Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1521588
MD5:de030225e0b09c45241b8169a8a96155
SHA1:bf568cfc34b708da4e740b13e91058d3a241fdd9
SHA256:85d96a1ba8fa7426e48bcf430d305c6e4764db53fb86abbe53d9b80c5e474e72
Tags:exex64user-jstrosch
Infos:

Detection

CredGrabber, Meduza Stealer
Score:96
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected CredGrabber
Yara detected Meduza Stealer
AI detected suspicious sample
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for sample
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to query locales information (e.g. system language)
Contains functionality to record screenshots
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Queries time zone information
Terminates after testing mutex exists (may check infected machine status)
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

  • System is w10x64
  • file.exe (PID: 2064 cmdline: "C:\Users\user\Desktop\file.exe" MD5: DE030225E0B09C45241B8169A8A96155)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
    Process Memory Space: file.exe PID: 2064JoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
      Process Memory Space: file.exe PID: 2064JoeSecurity_CredGrabberYara detected CredGrabberJoe Security
        Process Memory Space: file.exe PID: 2064JoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          No Sigma rule has matched
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-09-29T00:53:22.368592+020020494411A Network Trojan was detected192.168.2.749704176.124.204.20615666TCP
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-09-29T00:53:22.368592+020020508061A Network Trojan was detected192.168.2.749704176.124.204.20615666TCP
          2024-09-29T00:53:22.375741+020020508061A Network Trojan was detected192.168.2.749704176.124.204.20615666TCP
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-09-29T00:53:22.368592+020020508071A Network Trojan was detected192.168.2.749704176.124.204.20615666TCP
          2024-09-29T00:53:22.375741+020020508071A Network Trojan was detected192.168.2.749704176.124.204.20615666TCP

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: file.exeReversingLabs: Detection: 36%
          Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.9% probability
          Source: file.exeJoe Sandbox ML: detected
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633416A0 CryptUnprotectData,LocalFree,0_2_00007FF7633416A0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763307C80 CryptUnprotectData,LocalFree,_invalid_parameter_noinfo_noreturn,0_2_00007FF763307C80
          Source: unknownHTTPS traffic detected: 104.26.13.205:443 -> 192.168.2.7:49705 version: TLS 1.2
          Source: file.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76338BA38 FindClose,FindFirstFileExW,GetLastError,0_2_00007FF76338BA38
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76338BAE8 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,CloseHandle,CloseHandle,0_2_00007FF76338BAE8
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335A4B0 GetLogicalDriveStringsW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76335A4B0
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\migration\Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\migration\wtr\Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\microsoft-activedirectory-webservices\Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\microsoft-client-license-platform-service-migration\Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\hwvid-migration-2\Jump to behavior

          Networking

          barindex
          Source: Network trafficSuricata IDS: 2049441 - Severity 1 - ET MALWARE Win32/Unknown Grabber Base64 Data Exfiltration Attempt : 192.168.2.7:49704 -> 176.124.204.206:15666
          Source: Network trafficSuricata IDS: 2050806 - Severity 1 - ET MALWARE [ANY.RUN] Meduza Stealer Exfiltration M2 : 192.168.2.7:49704 -> 176.124.204.206:15666
          Source: Network trafficSuricata IDS: 2050807 - Severity 1 - ET MALWARE [ANY.RUN] Possible Meduza Stealer Exfiltration (TCP) : 192.168.2.7:49704 -> 176.124.204.206:15666
          Source: global trafficTCP traffic: 192.168.2.7:49704 -> 176.124.204.206:15666
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: text/html; text/plain; */*Host: api.ipify.orgCache-Control: no-cache
          Source: Joe Sandbox ViewIP Address: 176.124.204.206 176.124.204.206
          Source: Joe Sandbox ViewIP Address: 104.26.13.205 104.26.13.205
          Source: Joe Sandbox ViewIP Address: 104.26.13.205 104.26.13.205
          Source: Joe Sandbox ViewASN Name: GULFSTREAMUA GULFSTREAMUA
          Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
          Source: unknownDNS query: name: api.ipify.org
          Source: unknownDNS query: name: api.ipify.org
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: unknownTCP traffic detected without corresponding DNS query: 176.124.204.206
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763358400 InternetOpenA,InternetOpenUrlA,HttpQueryInfoW,HttpQueryInfoW,InternetQueryDataAvailable,InternetReadFile,InternetQueryDataAvailable,InternetCloseHandle,_invalid_parameter_noinfo_noreturn,Concurrency::cancel_current_task,0_2_00007FF763358400
          Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: text/html; text/plain; */*Host: api.ipify.orgCache-Control: no-cache
          Source: global trafficDNS traffic detected: DNS query: time.windows.com
          Source: global trafficDNS traffic detected: DNS query: api.ipify.org
          Source: file.exe, 00000000.00000003.1369057073.000001EA4B82D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2599494351.000001EA4B7EF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.m
          Source: file.exe, 00000000.00000003.1368512194.000001EA4DFB1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2600221699.000001EA4DFC0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.microsoft.t/Regi
          Source: file.exe, 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org
          Source: file.exe, 00000000.00000002.2599494351.000001EA4B7AF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org/
          Source: file.exe, 00000000.00000003.1369125819.000001EA4B7C8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2599494351.000001EA4B7AF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org/~
          Source: file.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696490019400400000.2&ci=1696490019252.
          Source: file.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696490019400400000.1&ci=1696490019252.12791&cta
          Source: file.exe, 00000000.00000003.1374444105.000001EA4E0F3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
          Source: file.exe, 00000000.00000003.1386227021.000001EA4E280000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1387286065.000001EA4E107000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/CuERQnIs4CzqjKBh9os6_h9d4CUDCHO3oiqmAQO6VLM.25122.jpg
          Source: file.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
          Source: file.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4pqWfpl%2B4pbW4pbWfpbW7ReNxR3UIG8zInwYIFIVs9e
          Source: file.exe, 00000000.00000003.1381574540.000001EA4D643000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D570000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1383468297.000001EA4E5D2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D578000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D64B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1386227021.000001EA4E18D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org
          Source: file.exe, 00000000.00000003.1381574540.000001EA4D57F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
          Source: file.exe, 00000000.00000003.1381574540.000001EA4D57F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.S3DiLP_FhcLK
          Source: file.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_ef0fa27a12d43fbd45649e195429e8a63ddcad7cf7e128c0
          Source: file.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.invisalign.com/?utm_source=admarketplace&utm_medium=paidsearch&utm_campaign=Invisalign&u
          Source: file.exe, 00000000.00000003.1381574540.000001EA4D643000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D570000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1383468297.000001EA4E5D2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D578000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D64B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1386227021.000001EA4E18D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org
          Source: file.exe, 00000000.00000003.1381574540.000001EA4D57F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.jXqaKJMO4ZEP
          Source: file.exe, 00000000.00000003.1381574540.000001EA4D57F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.NYz0wxyUaYSW
          Source: file.exe, 00000000.00000003.1381574540.000001EA4D653000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1383468297.000001EA4E5D9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D57F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/gro.allizom.www.d
          Source: file.exe, 00000000.00000003.1381574540.000001EA4D57F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
          Source: file.exe, 00000000.00000003.1381574540.000001EA4D653000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1383468297.000001EA4E5D9000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D57F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www.
          Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
          Source: unknownHTTPS traffic detected: 104.26.13.205:443 -> 192.168.2.7:49705 version: TLS 1.2
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763358CC0 GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetDC,GetDeviceCaps,GetDeviceCaps,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,SHCreateMemStream,SelectObject,DeleteDC,ReleaseDC,DeleteObject,EnterCriticalSection,LeaveCriticalSection,GetObjectW,IStream_Size,IStream_Reset,IStream_Read,SelectObject,DeleteDC,ReleaseDC,DeleteObject,DeleteObject,EnterCriticalSection,EnterCriticalSection,GdiplusShutdown,LeaveCriticalSection,LeaveCriticalSection,_invalid_parameter_noinfo_noreturn,0_2_00007FF763358CC0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335D700 RtlAcquirePebLock,NtAllocateVirtualMemory,lstrcpyW,lstrcatW,NtAllocateVirtualMemory,lstrcpyW,RtlInitUnicodeString,RtlInitUnicodeString,LdrEnumerateLoadedModules,RtlReleasePebLock,_invalid_parameter_noinfo_noreturn,CoInitializeEx,lstrcpyW,lstrcatW,CoGetObject,lstrcpyW,lstrcatW,CoGetObject,CoUninitialize,0_2_00007FF76335D700
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335CFC0 GetModuleHandleA,GetProcAddress,OpenProcess,NtQuerySystemInformation,NtQuerySystemInformation,GetCurrentProcess,NtQueryObject,GetFinalPathNameByHandleA,CloseHandle,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76335CFC0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633604400_2_00007FF763360440
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76332E4E00_2_00007FF76332E4E0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76330D5100_2_00007FF76330D510
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633584000_2_00007FF763358400
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335B4100_2_00007FF76335B410
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633012C00_2_00007FF7633012C0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633471A00_2_00007FF7633471A0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633518D00_2_00007FF7633518D0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335A7600_2_00007FF76335A760
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633796B80_2_00007FF7633796B8
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76330E5A00_2_00007FF76330E5A0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76330EC500_2_00007FF76330EC50
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763352D100_2_00007FF763352D10
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763358CC00_2_00007FF763358CC0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763300BD00_2_00007FF763300BD0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763357BC00_2_00007FF763357BC0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335FA580_2_00007FF76335FA58
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763331A800_2_00007FF763331A80
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76338BAE80_2_00007FF76338BAE8
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76332BAF00_2_00007FF76332BAF0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763361B000_2_00007FF763361B00
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633599600_2_00007FF763359960
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76330C9C00_2_00007FF76330C9C0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633140B00_2_00007FF7633140B0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763375EB40_2_00007FF763375EB4
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763301D4E0_2_00007FF763301D4E
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76336D4740_2_00007FF76336D474
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76331E4190_2_00007FF76331E419
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7632D64800_2_00007FF7632D6480
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76331C4E00_2_00007FF76331C4E0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76338E5000_2_00007FF76338E500
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633714C40_2_00007FF7633714C4
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76334F3700_2_00007FF76334F370
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76336E3540_2_00007FF76336E354
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333D2600_2_00007FF76333D260
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76336D28C0_2_00007FF76336D28C
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633352200_2_00007FF763335220
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633401800_2_00007FF763340180
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633561230_2_00007FF763356123
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633561330_2_00007FF763356133
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633808240_2_00007FF763380824
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333F8200_2_00007FF76333F820
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633448A00_2_00007FF7633448A0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7632D69000_2_00007FF7632D6900
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333D8B00_2_00007FF76333D8B0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633018F00_2_00007FF7633018F0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633467200_2_00007FF763346720
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7632F67700_2_00007FF7632F6770
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7632F97600_2_00007FF7632F9760
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7632F77B00_2_00007FF7632F77B0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76336B7B00_2_00007FF76336B7B0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76337765C0_2_00007FF76337765C
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633436700_2_00007FF763343670
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335D7000_2_00007FF76335D700
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633935700_2_00007FF763393570
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333D5900_2_00007FF76333D590
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633785DC0_2_00007FF7633785DC
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633396000_2_00007FF763339600
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763347C200_2_00007FF763347C20
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7632FACA00_2_00007FF7632FACA0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763350CA00_2_00007FF763350CA0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76331CB900_2_00007FF76331CB90
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763376B2C0_2_00007FF763376B2C
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333DBD00_2_00007FF76333DBD0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763309A590_2_00007FF763309A59
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335DA500_2_00007FF76335DA50
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76336DABC0_2_00007FF76336DABC
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76338E9800_2_00007FF76338E980
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633489800_2_00007FF763348980
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633799340_2_00007FF763379934
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633460800_2_00007FF763346080
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7632D60C00_2_00007FF7632D60C0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633200ED0_2_00007FF7633200ED
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633521000_2_00007FF763352100
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76336D0A40_2_00007FF76336D0A4
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333CF600_2_00007FF76333CF60
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763326F700_2_00007FF763326F70
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763353F800_2_00007FF763353F80
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763376FDC0_2_00007FF763376FDC
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7632D70100_2_00007FF7632D7010
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76334EFD00_2_00007FF76334EFD0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76336DE4C0_2_00007FF76336DE4C
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333FE500_2_00007FF76333FE50
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763307ED00_2_00007FF763307ED0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76330BEE00_2_00007FF76330BEE0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333DF000_2_00007FF76333DF00
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76332AF000_2_00007FF76332AF00
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763379EBC0_2_00007FF763379EBC
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763377D880_2_00007FF763377D88
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76330AE000_2_00007FF76330AE00
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 00007FF763301D20 appears 84 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 00007FF7632FD510 appears 63 times
          Source: C:\Users\user\Desktop\file.exeCode function: String function: 00007FF763306990 appears 41 times
          Source: classification engineClassification label: mal96.troj.spyw.winEXE@1/0@2/2
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76330E5A0 CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76330E5A0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333F820 CoInitializeEx,CoInitializeSecurity,CoCreateInstance,CoSetProxyBlanket,SysAllocStringByteLen,SysFreeString,SysAllocStringByteLen,SysFreeString,SysStringByteLen,SysFreeString,SysFreeString,SysStringByteLen,SysFreeString,SysFreeString,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76333F820
          Source: C:\Users\user\Desktop\file.exeMutant created: \Sessions\1\BaseNamedObjects\Mmm-A33C734061CA11EE8C18806E6F6E6963E1BD36C7
          Source: file.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: file.exeReversingLabs: Detection: 36%
          Source: file.exeString found in binary or memory: --help
          Source: file.exeString found in binary or memory: --help
          Source: file.exeString found in binary or memory: --help
          Source: file.exeString found in binary or memory: --help
          Source: file.exeString found in binary or memory: ipportgrabber_max_sizeextensionslinksbuild_nameself_destructtype must be boolean, but is type must be number, but is 0123456789ABCDEFntdll.dllFile DownloaderabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+=-&^%$#@!(){}[},.;'runasopen bad variant accessfalsetrueBad any_cast[VAR... , [default: [required][nargs: or more] ..[nargs= to or more provided. argument(s) expected. : required.: no value provided.-=--help-hshows help message and exits--version-vprints version information and exitsNo such argument:
          Source: file.exeString found in binary or memory: ipportgrabber_max_sizeextensionslinksbuild_nameself_destructtype must be boolean, but is type must be number, but is 0123456789ABCDEFntdll.dllFile DownloaderabcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+=-&^%$#@!(){}[},.;'runasopen bad variant accessfalsetrueBad any_cast[VAR... , [default: [required][nargs: or more] ..[nargs= to or more provided. argument(s) expected. : required.: no value provided.-=--help-hshows help message and exits--version-vprints version information and exitsNo such argument:
          Source: C:\Users\user\Desktop\file.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: wininet.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: rstrtmgr.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ncrypt.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ntasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: iertutil.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: winhttp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: winnsi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: urlmon.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: srvcli.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: netutils.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: schannel.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: mskeyprotect.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: dpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: ncryptsslp.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: windowscodecs.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: vaultcli.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
          Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
          Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
          Source: file.exeStatic PE information: Image base 0x140000000 > 0x60000000
          Source: file.exeStatic file information: File size 1116160 > 1048576
          Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
          Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
          Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
          Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
          Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
          Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
          Source: file.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
          Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
          Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
          Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
          Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
          Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
          Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76330D510 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76330D510
          Source: file.exeStatic PE information: section name: _RDATA
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333CBAC push rsp; retf 0_2_00007FF76333CBAD
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333CBB0 push rsp; retf 0_2_00007FF76333CBB1
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333CBB4 push rsp; retf 0_2_00007FF76333CBB5
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333CBB8 push rsp; retf 0_2_00007FF76333CBB9
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333CBBC push rsp; retf 0_2_00007FF76333CBBD
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333CBC0 push rsp; retf 0_2_00007FF76333CBC1
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333CBC4 push rsp; retf 0_2_00007FF76333CBC5
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76333CB00 push rsp; retf 0_2_00007FF76333CBA1
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633471A0 _invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,ExitProcess,ExitProcess,OpenMutexA,ExitProcess,CreateMutexExA,ExitProcess,ReleaseMutex,CloseHandle,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF7633471A0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76338BA38 FindClose,FindFirstFileExW,GetLastError,0_2_00007FF76338BA38
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76338BAE8 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,CloseHandle,CloseHandle,0_2_00007FF76338BAE8
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335A4B0 GetLogicalDriveStringsW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76335A4B0
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76336FBD0 VirtualQuery,GetSystemInfo,VirtualAlloc,VirtualProtect,0_2_00007FF76336FBD0
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\migration\Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\migration\wtr\Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\microsoft-activedirectory-webservices\Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\microsoft-client-license-platform-service-migration\Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\hwvid-migration-2\Jump to behavior
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696492231p
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU WestVMware20,11696492231n
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696492231}
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: interactivebrokers.co.inVMware20,11696492231d
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: netportal.hdfcbank.comVMware20,11696492231
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: outlook.office.comVMware20,11696492231s
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696492231
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: AMC password management pageVMware20,11696492231
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: interactivebrokers.comVMware20,11696492231
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,11696492231x
          Source: file.exe, 00000000.00000003.1369125819.000001EA4B7C8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2599494351.000001EA4B7AF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - COM.HKVMware20,11696492231
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696492231^
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Test URL for global passwords blocklistVMware20,11696492231
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: outlook.office365.comVMware20,11696492231t
          Source: file.exe, 00000000.00000003.1369125819.000001EA4B7C8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2599494351.000001EA4B7AF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW^
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696492231z
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: discord.comVMware20,11696492231f
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: global block list test formVMware20,11696492231
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: dev.azure.comVMware20,11696492231j
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.comVMware20,11696492231}
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.co.inVMware20,11696492231~
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: bankofamerica.comVMware20,11696492231x
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: trackpan.utiitsl.comVMware20,11696492231h
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: tasks.office.comVMware20,11696492231o
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: account.microsoft.com/profileVMware20,11696492231u
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696492231
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696492231
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ms.portal.azure.comVMware20,11696492231
          Source: file.exe, 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWp(~K
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: turbotax.intuit.comVMware20,11696492231t
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: secure.bankofamerica.comVMware20,11696492231|UE
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696492231x
          Source: file.exe, 00000000.00000003.1376275414.000001EA4E1F9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - HKVMware20,11696492231]
          Source: C:\Users\user\Desktop\file.exeAPI call chain: ExitProcess graph end nodegraph_0-69077
          Source: C:\Users\user\Desktop\file.exeProcess information queried: ProcessInformationJump to behavior
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335D700 RtlAcquirePebLock,NtAllocateVirtualMemory,lstrcpyW,lstrcatW,NtAllocateVirtualMemory,lstrcpyW,RtlInitUnicodeString,RtlInitUnicodeString,LdrEnumerateLoadedModules,RtlReleasePebLock,_invalid_parameter_noinfo_noreturn,CoInitializeEx,lstrcpyW,lstrcatW,CoGetObject,lstrcpyW,lstrcatW,CoGetObject,CoUninitialize,0_2_00007FF76335D700
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633683E8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7633683E8
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76338DC60 GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_00007FF76338DC60
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76330D510 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF76330D510
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7633683E8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7633683E8
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763385220 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF763385220
          Source: C:\Users\user\Desktop\file.exeCode function: EnumSystemLocalesW,0_2_00007FF76337F494
          Source: C:\Users\user\Desktop\file.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_2_00007FF76337F148
          Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoEx,FormatMessageA,0_2_00007FF76338B634
          Source: C:\Users\user\Desktop\file.exeCode function: EnumSystemLocalesW,0_2_00007FF76337F564
          Source: C:\Users\user\Desktop\file.exeCode function: EnumSystemLocalesW,0_2_00007FF763374518
          Source: C:\Users\user\Desktop\file.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF76337FB7C
          Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoW,0_2_00007FF763374A5C
          Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF76337F9A0
          Source: C:\Users\user\Desktop\file.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\file.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation TimeZoneKeyNameJump to behavior
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763385CD8 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF763385CD8
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF763359410 GetUserNameW,0_2_00007FF763359410
          Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF76335A760 GetTimeZoneInformation,0_2_00007FF76335A760

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 2064, type: MEMORYSTR
          Source: Yara matchFile source: 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 2064, type: MEMORYSTR
          Source: file.exe, 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Electrum
          Source: file.exe, 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: ElectronCash
          Source: file.exe, 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Jaxx Liberty
          Source: file.exe, 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Exodus
          Source: file.exe, 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Ethereum
          Source: file.exe, 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Ethereum\keystore
          Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-coreJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\key4.dbJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For AccountJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\MANIFEST-000001Jump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqliteJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\places.sqliteJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.logJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\prefs.jsJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\CURRENTJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOCKJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.oldJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension CookiesJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOGJump to behavior
          Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
          Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 2064, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 2064, type: MEMORYSTR
          Source: Yara matchFile source: 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: file.exe PID: 2064, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
          Command and Scripting Interpreter
          1
          DLL Side-Loading
          1
          DLL Side-Loading
          1
          Deobfuscate/Decode Files or Information
          1
          OS Credential Dumping
          12
          System Time Discovery
          Remote Services1
          Screen Capture
          21
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault Accounts1
          Native API
          Boot or Logon Initialization ScriptsBoot or Logon Initialization Scripts2
          Obfuscated Files or Information
          LSASS Memory21
          Security Software Discovery
          Remote Desktop Protocol1
          Email Collection
          1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
          DLL Side-Loading
          Security Account Manager2
          Process Discovery
          SMB/Windows Admin Shares1
          Archive Collected Data
          2
          Ingress Tool Transfer
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS1
          Account Discovery
          Distributed Component Object Model2
          Data from Local System
          2
          Non-Application Layer Protocol
          Traffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
          System Owner/User Discovery
          SSHKeylogging3
          Application Layer Protocol
          Scheduled TransferData Encrypted for Impact
          Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials1
          System Network Configuration Discovery
          VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
          DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync3
          File and Directory Discovery
          Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
          Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem24
          System Information Discovery
          Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          file.exe37%ReversingLabsWin64.Trojan.SpywareX
          file.exe100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          SourceDetectionScannerLabelLink
          https://api.ipify.org/0%URL Reputationsafe
          https://api.ipify.org0%URL Reputationsafe
          https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg0%URL Reputationsafe
          https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=0%URL Reputationsafe
          https://support.mozilla.org0%URL Reputationsafe
          https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br0%URL Reputationsafe
          NameIPActiveMaliciousAntivirus DetectionReputation
          api.ipify.org
          104.26.13.205
          truefalse
            unknown
            time.windows.com
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://api.ipify.org/false
              • URL Reputation: safe
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_ef0fa27a12d43fbd45649e195429e8a63ddcad7cf7e128c0file.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpfalse
                unknown
                https://api.ipify.orgfile.exe, 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://crl.mfile.exe, 00000000.00000003.1369057073.000001EA4B82D000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2599494351.000001EA4B7EF000.00000004.00000020.00020000.00000000.sdmpfalse
                  unknown
                  https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpgfile.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  https://api.ipify.org/~file.exe, 00000000.00000003.1369125819.000001EA4B7C8000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2599494351.000001EA4B7AF000.00000004.00000020.00020000.00000000.sdmpfalse
                    unknown
                    https://www.invisalign.com/?utm_source=admarketplace&utm_medium=paidsearch&utm_campaign=Invisalign&ufile.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpfalse
                      unknown
                      https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696490019400400000.2&ci=1696490019252.file.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpfalse
                        unknown
                        https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4pqWfpl%2B4pbW4pbWfpbW7ReNxR3UIG8zInwYIFIVs9efile.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpfalse
                          unknown
                          https://contile-images.services.mozilla.com/CuERQnIs4CzqjKBh9os6_h9d4CUDCHO3oiqmAQO6VLM.25122.jpgfile.exe, 00000000.00000003.1386227021.000001EA4E280000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1387286065.000001EA4E107000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpfalse
                            unknown
                            https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=file.exe, 00000000.00000003.1374444105.000001EA4E0F3000.00000004.00000020.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            https://support.mozilla.orgfile.exe, 00000000.00000003.1381574540.000001EA4D643000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D570000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1383468297.000001EA4E5D2000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D578000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1381574540.000001EA4D64B000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000003.1386227021.000001EA4E18D000.00000004.00000020.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://ns.microsoft.t/Regifile.exe, 00000000.00000003.1368512194.000001EA4DFB1000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.2600221699.000001EA4DFC0000.00000004.00000020.00020000.00000000.sdmpfalse
                              unknown
                              https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-brfile.exe, 00000000.00000003.1381574540.000001EA4D57F000.00000004.00000020.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              https://support.mozilla.org/products/firefoxgro.allizom.troppus.S3DiLP_FhcLKfile.exe, 00000000.00000003.1381574540.000001EA4D57F000.00000004.00000020.00020000.00000000.sdmpfalse
                                unknown
                                https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696490019400400000.1&ci=1696490019252.12791&ctafile.exe, 00000000.00000003.1387286065.000001EA4E0B3000.00000004.00000020.00020000.00000000.sdmpfalse
                                  unknown
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  176.124.204.206
                                  unknownRussian Federation
                                  59652GULFSTREAMUAtrue
                                  104.26.13.205
                                  api.ipify.orgUnited States
                                  13335CLOUDFLARENETUSfalse
                                  Joe Sandbox version:41.0.0 Charoite
                                  Analysis ID:1521588
                                  Start date and time:2024-09-29 00:52:10 +02:00
                                  Joe Sandbox product:CloudBasic
                                  Overall analysis duration:0h 5m 30s
                                  Hypervisor based Inspection enabled:false
                                  Report type:full
                                  Cookbook file name:default.jbs
                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                  Number of analysed new started processes analysed:8
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Sample name:file.exe
                                  Detection:MAL
                                  Classification:mal96.troj.spyw.winEXE@1/0@2/2
                                  EGA Information:
                                  • Successful, ratio: 100%
                                  HCA Information:
                                  • Successful, ratio: 97%
                                  • Number of executed functions: 86
                                  • Number of non-executed functions: 112
                                  Cookbook Comments:
                                  • Found application associated with file extension: .exe
                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                  • Excluded IPs from analysis (whitelisted): 20.101.57.9
                                  • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, twc.trafficmanager.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Report size exceeded maximum capacity and may have missing disassembly code.
