61eb36b327e2fb5272a65add76b6bf72c3a
    • Instruction ID: fc1878f37aeaad2fb7a7d1b5b127731130a29c8fbdb0983c082ef3bd9f9e9b38
    • Opcode Fuzzy Hash: 83fa541469f52ee94b3bbb6fca9bb61eb36b327e2fb5272a65add76b6bf72c3a
    • Instruction Fuzzy Hash: 20317E72D1CA8586D770CF14E44076ABAB1FBDA344F20232AF69946E98DFBCD1859F00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: CreateErrorLastObject
    • String ID: WARNING: The job `%S` already exists
    • API String ID: 4248079190-4281581335
    • Opcode ID: e8eb07b07746e81c035ddb58384e0e4cc2eb3e19b8a6143ed706fcabccce5dbf
    • Instruction ID: 46e19ad1de0ef65fa0897282c463eeebf88ba8b9777d3b2da7edaf454ab58057
    • Opcode Fuzzy Hash: e8eb07b07746e81c035ddb58384e0e4cc2eb3e19b8a6143ed706fcabccce5dbf
    • Instruction Fuzzy Hash: 7721D722A0864280FB119F15EC1536A6760EF95BF4F444238EAAD877EDEF3CD485C740
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ErrorExceptionStatusThrow
    • String ID: TpAllocJobNotification
    • API String ID: 2975549888-4284020128
    • Opcode ID: f61927787d72852f9fdaac7f0c0e8998226a466aeebdffbd7c02f35b4d58cf14
    • Instruction ID: 050f33a49b73c7a70943968ee75e8b08d72b2537e38a93759a6136132fd04eef
    • Opcode Fuzzy Hash: f61927787d72852f9fdaac7f0c0e8998226a466aeebdffbd7c02f35b4d58cf14
    • Instruction Fuzzy Hash: 3911E061B18A8641EB10DF25EC513AAA364AF917E4F400239EA7C8B3EDFF2CD449C700
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: CompareStringtry_get_function
    • String ID: CompareStringEx
    • API String ID: 3328479835-2590796910
    • Opcode ID: e30708fdca9faa82ee4021967cefd942d08ea59ea1a288b6a40aae4427e55f08
    • Instruction ID: 62672d2c2e9db63926ce6f6c0676ae9bb587a4c8b1d236e237066c9c09a24bc6
    • Opcode Fuzzy Hash: e30708fdca9faa82ee4021967cefd942d08ea59ea1a288b6a40aae4427e55f08
    • Instruction Fuzzy Hash: F0112932608B8186D760CF06B8402AAB7A5FBC9B94F14413AEE9D83B5DEF3CD540CB40
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Stringtry_get_function
    • String ID: LCMapStringEx
    • API String ID: 2588686239-3893581201
    • Opcode ID: c917a20356cf0e2e39461f52218a24a10f5fcfe25c90a44d35acd6f07afe251e
    • Instruction ID: 16f7f338c07a939b8c792efcf9fcff3d686fa31cbde937f9d4fb4a14ba99cfda
    • Opcode Fuzzy Hash: c917a20356cf0e2e39461f52218a24a10f5fcfe25c90a44d35acd6f07afe251e
    • Instruction Fuzzy Hash: B7113E31608B8186D760CF15B8402AAB7A5FBC9B94F54413AEE9D83B5DEF3CD5448B40
    APIs
    • GetACP.KERNEL32(?,?,000000A0,00007FF6F90E1806,?,?,?,?,?,00007FF6F90D5248), ref: 00007FF6F90E1606
      • Part of subcall function 00007FF6F90DA1BC: try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA1F5
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: try_get_function
    • String ID: ACP$OCP
    • API String ID: 2742660187-711371036
    • Opcode ID: 3f5ba32ff7b6033933c62adbd892b7fdbe58143f38fad2fa4be7ef050a0555ac
    • Instruction ID: 9d4a2fdf5baa1b920a1169445d5e3aae15f5884c702670545bbbcd9f1c0f746e
    • Opcode Fuzzy Hash: 3f5ba32ff7b6033933c62adbd892b7fdbe58143f38fad2fa4be7ef050a0555ac
    • Instruction Fuzzy Hash: 7F111F66A1864281FBB4EF22AD405BA6354AF58784F944039EA6EC36CDFF2CE945C740
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _handle_error
    • String ID: !$sqrt
    • API String ID: 1757819995-799759792
    • Opcode ID: 348202b51492dce202419fc9437d461dd1193513091198cbca563ddb68c51668
    • Instruction ID: a9515c66bc2263d2e8e4254b167c1f21568ef0ea198bdea8ae7fc78fde7d3575
    • Opcode Fuzzy Hash: 348202b51492dce202419fc9437d461dd1193513091198cbca563ddb68c51668
    • Instruction Fuzzy Hash: C8119676E18B8582DF01CF15A94032A6662FB967E4F108335FABC567CCEF2CE0859A00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: DateFormattry_get_function