                                  • Report size exceeded maximum capacity and may have missing network information.
                                  • Report size getting too big, too many NtOpenKeyEx calls found.
                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                  • VT rate limit hit for: file.exe
                                  No simulations
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  176.124.204.206file.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                    file.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                      file.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                        file.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                          mSLEwIfTGL.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                            104.26.13.205file.exeGet hashmaliciousLummaC, PrivateLoader, Stealc, VidarBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousUnknownBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, Stealc, VidarBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                            • api.ipify.org/
                                            SecuriteInfo.com.Win64.Evo-gen.13899.14592.exeGet hashmaliciousUnknownBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousLummaC, VidarBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                                            • api.ipify.org/
                                            file.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                                            • api.ipify.org/
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            api.ipify.orghttps://meta.com-case5173251.com/help/contact/500498727349033Get hashmaliciousUnknownBrowse
                                            • 104.26.12.205
                                            https://meta.com-case5173251.com/help/contact/424744076261560Get hashmaliciousUnknownBrowse
                                            • 104.26.13.205
                                            Balance payment.exeGet hashmaliciousAgentTeslaBrowse
                                            • 104.26.12.205
                                            http://glamorous-productive-baboon.glitch.me/Get hashmaliciousUnknownBrowse
                                            • 172.67.74.152
                                            http://zld.byd.mybluehost.me/Get hashmaliciousUnknownBrowse
                                            • 104.26.13.205
                                            file.exeGet hashmaliciousLummaC, PrivateLoader, Stealc, VidarBrowse
                                            • 104.26.13.205
                                            file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                            • 172.67.74.152
                                            file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                            • 104.26.13.205
                                            file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, Stealc, VidarBrowse
                                            • 172.67.74.152
                                            file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                            • 172.67.74.152
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CLOUDFLARENETUShttps://btinternet-105262.weeblysite.com/Get hashmaliciousUnknownBrowse
                                            • 104.18.86.42
                                            https://swiftversedapp.pages.dev/Get hashmaliciousHTMLPhisherBrowse
                                            • 188.114.96.3
                                            Full-Setup.exeGet hashmaliciousLummaCBrowse
                                            • 104.21.4.136
                                            https://ardam.pages.dev/Get hashmaliciousHTMLPhisherBrowse
                                            • 188.114.96.3
                                            http://krakennylog.gitbook.io/Get hashmaliciousHTMLPhisherBrowse
                                            • 104.16.117.116
                                            https://dappnoderestore.pages.dev/Get hashmaliciousHTMLPhisherBrowse
                                            • 188.114.96.3
                                            http://nftpack83.vercel.app/Get hashmaliciousHTMLPhisherBrowse
                                            • 104.17.25.14
                                            http://coin-pro-base-login.gitbook.io/Get hashmaliciousHTMLPhisherBrowse
                                            • 172.64.147.209
                                            http://nfthit7.vercel.app/Get hashmaliciousHTMLPhisherBrowse
                                            • 104.18.18.237
                                            https://server.h74w.com/invite/84350172Get hashmaliciousUnknownBrowse
                                            • 104.21.52.99
                                            GULFSTREAMUAfile.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                            • 176.124.204.206
                                            file.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                            • 176.124.204.206
                                            file.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                            • 176.124.204.206
                                            file.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                            • 176.124.204.206
                                            mSLEwIfTGL.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                            • 176.124.204.206
                                            https://darlin.com.au/Get hashmaliciousUnknownBrowse
                                            • 176.124.222.157
                                            LisectAVT_2403002A_415.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                            • 176.124.220.79
                                            qObijSd3Uj.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                            • 176.124.220.79
                                            zqixOh6Ktr.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                            • 176.124.192.196
                                            FaOty5cPp0.elfGet hashmaliciousUnknownBrowse
                                            • 176.124.192.196
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            37f463bf4616ecd445d4a1937da06e19file.exeGet hashmaliciousLummaC, VidarBrowse
                                            • 104.26.13.205
                                            file.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                                            • 104.26.13.205
                                            file.exeGet hashmaliciousVidarBrowse
                                            • 104.26.13.205
                                            file.exeGet hashmaliciousLummaC, Clipboard Hijacker, Cryptbot, LummaC Stealer, Neoreklami, Socks5SystemzBrowse
                                            • 104.26.13.205
                                            CpMQGUserR.exeGet hashmaliciousUnknownBrowse
                                            • 104.26.13.205
                                            Installer.msiGet hashmaliciousUnknownBrowse
                                            • 104.26.13.205
                                            CpMQGUserR.exeGet hashmaliciousUnknownBrowse
                                            • 104.26.13.205
                                            file.exeGet hashmaliciousRemcos, GuLoaderBrowse
                                            • 104.26.13.205
                                            New_Order-Rquest_Quotation_Specifications_Drawings_Samplespdf.bat.exeGet hashmaliciousRemcos, GuLoaderBrowse
                                            • 104.26.13.205
                                            PO-2609202412666 PNG2023-W101_pdf.bat.exeGet hashmaliciousRemcos, GuLoaderBrowse
                                            • 104.26.13.205
                                            No context
                                            No created / dropped files found
                                            File type:PE32+ executable (GUI) x86-64, for MS Windows
                                            Entropy (8bit):6.387884182537466
                                            TrID:
                                            • Win64 Executable GUI (202006/5) 92.65%
                                            • Win64 Executable (generic) (12005/4) 5.51%
                                            • Generic Win/DOS Executable (2004/3) 0.92%
                                            • DOS Executable Generic (2002/1) 0.92%
                                            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                            File name:file.exe
                                            File size:1'116'160 bytes
                                            MD5:de030225e0b09c45241b8169a8a96155
                                            SHA1:bf568cfc34b708da4e740b13e91058d3a241fdd9
                                            SHA256:85d96a1ba8fa7426e48bcf430d305c6e4764db53fb86abbe53d9b80c5e474e72
                                            SHA512:b1bf29226496e95f7959e1536cbb8346d224a0e9f8a8b241195684eb4639a96898308d2b2771d6567700a0187f79c9ece12094865666df78136c60581d90b1dd
                                            SSDEEP:24576:Al73m7L8JyNMqJUUvYo9lsnL2iq47DSuH7GJ/i+kG3O:E3m7L8YMquUvf8L2iq4a2GJaC+
                                            TLSH:C9354A151D5D02EDD4BE817C8E5A9A12F63638460371A7EB16D187523FA3BE0AF3E720
                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:%~.~D.R~D.R~D.R.6.S.D.R.6.S.D.R.:.S!D.R.:.SoD.R.:.SvD.R.6.S.D.R.6.SrD.R.6.ShD.R~D.RgE.R.6.ScD.Rj;.SqD.Rj;.R.D.Rj;.S.D.RRich~D.
                                            Icon Hash:00928e8e8686b000
                                            Entrypoint:0x1400b5714
                                            Entrypoint Section:.text
                                            Digitally signed:false
                                            Imagebase:0x140000000
                                            Subsystem:windows gui
                                            Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                            DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                            Time Stamp:0x66F81FDF [Sat Sep 28 15:25:19 2024 UTC]
                                            TLS Callbacks:
                                            CLR (.Net) Version:
                                            OS Version Major:6
                                            OS Version Minor:0
                                            File Version Major:6
                                            File Version Minor:0
                                            Subsystem Version Major:6
                                            Subsystem Version Minor:0
                                            Import Hash:2c34752585cf27cdff9273031768b19e
                                            Instruction
                                            dec eax
                                            sub esp, 28h
                                            call 00007F93B4CF97B0h
                                            dec eax
                                            add esp, 28h
                                            jmp 00007F93B4CF906Fh
                                            int3
                                            int3
                                            and dword ptr [00055831h], 00000000h
                                            ret
                                            dec eax
                                            mov dword ptr [esp+08h], ebx
                                            push ebp
                                            dec eax
                                            lea ebp, dword ptr [esp-000004C0h]
                                            dec eax
                                            sub esp, 000005C0h
                                            mov ebx, ecx
                                            mov ecx, 00000017h
                                            call dword ptr [00022B5Eh]
                                            test eax, eax
                                            je 00007F93B4CF91F6h
                                            mov ecx, ebx
                                            int 29h
                                            mov ecx, 00000003h
                                            call 00007F93B4CF91B9h
                                            xor edx, edx
                                            dec eax
                                            lea ecx, dword ptr [ebp-10h]
                                            inc ecx
                                            mov eax, 000004D0h
                                            call 00007F93B4CFB020h
                                            dec eax
                                            lea ecx, dword ptr [ebp-10h]
                                            call dword ptr [00022B01h]
                                            dec eax
                                            mov ebx, dword ptr [ebp+000000E8h]
                                            dec eax
                                            lea edx, dword ptr [ebp+000004D8h]
                                            dec eax
                                            mov ecx, ebx
                                            inc ebp
                                            xor eax, eax
                                            call dword ptr [00022AEFh]
                                            dec eax
                                            test eax, eax
                                            je 00007F93B4CF922Eh
                                            dec eax
                                            and dword ptr [esp+38h], 00000000h
                                            dec eax
                                            lea ecx, dword ptr [ebp+000004E0h]
                                            dec eax
                                            mov edx, dword ptr [ebp+000004D8h]
                                            dec esp
                                            mov ecx, eax
                                            dec eax
                                            mov dword ptr [esp+30h], ecx
                                            dec esp
                                            mov eax, ebx
                                            dec eax
                                            lea ecx, dword ptr [ebp+000004E8h]
                                            dec eax
                                            mov dword ptr [esp+28h], ecx
                                            dec eax
                                            lea ecx, dword ptr [ebp-10h]
                                            dec eax
                                            mov dword ptr [esp+20h], ecx
                                            xor ecx, ecx
                                            call dword ptr [00022AB6h]
                                            dec eax
                                            NameVirtual AddressVirtual Size Is in Section
                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x101ec80x12c.rdata
                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x1150000x1e0.rsrc
                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x10d0000x6f90.pdata
                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x1160000xd64.reloc
                                            IMAGE_DIRECTORY_ENTRY_DEBUG0xeb6f00x38.rdata
                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_TLS0xeb7800x28.rdata
                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xeb5b00x140.rdata
                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IAT0xd80000x728.rdata
                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                            .text0x10000xd680c0xd6a00f1601782b52c4cb431ea0417c6f96ab8False0.429264341875364zlib compressed data6.324100274082822IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                            .rdata0xd80000x2b6680x2b8006dc9f09c9ccb0ebc4a2dab62b6e18fd7False0.4740312948994253data5.695115421644324IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .data0x1040000x85a40x60005fbcdd9847679f1c63be9c85e41b833eFalse0.08390299479166667data4.559223452785583IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            .pdata0x10d0000x6f900x7000f381a8535b726f61cfa0a09a9a2be008False0.48440987723214285data6.038027055538376IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            _RDATA0x1140000x15c0x2003e44d45ac99d1dc88510f7cf5192f4a0False0.412109375data3.3233506391074092IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .rsrc0x1150000x1e00x200da9e8769aa702da1ca0713d6a0336d18False0.529296875data4.7122981932940915IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .reloc0x1160000xd640xe009d956dede158c1086b11601644b09e1fFalse0.482421875data5.357547607987294IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                            RT_MANIFEST0x1150600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
                                            DLLImport
                                            WS2_32.dllinet_pton, WSAStartup, send, socket, connect, recv, closesocket, htons, WSACleanup
                                            CRYPT32.dllCryptUnprotectData
                                            WININET.dllHttpQueryInfoW, InternetQueryDataAvailable, InternetReadFile, InternetCloseHandle, InternetOpenW, InternetOpenA, InternetOpenUrlA
                                            ntdll.dllNtQuerySystemInformation, RtlInitUnicodeString, NtAllocateVirtualMemory, LdrEnumerateLoadedModules, RtlAcquirePebLock, RtlReleasePebLock, NtQueryObject
                                            RstrtMgr.DLLRmGetList, RmStartSession, RmRegisterResources, RmEndSession
                                            KERNEL32.dllCompareStringEx, LCMapStringEx, FindFirstFileW, FindNextFileW, FindClose, OpenProcess, CreateToolhelp32Snapshot, Process32NextW, LoadLibraryA, Process32FirstW, CloseHandle, GetSystemInfo, GetProcAddress, LocalFree, FreeLibrary, ExitProcess, MultiByteToWideChar, WideCharToMultiByte, TerminateProcess, GetModuleFileNameW, CreateMutexA, ReleaseMutex, OpenMutexA, ReadFile, GetModuleFileNameA, GetVolumeInformationW, SetHandleInformation, GetGeoInfoA, HeapFree, EnterCriticalSection, GetCurrentProcess, GetStdHandle, GetProcessId, LeaveCriticalSection, CreatePipe, SetFilePointer, InitializeCriticalSectionEx, FreeEnvironmentStringsW, GetModuleHandleA, HeapSize, GetLogicalDriveStringsW, GetFinalPathNameByHandleA, GetTimeZoneInformation, GetLastError, lstrcatW, HeapReAlloc, HeapAlloc, GetUserGeoID, DecodePointer, GetFileSize, DeleteCriticalSection, GetComputerNameW, GetProcessHeap, GlobalMemoryStatusEx, GetModuleHandleW, lstrcpyW, SetLastError, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, IsDebuggerPresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsProcessorFeaturePresent, GetCurrentProcessId, GetSystemTimeAsFileTime, GetModuleHandleExW, GetCommandLineA, GetCommandLineW, VirtualAlloc, VirtualProtect, VirtualQuery, GetFileSizeEx, SetFilePointerEx, GetCurrentThreadId, GetFileType, GetStartupInfoW, FlushFileBuffers, WriteFile, GetConsoleOutputCP, GetConsoleMode, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, InitializeCriticalSectionAndSpinCount, LoadLibraryExW, GetDateFormatW, GetTimeFormatW, CompareStringW, LCMapStringW, GetLocaleInfoW, IsValidLocale, GetUserDefaultLCID, EnumSystemLocalesW, ReadConsoleW, RaiseException, SetStdHandle, IsValidCodePage, GetACP, SetEndOfFile, GetCPInfo, GetStringTypeW, CreateFileW, WriteConsoleW, OutputDebugStringW, SetEnvironmentVariableW, SetEvent, ResetEvent, WaitForSingleObjectEx, CreateEventW, QueryPerformanceCounter, InitializeSListHead, RtlUnwindEx, RtlUnwind, RtlPcToFileHeader, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetNativeSystemInfo, GetFileInformationByHandleEx, GetEnvironmentStringsW, CreateProcessA, GetOEMCP, AreFileApisANSI, GetTempPathW, SetFileInformationByHandle, GetFileAttributesExW, GetFileAttributesW, FindFirstFileExW, GetCurrentDirectoryW, GetLocaleInfoEx, FormatMessageA
                                            USER32.dllEnumDisplayDevicesW, GetDesktopWindow, GetWindowRect, ReleaseDC, GetSystemMetrics, GetDC
                                            GDI32.dllCreateCompatibleBitmap, SelectObject, CreateCompatibleDC, BitBlt, DeleteDC, GetObjectW, DeleteObject, GetDeviceCaps
                                            ADVAPI32.dllGetCurrentHwProfileW, RegCloseKey, RegGetValueA, RegQueryValueExA, OpenProcessToken, RegOpenKeyExA, GetUserNameW, RegEnumKeyExA, GetTokenInformation, CredEnumerateA, CredFree
                                            SHELL32.dllSHGetKnownFolderPath, ShellExecuteW
                                            ole32.dllCoInitializeSecurity, CoGetObject, CoTaskMemFree, CoUninitialize, CoCreateInstance, CoSetProxyBlanket, CoInitializeEx
                                            OLEAUT32.dllSysAllocStringByteLen, SysFreeString, SysStringByteLen
                                            SHLWAPI.dll
                                            gdiplus.dllGdipSaveImageToStream, GdipGetImageEncodersSize, GdipFree, GdiplusStartup, GdiplusShutdown, GdipGetImageEncoders, GdipCloneImage, GdipAlloc, GdipCreateBitmapFromHBITMAP, GdipDisposeImage, GdipCreateBitmapFromScan0
                                            Language of compilation systemCountry where language is spokenMap
                                            EnglishUnited States
                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                            2024-09-29T00:53:22.368592+02002049441ET MALWARE Win32/Unknown Grabber Base64 Data Exfiltration Attempt1192.168.2.749704176.124.204.20615666TCP
                                            2024-09-29T00:53:22.368592+02002050806ET MALWARE [ANY.RUN] Meduza Stealer Exfiltration M21192.168.2.749704176.124.204.20615666TCP
                                            2024-09-29T00:53:22.368592+02002050807ET MALWARE [ANY.RUN] Possible Meduza Stealer Exfiltration (TCP)1192.168.2.749704176.124.204.20615666TCP
                                            2024-09-29T00:53:22.375741+02002050806ET MALWARE [ANY.RUN] Meduza Stealer Exfiltration M21192.168.2.749704176.124.204.20615666TCP
                                            2024-09-29T00:53:22.375741+02002050807ET MALWARE [ANY.RUN] Possible Meduza Stealer Exfiltration (TCP)1192.168.2.749704176.124.204.20615666TCP
                                            TimestampSource PortDest PortSource IPDest IP
                                            Sep 29, 2024 00:53:17.022834063 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:17.030420065 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:17.030564070 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:17.566451073 CEST49705443192.168.2.7104.26.13.205
                                            Sep 29, 2024 00:53:17.566509008 CEST44349705104.26.13.205192.168.2.7
                                            Sep 29, 2024 00:53:17.566602945 CEST49705443192.168.2.7104.26.13.205
                                            Sep 29, 2024 00:53:17.578805923 CEST49705443192.168.2.7104.26.13.205
                                            Sep 29, 2024 00:53:17.578845978 CEST44349705104.26.13.205192.168.2.7
                                            Sep 29, 2024 00:53:18.053302050 CEST44349705104.26.13.205192.168.2.7
                                            Sep 29, 2024 00:53:18.053446054 CEST49705443192.168.2.7104.26.13.205
                                            Sep 29, 2024 00:53:18.127844095 CEST49705443192.168.2.7104.26.13.205
                                            Sep 29, 2024 00:53:18.127882004 CEST44349705104.26.13.205192.168.2.7
                                            Sep 29, 2024 00:53:18.128230095 CEST44349705104.26.13.205192.168.2.7
                                            Sep 29, 2024 00:53:18.128312111 CEST49705443192.168.2.7104.26.13.205
                                            Sep 29, 2024 00:53:18.129591942 CEST49705443192.168.2.7104.26.13.205
                                            Sep 29, 2024 00:53:18.175412893 CEST44349705104.26.13.205192.168.2.7
                                            Sep 29, 2024 00:53:18.240852118 CEST44349705104.26.13.205192.168.2.7
                                            Sep 29, 2024 00:53:18.240925074 CEST44349705104.26.13.205192.168.2.7
                                            Sep 29, 2024 00:53:18.240946054 CEST49705443192.168.2.7104.26.13.205
                                            Sep 29, 2024 00:53:18.240978003 CEST49705443192.168.2.7104.26.13.205
                                            Sep 29, 2024 00:53:18.241285086 CEST49705443192.168.2.7104.26.13.205
                                            Sep 29, 2024 00:53:18.241311073 CEST44349705104.26.13.205192.168.2.7
                                            Sep 29, 2024 00:53:22.368592024 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.375663996 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.375679016 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.375699997 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.375710011 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.375736952 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.375741005 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.375771999 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.375783920 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.377258062 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.377269983 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.377279997 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.377332926 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.377355099 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.377386093 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.378968954 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.379431963 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.381799936 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.381863117 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.382345915 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.382421017 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.382431984 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.382441044 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.382539988 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.382958889 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.383268118 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.384115934 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.384172916 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.384181023 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.384192944 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.384248018 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.384732008 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.384859085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.384923935 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.385890007 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.387232065 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.388123989 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.388789892 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.388849974 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.389265060 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.390417099 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.390479088 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.390654087 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.391187906 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.392412901 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.394102097 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.394177914 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.395488977 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.395498037 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.395508051 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.395560026 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.395911932 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.395962000 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.397020102 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397028923 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397063017 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.397063971 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397083998 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.397125959 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.397154093 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397557974 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397610903 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.397633076 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397663116 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397671938 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397680998 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397730112 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.397730112 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.397763968 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397774935 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.397871971 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.398261070 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.398271084 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.398308992 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.398319006 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.399214983 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.400657892 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.400667906 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.400686026 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.400693893 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.400719881 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.400719881 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.400743961 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.400757074 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.400765896 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.400774002 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.400815010 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.400830030 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.402322054 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.402369976 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.402369976 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.402380943 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.402390003 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.402399063 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.402432919 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.402445078 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.402445078 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.402488947 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.403795958 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.403805971 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.403815031 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.403866053 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.404205084 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404257059 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404267073 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404275894 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404310942 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.404328108 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.404751062 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404798031 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.404800892 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404845953 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.404885054 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404896021 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404905081 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404937983 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404947996 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404953957 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.404953957 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.404967070 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404978991 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.404992104 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.405040026 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.406049013 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.406095028 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.407342911 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.407352924 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.407370090 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.407381058 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.407402992 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.407414913 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.407428980 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.407434940 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.407444954 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.407490015 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.407864094 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.407953978 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.407974005 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.408132076 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.409189939 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.409199953 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.409209013 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.409219980 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.409236908 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.409245968 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.409256935 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.409259081 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.409280062 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.409312010 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.410878897 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.410897017 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.410907030 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.410959959 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.410968065 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.411000013 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.411015034 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.411031961 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.411046028 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.411051989 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.411072016 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.411078930 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.411094904 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.411123991 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.411534071 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.411545038 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.411600113 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.412782907 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.412794113 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.412852049 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.412880898 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.412890911 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.412904978 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.412911892 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.412919044 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.412929058 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.412941933 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.412954092 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.412955999 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.412966967 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.412969112 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.412997961 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.413012981 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.414657116 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.414668083 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.414675951 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.414689064 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.414697886 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.414716005 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.414724112 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.414747953 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.414761066 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.415834904 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.415846109 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.415853977 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.415894985 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.415894985 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.416577101 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.416588068 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.416598082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.416631937 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.416631937 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.416668892 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.416680098 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.416696072 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.416706085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.416714907 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.416737080 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.416762114 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.416779041 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.417854071 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.417865038 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.417874098 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.417882919 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.417892933 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.417906046 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.417910099 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.417912006 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.417927980 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.417943001 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.417952061 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.417957067 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.417992115 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.418458939 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.418505907 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.418579102 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.418622017 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.420101881 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420109987 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420139074 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.420156002 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.420166016 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420231104 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.420250893 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420389891 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420402050 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420413971 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420432091 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420439005 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.420466900 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.420475006 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420476913 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.420486927 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420500994 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.420528889 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.420545101 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.421765089 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.421777964 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.421787977 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.421801090 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.421818018 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.421835899 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.421849012 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.421853065 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.421859980 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.421869040 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.421902895 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.421920061 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.422911882 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.422957897 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423017979 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.423036098 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423046112 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423054934 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423099995 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.423099995 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.423552036 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423563004 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423573971 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423583984 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423604965 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423614025 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423621893 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.423623085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.423633099 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.423674107 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.424185038 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.424223900 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.424236059 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.424258947 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.424268961 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.424312115 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.424314022 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.424321890 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.424352884 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.424354076 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.424357891 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.424380064 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.424406052 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.424412966 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.424417973 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.424463987 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.425549030 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.425559998 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.425617933 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.427207947 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427218914 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427227974 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427237988 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427253962 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427263021 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427273989 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.427280903 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427285910 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.427292109 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427306890 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427313089 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.427325010 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427342892 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427344084 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.427352905 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.427360058 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.427396059 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.427407026 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.429105997 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.429116964 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.429157972 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.429168940 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.429178953 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.429181099 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.429188967 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.429214001 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.429215908 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.429227114 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.429229975 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.429263115 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.429276943 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.429944992 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.429955959 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.429994106 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430006981 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.430038929 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.430042982 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430053949 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430063009 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430100918 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.430128098 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.430565119 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430576086 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430613995 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430618048 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430627108 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.430663109 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430672884 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430675030 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.430682898 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.430713892 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.430728912 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.431252956 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.431302071 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.431312084 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.431356907 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.431361914 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.431374073 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.431390047 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.431407928 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.432118893 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.432156086 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.432183981 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.432193041 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.432203054 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.432210922 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.432226896 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.432260990 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.432276011 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.432763100 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.432774067 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.432781935 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.432822943 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.432841063 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.434181929 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434192896 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434236050 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434247971 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434248924 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.434257030 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434267998 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434278011 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434287071 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434288025 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.434297085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434315920 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.434345961 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.434828043 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434878111 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.434911013 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434921026 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434930086 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.434976101 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.434976101 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.435502052 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.435512066 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.435530901 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.435545921 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.435554981 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.435559034 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.435566902 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.435570955 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.435585022 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.435590029 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.435600042 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.435607910 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.435617924 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.435632944 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.435658932 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.436842918 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.436892033 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.436943054 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.436949968 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.436952114 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.436954021 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.436959028 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.437022924 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.437589884 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.437637091 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.437639952 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.437681913 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.437711954 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.437721968 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.437766075 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.437798977 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.437808990 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.437851906 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.437869072 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.438349009 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.438492060 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.438548088 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.439702988 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.439718962 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.439724922 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.439727068 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.439779997 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.440253973 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440263987 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440315008 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.440341949 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440351963 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440362930 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440373898 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440395117 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.440407991 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440419912 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440421104 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.440458059 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.440557957 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440568924 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440577030 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.440608978 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.440627098 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.442095995 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442116022 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442126036 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442133904 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442174911 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.442193031 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.442298889 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442308903 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442337990 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442347050 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442351103 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.442388058 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442389011 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.442399025 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442433119 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.442461967 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.442863941 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442874908 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442918062 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.442920923 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442931890 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.442970991 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.444591999 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444602966 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444612980 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444622993 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444642067 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444652081 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444657087 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.444663048 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444673061 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444685936 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444694042 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.444694996 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444715023 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444722891 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.444725037 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444736004 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444751978 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.444768906 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.444785118 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.444808960 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444822073 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444830894 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444839954 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.444861889 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.444886923 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.445277929 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.445287943 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.445307016 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.445316076 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.445322990 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.445327997 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.445348978 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.445358038 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.445368052 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.445391893 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.447052002 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447062969 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447114944 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.447124004 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447134972 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447143078 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447153091 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447160959 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447174072 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.447196960 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.447207928 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.447673082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447717905 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447724104 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447763920 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447771072 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.447774887 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447788000 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447798014 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447805882 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.447815895 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.447865009 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.447865009 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.448916912 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.448926926 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.448945999 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.448955059 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.448981047 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.448997974 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.449531078 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.449552059 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.449556112 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.449563980 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.449570894 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.449604988 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.450114965 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.450125933 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.450135946 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.450145006 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.450162888 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.450167894 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.450179100 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.450187922 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.450207949 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.451848984 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.451859951 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.451869965 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.451884031 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.451894045 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.451913118 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.451941967 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.452387094 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452397108 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452414036 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452423096 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452459097 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.452476025 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.452495098 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452505112 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452513933 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452522039 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452539921 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452548981 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452553988 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.452568054 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.452569008 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.452584982 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.452608109 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.452621937 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.453021049 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.453032017 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.453051090 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.453068972 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.453083038 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.453099012 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.453102112 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.453113079 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.453123093 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.453131914 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.453159094 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.453176975 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.454288960 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.454299927 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.454334021 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.454339981 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.454344034 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.454355955 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.454360962 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.454363108 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.454377890 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.454401016 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.454415083 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.455542088 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.455552101 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.455558062 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.455605984 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.462323904 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.463956118 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.463964939 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.463985920 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.464122057 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.464199066 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.464212894 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472315073 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472327948 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472346067 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472354889 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472388983 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472409964 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472430944 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472440958 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472457886 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472467899 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472481966 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472486019 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472491980 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472502947 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472510099 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472511053 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472529888 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472539902 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472541094 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472552061 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472553015 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472562075 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472573042 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472582102 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472585917 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472595930 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472634077 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472673893 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472683907 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472692966 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472702026 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472709894 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472718000 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472722054 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472727060 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472738981 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.472763062 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.472785950 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.513408899 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.517299891 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.517409086 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.517429113 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.557571888 