    • String ID: GetDateFormatEx
    • API String ID: 595753042-159735388
    • Opcode ID: 2bf0957a3943ed249e3f4e5b25a9bf8a193e9f2cf9eb8c57c5090b071b9b4efc
    • Instruction ID: 005774c4ad54102b820880d6438ca77e833753c4d0a967cf38fc7ec4957a2795
    • Opcode Fuzzy Hash: 2bf0957a3943ed249e3f4e5b25a9bf8a193e9f2cf9eb8c57c5090b071b9b4efc
    • Instruction Fuzzy Hash: 6D114F35A0C78186E750CF55B84019AB7A5FB88BD4F14413AEE9D83BADDE3CD5448B40
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: FormatTimetry_get_function
    • String ID: GetTimeFormatEx
    • API String ID: 3261793192-1692793031
    • Opcode ID: 3f565d0934326b8aa429ea9e8609bb467a998215688a4ff4575eafb9de89481e
    • Instruction ID: 7c43e60bf60dac0748601a7e71ecdecb84dffba8c2db026fab7fab3f8eabb8d5
    • Opcode Fuzzy Hash: 3f565d0934326b8aa429ea9e8609bb467a998215688a4ff4575eafb9de89481e
    • Instruction Fuzzy Hash: AE114271A0878186D7509F5AA80006AB7A5FB88BD4F58413AEF9D83BADDE3CD541CB00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: InformationObject
    • String ID: bObj$ect
    • API String ID: 1757262956-2883911777
    • Opcode ID: 181f8773557602518332b39cfab75dc2eab3facf77df02703d3059a275ed80a4
    • Instruction ID: 1922895889bdb776eddebde94cebceab0447b5b8ef9657ed34b4047b824e1521
    • Opcode Fuzzy Hash: 181f8773557602518332b39cfab75dc2eab3facf77df02703d3059a275ed80a4
    • Instruction Fuzzy Hash: F311A322A0878585E7009F15F8003AABB60EBD6BB4F501234EBA9477E9EF3CD445CB00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: AssignObjectProcess
    • String ID: ject$obOb
    • API String ID: 1819803957-1437108869
    • Opcode ID: 026b69001e6f5926d1c7d5d81b9544aa90aedd84aa45b1ea6bc8c0301b96e945
    • Instruction ID: 96a280e9cc272d19730f9dacaaadf16d680fbf5d2c853108c98c545313ca3f88
    • Opcode Fuzzy Hash: 026b69001e6f5926d1c7d5d81b9544aa90aedd84aa45b1ea6bc8c0301b96e945
    • Instruction Fuzzy Hash: 26119E22A0868585EB109B14E85036ABB60EB957A4F201234E6A946AEEEF3CD185CB40
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: _handle_error
    • String ID: "$exp
    • API String ID: 1757819995-2878093337
    • Opcode ID: 5a6c6d975f34168b8b8bcb3c0312aff62d09fa0c83abc7666c3210c43f7286e6
    • Instruction ID: 1050749fab65424b091e7895bd053446ce827b61e5b8964aafcb2d5e7c5a5dca
    • Opcode Fuzzy Hash: 5a6c6d975f34168b8b8bcb3c0312aff62d09fa0c83abc7666c3210c43f7286e6
    • Instruction Fuzzy Hash: FA01C876928B89C3E320CF24D4496AA7670FFEA704F201319E744166A4DB7DD0C1DF00
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrowstd::invalid_argument::invalid_argument
    • String ID: pContext
    • API String ID: 1079095653-2046700901
    • Opcode ID: a63eeca57b122d3f82af4e720a215af2ed958f378462ecbf4202b0998b7d0082
    • Instruction ID: d14035080e2cfa28fd8c569226a3290f64c99297bebd143967de68e49b691a6f
    • Opcode Fuzzy Hash: a63eeca57b122d3f82af4e720a215af2ed958f378462ecbf4202b0998b7d0082
    • Instruction Fuzzy Hash: ABF03CA2A08A4A91EF55DF06ED400696331FF84BC8B448035DA2D877B8EE2CD554C304
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: DefaultUsertry_get_function
    • String ID: GetUserDefaultLocaleName
    • API String ID: 3217810228-151340334
    • Opcode ID: 953e090cd37d012c1926a9250a7ae5437c1c115a0ac37595c061395919b20f14
    • Instruction ID: ce09210e24a6ad54dc0676f54084e4caf529bbbb394604771761b327d3f8b6a1
    • Opcode Fuzzy Hash: 953e090cd37d012c1926a9250a7ae5437c1c115a0ac37595c061395919b20f14
    • Instruction Fuzzy Hash: C1F0DA50B0C58282EB959F55AA846B95352AF887C8F44503AEA3D867D9EE2CE5448710
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: CountCriticalInitializeSectionSpintry_get_function
    • String ID: InitializeCriticalSectionEx