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.561304092 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.561398029 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.561417103 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.567846060 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.567903996 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.567903042 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.567914963 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.567924976 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.567939997 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.567945957 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.567958117 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.567961931 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.567971945 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.567980051 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568007946 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568017006 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568023920 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568026066 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568038940 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568056107 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568073988 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568084002 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568093061 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568104029 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568105936 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568119049 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568135977 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568141937 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568145990 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568151951 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568157911 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568162918 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568172932 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568182945 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568193913 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568193913 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568203926 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568213940 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568222046 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568222046 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568232059 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568249941 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568250895 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568259954 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568279028 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568284988 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568294048 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568295002 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568304062 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568317890 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568319082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568325043 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568329096 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.568358898 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.568375111 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.569907904 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.569916964 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.569926023 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.569936037 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.569955111 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.569981098 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.569996119 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570007086 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570017099 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570025921 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570029020 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570034981 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570044994 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570054054 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570070028 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570075035 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570076942 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570087910 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570087910 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570099115 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570106983 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570108891 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570118904 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570122004 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570130110 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570142031 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570149899 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570162058 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570167065 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570172071 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570182085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570184946 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570200920 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570208073 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570210934 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570228100 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570235014 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570244074 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570246935 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570264101 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570272923 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570287943 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570296049 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570317030 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570333958 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570346117 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570353985 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570364952 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.570372105 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570391893 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.570415020 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.574124098 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574134111 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574286938 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.574692965 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574703932 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574707031 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574712992 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574724913 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574754953 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.574774981 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.574794054 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574805021 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574814081 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574840069 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.574862957 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.574908972 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574918985 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574935913 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574945927 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574954033 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574956894 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.574964046 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574974060 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.574980021 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.574984074 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.575001955 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.575011015 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.575016975 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.575021029 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.575030088 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.575041056 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.575050116 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.575057983 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.575058937 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.575069904 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.575117111 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.617463112 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.617660999 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.617779016 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.617824078 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622626066 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622637033 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622644901 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622667074 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622675896 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622689009 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622694016 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622704029 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622725964 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622728109 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622735977 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622746944 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622746944 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622759104 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622775078 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622780085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622791052 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622791052 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622800112 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622808933 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622818947 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622855902 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622878075 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622889042 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622896910 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622905970 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622915030 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622922897 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622924089 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622946024 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622957945 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622958899 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622967005 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.622971058 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.622977972 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623003006 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.623011112 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623020887 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623028994 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623034000 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.623039007 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623049021 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.623058081 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623066902 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623084068 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.623109102 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.623114109 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623116970 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623119116 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623120070 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623125076 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623172045 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623182058 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.623182058 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623192072 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623204947 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.623222113 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.623253107 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.665385962 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.665570974 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.665672064 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.665699959 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.696312904 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.696600914 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.696727991 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.696758032 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701497078 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701508999 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701525927 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701534986 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701555014 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701587915 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701601028 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701607943 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701616049 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701621056 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701632023 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701637030 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701642990 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701666117 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701692104 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701704979 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701714993 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701721907 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701744080 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701746941 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701755047 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701762915 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701764107 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701792955 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701795101 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701809883 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701838017 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701847076 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701855898 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701891899 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701905012 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701915026 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701922894 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701931000 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701946974 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701976061 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701980114 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.701986074 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.701993942 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702003002 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702012062 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702014923 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.702033997 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702039003 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.702044010 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702052116 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702056885 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.702085018 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.702107906 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702117920 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702125072 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.702142000 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702142954 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.702151060 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702167034 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.702193975 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.702219009 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702229023 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.702261925 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.745440960 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.745548964 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.745636940 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.755640984 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.755784035 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.755872011 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.755898952 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.760715961 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.760740995 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.760754108 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.760763884 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.760770082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.760788918 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.760823965 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.760900021 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.760936022 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.760967016 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761008024 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761013031 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761059046 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761065006 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761112928 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761141062 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761179924 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761189938 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761198997 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761209965 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761236906 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761255026 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761282921 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761292934 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761296988 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761333942 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761497974 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761512995 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761542082 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761552095 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761567116 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761585951 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761641026 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761650085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761687040 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761689901 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761737108 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761769056 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761781931 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761805058 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761806965 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761826038 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761831045 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761846066 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761866093 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761874914 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761904001 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.761962891 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761972904 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761981010 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.761989117 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762006998 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762023926 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762029886 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762032986 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762038946 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762063980 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762087107 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762109041 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762171030 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762180090 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762187958 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762201071 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762216091 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762232065 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762247086 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762306929 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762347937 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762350082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762362003 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762392044 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762404919 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762408972 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762448072 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762449980 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762491941 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762521029 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762532949 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762556076 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762561083 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762573004 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762604952 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.762615919 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.762659073 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.765712976 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.765753031 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.765763998 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.765808105 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.765860081 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.765896082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.765909910 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.765938044 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.766022921 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766066074 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.766139984 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766179085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766180992 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.766218901 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.766433954 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766446114 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766450882 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766460896 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766495943 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.766518116 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.766527891 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766583920 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.766602993 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766647100 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.766704082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766747952 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.766809940 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.766844988 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.766999960 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767009974 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767044067 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767045021 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767086983 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767095089 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767102957 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767151117 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767232895 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767250061 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767292023 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767318964 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767348051 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767414093 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767424107 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767429113 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767453909 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767456055 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767467976 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767473936 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767493963 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767503977 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767513990 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767518997 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767554045 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767596960 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767606974 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767647028 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767648935 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767657042 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767700911 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767735004 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767745972 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767772913 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767791986 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767801046 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767808914 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767824888 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767842054 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767868996 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767869949 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767910004 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.767914057 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767925978 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.767959118 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.770561934 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.770603895 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.770608902 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.770649910 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.770795107 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.770803928 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.770812035 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.770834923 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.770860910 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771003962 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771013021 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771050930 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771327972 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771369934 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771368980 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771413088 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771423101 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771434069 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771466970 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771481991 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771512985 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771553040 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771563053 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771574974 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771600008 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771620035 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771647930 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771661043 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771671057 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.771688938 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771722078 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.771949053 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772022963 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772034883 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772052050 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772068024 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772072077 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772110939 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772126913 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772136927 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772175074 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772200108 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772222042 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772243977 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772279978 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772324085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772361994 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772427082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772469997 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772504091 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772547960 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772583961 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772593975 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772603989 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772634029 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772636890 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772649050 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772659063 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772680998 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772691011 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772732019 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772742987 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772787094 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772810936 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772852898 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.772860050 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.772905111 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.773127079 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.773139000 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.773164988 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.773176908 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.773207903 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.773230076 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.775449991 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.775516033 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.775525093 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.775549889 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.775574923 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.775592089 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.775618076 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.775635004 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.775715113 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.775723934 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.775765896 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.775953054 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.775960922 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776001930 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776241064 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776288033 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776355982 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776365042 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776371956 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776401997 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776402950 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776417971 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776448011 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776451111 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776479959 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776499033 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776521921 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776573896 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776582956 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776591063 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776621103 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776626110 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776638031 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776671886 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776863098 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.776906967 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.776993036 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777002096 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777041912 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777045012 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777067900 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777076960 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777090073 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777107954 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777177095 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777187109 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777242899 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777278900 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777324915 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777470112 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777512074 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777630091 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777657032 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777676105 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777699947 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777707100 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777708054 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777749062 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777767897 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777777910 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777817965 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777848959 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777858019 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777864933 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777898073 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777914047 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.777940989 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.777987957 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.778049946 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.778076887 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.778090000 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.778115988 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.778136015 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.778178930 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.778203964 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.778212070 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.778253078 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.778266907 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.778275967 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.778283119 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.778342962 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.780426025 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.780435085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.780488014 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.780543089 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.780590057 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.780725956 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.780736923 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.780775070 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.780843973 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.780879021 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.780881882 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.780930042 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.781104088 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781150103 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.781172991 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781212091 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.781235933 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781279087 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.781308889 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781316996 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781356096 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.781400919 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781414032 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781450987 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.781461954 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781514883 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.781580925 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781591892 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781651020 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.781896114 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781904936 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781944036 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.781960011 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.781980991 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.781982899 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782011032 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.782022953 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.782107115 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782150030 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.782172918 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782215118 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.782310009 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782341003 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782346964 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.782351017 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782391071 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.782509089 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782517910 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782562017 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.782644033 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782691002 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.782716036 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782758951 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.782969952 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782980919 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.782989979 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783006907 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783015013 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.783034086 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.783060074 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.783101082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783109903 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783157110 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.783191919 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783195972 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783201933 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783210993 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783236027 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.783265114 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.783334970 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783375978 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.783596992 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783641100 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.783701897 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783710003 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783718109 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.783749104 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.783770084 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.785237074 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.785300016 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.785501003 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.785514116 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.785564899 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.785691977 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.785744905 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.785753965 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.785801888 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786043882 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786052942 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786087036 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786148071 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786150932 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786201954 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786209106 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786220074 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786264896 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786274910 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786322117 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786326885 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786353111 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786370039 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786396027 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786406994 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786441088 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786443949 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786490917 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786518097 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786566019 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786583900 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786631107 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786823034 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786874056 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.786941051 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.786983013 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.787067890 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.787117958 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.829586029 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.829804897 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.829901934 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.829966068 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.841779947 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.841984987 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.842081070 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.842138052 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847053051 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847112894 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847155094 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847165108 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847227097 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847301960 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847357988 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847408056 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847429037 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847469091 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847475052 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847507954 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847508907 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847522020 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847548962 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847553015 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847598076 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847661018 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847670078 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847712040 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847733974 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847783089 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847917080 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847927094 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847944975 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847955942 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.847978115 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.847992897 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848006010 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848016024 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848054886 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848088980 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848135948 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848162889 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848212004 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848304033 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848354101 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848383904 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848392963 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848414898 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848429918 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848450899 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848462105 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848612070 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848620892 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848629951 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848671913 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848684072 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848690033 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848699093 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848707914 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848757982 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848824024 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848862886 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848880053 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848903894 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.848912954 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.848963022 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.849004984 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849015951 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849061966 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.849067926 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849088907 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849124908 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.849139929 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.849164963 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849215031 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.849231958 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849241972 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849256039 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849288940 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.849311113 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.849385023 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849394083 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849402905 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849442959 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.849468946 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.849477053 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.849525928 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852063894 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852123022 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852157116 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852171898 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852184057 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852204084 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852207899 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852229118 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852242947 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852264881 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852269888 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852325916 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852788925 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852799892 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852808952 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852817059 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852827072 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852835894 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852844954 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852847099 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852853060 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852861881 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852870941 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852874994 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852888107 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852895021 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852895975 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852907896 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852912903 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852917910 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852926970 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852941036 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852943897 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852967024 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.852971077 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.852993011 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.853009939 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.853094101 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853142977 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.853157043 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853166103 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853213072 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.853317976 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853369951 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.853502035 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853512049 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853568077 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.853574991 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853614092 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853627920 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.853629112 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853662968 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.853677034 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.853830099 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853840113 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.853888035 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.854233980 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.854291916 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.854341984 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.854460001 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.854475975 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.854485035 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.854509115 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.854527950 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.857105017 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.857167959 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.857177973 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.857237101 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.857781887 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.857831001 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.857968092 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858023882 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858032942 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858038902 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858042955 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858072996 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858083010 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858087063 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858093023 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858139992 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858190060 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858200073 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858207941 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858242035 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858256102 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858299971 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858311892 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858323097 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858339071 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858361006 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858369112 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858388901 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858411074 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858493090 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858541965 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858582020 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858591080 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858634949 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858638048 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858654976 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858664989 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858674049 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858684063 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858710051 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858736992 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858748913 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858757973 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858810902 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858830929 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858839989 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858848095 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858856916 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.858885050 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.858906031 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.860320091 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860373020 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.860409975 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860419035 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860426903 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860454082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860464096 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860482931 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.860507011 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.860946894 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860956907 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860965967 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860975027 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860982895 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.860991955 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.861000061 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.861006021 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.861008883 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.861016989 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.861052036 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.861089945 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.861988068 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.862045050 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.862114906 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.862170935 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.862315893 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.862325907 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.862334013 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.862368107 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.862385035 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.862970114 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.862979889 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.862987995 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863035917 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863040924 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863094091 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863133907 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863204956 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863251925 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863261938 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863272905 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863322020 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863336086 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863389969 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863446951 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863511086 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863511086 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863521099 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863565922 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863604069 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863614082 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863661051 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863686085 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863696098 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863744020 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863781929 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863792896 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863837004 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863864899 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.863913059 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.863950968 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.864010096 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.865319967 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.865374088 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.865886927 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.865896940 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.865947962 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.865973949 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.865983009 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.865992069 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866029978 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.866034031 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866051912 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866085052 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.866102934 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.866146088 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866197109 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866223097 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.866250992 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.866275072 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866337061 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.866421938 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866431952 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866441011 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866476059 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.866477013 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866492033 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.866523981 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.866919994 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.866967916 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.867163897 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.867213011 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.867228985 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.867238998 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.867281914 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.867288113 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.867336988 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.867357016 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.867366076 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.867422104 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.867952108 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868004084 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.868575096 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868586063 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868596077 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868604898 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868613958 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868623018 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868633032 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868643045 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868679047 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.868721008 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868729115 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.868731022 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868760109 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868779898 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.868814945 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.868880987 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868891001 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868932962 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868932962 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.868949890 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868959904 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.868980885 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.868993044 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.869012117 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.869045019 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.870587111 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.870639086 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.870865107 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.870932102 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.870939016 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.871006012 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.871010065 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.871021986 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.871068001 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.871124029 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.871176004 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.871251106 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.871300936 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.871403933 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.871426105 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.871464014 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.871824980 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.871880054 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.883071899 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.883209944 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.885060072 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.885113001 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.885452986 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.885535955 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.885648966 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.885658979 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.885737896 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.886027098 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.886037111 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.886116028 