    • API String ID: 539475747-3084827643
    • Opcode ID: 8e7c9e4892d63184810f56739f4c18e6cf80bfe9966347dd0e2536f2d0056b81
    • Instruction ID: 9d22119bf28bbe33023494e136b4abbc0d091d96a852340a87c9d32dbfb45bd6
    • Opcode Fuzzy Hash: 8e7c9e4892d63184810f56739f4c18e6cf80bfe9966347dd0e2536f2d0056b81
    • Instruction Fuzzy Hash: CFF05E25B0C64282EB849F45A9804A96222FF48B84F48413AFA7D83B9DEE3CE645C744
    APIs
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90DA0D9
    • TlsSetValue.KERNEL32(?,?,8000000000000000,00007FF6F90D69A3,?,?,8000000000000000,00007FF6F90C9335,?,?,?,?,00007FF6F90D6B15), ref: 00007FF6F90DA0F0
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Valuetry_get_function
    • String ID: FlsSetValue
    • API String ID: 738293619-3750699315
    • Opcode ID: 931aeb7f1220c766093666277d4b86b90bb8f83355d16acf48f3da58c7a5e309
    • Instruction ID: 897a70df2db8ddb8af5217ab8655021312ffc708aac69486e2c0f0b67473912a
    • Opcode Fuzzy Hash: 931aeb7f1220c766093666277d4b86b90bb8f83355d16acf48f3da58c7a5e309
    • Instruction Fuzzy Hash: B3E03961A0C64282EF985F54AD005B52222AF48798F48803ADA3D863E8FE2DE984C214
    APIs
    • try_get_function.LIBVCRUNTIME ref: 00007FF6F90C3FA5
    • TlsSetValue.KERNEL32(?,?,00000000,00007FF6F90C253A,?,?,?,00007FF6F90C24D5,?,?,?,?,00007FF6F90C11B2), ref: 00007FF6F90C3FBC
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: Valuetry_get_function
    • String ID: FlsSetValue
    • API String ID: 738293619-3750699315
    • Opcode ID: 7f996b25490785f67e52861f284fb4e0bd7cd4a8db9972613c5d2c426176c3a1
    • Instruction ID: e13a949c3b63eaea97961af7bd15c843aeae01d5070c47238ddf2f5507196450
    • Opcode Fuzzy Hash: 7f996b25490785f67e52861f284fb4e0bd7cd4a8db9972613c5d2c426176c3a1
    • Instruction Fuzzy Hash: 9FE06DA1A1860292EB096F54FC408B96261EF48784F58503EDA3D863DCEE3CEA96C310
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: DownlevelLocaleName__crttry_get_function
    • String ID: LocaleNameToLCID
    • API String ID: 404522899-2050040251
    • Opcode ID: 8f7a26459eebdbe9ebcdac47c1d9243744081d28dddbc00ce074c770542b637c
    • Instruction ID: a7967e779c59df15d4a625dc1f692546d83da70a3c137ec6a41ebe7d5addb32d
    • Opcode Fuzzy Hash: 8f7a26459eebdbe9ebcdac47c1d9243744081d28dddbc00ce074c770542b637c
    • Instruction Fuzzy Hash: 09E0ED61E0C64792EB85AF55AC414F53222AF84748F58803AF63D863DDFE3CEA59D204
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1434859185.00007FF6F9071000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF6F9070000, based on PE: true
    • Associated: 00000000.00000002.1434843294.00007FF6F9070000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434905579.00007FF6F90E9000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434929076.00007FF6F9113000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434941788.00007FF6F9114000.00000008.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434954651.00007FF6F9116000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9119000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1434968214.00007FF6F9146000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff6f9070000_#U8f6f#U4ef6#U5b89#U88c5#U7a0b#U5e8f_uninstc.jbxd
    Similarity
    • API ID: ExceptionThrowstd::invalid_argument::invalid_argument
    • String ID: pThreadProxy
    • API String ID: 1079095653-3651400591
    • Opcode ID: 2ca3c2a8cdd9b7f389f3caa147fc552e775271ba4e2d69ac51743d6edc72005a
    • Instruction ID: b50da53e3e5200b9a16540090bfa594768e04d7049ee0453d13b0a02c2edf0ae
    • Opcode Fuzzy Hash: 2ca3c2a8cdd9b7f389f3caa147fc552e775271ba4e2d69ac51743d6edc72005a
    • Instruction Fuzzy Hash: 0FD08CA2A1860390EF15AF00EC000A82232FB90388F904038D17D865FDFF1CE20A8700