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.886689901 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.886768103 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.889544964 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.889683962 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.892046928 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.892167091 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.892883062 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.892998934 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.895092010 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.895103931 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.895211935 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.895585060 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.895636082 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.898432970 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.898596048 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.898670912 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.898696899 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.900152922 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.900209904 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.902256966 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.902379036 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.903989077 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.904057980 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.904356956 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.904453993 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.905673981 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.905801058 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.907396078 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.907449007 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.909250021 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.909373999 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.909533978 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.909600973 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.911324024 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.911398888 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.911428928 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.911500931 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.911518097 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.911565065 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.911569118 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.911614895 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.912589073 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.912638903 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.914773941 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.914778948 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.914884090 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.915009022 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.915088892 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.915230036 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.915292025 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.916713953 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.916822910 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.918613911 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.918725014 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.920751095 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.920892954 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.920958996 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.921737909 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.921792030 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.922446966 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.922549009 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.924494028 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.924618959 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.927505970 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.927515030 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.927643061 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.927707911 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.932686090 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.932838917 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.932904959 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.932923079 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.933429003 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.933569908 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.933638096 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.937735081 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.937810898 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.939779997 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.939961910 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.940032005 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.940079927 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.940136909 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.940152884 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.942653894 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.942704916 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.944845915 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.944900036 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.945230007 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.945314884 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.946808100 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.946939945 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.946999073 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.947043896 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.947556019 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.947613001 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.949851036 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.949901104 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.968492031 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:22.968679905 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.968758106 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.968811989 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.968868971 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:22.968892097 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.021528006 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:23.021769047 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.021888971 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.021950960 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.022016048 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.022047997 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.070522070 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:23.070749044 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.070838928 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.070884943 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.070943117 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.070956945 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.117435932 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:23.117604017 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.117697001 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.117746115 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.117809057 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.117830038 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.169440985 CEST1566649704176.124.204.206192.168.2.7
                                            Sep 29, 2024 00:53:23.169625998 CEST4970415666192.168.2.7176.124.204.206
                                            Sep 29, 2024 00:53:23.169729948 CEST4970415666192.168.2.7176.124.204.206
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Sep 29, 2024 00:53:13.088953972 CEST192.168.2.71.1.1.10x5020Standard query (0)time.windows.comA (IP address)IN (0x0001)false
                                            Sep 29, 2024 00:53:17.552046061 CEST192.168.2.71.1.1.10x581aStandard query (0)api.ipify.orgA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Sep 29, 2024 00:53:13.097594023 CEST1.1.1.1192.168.2.70x5020No error (0)time.windows.comtwc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                            Sep 29, 2024 00:53:17.561027050 CEST1.1.1.1192.168.2.70x581aNo error (0)api.ipify.org104.26.13.205A (IP address)IN (0x0001)false
                                            Sep 29, 2024 00:53:17.561027050 CEST1.1.1.1192.168.2.70x581aNo error (0)api.ipify.org172.67.74.152A (IP address)IN (0x0001)false
                                            Sep 29, 2024 00:53:17.561027050 CEST1.1.1.1192.168.2.70x581aNo error (0)api.ipify.org104.26.12.205A (IP address)IN (0x0001)false
                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            0192.168.2.749705104.26.13.2054432064C:\Users\user\Desktop\file.exe
                                            TimestampBytes transferredDirectionData
                                            2024-09-28 22:53:18 UTC100OUTGET / HTTP/1.1
                                            Accept: text/html; text/plain; */*
                                            Host: api.ipify.org
                                            Cache-Control: no-cache
                                            2024-09-28 22:53:18 UTC211INHTTP/1.1 200 OK
                                            Date: Sat, 28 Sep 2024 22:53:18 GMT
                                            Content-Type: text/plain
                                            Content-Length: 11
                                            Connection: close
                                            Vary: Origin
                                            CF-Cache-Status: DYNAMIC
                                            Server: cloudflare
                                            CF-RAY: 8ca74f0cabe6c45e-EWR
                                            2024-09-28 22:53:18 UTC11INData Raw: 38 2e 34 36 2e 31 32 33 2e 33 33
                                            Data Ascii: 8.46.123.33


                                            Click to jump to process

                                            Click to jump to process

                                            Click to dive into process behavior distribution

                                            Target ID:0
                                            Start time:18:53:16
                                            Start date:28/09/2024
                                            Path:C:\Users\user\Desktop\file.exe
                                            Wow64 process (32bit):false
                                            Commandline:"C:\Users\user\Desktop\file.exe"
                                            Imagebase:0x7ff7632d0000
                                            File size:1'116'160 bytes
                                            MD5 hash:DE030225E0B09C45241B8169A8A96155
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_MeduzaStealer, Description: Yara detected Meduza Stealer, Source: 00000000.00000002.2599494351.000001EA4B76A000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:low
                                            Has exited:false

                                            Reset < >

                                              Execution Graph

                                              Execution Coverage:7%
                                              Dynamic/Decrypted Code Coverage:0%
                                              Signature Coverage:38.2%
                                              Total number of Nodes:2000
                                              Total number of Limit Nodes:108
                                              execution_graph 69066 7ff76334783a 69067 7ff763347855 69066->69067 69068 7ff76334bb70 92 API calls 69067->69068 69069 7ff76334788f 69068->69069 69070 7ff763347899 69069->69070 69071 7ff76334797e 69069->69071 69144 7ff76334bc60 92 API calls Concurrency::cancel_current_task 69070->69144 69072 7ff763334e60 92 API calls 69071->69072 69075 7ff763347a01 69072->69075 69074 7ff763347a45 OpenMutexA 69077 7ff763347a8a ExitProcess 69074->69077 69078 7ff763347a96 CreateMutexExA 69074->69078 69075->69074 69076 7ff763347a40 ISource 69075->69076 69080 7ff763347c05 69075->69080 69076->69074 69082 7ff763347ac7 69078->69082 69079 7ff7633478d2 69081 7ff763347975 ExitProcess 69079->69081 69145 7ff76333f820 100 API calls 3 library calls 69079->69145 69083 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69080->69083 69086 7ff7633529e0 98 API calls 69082->69086 69085 7ff763347c0a 69083->69085 69088 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69085->69088 69087 7ff763347acc 69086->69087 69089 7ff763347adc 69087->69089 69090 7ff763347ad0 ExitProcess 69087->69090 69092 7ff763347c10 69088->69092 69091 7ff76335b410 216 API calls 69089->69091 69096 7ff763347ae1 69091->69096 69093 7ff763347967 69093->69081 69094 7ff763347900 69094->69093 69095 7ff7633152c0 126 API calls 69094->69095 69097 7ff763347925 69095->69097 69098 7ff76330d510 96 API calls 69096->69098 69146 7ff763311300 RtlPcToFileHeader RaiseException 69097->69146 69100 7ff763347ae7 69098->69100 69103 7ff76330e5a0 133 API calls 69100->69103 69101 7ff763347935 69147 7ff763341800 86 API calls _Strxfrm 69101->69147 69104 7ff763347af4 69103->69104 69105 7ff76330ec50 130 API calls 69104->69105 69106 7ff763347af9 69105->69106 69108 7ff76330fa60 133 API calls 69106->69108 69107 7ff763347945 69110 7ff763311990 83 API calls 69107->69110 69109 7ff763347afe 69108->69109 69111 7ff76330c9c0 88 API calls 69109->69111 69110->69093 69112 7ff763347b03 69111->69112 69113 7ff7633314c0 115 API calls 69112->69113 69114 7ff763347b08 69113->69114 69115 7ff7633341a0 115 API calls 69114->69115 69116 7ff763347b0d 69115->69116 69117 7ff763302c20 85 API calls 69116->69117 69118 7ff763347b12 69117->69118 69119 7ff76330ae00 225 API calls 69118->69119 69120 7ff763347b17 69119->69120 69121 7ff76334ff00 138 API calls 69120->69121 69122 7ff763347b21 69121->69122 69123 7ff76330bee0 220 API calls 69122->69123 69124 7ff763347b26 69123->69124 69125 7ff763307810 86 API calls 69124->69125 69126 7ff763347b2b 69125->69126 69127 7ff763307b00 89 API calls 69126->69127 69128 7ff763347b35 69127->69128 69129 7ff763357bc0 103 API calls 69128->69129 69130 7ff763347b3b 69129->69130 69148 7ff763342540 94 API calls 3 library calls 69130->69148 69132 7ff763347b48 69133 7ff763347b4d ReleaseMutex CloseHandle 69132->69133 69134 7ff763347b5f 69132->69134 69133->69134 69135 7ff763347b68 69134->69135 69136 7ff763347b6e 69134->69136 69149 7ff763347c20 88 API calls 4 library calls 69135->69149 69136->69085 69138 7ff763347ba8 ISource 69136->69138 69139 7ff7633471a0 408 API calls 69138->69139 69141 7ff763347bd3 69139->69141 69140 7ff763347b6d 69140->69136 69142 7ff763384bd0 _Strxfrm 8 API calls 69141->69142 69143 7ff763347be5 69142->69143 69144->69079 69145->69094 69146->69101 69147->69107 69148->69132 69149->69140 65076 7ff763359edb RegOpenKeyExA 65077 7ff763359f05 RegQueryValueExA 65076->65077 65085 7ff763359f7d ISource 65076->65085 65082 7ff763359f44 65077->65082 65077->65085 65078 7ff763359fda 65091 7ff763384bd0 65078->65091 65079 7ff763359fd4 RegCloseKey 65079->65078 65086 7ff7633119f0 65082->65086 65085->65078 65085->65079 65087 7ff763311a33 ISource 65086->65087 65088 7ff763311a05 65086->65088 65087->65085 65088->65087 65100 7ff7633686d8 65088->65100 65092 7ff763384bd9 65091->65092 65093 7ff763359fed 65092->65093 65094 7ff763385254 IsProcessorFeaturePresent 65092->65094 65095 7ff76338526c 65094->65095 65111 7ff763385448 RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind 65095->65111 65097 7ff76338527f 65112 7ff763385220 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 65097->65112 65105 7ff76336854c 83 API calls _invalid_parameter_noinfo_noreturn 65100->65105 65102 7ff7633686f1 65106 7ff763368708 IsProcessorFeaturePresent 65102->65106 65105->65102 65107 7ff76336871b 65106->65107 65110 7ff7633683e8 14 API calls 3 library calls 65107->65110 65109 7ff763368736 GetCurrentProcess TerminateProcess 65110->65109 65111->65097 65113 7ff763316d59 65114 7ff763316d77 65113->65114 65115 7ff763316de2 65114->65115 65116 7ff763316db6 65114->65116 65120 7ff763384e90 std::_Facet_Register 86 API calls 65115->65120 65123 7ff763316dcb _Strxfrm 65115->65123 65117 7ff763316e6e 65116->65117 65118 7ff763316dc3 65116->65118 65136 7ff7632fd390 86 API calls 2 library calls 65117->65136 65126 7ff763384e90 65118->65126 65120->65123 65122 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65125 7ff763316e79 65122->65125 65123->65122 65124 7ff763316e35 ISource _Strxfrm 65123->65124 65128 7ff763384e9b 65126->65128 65129 7ff763384eb4 65128->65129 65132 7ff763384eba 65128->65132 65137 7ff763380150 65128->65137 65140 7ff763370454 65128->65140 65129->65123 65131 7ff763384ec5 65148 7ff7632fd390 86 API calls 2 library calls 65131->65148 65132->65131 65147 7ff763385cac RtlPcToFileHeader RaiseException Concurrency::cancel_current_task std::bad_alloc::bad_alloc 65132->65147 65135 7ff763384ecb 65136->65123 65149 7ff76338018c 65137->65149 65141 7ff7633767a4 wcsftime 65140->65141 65142 7ff7633767ef 65141->65142 65144 7ff7633767d6 HeapAlloc 65141->65144 65146 7ff763380150 std::_Facet_Register 2 API calls 65141->65146 65155 7ff76336cb7c 11 API calls _Strcoll 65142->65155 65144->65141 65145 7ff7633767ed 65144->65145 65145->65128 65146->65141 65147->65131 65148->65135 65154 7ff763372f5c EnterCriticalSection 65149->65154 65155->65145 69150 7ff76336247e 69155 7ff763362df0 69150->69155 69153 7ff763384bd0 _Strxfrm 8 API calls 69154 7ff7633624bb 69153->69154 69156 7ff763362e0e 69155->69156 69157 7ff763362e41 69156->69157 69158 7ff76333bc80 86 API calls 69156->69158 69159 7ff763363710 86 API calls 69157->69159 69158->69157 69161 7ff763362e7a 69159->69161 69160 7ff763362486 69160->69153 69161->69160 69163 7ff763363710 86 API calls 69161->69163 69164 7ff763317540 86 API calls 5 library calls 69161->69164 69163->69161 69164->69161 65156 7ff76335fa58 65157 7ff76335fa7e 65156->65157 65176 7ff76335fa69 65156->65176 65158 7ff76335fa87 65157->65158 65172 7ff76335fc2b 65157->65172 65175 7ff76335fae1 65158->65175 65196 7ff7633118d0 65158->65196 65159 7ff76335fcd7 65163 7ff763360440 89 API calls 65159->65163 65161 7ff763384bd0 _Strxfrm 8 API calls 65162 7ff7633602eb 65161->65162 65164 7ff76335fcf0 65163->65164 65168 7ff76335fa00 8 API calls 65164->65168 65165 7ff763360440 89 API calls 65165->65172 65166 7ff76335fba0 65167 7ff763360440 89 API calls 65166->65167 65170 7ff76335fbd2 65167->65170 65168->65176 65173 7ff76335fa00 8 API calls 65170->65173 65171 7ff76335fa00 8 API calls 65171->65172 65172->65159 65172->65165 65172->65171 65173->65176 65175->65166 65177 7ff763360440 65175->65177 65192 7ff76335fa00 65175->65192 65176->65161 65178 7ff76336047f 65177->65178 65183 7ff763360683 65177->65183 65180 7ff7633606ff 65178->65180 65185 7ff76336067e 65178->65185 65202 7ff76332adc0 86 API calls 65178->65202 65203 7ff76332ae20 8 API calls _Strxfrm 65180->65203 65182 7ff763360720 65204 7ff7633163e0 65182->65204 65183->65175 65185->65183 65188 7ff7633163e0 86 API calls 65185->65188 65189 7ff763360794 65188->65189 65190 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65189->65190 65191 7ff7633607a5 65190->65191 65191->65175 65193 7ff76335fa2d 65192->65193 65194 7ff763384bd0 _Strxfrm 8 API calls 65193->65194 65195 7ff7633602eb 65194->65195 65195->65175 65197 7ff7633118e5 65196->65197 65198 7ff7633118fb 65196->65198 65197->65175 65201 7ff763311915 memcpy_s 65198->65201 65245 7ff7633176b0 65198->65245 65200 7ff763311961 65200->65175 65201->65175 65202->65178 65203->65182 65205 7ff763316437 65204->65205 65227 7ff7633004b0 65205->65227 65207 7ff763316473 ISource 65208 7ff763316647 65207->65208 65211 7ff76331664d 65207->65211 65212 7ff763316653 65207->65212 65237 7ff763386b14 65207->65237 65209 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65208->65209 65209->65211 65213 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65211->65213 65216 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65212->65216 65213->65212 65214 7ff7633165c2 65215 7ff76331660f ISource 65214->65215 65219 7ff763316642 65214->65219 65218 7ff763384bd0 _Strxfrm 8 API calls 65215->65218 65217 7ff763316659 65216->65217 65220 7ff763316634 65218->65220 65221 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65219->65221 65222 7ff763387db4 65220->65222 65221->65208 65223 7ff763387dd3 65222->65223 65224 7ff763387df0 RtlPcToFileHeader 65222->65224 65223->65224 65225 7ff763387e17 RaiseException 65224->65225 65226 7ff763387e08 65224->65226 65225->65185 65226->65225 65228 7ff7633004eb 65227->65228 65230 7ff763300620 65228->65230 65243 7ff763317540 86 API calls 5 library calls 65228->65243 65231 7ff7633006c3 ISource 65230->65231 65233 7ff7633006fc 65230->65233 65232 7ff763384bd0 _Strxfrm 8 API calls 65231->65232 65234 7ff7633006e8 65232->65234 65235 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65233->65235 65234->65207 65236 7ff763300701 ISource __std_exception_destroy 65235->65236 65236->65207 65238 7ff763386b6a __std_exception_destroy 65237->65238 65239 7ff763386b35 65237->65239 65238->65214 65239->65238 65240 7ff763370454 _Yarn 12 API calls 65239->65240 65241 7ff763386b53 65240->65241 65241->65238 65244 7ff76336f09c 83 API calls 2 library calls 65241->65244 65243->65230 65244->65238 65246 7ff7633176de 65245->65246 65247 7ff763317842 65245->65247 65250 7ff763317748 65246->65250 65251 7ff763317774 65246->65251 65260 7ff7632fd450 86 API calls 65247->65260 65249 7ff763317847 65261 7ff7632fd390 86 API calls 2 library calls 65249->65261 65250->65249 65252 7ff763317755 65250->65252 65253 7ff76331775d memcpy_s _Strxfrm 65251->65253 65256 7ff763384e90 std::_Facet_Register 86 API calls 65251->65256 65255 7ff763384e90 std::_Facet_Register 86 API calls 65252->65255 65257 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65253->65257 65259 7ff7633177f1 ISource memcpy_s _Strxfrm 65253->65259 65255->65253 65256->65253 65258 7ff763317853 65257->65258 65259->65200 65261->65253 69165 7ff763307671 69166 7ff7632ff3f0 83 API calls 69165->69166 69167 7ff7633076a4 FindNextFileW 69166->69167 69168 7ff7633076c2 69167->69168 69169 7ff763384bd0 _Strxfrm 8 API calls 69168->69169 69170 7ff7633076e9 69169->69170 65262 7ff763301d4e 65263 7ff763301d54 _Strxfrm 65262->65263 65264 7ff763301d6c 65262->65264 65265 7ff763301d7d 65264->65265 65266 7ff763301dc2 65264->65266 65267 7ff763301dcd 65264->65267 65269 7ff763384e90 std::_Facet_Register 86 API calls 65265->65269 65266->65265 65268 7ff763301e10 65266->65268 65270 7ff763384e90 std::_Facet_Register 86 API calls 65267->65270 65273 7ff763301d98 _Strxfrm 65267->65273 65276 7ff7632fd390 86 API calls 2 library calls 65268->65276 65272 7ff763301d93 65269->65272 65270->65273 65272->65273 65274 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65272->65274 65275 7ff763301e1b 65274->65275 65276->65272 65277 7ff76335aae6 65279 7ff76335aaf8 ISource 65277->65279 65278 7ff76335b0bb 65281 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65278->65281 65279->65278 65308 7ff76335b0b5 65279->65308 65309 7ff76334d4d0 65279->65309 65280 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65280->65278 65283 7ff76335b0c1 65281->65283 65285 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65283->65285 65284 7ff76335ac0a 65288 7ff76335ac1a ISource 65284->65288 65313 7ff763317540 86 API calls 5 library calls 65284->65313 65287 7ff76335b0c7 65285->65287 65289 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65287->65289 65288->65283 65288->65287 65290 7ff76335b0cd 65288->65290 65292 7ff76335b0d3 65288->65292 65294 7ff76335b0d9 65288->65294 65296 7ff76335b0df 65288->65296 65298 7ff76335b0e5 65288->65298 65300 7ff76335b0eb 65288->65300 65301 7ff76335b066 ISource 65288->65301 65304 7ff76335b0b0 65288->65304 65289->65290 65291 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65290->65291 65291->65292 65293 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65292->65293 65293->65294 65295 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65294->65295 65295->65296 65297 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65296->65297 65297->65298 65299 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65298->65299 65299->65300 65303 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65300->65303 65302 7ff763384bd0 _Strxfrm 8 API calls 65301->65302 65305 7ff76335b094 65302->65305 65306 7ff76335b0f1 65303->65306 65307 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65304->65307 65307->65308 65308->65280 65310 7ff76334d52b 65309->65310 65311 7ff76334d503 _Strxfrm 65309->65311 65314 7ff76334c1f0 86 API calls 6 library calls 65310->65314 65311->65284 65313->65288 65314->65311 65315 7ff76332e4e0 65500 7ff763352d10 65315->65500 65318 7ff76332e53b 65320 7ff763302bb0 83 API calls 65318->65320 65319 7ff76332e54c memcpy_s 65321 7ff76332e560 GetModuleFileNameW 65319->65321 65323 7ff763330a99 65320->65323 65322 7ff76332e5a0 65321->65322 65322->65322 65580 7ff763306990 65322->65580 65324 7ff763384bd0 _Strxfrm 8 API calls 65323->65324 65326 7ff763330aab 65324->65326 65327 7ff76332e5be 65328 7ff763306990 86 API calls 65327->65328 65329 7ff76332e7cb 65328->65329 65596 7ff763306c10 65329->65596 65331 7ff76332e7db 65611 7ff763314980 90 API calls 65331->65611 65333 7ff763330add 65336 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65333->65336 65334 7ff763330ae3 65338 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65334->65338 65335 7ff76332e7f9 ISource 65335->65333 65335->65334 65335->65335 65339 7ff763306990 86 API calls 65335->65339 65428 7ff76332e8ca ISource 65335->65428 65336->65334 65340 7ff763330ae9 65338->65340 65341 7ff76332ea70 65339->65341 65342 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65340->65342 65343 7ff763306c10 86 API calls 65341->65343 65344 7ff763330aef 65342->65344 65345 7ff76332ea80 65343->65345 65348 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65344->65348 65612 7ff763314980 90 API calls 65345->65612 65349 7ff763330af5 65348->65349 65352 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65349->65352 65350 7ff76332f31f ISource 65357 7ff763330b19 65350->65357 65358 7ff763330ad7 65350->65358 65367 7ff763330ad1 65350->65367 65375 7ff763330acb 65350->65375 65619 7ff7633003b0 65350->65619 65351 7ff763330b1f 65761 7ff7632ffb70 65351->65761 65353 7ff763330afb 65352->65353 65359 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65353->65359 65355 7ff76332ea9f ISource 65355->65340 65355->65344 65355->65355 65362 7ff763306990 86 API calls 65355->65362 65355->65428 65356 7ff763330b33 65369 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65356->65369 65361 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65357->65361 65366 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65358->65366 65364 7ff763330b01 65359->65364 65360 7ff763330c18 65365 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65360->65365 65361->65351 65370 7ff76332ed0b 65362->65370 65363 7ff76332f99a ISource 65363->65351 65363->65356 65378 7ff76332f9c4 ISource 65363->65378 65625 7ff7633518d0 65363->65625 65379 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65364->65379 65373 7ff763330c1e 65365->65373 65366->65333 65376 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65367->65376 65368 7ff763330ac6 65374 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65368->65374 65371 7ff763330b39 65369->65371 65613 7ff7632fefe0 86 API calls 65370->65613 65381 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65371->65381 65374->65375 65380 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65375->65380 65376->65358 65377 7ff76332ed26 65614 7ff763314980 90 API calls 65377->65614 65378->65360 65378->65368 65499 7ff76332fa6e ISource 65378->65499 65384 7ff763330b07 65379->65384 65380->65367 65385 7ff763330b3f 65381->65385 65386 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65384->65386 65387 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65385->65387 65388 7ff763330b0d 65386->65388 65390 7ff763330b45 65387->65390 65395 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65388->65395 65389 7ff763302bb0 83 API calls 65389->65378 65767 7ff7632fea20 65390->65767 65391 7ff76332ed3d 65393 7ff763306990 86 API calls 65391->65393 65407 7ff76332ef22 ISource 65391->65407 65392 7ff76332fb69 memcpy_s 65471 7ff7633308ee 65392->65471 65683 7ff763334cb0 153 API calls Concurrency::cancel_current_task 65392->65683 65397 7ff76332eef0 65393->65397 65399 7ff763330b13 65395->65399 65615 7ff7632fefe0 86 API calls 65397->65615 65398 7ff76332fba4 65401 7ff76332fd3a 65398->65401 65402 7ff76332fbb3 65398->65402 65405 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65399->65405 65401->65390 65690 7ff7633347b0 65401->65690 65684 7ff763323610 87 API calls 65402->65684 65403 7ff76332ef0b 65616 7ff763314980 90 API calls 65403->65616 65405->65357 65407->65349 65407->65353 65407->65364 65407->65384 65413 7ff763306990 86 API calls 65407->65413 65407->65428 65409 7ff76332fc07 65685 7ff763302bb0 65409->65685 65411 7ff763330b4b 65771 7ff7632fe870 86 API calls 65411->65771 65415 7ff76332f210 65413->65415 65414 7ff76332fd7d 65728 7ff763323e70 87 API calls 65414->65728 65419 7ff763306c10 86 API calls 65415->65419 65422 7ff76332f220 65419->65422 65420 7ff76332fc78 65420->65371 65423 7ff76332fcba ISource 65420->65423 65421 7ff763330b8f 65424 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65421->65424 65617 7ff763314980 90 API calls 65422->65617 65423->65385 65423->65499 65426 7ff763330ba2 65424->65426 65427 7ff7632fea20 2 API calls 65426->65427 65431 7ff763330ba8 65427->65431 65428->65378 65428->65388 65428->65399 65618 7ff763352630 88 API calls 65428->65618 65429 7ff76332fd89 65429->65411 65429->65426 65729 7ff76338b798 65429->65729 65772 7ff7632feaf0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 65431->65772 65433 7ff76332ff27 65436 7ff763330bb6 65433->65436 65736 7ff7633365c0 65433->65736 65773 7ff7632feaf0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 65436->65773 65437 7ff76332ff79 65741 7ff763335890 65437->65741 65439 7ff76332fee9 65439->65431 65443 7ff7633118d0 86 API calls 65439->65443 65441 7ff763330bbe 65444 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65441->65444 65445 7ff76332ff07 65443->65445 65446 7ff763330bc4 65444->65446 65735 7ff76338b808 WideCharToMultiByte WideCharToMultiByte GetLastError WideCharToMultiByte GetLastError 65445->65735 65448 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65446->65448 65449 7ff763330bca 65448->65449 65450 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65449->65450 65451 7ff763330bd0 65450->65451 65452 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65451->65452 65453 7ff763330bd6 65452->65453 65454 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65453->65454 65456 7ff763330bdc 65454->65456 65455 7ff763330022 ISource 65455->65441 65455->65446 65455->65449 65455->65451 65455->65453 65455->65456 65458 7ff763330be2 65455->65458 65755 7ff763352100 98 API calls 5 library calls 65455->65755 65459 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65456->65459 65461 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65458->65461 65459->65458 65460 7ff763330823 65759 7ff76338bf14 103 API calls 3 library calls 65460->65759 65467 7ff763330be8 65461->65467 65463 7ff76333083f 65465 7ff763302bb0 83 API calls 65463->65465 65464 7ff7633303a3 65464->65460 65472 7ff7633303fb 65464->65472 65466 7ff76333084c ISource 65465->65466 65470 7ff763330c12 65466->65470 65760 7ff763323610 87 API calls 65466->65760 65469 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65467->65469 65473 7ff763330bf4 65469->65473 65474 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65470->65474 65471->65389 65472->65467 65756 7ff763341970 86 API calls memcpy_s 65472->65756 65475 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65473->65475 65474->65360 65477 7ff763330bfa 65475->65477 65479 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65477->65479 65478 7ff7633304da ISource 65478->65473 65481 7ff763330558 ISource 65478->65481 65480 7ff763330c00 65479->65480 65484 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65480->65484 65481->65477 65483 7ff7633305b8 ISource 65481->65483 65482 7ff76333048f 65482->65467 65482->65478 65757 7ff76338bf14 103 API calls 3 library calls 65483->65757 65486 7ff763330c06 65484->65486 65489 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65486->65489 65487 7ff7633305f0 65488 7ff763302bb0 83 API calls 65487->65488 65490 7ff76333064e 65488->65490 65491 7ff763330c0c 65489->65491 65490->65480 65492 7ff76333068b ISource 65490->65492 65494 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65491->65494 65758 7ff763323610 87 API calls 65492->65758 65494->65470 65495 7ff7633306f0 65496 7ff763302bb0 83 API calls 65495->65496 65497 7ff763330761 65496->65497 65497->65486 65499->65318 65501 7ff763352d6e 65500->65501 65518 7ff763352e54 65500->65518 65818 7ff763384d80 EnterCriticalSection LeaveCriticalSection LeaveCriticalSection WaitForSingleObjectEx EnterCriticalSection 65501->65818 65504 7ff763352fe9 65774 7ff7632ff320 65504->65774 65507 7ff763353058 ISource 65508 7ff7633003b0 107 API calls 65507->65508 65510 7ff763353563 65507->65510 65519 7ff7633530c9 memcpy_s 65508->65519 65513 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65510->65513 65524 7ff763353569 65513->65524 65517 7ff763353622 65863 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 65517->65863 65518->65504 65819 7ff763384d80 EnterCriticalSection LeaveCriticalSection LeaveCriticalSection WaitForSingleObjectEx EnterCriticalSection 65518->65819 65537 7ff763353408 65519->65537 65777 7ff7633608e0 65519->65777 65522 7ff76335321a ISource 65525 7ff763384bd0 _Strxfrm 8 API calls 65522->65525 65860 7ff7632fe870 86 API calls 65524->65860 65529 7ff76332e531 65525->65529 65527 7ff76335355e 65531 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65527->65531 65529->65318 65529->65319 65531->65510 65532 7ff763353593 65534 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65532->65534 65533 7ff76335339c 65533->65522 65859 7ff763323610 87 API calls 65533->65859 65538 7ff7633535a7 65534->65538 65537->65517 65537->65522 65537->65527 65861 7ff7632fe870 86 API calls 65538->65861 65545 7ff7633535d0 65548 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65545->65548 65553 7ff7633535e4 65548->65553 65862 7ff7632fe870 86 API calls 65553->65862 65561 7ff76335360e 65564 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65561->65564 65564->65517 65581 7ff763306ab1 65580->65581 65586 7ff7633069b6 65580->65586 66596 7ff7632fd450 86 API calls 65581->66596 65583 7ff7633069c9 _Strxfrm 65583->65327 65584 7ff763306a03 65587 7ff763306aac 65584->65587 65590 7ff763306a4a 65584->65590 65585 7ff763306a52 65591 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65585->65591 65595 7ff763306a57 _Strxfrm 65585->65595 65586->65583 65586->65584 65586->65587 65589 7ff763306a65 65586->65589 66595 7ff7632fd390 86 API calls 2 library calls 65587->66595 65594 7ff763384e90 std::_Facet_Register 86 API calls 65589->65594 65589->65595 65592 7ff763384e90 std::_Facet_Register 86 API calls 65590->65592 65593 7ff763306abd 65591->65593 65592->65585 65594->65595 65595->65327 65599 7ff763306c3e 65596->65599 65597 7ff763306d33 66598 7ff7632fd450 86 API calls 65597->66598 65598 7ff763306c62 65598->65331 65599->65597 65599->65598 65601 7ff763306c8a 65599->65601 65603 7ff763306d2d 65599->65603 65605 7ff763306cef 65599->65605 65601->65603 65607 7ff763384e90 std::_Facet_Register 86 API calls 65601->65607 66597 7ff7632fd390 86 API calls 2 library calls 65603->66597 65606 7ff763306ce1 _Strxfrm 65605->65606 65608 7ff763384e90 std::_Facet_Register 86 API calls 65605->65608 65606->65331 65609 7ff763306cd9 65607->65609 65608->65606 65609->65606 65610 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65609->65610 65610->65603 65611->65335 65612->65355 65613->65377 65614->65391 65615->65403 65616->65407 65617->65428 65618->65350 65620 7ff7633003e1 65619->65620 66599 7ff76338bae8 65620->66599 65623 7ff763384bd0 _Strxfrm 8 API calls 65624 7ff763300482 65623->65624 65624->65363 65626 7ff7633003b0 107 API calls 65625->65626 65627 7ff763351921 65626->65627 65628 7ff76335200e 65627->65628 65633 7ff76335195d memcpy_s 65627->65633 65629 7ff76335204c 65628->65629 65630 7ff763351fbe 65628->65630 66687 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 65629->66687 65632 7ff763384bd0 _Strxfrm 8 API calls 65630->65632 65635 7ff763352030 65632->65635 65633->65630 65636 7ff7633608e0 153 API calls 65633->65636 65634 7ff763352062 65637 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65634->65637 65635->65392 65638 7ff763351988 65636->65638 65647 7ff763352068 65637->65647 65639 7ff763351e09 65638->65639 65640 7ff7633519c4 65638->65640 66652 7ff763326800 65639->66652 66647 7ff76335cdc0 38 API calls 3 library calls 65640->66647 65645 7ff7633519d6 66648 7ff76335cfc0 111 API calls 6 library calls 65645->66648 66688 7ff7632fe870 86 API calls 65647->66688 65649 7ff763351e37 65656 7ff763326800 88 API calls 65649->65656 65651 7ff7633519e7 65653 7ff763351aea GetFileSize 65651->65653 65654 7ff7633519fa 65651->65654 65652 7ff76335208e 65655 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65652->65655 65657 7ff763351b2b 65653->65657 65661 7ff763351b06 memcpy_s 65653->65661 65654->65634 65658 7ff763351a41 ISource 65654->65658 65666 7ff76335209f 65655->65666 65659 7ff763351e70 65656->65659 65657->65661 65664 7ff7633176b0 86 API calls 65657->65664 66649 7ff763323610 87 API calls 65658->66649 66671 7ff763360a80 65659->66671 65660 7ff763351b90 SetFilePointer ReadFile 65675 7ff763351d0b 65660->65675 65677 7ff763351bdf 65660->65677 65661->65660 65664->65660 66689 7ff7632fe870 86 API calls 65666->66689 65667 7ff763351ef8 66685 7ff763323e70 87 API calls 65667->66685 65669 7ff763351f01 65669->65666 65673 7ff763351f33 65669->65673 65670 7ff763351d60 ISource 66651 7ff763323610 87 API calls 65670->66651 65671 7ff763351c62 ISource 66650 7ff763323610 87 API calls 65671->66650 66686 7ff763323610 87 API calls 65673->66686 65675->65634 65675->65670 65677->65634 65677->65671 65678 7ff7633520e4 65681 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65678->65681 65680 7ff763351a99 65680->65630 65682 7ff7633520f5 65681->65682 65683->65398 65684->65409 65686 7ff763302bc4 65685->65686 65687 7ff763302bf2 ISource 65685->65687 65686->65687 65688 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65686->65688 65687->65420 65689 7ff763302c18 65688->65689 65691 7ff7633347ef 65690->65691 65693 7ff763334804 65691->65693 65694 7ff763318af0 86 API calls 65691->65694 65692 7ff763334837 65695 7ff7633348e5 65692->65695 65696 7ff7633348a3 65692->65696 65693->65692 66803 7ff7633113e0 65693->66803 65694->65693 66808 7ff7632fe870 86 API calls 65695->66808 65697 7ff76332fd71 65696->65697 66807 7ff7633195d0 86 API calls 2 library calls 65696->66807 65704 7ff763318af0 65697->65704 65700 7ff763334927 65701 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65700->65701 65702 7ff763334938 65701->65702 65705 7ff763318bae 65704->65705 65706 7ff763318b2e 65704->65706 65708 7ff763384bd0 _Strxfrm 8 API calls 65705->65708 66826 7ff7633185f0 86 API calls 65706->66826 65710 7ff763318bdb 65708->65710 65709 7ff763318b3b 65711 7ff763318b9b 65709->65711 65713 7ff763318bf0 65709->65713 65710->65414 65711->65705 66827 7ff7633195d0 86 API calls 2 library calls 65711->66827 66828 7ff7632fe870 86 API calls 65713->66828 65715 7ff763318c32 65716 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65715->65716 65717 7ff763318c43 65716->65717 65718 7ff763318af0 86 API calls 65717->65718 65719 7ff763318c9b 65717->65719 65718->65719 65720 7ff763318d62 65719->65720 65722 7ff763318da0 65719->65722 65721 7ff763318d73 65720->65721 66829 7ff7633195d0 86 API calls 2 library calls 65720->66829 65721->65414 66830 7ff7632fe870 86 API calls 65722->66830 65725 7ff763318de2 65726 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65725->65726 65727 7ff763318df3 65726->65727 65727->65414 65728->65429 66831 7ff76337ce9c 65729->66831 65732 7ff76332fe94 65732->65431 65732->65433 65734 7ff76338b808 WideCharToMultiByte WideCharToMultiByte GetLastError WideCharToMultiByte GetLastError 65732->65734 65733 7ff76338b7aa AreFileApisANSI 65733->65732 65734->65439 65735->65433 65737 7ff763336685 65736->65737 65740 7ff7633365f0 _Strxfrm 65736->65740 66836 7ff76333a790 92 API calls 5 library calls 65737->66836 65739 7ff76333669a 65739->65437 65740->65437 65742 7ff7633358dd 65741->65742 65744 7ff7633359dd 65742->65744 65745 7ff763335a05 65742->65745 65751 7ff7633358e2 _Strxfrm 65742->65751 65754 7ff763335a6d 65742->65754 65746 7ff763335a73 65744->65746 65747 7ff763384e90 std::_Facet_Register 86 API calls 65744->65747 65748 7ff763384e90 std::_Facet_Register 86 API calls 65745->65748 65745->65751 66838 7ff7632fd390 86 API calls 2 library calls 65746->66838 65752 7ff7633359f2 65747->65752 65748->65751 65750 7ff763335a79 65751->65455 65752->65751 65753 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 65752->65753 65753->65754 66837 7ff7632fd450 86 API calls 65754->66837 65755->65464 65756->65482 65757->65487 65758->65495 65759->65463 65760->65471 65762 7ff7632ffb89 65761->65762 66839 7ff7632ff520 91 API calls 2 library calls 65762->66839 65764 7ff7632ffbc0 65765 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65764->65765 65766 7ff7632ffbd1 65765->65766 65768 7ff7632fea3d 65767->65768 65769 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65768->65769 65770 7ff7632fea4e 65769->65770 65771->65421 65775 7ff763306c10 86 API calls 65774->65775 65776 7ff7632ff342 65775->65776 65776->65507 65778 7ff763360906 65777->65778 65864 7ff7633136e0 65778->65864 65784 7ff763353141 65784->65533 65790 7ff763360c90 65784->65790 65785 7ff7633609ca 65785->65784 65891 7ff7632fe870 86 API calls 65785->65891 65787 7ff763360a68 65788 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65787->65788 65789 7ff763360a79 65788->65789 66103 7ff763312620 65790->66103 65792 7ff763360cc6 66113 7ff763363a00 65792->66113 65796 7ff763360d35 66187 7ff763361a30 65796->66187 65859->65537 65860->65532 65861->65545 65862->65561 65865 7ff763384e90 std::_Facet_Register 86 API calls 65864->65865 65866 7ff763313740 65865->65866 65892 7ff76338ca40 65866->65892 65868 7ff763313750 65901 7ff763313bc0 65868->65901 65871 7ff7633137e0 65872 7ff7633137ed 65871->65872 65916 7ff76338cd0c 6 API calls std::_Lockit::_Lockit 65871->65916 65879 7ff763324230 65872->65879 65874 7ff763313808 65917 7ff7632fe870 86 API calls 65874->65917 65876 7ff763313848 65877 7ff763387db4 Concurrency::cancel_current_task 2 API calls 65876->65877 65878 7ff763313859 65877->65878 65928 7ff7633132f0 65879->65928 65882 7ff763336460 65883 7ff763336485 65882->65883 65884 7ff763336514 65882->65884 65933 7ff76338cf7c 65883->65933 65884->65785 65888 7ff7633364ab 65942 7ff763325750 119 API calls 4 library calls 65888->65942 65890 7ff7633364d1 65890->65785 65891->65787 65918 7ff76338c41c 65892->65918 65894 7ff76338ca62 65898 7ff76338cac4 _Strxfrm 65894->65898 65922 7ff76338cc38 86 API calls std::_Facet_Register 65894->65922 65896 7ff76338ca7a 65923 7ff76338cc68 84 API calls std::locale::_Setgloballocale 65896->65923 65898->65868 65899 7ff76338ca85 __std_exception_destroy 65899->65898 65900 7ff763370454 _Yarn 12 API calls 65899->65900 65900->65898 65902 7ff76338c41c std::_Lockit::_Lockit 6 API calls 65901->65902 65903 7ff763313bf0 65902->65903 65904 7ff76338c41c std::_Lockit::_Lockit 6 API calls 65903->65904 65906 7ff763313c15 65903->65906 65904->65906 65905 7ff763313c8d 65907 7ff763384bd0 _Strxfrm 8 API calls 65905->65907 65906->65905 65925 7ff7632fe510 126 API calls 7 library calls 65906->65925 65908 7ff763313785 65907->65908 65908->65871 65908->65874 65910 7ff763313c9f 65911 7ff763313ca5 65910->65911 65912 7ff763313d06 65910->65912 65926 7ff76338ca00 86 API calls std::_Facet_Register 65911->65926 65927 7ff7632fe050 86 API calls 2 library calls 65912->65927 65915 7ff763313d0b 65916->65872 65917->65876 65919 7ff76338c430 65918->65919 65920 7ff76338c42b 65918->65920 65919->65894 65924 7ff763372fcc 6 API calls std::_Lockit::_Lockit 65920->65924 65922->65896 65923->65899 65925->65910 65926->65905 65927->65915 65929 7ff763384e90 std::_Facet_Register 86 API calls 65928->65929 65930 7ff763313311 65929->65930 65931 7ff76338ca40 93 API calls 65930->65931 65932 7ff763313321 65931->65932 65932->65882 65934 7ff76338cfbe 65933->65934 65937 7ff763336495 65934->65937 65943 7ff76338e978 65934->65943 65937->65884 65941 7ff763323d70 83 API calls _Strxfrm 65937->65941 65939 7ff76338d00b 65939->65937 65963 7ff763367030 86 API calls _invalid_parameter_noinfo_noreturn 65939->65963 65941->65888 65942->65890 65944 7ff76338e8a4 65943->65944 65945 7ff76338e8ca 65944->65945 65948 7ff76338e8fd 65944->65948 65976 7ff76336cb7c 11 API calls _Strcoll 65945->65976 65947 7ff76338e8cf 65977 7ff7633686b8 83 API calls _invalid_parameter_noinfo_noreturn 65947->65977 65950 7ff76338e910 65948->65950 65951 7ff76338e903 65948->65951 65964 7ff7633740e4 65950->65964 65978 7ff76336cb7c 11 API calls _Strcoll 65951->65978 65961 7ff76338cff1 65961->65937 65962 7ff763368294 83 API calls _invalid_parameter_noinfo_noreturn 65961->65962 65962->65939 65963->65937 65981 7ff763372f5c EnterCriticalSection 65964->65981 65976->65947 65977->65961 65978->65961 66104 7ff763312653 66103->66104 66105 7ff763312776 66103->66105 66107 7ff763384bd0 _Strxfrm 8 API calls 66104->66107 66105->66104 66106 7ff763312783 66105->66106 66193 7ff763316f90 86 API calls 4 library calls 66106->66193 66108 7ff763312682 66107->66108 66108->65792 66110 7ff7633127a4 66111 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66110->66111 66112 7ff7633127b5 66111->66112 66114 7ff763363a54 66113->66114 66194 7ff76336ca74 66114->66194 66119 7ff763363b5f 66217 7ff763350990 66119->66217 66121 7ff763384bd0 _Strxfrm 8 API calls 66122 7ff763360d29 66121->66122 66123 7ff763361b00 66122->66123 66124 7ff763361e1d 66123->66124 66128 7ff763361b47 memcpy_s 66123->66128 66371 7ff763365180 66124->66371 66127 7ff7633621a0 86 API calls 66135 7ff763361e5c 66127->66135 66435 7ff763335c60 86 API calls 66128->66435 66130 7ff763361b97 66436 7ff7633642e0 89 API calls 2 library calls 66130->66436 66132 7ff763361e18 ISource 66138 7ff763384bd0 _Strxfrm 8 API calls 66132->66138 66133 7ff763361ba7 66136 7ff7633621a0 86 API calls 66133->66136 66134 7ff763312620 86 API calls 66146 7ff763362024 66134->66146 66137 7ff763335dc0 89 API calls 66135->66137 66180 7ff763361fe7 ISource 66135->66180 66150 7ff763361bb3 66136->66150 66141 7ff763361ea5 66137->66141 66139 7ff7633620b4 66138->66139 66139->65796 66140 7ff763362108 66142 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66140->66142 66143 7ff763339600 89 API calls 66141->66143 66147 7ff76336210e 66142->66147 66148 7ff763361ecb 66143->66148 66144 7ff763361d69 66149 7ff763312620 86 API calls 66144->66149 66145 7ff763361db1 66152 7ff763361d84 66145->66152 66153 7ff763312620 86 API calls 66145->66153 66146->66132 66146->66140 66548 7ff763334a10 84 API calls 66147->66548 66151 7ff763336340 89 API calls 66148->66151 66149->66152 66186 7ff763361d48 ISource 66150->66186 66437 7ff763335dc0 66150->66437 66177 7ff763361eda ISource __std_exception_destroy 66151->66177 66547 7ff763335a80 83 API calls 2 library calls 66152->66547 66153->66152 66157 7ff763361bff 66456 7ff763339600 66157->66456 66158 7ff76336211b 66159 7ff76336213d 66164 7ff763361c25 66540 7ff763336340 66164->66540 66166 7ff76336215a 66172 7ff763362160 66174 7ff763361c4a 66177->66159 66177->66166 66177->66172 66177->66180 66181 7ff763362103 66177->66181 66180->66134 66180->66146 66182 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66181->66182 66182->66140 66186->66144 66186->66145 66190 7ff763361a4c ISource 66187->66190 66188 7ff763361ae4 66191 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66188->66191 66189 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66189->66188 66190->66188 66190->66189 66192 7ff763361aea 66191->66192 66193->66110 66224 7ff763370a8c GetLastError 66194->66224 66199 7ff7633621a0 66200 7ff7633621c3 66199->66200 66204 7ff763362210 66199->66204 66287 7ff763363710 66200->66287 66202 7ff763363710 86 API calls 66202->66204 66203 7ff7633621c8 66203->66204 66205 7ff763363710 86 API calls 66203->66205 66204->66202 66215 7ff763362263 66204->66215 66206 7ff7633621d7 66205->66206 66207 7ff7633621ed 66206->66207 66209 7ff763363710 86 API calls 66206->66209 66208 7ff763384bd0 _Strxfrm 8 API calls 66207->66208 66210 7ff76336220a 66208->66210 66212 7ff7633621e6 66209->66212 66210->66119 66211 7ff763362368 66213 7ff763384bd0 _Strxfrm 8 API calls 66211->66213 66212->66204 66212->66207 66214 7ff7633624bb 66213->66214 66214->66119 66215->66211 66216 7ff763363710 86 API calls 66215->66216 66216->66215 66218 7ff7633509c7 66217->66218 66219 7ff76335099e 66217->66219 66218->66121 66219->66218 66370 7ff7632fe870 86 API calls 66219->66370 66221 7ff7633509fe 66222 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66221->66222 66223 7ff763350a0f 66222->66223 66225 7ff763370acd FlsSetValue 66224->66225 66226 7ff763370ab0 FlsGetValue 66224->66226 66227 7ff763370adf 66225->66227 66228 7ff763370abd 66225->66228 66226->66228 66229 7ff763370ac7 66226->66229 66269 7ff76337446c 66227->66269 66230 7ff763370b39 SetLastError 66228->66230 66229->66225 66233 7ff763370b59 66230->66233 66234 7ff76336ca7d 66230->66234 66283 7ff76337045c 83 API calls 2 library calls 66233->66283 66265 7ff763372d14 66234->66265 66236 7ff763370b0c FlsSetValue 66240 7ff763370b2a 66236->66240 66241 7ff763370b18 FlsSetValue 66236->66241 66237 7ff763370afc FlsSetValue 66239 7ff763370b05 66237->66239 66276 7ff763373e04 66239->66276 66282 7ff76337083c 11 API calls _Getctype 66240->66282 66241->66239 66249 7ff763370b32 66253 7ff763373e04 __free_lconv_mon 11 API calls 66249->66253 66253->66230 66266 7ff763372d29 66265->66266 66267 7ff763363b3a 66265->66267 66266->66267 66286 7ff76337c10c 83 API calls 3 library calls 66266->66286 66267->66199 66274 7ff76337447d wcsftime 66269->66274 66270 7ff7633744ce 66284 7ff76336cb7c 11 API calls _Strcoll 66270->66284 66271 7ff7633744b2 HeapAlloc 66272 7ff763370aee 66271->66272 66271->66274 66272->66236 66272->66237 66274->66270 66274->66271 66275 7ff763380150 std::_Facet_Register 2 API calls 66274->66275 66275->66274 66277 7ff763373e09 RtlFreeHeap 66276->66277 66278 7ff763373e38 66276->66278 66277->66278 66279 7ff763373e24 GetLastError 66277->66279 66278->66228 66280 7ff763373e31 __free_lconv_mon 66279->66280 66285 7ff76336cb7c 11 API calls _Strcoll 66280->66285 66282->66249 66284->66272 66285->66278 66286->66267 66288 7ff763363733 66287->66288 66291 7ff76336372d 66287->66291 66289 7ff76336374a 66288->66289 66304 7ff763322fd0 66288->66304 66289->66291 66293 7ff7633637e4 66289->66293 66290 7ff7633637b7 66290->66203 66291->66290 66325 7ff76333bc80 66291->66325 66339 7ff7632fe870 86 API calls 66293->66339 66295 7ff763363826 66296 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66295->66296 66297 7ff763363837 66296->66297 66302 7ff763363865 66297->66302 66340 7ff763317540 86 API calls 5 library calls 66297->66340 66299 7ff763363910 66299->66203 66300 7ff763363710 86 API calls 66300->66302 66302->66299 66302->66300 66341 7ff763317540 86 API calls 5 library calls 66302->66341 66305 7ff76332300d 66304->66305 66307 7ff763323081 66305->66307 66308 7ff7633230a3 66305->66308 66312 7ff76332301d ISource 66305->66312 66306 7ff763384bd0 _Strxfrm 8 API calls 66309 7ff76332324f 66306->66309 66342 7ff763367114 66307->66342 66311 7ff763367114 83 API calls 66308->66311 66309->66289 66318 7ff7633230d1 _Strxfrm 66311->66318 66312->66306 66313 7ff7633231f1 66313->66312 66315 7ff7633232d7 66313->66315 66316 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66315->66316 66317 7ff7633232dc 66316->66317 66319 7ff763323304 66317->66319 66324 7ff763322fd0 86 API calls 66317->66324 66318->66313 66321 7ff763367114 83 API calls 66318->66321 66323 7ff763323287 66318->66323 66363 7ff763317540 86 API calls 5 library calls 66318->66363 66319->66289 66320 7ff76332331b 66320->66289 66321->66318 66323->66313 66364 7ff763367bf4 83 API calls 3 library calls 66323->66364 66324->66320 66326 7ff76333bcc8 66325->66326 66327 7ff76333be1e 66325->66327 66328 7ff76333bce4 66326->66328 66331 7ff76333bd3a 66326->66331 66368 7ff763310670 86 API calls ISource 66327->66368 66330 7ff76333be24 66328->66330 66332 7ff763384e90 std::_Facet_Register 86 API calls 66328->66332 66369 7ff7632fd390 86 API calls 2 library calls 66330->66369 66333 7ff763384e90 std::_Facet_Register 86 API calls 66331->66333 66337 7ff76333bcf8 _Strxfrm 66331->66337 66332->66337 66333->66337 66335 7ff76333be2a 66336 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66336->66327 66337->66336 66338 7ff76333bde1 ISource 66337->66338 66338->66290 66339->66295 66340->66302 66341->66302 66343 7ff76336714e 66342->66343 66344 7ff763367130 66342->66344 66365 7ff7633673fc EnterCriticalSection 66343->66365 66366 7ff76336cb7c 11 API calls _Strcoll 66344->66366 66347 7ff763367135 66367 7ff7633686b8 83 API calls _invalid_parameter_noinfo_noreturn 66347->66367 66353 7ff763367140 66353->66312 66363->66318 66364->66323 66366->66347 66367->66353 66368->66330 66369->66335 66370->66221 66372 7ff7633651fe 66371->66372 66373 7ff763335dc0 89 API calls 66372->66373 66374 7ff763365dcf 66373->66374 66375 7ff763339600 89 API calls 66374->66375 66376 7ff763365df5 66375->66376 66377 7ff763336340 89 API calls 66376->66377 66378 7ff763365e05 66377->66378 66379 7ff763365e78 66378->66379 66380 7ff763365e10 66378->66380 66555 7ff763334a10 84 API calls 66379->66555 66382 7ff763311990 83 API calls 66380->66382 66384 7ff763365e1a 66382->66384 66383 7ff763365e84 66385 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66383->66385 66387 7ff763311990 83 API calls 66384->66387 66386 7ff763365e94 66385->66386 66556 7ff763334a10 84 API calls 66386->66556 66389 7ff763365e2e 66387->66389 66391 7ff763311990 83 API calls 66389->66391 66390 7ff763365ea1 66392 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66390->66392 66394 7ff763365e39 66391->66394 66393 7ff763365eb1 66392->66393 66557 7ff763334a10 84 API calls 66393->66557 66550 7ff763319570 66394->66550 66397 7ff763365ebe 66399 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66397->66399 66398 7ff763365e47 66400 7ff763384bd0 _Strxfrm 8 API calls 66398->66400 66401 7ff763365ece 66399->66401 66402 7ff763361e50 66400->66402 66558 7ff76333b370 84 API calls 66401->66558 66402->66127 66404 7ff763365edb 66405 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66404->66405 66406 7ff763365eeb 66405->66406 66559 7ff763334a10 84 API calls 66406->66559 66408 7ff763365ef8 66409 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66408->66409 66410 7ff763365f08 66409->66410 66435->66130 66436->66133 66439 7ff763335e0c 66437->66439 66438 7ff763336340 89 API calls 66445 7ff763335f69 66438->66445 66441 7ff763335e9d ISource 66439->66441 66566 7ff763317540 86 API calls 5 library calls 66439->66566 66441->66438 66442 7ff76333631f 66441->66442 66453 7ff763336023 ISource 66441->66453 66443 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66442->66443 66444 7ff763336325 66443->66444 66446 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66444->66446 66445->66453 66567 7ff763317540 86 API calls 5 library calls 66445->66567 66447 7ff76333632b 66446->66447 66451 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66447->66451 66449 7ff763336331 66450 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66449->66450 66452 7ff763336337 66450->66452 66451->66449 66453->66444 66453->66447 66453->66449 66454 7ff7633362f1 ISource 66453->66454 66455 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66453->66455 66454->66157 66455->66442 66457 7ff76333965f 66456->66457 66568 7ff76332b300 83 API calls 3 library calls 66457->66568 66459 7ff763339676 66460 7ff7633004b0 86 API calls 66459->66460 66466 7ff7633396ae ISource 66460->66466 66461 7ff7633398fa 66463 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66461->66463 66462 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66462->66461 66465 7ff763339900 66463->66465 66464 7ff763386b14 __std_exception_copy 84 API calls 66469 7ff76333985f 66464->66469 66467 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66465->66467 66466->66461 66466->66464 66466->66465 66470 7ff763339906 66466->66470 66476 7ff7633398f4 66466->66476 66467->66470 66468 7ff7633398b3 ISource 66472 7ff763384bd0 _Strxfrm 8 API calls 66468->66472 66469->66468 66473 7ff7633398ef 66469->66473 66471 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66470->66471 66477 7ff76333990c 66471->66477 66474 7ff7633398d8 66472->66474 66475 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66473->66475 66474->66164 66475->66476 66476->66462 66478 7ff763335dc0 89 API calls 66477->66478 66479 7ff76333a55f 66478->66479 66480 7ff763339600 89 API calls 66479->66480 66481 7ff76333a585 66480->66481 66482 7ff763336340 89 API calls 66481->66482 66483 7ff76333a595 66482->66483 66484 7ff76333a608 66483->66484 66485 7ff76333a5a0 66483->66485 66569 7ff763334a10 84 API calls 66484->66569 66486 7ff763311990 83 API calls 66485->66486 66541 7ff763336437 66540->66541 66545 7ff763336396 66540->66545 66542 7ff763384bd0 _Strxfrm 8 API calls 66541->66542 66543 7ff763336447 66542->66543 66543->66147 66543->66174 66545->66541 66580 7ff76332adc0 86 API calls 66545->66580 66581 7ff763317540 86 API calls 5 library calls 66545->66581 66547->66132 66548->66158 66551 7ff763319586 66550->66551 66552 7ff7633195af ISource 66550->66552 66551->66552 66553 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66551->66553 66552->66398 66554 7ff7633195cf 66553->66554 66555->66383 66556->66390 66557->66397 66558->66404 66559->66408 66566->66441 66567->66453 66568->66459 66580->66545 66581->66545 66595->65581 66597->65597 66601 7ff76338bb2a 66599->66601 66600 7ff76338bb33 66603 7ff763384bd0 _Strxfrm 8 API calls 66600->66603 66601->66600 66602 7ff76338bc45 66601->66602 66604 7ff76338bb8b GetFileAttributesExW 66601->66604 66642 7ff76338bebc CreateFileW GetLastError 66602->66642 66605 7ff7633003fd 66603->66605 66607 7ff76338bb9f GetLastError 66604->66607 66608 7ff76338bbf0 66604->66608 66605->65623 66607->66600 66610 7ff76338bbae FindFirstFileW 66607->66610 66608->66600 66608->66602 66609 7ff76338bc68 66611 7ff76338bc8e 66609->66611 66612 7ff76338bc6e 66609->66612 66617 7ff76338bbc2 GetLastError 66610->66617 66618 7ff76338bbcd FindClose 66610->66618 66615 7ff76338bd3b 66611->66615 66616 7ff76338bc9d GetFileInformationByHandleEx 66611->66616 66613 7ff76338bc87 66612->66613 66614 7ff76338bc79 CloseHandle 66612->66614 66613->66600 66614->66613 66619 7ff76338bdfd 66614->66619 66620 7ff76338bd90 66615->66620 66621 7ff76338bd56 GetFileInformationByHandleEx 66615->66621 66622 7ff76338bcb7 GetLastError 66616->66622 66623 7ff76338bcdd 66616->66623 66617->66600 66618->66608 66643 7ff76337811c 88 API calls 2 library calls 66619->66643 66627 7ff76338bde3 66620->66627 66628 7ff76338bda7 66620->66628 66621->66620 66625 7ff76338bd6c GetLastError 66621->66625 66622->66613 66626 7ff76338bcc5 CloseHandle 66622->66626 66623->66615 66632 7ff76338bcfe GetFileInformationByHandleEx 66623->66632 66625->66613 66630 7ff76338bd7e CloseHandle 66625->66630 66626->66613 66641 7ff76338be0e 66626->66641 66627->66613 66633 7ff76338bde9 CloseHandle 66627->66633 66628->66600 66631 7ff76338bdad CloseHandle 66628->66631 66629 7ff76338be02 66644 7ff76337811c 88 API calls 2 library calls 66629->66644 66630->66613 66640 7ff76338be08 66630->66640 66631->66600 66631->66619 66632->66615 66635 7ff76338bd1a GetLastError 66632->66635 66633->66613 66633->66619 66635->66613 66639 7ff76338bd28 CloseHandle 66635->66639 66638 7ff76338be14 66639->66613 66639->66629 66645 7ff76337811c 88 API calls 2 library calls 66640->66645 66646 7ff76337811c 88 API calls 2 library calls 66641->66646 66642->66609 66643->66629 66644->66640 66645->66641 66646->66638 66647->65645 66648->65651 66649->65680 66650->65680 66651->65680 66653 7ff76332685d 66652->66653 66655 7ff763326942 66652->66655 66690 7ff763327080 66653->66690 66713 7ff7632fe870 86 API calls 66655->66713 66656 7ff763326882 66660 7ff7633268b9 66656->66660 66703 7ff763322bf0 66656->66703 66657 7ff76332690f 66667 7ff763326720 66657->66667 66659 7ff763326984 66661 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66659->66661 66660->66657 66714 7ff7632fe870 86 API calls 66660->66714 66661->66660 66663 7ff7633269dd 66664 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66663->66664 66665 7ff7633269f1 66664->66665 66668 7ff763326750 66667->66668 66669 7ff763327080 86 API calls 66668->66669 66670 7ff76332675f 66669->66670 66670->65649 66672 7ff763360ad8 66671->66672 66673 7ff763360af6 66671->66673 66672->66673 66684 7ff763322fd0 86 API calls 66672->66684 66674 7ff763360bb6 66673->66674 66783 7ff7633660d0 66673->66783 66678 7ff763360bc1 66674->66678 66796 7ff7633133a0 86 API calls Concurrency::cancel_current_task 66674->66796 66677 7ff763384bd0 _Strxfrm 8 API calls 66679 7ff763351ed3 66677->66679 66680 7ff763360c85 66678->66680 66681 7ff763360c46 ISource 66678->66681 66679->65647 66679->65667 66682 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66680->66682 66681->66677 66683 7ff763360c8a 66682->66683 66684->66673 66685->65669 66686->65630 66688->65652 66689->65678 66691 7ff7633270c0 66690->66691 66695 7ff76332709d 66690->66695 66693 7ff7633270ce 66691->66693 66694 7ff763318af0 86 API calls 66691->66694 66692 7ff7633270ba 66692->66656 66693->66656 66694->66693 66695->66692 66715 7ff7632fe870 86 API calls 66695->66715 66697 7ff763327123 66698 7ff763387db4 Concurrency::cancel_current_task 2 API calls 66697->66698 66702 7ff763327134 ISource 66698->66702 66699 7ff763327295 66699->66656 66700 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66701 7ff7633273e8 66700->66701 66702->66699 66702->66700 66704 7ff763322c23 66703->66704 66712 7ff763322c7b 66704->66712 66716 7ff763323c80 66704->66716 66706 7ff763384bd0 _Strxfrm 8 API calls 66708 7ff763322ce9 66706->66708 66707 7ff763322c46 66709 7ff763322c66 66707->66709 66707->66712 66726 7ff7633681fc 66707->66726 66708->66660 66709->66712 66734 7ff763367814 66709->66734 66712->66706 66713->66659 66714->66663 66715->66697 66717 7ff763323d52 66716->66717 66718 7ff763323ca3 66716->66718 66719 7ff763384bd0 _Strxfrm 8 API calls 66717->66719 66718->66717 66723 7ff763323cad 66718->66723 66720 7ff763323d61 66719->66720 66720->66707 66721 7ff763384bd0 _Strxfrm 8 API calls 66722 7ff763323d0e 66721->66722 66722->66707 66724 7ff763323cf1 66723->66724 66743 7ff763367770 84 API calls _invalid_parameter_noinfo_noreturn 66723->66743 66724->66721 66727 7ff76336822c 66726->66727 66744 7ff763367fac 66727->66744 66730 7ff76336826a 66732 7ff76336827f 66730->66732 66756 7ff763366678 83 API calls 2 library calls 66730->66756 66732->66709 66735 7ff76336783d 66734->66735 66736 7ff763367828 66734->66736 66735->66736 66737 7ff763367842 66735->66737 66759 7ff76336cb7c 11 API calls _Strcoll 66736->66759 66761 7ff7633757dc 66737->66761 66740 7ff76336782d 66760 7ff7633686b8 83 API calls _invalid_parameter_noinfo_noreturn 66740->66760 66742 7ff763367838 66742->66712 66743->66724 66745 7ff763368016 66744->66745 66746 7ff763367fd6 66744->66746 66745->66746 66748 7ff76336801b 66745->66748 66757 7ff7633685e8 83 API calls _invalid_parameter_noinfo_noreturn 66746->66757 66758 7ff7633673fc EnterCriticalSection 66748->66758 66754 7ff763367ffd 66754->66730 66755 7ff763366678 83 API calls 2 library calls 66754->66755 66755->66730 66756->66732 66757->66754 66759->66740 66760->66742 66762 7ff76337580c 66761->66762 66769 7ff7633752f0 66762->66769 66765 7ff76337584b 66766 7ff763375860 66765->66766 66780 7ff763366678 83 API calls 2 library calls 66765->66780 66766->66742 66770 7ff76337530b 66769->66770 66771 7ff76337533a 66769->66771 66781 7ff7633685e8 83 API calls _invalid_parameter_noinfo_noreturn 66770->66781 66782 7ff7633673fc EnterCriticalSection 66771->66782 66774 7ff76337532b 66774->66765 66779 7ff763366678 83 API calls 2 library calls 66774->66779 66779->66765 66780->66766 66781->66774 66797 7ff763366000 66783->66797 66785 7ff7633662dd 66785->66674 66787 7ff76336610e ISource _Strxfrm 66787->66785 66788 7ff763366316 66787->66788 66790 7ff763366000 86 API calls 66787->66790 66792 7ff763384e90 86 API calls std::_Facet_Register 66787->66792 66793 7ff76336630b 66787->66793 66795 7ff763366310 66787->66795 66802 7ff7632fd390 86 API calls 2 library calls 66788->66802 66790->66787 66791 7ff76336631c 66792->66787 66794 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66793->66794 66794->66795 66801 7ff7632fd450 86 API calls 66795->66801 66798 7ff763366016 66797->66798 66799 7ff763366033 66797->66799 66798->66799 66800 7ff763322fd0 86 API calls 66798->66800 66799->66787 66800->66799 66802->66791 66804 7ff76331146f 66803->66804 66805 7ff763311406 _Strxfrm 66803->66805 66804->65692 66805->66804 66809 7ff763311020 66805->66809 66807->65697 66808->65700 66810 7ff763311046 66809->66810 66824 7ff76331104b ISource 66809->66824 66811 7ff7633110ad 66810->66811 66812 7ff7633110be 66810->66812 66810->66824 66813 7ff763384e90 std::_Facet_Register 86 API calls 66811->66813 66814 7ff7633110d7 66812->66814 66815 7ff7633110e6 66812->66815 66817 7ff7633110e4 66812->66817 66821 7ff7633110b9 _Strxfrm 66813->66821 66816 7ff76331120f 66814->66816 66814->66817 66820 7ff763384e90 std::_Facet_Register 86 API calls 66815->66820 66815->66821 66825 7ff7632fd390 86 API calls 2 library calls 66816->66825 66818 7ff763384e90 std::_Facet_Register 86 API calls 66817->66818 66817->66824 66818->66821 66820->66821 66822 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66821->66822 66821->66824 66823 7ff76331121a 66822->66823 66824->66805 66825->66821 66826->65709 66827->65705 66828->65715 66829->65721 66830->65725 66832 7ff763370a8c _Getctype 83 API calls 66831->66832 66833 7ff76337cea5 66832->66833 66834 7ff763372d14 _Getctype 83 API calls 66833->66834 66835 7ff76337cebe 66834->66835 66835->65732 66835->65733 66836->65739 66838->65750 66839->65764 69171 7ff763331a80 69172 7ff7633003b0 107 API calls 69171->69172 69173 7ff763331ae0 69172->69173 69174 7ff7633003b0 107 API calls 69173->69174 69175 7ff763332370 69174->69175 69176 7ff7632ff020 86 API calls 69175->69176 69188 7ff76333278c ISource 69175->69188 69178 7ff7633323a9 69176->69178 69177 7ff763384bd0 _Strxfrm 8 API calls 69179 7ff7633327b7 69177->69179 69180 7ff7632feeb0 92 API calls 69178->69180 69181 7ff7633323b6 69180->69181 69270 7ff763334a50 69181->69270 69184 7ff763352540 214 API calls 69185 7ff763332483 69184->69185 69186 7ff763302bb0 83 API calls 69185->69186 69187 7ff763332753 69186->69187 69187->69188 69189 7ff7633327d3 69187->69189 69188->69177 69190 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69189->69190 69191 7ff7633327d8 69190->69191 69192 7ff7633163e0 86 API calls 69191->69192 69193 7ff763332811 69192->69193 69194 7ff763387db4 Concurrency::cancel_current_task 2 API calls 69193->69194 69195 7ff763332824 69194->69195 69196 7ff7632ffb70 91 API calls 69195->69196 69197 7ff763332834 69196->69197 69198 7ff7632ffb70 91 API calls 69197->69198 69199 7ff763332846 69198->69199 69200 7ff7632ffb70 91 API calls 69199->69200 69201 7ff763332856 69200->69201 69202 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69201->69202 69203 7ff76333285c 69202->69203 69204 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69203->69204 69205 7ff763332862 69204->69205 69206 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69205->69206 69207 7ff763332868 69206->69207 69208 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69207->69208 69209 7ff76333286e 69208->69209 69210 7ff7632ffb70 91 API calls 69209->69210 69211 7ff76333287e 69210->69211 69212 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69211->69212 69213 7ff763332884 69212->69213 69214 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69213->69214 69215 7ff76333288a 69214->69215 69216 7ff7632fea20 2 API calls 69215->69216 69217 7ff763332890 69216->69217 69218 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69217->69218 69219 7ff763332896 69218->69219 69220 7ff7632ffb70 91 API calls 69219->69220 69221 7ff7633328a6 69220->69221 69222 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69221->69222 69223 7ff7633328ac 69222->69223 69224 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69223->69224 69225 7ff7633328b2 69224->69225 69226 7ff7632fea20 2 API calls 69225->69226 69227 7ff7633328b8 69226->69227 69228 7ff7632ff020 86 API calls 69227->69228 69229 7ff76333290a 69228->69229 69230 7ff7632feeb0 92 API calls 69229->69230 69231 7ff76333291b 69230->69231 69232 7ff7632ff320 86 API calls 69231->69232 69233 7ff763332e15 69232->69233 69234 7ff7632ff3f0 83 API calls 69233->69234 69235 7ff763332e23 69234->69235 69236 7ff763306c10 86 API calls 69235->69236 69237 7ff76333301e 69236->69237 69238 7ff7633518d0 214 API calls 69237->69238 69239 7ff763333050 69238->69239 69240 7ff7632ff3f0 83 API calls 69239->69240 69241 7ff763333065 69240->69241 69242 7ff7632ff3f0 83 API calls 69241->69242 69243 7ff763333073 69242->69243 69274 7ff763311d90 127 API calls 4 library calls 69243->69274 69245 7ff76333331d 69275 7ff763316070 86 API calls 4 library calls 69245->69275 69247 7ff763333359 69251 7ff763333d49 69247->69251 69276 7ff763300310 115 API calls _Strxfrm 69247->69276 69249 7ff763333375 69249->69251 69253 7ff763333e66 69249->69253 69250 7ff763302bb0 83 API calls 69252 7ff763333ddd 69250->69252 69251->69250 69255 7ff763311990 83 API calls 69252->69255 69254 7ff7632fea20 2 API calls 69253->69254 69256 7ff763333e6b 69254->69256 69257 7ff763333deb 69255->69257 69277 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 69256->69277 69259 7ff7632ff3f0 83 API calls 69257->69259 69261 7ff763333df9 69259->69261 69263 7ff763311990 83 API calls 69261->69263 69265 7ff763333e07 69263->69265 69267 7ff763384bd0 _Strxfrm 8 API calls 69265->69267 69269 7ff763333e37 69267->69269 69271 7ff763334a76 69270->69271 69272 7ff7633365c0 92 API calls 69271->69272 69273 7ff7633323c9 69272->69273 69273->69184 69274->69245 69275->69247 69276->69249 66840 7ff763347aea 66841 7ff763347aef 66840->66841 66884 7ff76330e5a0 CreateToolhelp32Snapshot 66841->66884 66885 7ff76330e605 memcpy_s 66884->66885 67452 7ff76330ffc0 66885->67452 66888 7ff76330e61c Process32FirstW 66919 7ff76330e630 ISource 66888->66919 66889 7ff76330e834 67473 7ff76330fee0 66889->67473 66893 7ff76330ea98 CloseHandle 66894 7ff76330eada ISource 66893->66894 66895 7ff76330eaaf 66893->66895 67482 7ff76330eb50 66894->67482 66895->66894 66900 7ff76330eb34 66895->66900 66902 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66900->66902 66901 7ff76330eb04 66903 7ff763384bd0 _Strxfrm 8 API calls 66901->66903 66904 7ff76330eb39 66902->66904 66906 7ff76330eb13 66903->66906 66907 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66904->66907 66905 7ff7633152c0 126 API calls 66905->66919 66923 7ff76330ec50 66906->66923 66909 7ff76330eb3f 66907->66909 66908 7ff76330e899 67491 7ff763310ac0 66908->67491 66911 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66909->66911 66913 7ff76330eb45 66911->66913 66912 7ff76331ad00 86 API calls 66912->66919 66914 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66913->66914 66916 7ff76330eb4b 66914->66916 66915 7ff76330e96b 66918 7ff763310ac0 86 API calls 66915->66918 66921 7ff76330ea22 ISource 66918->66921 66919->66889 66919->66904 66919->66905 66919->66909 66919->66912 66920 7ff763318af0 86 API calls 66919->66920 66922 7ff76330e80f Process32NextW 66919->66922 67457 7ff7633413f0 66919->67457 67469 7ff763313a20 66919->67469 66920->66919 66921->66893 66921->66913 66922->66919 66924 7ff76330eca4 memcpy_s 66923->66924 66925 7ff76330ffc0 127 API calls 66924->66925 66926 7ff76330ecb0 66925->66926 67532 7ff76335a1a0 66926->67532 66928 7ff76330f3e7 66929 7ff76335a1a0 89 API calls 66928->66929 66932 7ff76330f40d ISource 66929->66932 66930 7ff76330f5cc 67553 7ff763312590 66930->67553 66932->66930 66937 7ff76331ad00 86 API calls 66932->66937 66938 7ff76330fa2a 66932->66938 66944 7ff76330fa30 66932->66944 66952 7ff763313a20 126 API calls 66932->66952 66964 7ff7633152c0 126 API calls 66932->66964 66966 7ff763318af0 86 API calls 66932->66966 66933 7ff76330f5d8 66935 7ff76330fee0 86 API calls 66933->66935 66934 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66934->66938 66936 7ff76330f5eb 66935->66936 66941 7ff7633140b0 86 API calls 66936->66941 66980 7ff76330f7a2 ISource 66936->66980 66937->66932 66943 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66938->66943 66939 7ff7633152c0 126 API calls 66942 7ff76330f23a ISource 66939->66942 66940 7ff763313a20 126 API calls 66940->66942 66945 7ff76330f629 66941->66945 66942->66928 66942->66939 66942->66940 66946 7ff76331ad00 86 API calls 66942->66946 66953 7ff763318af0 86 API calls 66942->66953 66967 7ff76330fa1e 66942->66967 66976 7ff76330fa24 66942->66976 66943->66944 66947 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66944->66947 66949 7ff763314380 86 API calls 66945->66949 66946->66942 66950 7ff76330fa36 66947->66950 66948 7ff763312590 83 API calls 66958 7ff76330f880 ISource 66948->66958 66960 7ff76330f63f 66949->66960 66955 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66950->66955 66951 7ff76330fa3c 66954 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66951->66954 66952->66932 66953->66942 66956 7ff76330fa42 66954->66956 66955->66951 66961 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66956->66961 66957 7ff76330f9c1 ISource 66963 7ff76330eb50 83 API calls 66957->66963 66958->66956 66958->66957 66959 7ff76330fa48 66958->66959 66965 7ff76330fa4e 66958->66965 66968 7ff76330fa19 66958->66968 66962 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66959->66962 66971 7ff763310ac0 86 API calls 66960->66971 66961->66959 66962->66965 66970 7ff76330f9e9 66963->66970 66964->66932 66969 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66965->66969 66966->66932 66972 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66967->66972 66975 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66968->66975 66973 7ff76330fa54 66969->66973 66974 7ff763384bd0 _Strxfrm 8 API calls 66970->66974 66978 7ff76330f6ec 66971->66978 66972->66976 66977 7ff76330f9f8 66974->66977 66975->66967 66976->66934 66981 7ff76330fa60 66977->66981 66979 7ff763310ac0 86 API calls 66978->66979 66979->66980 66980->66948 66980->66950 66980->66951 67564 7ff76335d530 GetEnvironmentStringsW 66981->67564 66983 7ff76330fab6 memcpy_s 66984 7ff76330ffc0 127 API calls 66983->66984 67002 7ff76330fad1 ISource _Strxfrm 66984->67002 66985 7ff76330fbe2 66986 7ff76330fee0 86 API calls 66985->66986 66987 7ff76330fbef 66986->66987 66989 7ff7633140b0 86 API calls 66987->66989 67012 7ff76330fdc2 ISource 66987->67012 66992 7ff76330fc1f 66989->66992 66990 7ff76330fe6e ISource 66991 7ff76330eb50 83 API calls 66990->66991 66993 7ff76330fe8c 66991->66993 66995 7ff763314380 86 API calls 66992->66995 67000 7ff763384bd0 _Strxfrm 8 API calls 66993->67000 67003 7ff76330fc36 66995->67003 66996 7ff76330fec6 66997 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66996->66997 66999 7ff76330fecb 66997->66999 66998 7ff763313a20 126 API calls 66998->67002 67004 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 66999->67004 67001 7ff76330fea5 67000->67001 67013 7ff76330c9c0 CredEnumerateA 67001->67013 67002->66985 67002->66998 67002->66999 67006 7ff763318af0 86 API calls 67002->67006 67574 7ff763341500 88 API calls _Strxfrm 67002->67574 67575 7ff76331ad00 67002->67575 67007 7ff763310ac0 86 API calls 67003->67007 67005 7ff76330fed1 67004->67005 67008 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67005->67008 67006->67002 67010 7ff76330fd0b 67007->67010 67009 7ff76330fed7 67008->67009 67011 7ff763310ac0 86 API calls 67010->67011 67011->67012 67012->66990 67012->66996 67012->67005 67014 7ff76330d43a 67013->67014 67023 7ff76330ca30 ISource 67013->67023 67016 7ff763384bd0 _Strxfrm 8 API calls 67014->67016 67015 7ff76330d42d CredFree 67015->67014 67017 7ff76330d449 67016->67017 67050 7ff7633314c0 67017->67050 67018 7ff763384e90 86 API calls std::_Facet_Register 67018->67023 67019 7ff7633140b0 86 API calls 67019->67023 67020 7ff763314380 86 API calls 67020->67023 67021 7ff763310ac0 86 API calls 67021->67023 67022 7ff7633155e0 86 API calls 67022->67023 67023->67015 67023->67018 67023->67019 67023->67020 67023->67021 67023->67022 67024 7ff76330d4c1 67023->67024 67025 7ff76330d4e5 67023->67025 67027 7ff76330d4c7 67023->67027 67028 7ff76330d46a 67023->67028 67031 7ff76330d4d3 67023->67031 67032 7ff76330d4d9 67023->67032 67034 7ff76330d4cd 67023->67034 67035 7ff76330d4bb 67023->67035 67039 7ff76330d4df 67023->67039 67043 7ff763312620 86 API calls 67023->67043 67044 7ff76330d46f 67023->67044 67591 7ff76332a460 86 API calls std::_Facet_Register 67023->67591 67592 7ff76331b840 86 API calls 3 library calls 67023->67592 67026 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67024->67026 67029 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67025->67029 67026->67027 67033 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67027->67033 67037 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67028->67037 67046 7ff76330d4eb ISource 67029->67046 67036 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67031->67036 67040 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67032->67040 67033->67034 67038 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67034->67038 67041 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67035->67041 67036->67032 67037->67044 67038->67031 67042 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67039->67042 67040->67039 67041->67024 67042->67025 67043->67023 67047 7ff7633163e0 86 API calls 67044->67047 67048 7ff76330d4a8 67047->67048 67049 7ff763387db4 Concurrency::cancel_current_task 2 API calls 67048->67049 67049->67035 67051 7ff7633317df 67050->67051 67065 7ff763331515 ISource 67050->67065 67052 7ff763384bd0 _Strxfrm 8 API calls 67051->67052 67053 7ff7633317eb 67052->67053 67070 7ff7633341a0 67053->67070 67054 7ff7633003b0 107 API calls 67054->67065 67055 7ff763331835 67056 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67055->67056 67057 7ff76333183b 67056->67057 67060 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67057->67060 67058 7ff763331820 67594 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 67058->67594 67061 7ff763331841 67060->67061 67062 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67061->67062 67064 7ff763331847 67062->67064 67063 7ff7632ff320 86 API calls 67063->67065 67066 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67064->67066 67065->67051 67065->67054 67065->67055 67065->67057 67065->67058 67065->67061 67065->67063 67065->67064 67068 7ff76333180c 67065->67068 67067 7ff76333184d 67066->67067 67593 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 67068->67593 67071 7ff7633344bf 67070->67071 67085 7ff7633341f5 ISource 67070->67085 67072 7ff763384bd0 _Strxfrm 8 API calls 67071->67072 67073 7ff7633344cb 67072->67073 67090 7ff763302c20 67073->67090 67074 7ff7632ff320 86 API calls 67074->67085 67075 7ff763334515 67076 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67075->67076 67077 7ff76333451b 67076->67077 67079 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67077->67079 67080 7ff763334521 67079->67080 67081 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67080->67081 67082 7ff763334527 67081->67082 67084 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67082->67084 67083 7ff7633003b0 107 API calls 67083->67085 67086 7ff76333452d 67084->67086 67085->67071 67085->67074 67085->67075 67085->67077 67085->67080 67085->67082 67085->67083 67087 7ff7633344ec 67085->67087 67089 7ff763334500 67085->67089 67595 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 67087->67595 67596 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 67089->67596 67597 7ff763300bd0 67090->67597 67094 7ff763302d83 67096 7ff763302d95 67094->67096 67623 7ff7633117b0 67094->67623 67095 7ff763302dd1 67095->67096 67099 7ff7632ff3f0 83 API calls 67095->67099 67100 7ff7632ff3f0 83 API calls 67096->67100 67112 7ff763302df3 67096->67112 67098 7ff763302f29 67101 7ff7632fea20 2 API calls 67098->67101 67099->67096 67100->67112 67103 7ff763302f2f 67101->67103 67107 7ff7632fea20 2 API calls 67103->67107 67109 7ff763302f35 67107->67109 67108 7ff763302c53 ISource 67108->67098 67110 7ff763302f24 67108->67110 67610 7ff7633012c0 67108->67610 67111 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67110->67111 67111->67098 67112->67103 67112->67110 67113 7ff763302ed9 ISource 67112->67113 67507 7ff763312230 67452->67507 67455 7ff7633132f0 93 API calls 67456 7ff76330e611 67455->67456 67456->66888 67456->66889 67458 7ff76334143e 67457->67458 67465 7ff76334141f ISource 67457->67465 67461 7ff763306990 86 API calls 67458->67461 67459 7ff763384bd0 _Strxfrm 8 API calls 67460 7ff7633414de 67459->67460 67460->66919 67462 7ff763341467 67461->67462 67510 7ff763341500 88 API calls _Strxfrm 67462->67510 67464 7ff763341475 67464->67465 67466 7ff7633414ec 67464->67466 67465->67459 67467 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67466->67467 67468 7ff7633414f1 67467->67468 67470 7ff763313a44 67469->67470 67471 7ff763313bc0 126 API calls 67470->67471 67472 7ff763313a56 67471->67472 67472->66919 67474 7ff76330ff28 67473->67474 67475 7ff76330e847 67474->67475 67511 7ff7633133a0 86 API calls Concurrency::cancel_current_task 67474->67511 67475->66893 67477 7ff7633140b0 67475->67477 67478 7ff7633118d0 86 API calls 67477->67478 67479 7ff76331411a 67478->67479 67480 7ff7633118d0 86 API calls 67479->67480 67481 7ff76330e885 67480->67481 67485 7ff763314380 67481->67485 67512 7ff763311220 67482->67512 67484 7ff76330eb9d 67484->66901 67486 7ff7633143c4 67485->67486 67487 7ff763384e90 std::_Facet_Register 86 API calls 67486->67487 67488 7ff7633143d9 67487->67488 67489 7ff763384bd0 _Strxfrm 8 API calls 67488->67489 67490 7ff76331442d 67489->67490 67490->66908 67492 7ff763310af7 67491->67492 67493 7ff763310aff 67491->67493 67530 7ff7633167a0 86 API calls 2 library calls 67492->67530 67498 7ff763310b99 67493->67498 67520 7ff763316660 67493->67520 67496 7ff763310b1d 67497 7ff763310b50 ISource 67496->67497 67501 7ff763310b94 67496->67501 67499 7ff763384bd0 _Strxfrm 8 API calls 67497->67499 67500 7ff7633163e0 86 API calls 67498->67500 67502 7ff763310b7f 67499->67502 67504 7ff763310bc9 67500->67504 67503 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67501->67503 67502->66915 67503->67498 67505 7ff763387db4 Concurrency::cancel_current_task 2 API calls 67504->67505 67506 7ff763310bda 67505->67506 67508 7ff7633136e0 127 API calls 67507->67508 67509 7ff763310039 67508->67509 67509->67455 67510->67464 67515 7ff763312b20 67512->67515 67514 7ff76331123c 67514->67484 67516 7ff763312b2f 67515->67516 67517 7ff763312b7d ISource 67515->67517 67516->67517 67518 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67516->67518 67517->67514 67519 7ff763312bc2 67518->67519 67523 7ff763316686 67520->67523 67521 7ff7633166cc 67524 7ff763384e90 std::_Facet_Register 86 API calls 67521->67524 67522 7ff763316791 67531 7ff7632fd470 86 API calls 67522->67531 67523->67521 67523->67522 67526 7ff76331673d 67523->67526 67527 7ff7633166e8 67524->67527 67526->67496 67529 7ff763312620 86 API calls 67527->67529 67529->67526 67530->67493 67533 7ff76335a214 RegOpenKeyExA 67532->67533 67534 7ff76335a45b 67533->67534 67540 7ff76335a237 ISource 67533->67540 67535 7ff76335a46a 67534->67535 67536 7ff76335a464 RegCloseKey 67534->67536 67538 7ff763384bd0 _Strxfrm 8 API calls 67535->67538 67536->67535 67537 7ff76335a244 RegEnumKeyExA 67537->67540 67539 7ff76335a47c 67538->67539 67539->66942 67540->67534 67540->67537 67543 7ff76335a4a2 67540->67543 67544 7ff763335890 86 API calls 67540->67544 67546 7ff76335a4a8 67540->67546 67550 7ff76335a497 67540->67550 67552 7ff76335a49c 67540->67552 67560 7ff763318e20 86 API calls 6 library calls 67540->67560 67561 7ff763321bc0 86 API calls _invalid_parameter_noinfo_noreturn 67540->67561 67545 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67543->67545 67544->67540 67545->67546 67548 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67546->67548 67549 7ff76335a4ae 67548->67549 67551 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67550->67551 67551->67552 67562 7ff7632fd450 86 API calls 67552->67562 67554 7ff7633125d6 ISource 67553->67554 67555 7ff7633125a1 67553->67555 67554->66933 67563 7ff763316f00 83 API calls 2 library calls 67555->67563 67557 7ff7633125aa 67557->67554 67558 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67557->67558 67559 7ff7633125f6 67558->67559 67559->66933 67560->67540 67563->67557 67567 7ff76335d580 ISource 67564->67567 67568 7ff76335d648 FreeEnvironmentStringsW 67567->67568 67569 7ff76335d675 67567->67569 67587 7ff763360ed0 86 API calls 4 library calls 67567->67587 67588 7ff763363bd0 86 API calls 4 library calls 67567->67588 67568->66983 67570 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67569->67570 67571 7ff76335d67a 67570->67571 67572 7ff76335d6e4 67571->67572 67573 7ff76335d6b3 RtlInitUnicodeString RtlInitUnicodeString 67571->67573 67572->66983 67573->66983 67574->67002 67576 7ff76331ad3d 67575->67576 67577 7ff763318af0 86 API calls 67576->67577 67578 7ff76331ad72 67576->67578 67577->67578 67579 7ff76331af5c 67578->67579 67581 7ff76331af1d 67578->67581 67590 7ff7632fe870 86 API calls 67579->67590 67580 7ff76331af2e 67580->67002 67581->67580 67589 7ff7633195d0 86 API calls 2 library calls 67581->67589 67584 7ff76331afa0 67585 7ff763387db4 Concurrency::cancel_current_task 2 API calls 67584->67585 67586 7ff76331afb1 67585->67586 67587->67567 67588->67567 67589->67580 67590->67584 67591->67023 67592->67023 67600 7ff763300ee0 ISource 67597->67600 67598 7ff7633011f4 67602 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67598->67602 67599 7ff763384bd0 _Strxfrm 8 API calls 67605 7ff7633010b4 67599->67605 67600->67598 67601 7ff7633011e9 67600->67601 67604 7ff763301040 ISource 67600->67604 67606 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67601->67606 67607 7ff7633011fa 67602->67607 67603 7ff7633011ee 67608 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67603->67608 67604->67603 67609 7ff76330108c ISource 67604->67609 67605->67108 67606->67603 67607->67108 67608->67598 67609->67599 67613 7ff7633015d0 ISource 67610->67613 67611 7ff7633018e4 67615 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67611->67615 67612 7ff763384bd0 _Strxfrm 8 API calls 67619 7ff7633017a4 67612->67619 67613->67611 67614 7ff7633018d9 67613->67614 67618 7ff763301730 ISource 67613->67618 67620 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67614->67620 67616 7ff7633018ea 67615->67616 67617 7ff7633018de 67621 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67617->67621 67618->67617 67622 7ff76330177c ISource 67618->67622 67619->67094 67619->67095 67620->67617 67621->67611 67622->67612 67624 7ff7633117c5 67623->67624 67625 7ff7633117f8 ISource 67623->67625 67624->67625 67626 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 67624->67626 67625->67096 68800 7ff7633135e9 68801 7ff763384e90 std::_Facet_Register 86 API calls 68800->68801 68802 7ff7633135fc 68801->68802 68803 7ff763311a80 86 API calls 68802->68803 68804 7ff763313619 68803->68804 68805 7ff763384bd0 _Strxfrm 8 API calls 68804->68805 68806 7ff7633136a4 68805->68806 69278 7ff76335ffc7 69279 7ff76335ffd1 69278->69279 69280 7ff763360440 89 API calls 69279->69280 69281 7ff76335ffe0 69280->69281 69282 7ff763384bd0 _Strxfrm 8 API calls 69281->69282 69283 7ff7633602eb 69282->69283 68807 7ff76331356d 68808 7ff763384e90 std::_Facet_Register 86 API calls 68807->68808 68809 7ff763313580 68808->68809 68814 7ff76331c7c0 68809->68814 68812 7ff763384bd0 _Strxfrm 8 API calls 68813 7ff7633136a4 68812->68813 68815 7ff763384e90 std::_Facet_Register 86 API calls 68814->68815 68816 7ff76331c7f8 68815->68816 68819 7ff763328080 68816->68819 68820 7ff76331359d 68819->68820 68821 7ff7633280b4 68819->68821 68820->68812 68822 7ff763384e90 std::_Facet_Register 86 API calls 68821->68822 68823 7ff7633280cd 68822->68823 68824 7ff763311a80 86 API calls 68823->68824 68825 7ff7633280ea 68824->68825 68826 7ff763313510 8 API calls 68825->68826 68827 7ff7633280f8 68826->68827 68828 7ff763328080 86 API calls 68827->68828 68828->68820 68829 7ff763322e30 68830 7ff763322e47 68829->68830 68831 7ff763322e52 _Strxfrm 68829->68831 68832 7ff763322e63 _Strxfrm 68831->68832 68833 7ff763322f8d 68831->68833 68836 7ff763367ee4 68831->68836 68833->68832 68835 7ff763367ee4 _fread_nolock 92 API calls 68833->68835 68835->68832 68839 7ff763367f04 68836->68839 68840 7ff763367f2e 68839->68840 68851 7ff763367efc 68839->68851 68841 7ff763367f3d memcpy_s 68840->68841 68842 7ff763367f7a 68840->68842 68840->68851 68853 7ff76336cb7c 11 API calls _Strcoll 68841->68853 68852 7ff7633673fc EnterCriticalSection 68842->68852 68846 7ff763367f52 68854 7ff7633686b8 83 API calls _invalid_parameter_noinfo_noreturn 68846->68854 68851->68831 68853->68846 68854->68851 69284 7ff763312f11 69285 7ff763312f24 69284->69285 69304 7ff763313272 69284->69304 69305 7ff763313960 69285->69305 69288 7ff763313278 69313 7ff763310670 86 API calls ISource 69304->69313 69308 7ff763313994 69305->69308 69311 7ff7633139f1 69305->69311 69307 7ff763313a17 69310 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69307->69310 69314 7ff763317b50 8 API calls _Strxfrm 69308->69314 69312 7ff763313a1d 69310->69312 69315 7ff7632fd390 86 API calls 2 library calls 69311->69315 69313->69288 69314->69311 69315->69307 68855 7ff76332baf0 68856 7ff7632ff020 86 API calls 68855->68856 68857 7ff76332bb50 68856->68857 68858 7ff7632feeb0 92 API calls 68857->68858 68859 7ff76332bb61 68858->68859 68860 7ff76332e288 68859->68860 68861 7ff76332bba5 ISource 68859->68861 68862 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68860->68862 68952 7ff76332bc7f ISource 68861->68952 69018 7ff7633133a0 86 API calls Concurrency::cancel_current_task 68861->69018 68864 7ff76332e28d 68862->68864 68866 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68864->68866 68865 7ff76332c006 68869 7ff7632ff320 86 API calls 68865->68869 68867 7ff76332e293 68866->68867 68871 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68867->68871 68868 7ff763306c10 86 API calls 68868->68952 68870 7ff76332c195 68869->68870 68872 7ff76332c1d9 ISource 68870->68872 68873 7ff76332e299 68870->68873 68871->68873 68874 7ff7633003b0 107 API calls 68872->68874 68876 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68873->68876 68875 7ff76332c20c 68874->68875 68880 7ff763313ef0 97 API calls 68875->68880 69010 7ff76332c85c ISource _Strxfrm 68875->69010 68878 7ff76332e29f 68876->68878 68877 7ff7633003b0 107 API calls 68877->68952 69028 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 68878->69028 68879 7ff76332e2ef 69029 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 68879->69029 68882 7ff76332c289 68880->68882 68885 7ff76332e2bc 68882->68885 69002 7ff76332c298 68882->69002 68884 7ff76332e30c 68889 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68884->68889 68890 7ff7632ffb70 91 API calls 68885->68890 68886 7ff76332e19d 68887 7ff76332e1e0 ISource 68886->68887 68894 7ff76332e4c6 68886->68894 68892 7ff76332e23c ISource 68887->68892 68900 7ff76332e4cc 68887->68900 68888 7ff763352540 214 API calls 68888->68952 68893 7ff76332e312 68889->68893 68891 7ff76332e2d3 68890->68891 68898 7ff7632ffb70 91 API calls 68891->68898 68895 7ff763384bd0 _Strxfrm 8 API calls 68892->68895 68903 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68893->68903 68902 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68894->68902 68901 7ff76332e26d 68895->68901 68896 7ff7633003b0 107 API calls 68896->69010 68897 7ff763302bb0 83 API calls 68897->68952 68907 7ff76332e2e3 68898->68907 68899 7ff7633242c0 86 API calls 68899->68952 68905 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68900->68905 68902->68900 68904 7ff76332e318 68903->68904 68909 7ff7632ffb70 91 API calls 68904->68909 68908 7ff76332e4d2 68905->68908 68906 7ff763306c10 86 API calls 68906->69010 68911 7ff7632fea20 2 API calls 68907->68911 68912 7ff76332e328 68909->68912 68910 7ff76332e3c9 69033 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 68910->69033 68914 7ff76332e2e9 68911->68914 68918 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68912->68918 68919 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68914->68919 68915 7ff76332e3e6 68923 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68915->68923 68916 7ff7633003b0 107 API calls 68916->69002 68921 7ff76332e32e 68918->68921 68919->68879 68920 7ff763306c10 86 API calls 69015 7ff76332d5b1 ISource _Strxfrm 68920->69015 68928 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68921->68928 68922 7ff76332e391 68927 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68922->68927 68926 7ff76332e3ec 68923->68926 68924 7ff76332e3b2 68925 7ff7632ffb70 91 API calls 68924->68925 68925->68910 68933 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68926->68933 68931 7ff76332e397 68927->68931 68932 7ff76332e334 68928->68932 68929 7ff763300070 88 API calls 68929->69002 68930 7ff763352540 214 API calls 68930->69002 69031 7ff7632fd450 86 API calls 68931->69031 69030 7ff7632fd390 86 API calls 2 library calls 68932->69030 68935 7ff76332e3f2 68933->68935 68934 7ff763311a80 86 API calls 68934->68952 68942 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68935->68942 68936 7ff7632ff020 86 API calls 68936->69002 68938 7ff763310ac0 86 API calls 68938->68952 68940 7ff76332e39d 68944 7ff7632fea20 2 API calls 68940->68944 68941 7ff7633003b0 107 API calls 68941->69015 68945 7ff76332e3f8 68942->68945 68943 7ff7632feeb0 92 API calls 68943->69002 68946 7ff76332e3a3 68944->68946 68950 7ff7632ffb70 91 API calls 68945->68950 69032 7ff7632ffa60 86 API calls 2 library calls 68946->69032 68947 7ff7632ff3f0 83 API calls 68947->69002 68948 7ff76332e33a 68958 7ff7633163e0 86 API calls 68948->68958 68949 7ff76332e4a9 69037 7ff7632ffbe0 91 API calls Concurrency::cancel_current_task 68949->69037 68953 7ff76332e408 68950->68953 68952->68864 68952->68865 68952->68867 68952->68868 68952->68877 68952->68878 68952->68888 68952->68897 68952->68899 68952->68934 68952->68938 68959 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68953->68959 68955 7ff763311990 83 API calls 68955->69002 68964 7ff76332e377 68958->68964 68966 7ff76332e40e 68959->68966 68960 7ff763352540 214 API calls 68960->69010 68961 7ff763302bb0 83 API calls 68961->69002 68963 7ff76332e471 68968 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68963->68968 68969 7ff763387db4 Concurrency::cancel_current_task 2 API calls 68964->68969 68965 7ff76332e492 68970 7ff7632ffb70 91 API calls 68965->68970 68973 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68966->68973 68967 7ff7633242c0 86 API calls 68967->69002 68971 7ff76332e477 68968->68971 68972 7ff76332e38b 68969->68972 68970->68949 69035 7ff7632fd450 86 API calls 68971->69035 68977 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68972->68977 68975 7ff76332e414 68973->68975 68974 7ff763302bb0 83 API calls 68974->69010 69034 7ff7632fd390 86 API calls 2 library calls 68975->69034 68977->68922 68978 7ff76332e47d 68981 7ff7632fea20 2 API calls 68978->68981 68980 7ff763306990 86 API calls 68980->69010 68982 7ff76332e483 68981->68982 69036 7ff7632ffa60 86 API calls 2 library calls 68982->69036 68983 7ff76332e41a 68987 7ff7633163e0 86 API calls 68983->68987 68984 7ff7632feeb0 92 API calls 68984->69010 68986 7ff763352540 214 API calls 68986->69015 68990 7ff76332e457 68987->68990 68992 7ff763387db4 Concurrency::cancel_current_task 2 API calls 68990->68992 68991 7ff763310ac0 86 API calls 68991->69002 68993 7ff76332e46b 68992->68993 68995 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 68993->68995 68994 7ff763302bb0 83 API calls 68994->69015 68995->68963 68996 7ff763306990 86 API calls 68996->69015 68997 7ff7632feeb0 92 API calls 68997->69015 68998 7ff7633242c0 86 API calls 68998->69010 69000 7ff763311a80 86 API calls 69000->69002 69001 7ff763310ac0 86 API calls 69001->69015 69002->68891 69002->68907 69002->68916 69002->68929 69002->68930 69002->68936 69002->68943 69002->68947 69002->68955 69002->68961 69002->68967 69002->68991 69002->69000 69003 7ff7633109e0 86 API calls 69002->69003 69002->69010 69019 7ff763312870 86 API calls 3 library calls 69002->69019 69003->69002 69004 7ff7633242c0 86 API calls 69004->69015 69005 7ff763311a80 86 API calls 69005->69010 69006 7ff763311a80 86 API calls 69006->69015 69007 7ff763384e90 86 API calls std::_Facet_Register 69007->69010 69008 7ff763310ac0 86 API calls 69008->69010 69009 7ff763312620 86 API calls 69009->69010 69010->68879 69010->68884 69010->68893 69010->68896 69010->68904 69010->68906 69010->68910 69010->68912 69010->68914 69010->68921 69010->68922 69010->68924 69010->68931 69010->68932 69010->68940 69010->68946 69010->68948 69010->68960 69010->68972 69010->68974 69010->68980 69010->68984 69010->68998 69010->69005 69010->69007 69010->69008 69010->69009 69011 7ff763313510 8 API calls 69010->69011 69010->69015 69020 7ff763334ad0 97 API calls 2 library calls 69010->69020 69021 7ff763310c60 86 API calls 69010->69021 69022 7ff76331b9d0 86 API calls 3 library calls 69010->69022 69023 7ff76332af00 116 API calls _Strxfrm 69010->69023 69011->69010 69013 7ff763384e90 86 API calls std::_Facet_Register 69013->69015 69014 7ff763312620 86 API calls 69014->69015 69015->68886 69015->68915 69015->68920 69015->68926 69015->68935 69015->68941 69015->68945 69015->68949 69015->68953 69015->68963 69015->68965 69015->68966 69015->68971 69015->68975 69015->68978 69015->68982 69015->68983 69015->68986 69015->68993 69015->68994 69015->68996 69015->68997 69015->69001 69015->69004 69015->69006 69015->69013 69015->69014 69017 7ff763313510 8 API calls 69015->69017 69024 7ff763334ad0 97 API calls 2 library calls 69015->69024 69025 7ff763310c60 86 API calls 69015->69025 69026 7ff76331b9d0 86 API calls 3 library calls 69015->69026 69027 7ff76332af00 116 API calls _Strxfrm 69015->69027 69017->69015 69019->69002 69020->69010 69021->69010 69022->69010 69023->69010 69024->69015 69025->69015 69026->69015 69027->69015 69030->68948 69032->68924 69034->68983 69036->68965 69316 7ff76332b750 69317 7ff763353640 190 API calls 69316->69317 69318 7ff76332b785 69317->69318 69319 7ff7633150b0 86 API calls 69318->69319 69327 7ff76332b87f ISource 69318->69327 69323 7ff76332b7a3 69319->69323 69320 7ff763302bb0 83 API calls 69321 7ff76332b8af 69320->69321 69322 7ff763384bd0 _Strxfrm 8 API calls 69321->69322 69324 7ff76332b8c2 69322->69324 69325 7ff7633416a0 88 API calls 69323->69325 69326 7ff76332b7d6 ISource 69325->69326 69326->69327 69328 7ff76332b8d0 69326->69328 69329 7ff76332b8cb 69326->69329 69327->69320 69330 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69328->69330 69331 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69329->69331 69332 7ff76332b8d6 69330->69332 69331->69328 69038 7ff763359d30 GetCurrentHwProfileW 69039 7ff763359d78 69038->69039 69040 7ff763359dd8 69038->69040 69041 7ff7633413f0 88 API calls 69039->69041 69043 7ff763384bd0 _Strxfrm 8 API calls 69040->69043 69042 7ff763359d87 69041->69042 69042->69040 69046 7ff763366948 90 API calls 69042->69046 69045 7ff763359e50 69043->69045 69046->69042 69333 7ff763359550 69354 7ff763352670 69333->69354 69335 7ff763359598 GetVolumeInformationW 69337 7ff7633595f4 69335->69337 69340 7ff763359626 ISource memcpy_s 69335->69340 69339 7ff7633597be 69337->69339 69337->69340 69338 7ff763359643 69341 7ff763384bd0 _Strxfrm 8 API calls 69338->69341 69342 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69339->69342 69340->69338 69343 7ff763312230 127 API calls 69340->69343 69344 7ff7633597a5 69341->69344 69345 7ff7633597c3 69342->69345 69346 7ff7633596da 69343->69346 69347 7ff7633132f0 93 API calls 69346->69347 69348 7ff763359713 69347->69348 69349 7ff76334d2b0 119 API calls 69348->69349 69350 7ff76335974b 69349->69350 69351 7ff76330fee0 86 API calls 69350->69351 69352 7ff763359758 69351->69352 69353 7ff76330eb50 83 API calls 69352->69353 69353->69338 69367 7ff763311620 69354->69367 69357 7ff76335277b 69362 7ff763306990 86 API calls 69357->69362 69366 7ff76335288f 69357->69366 69358 7ff7633526cf 69358->69357 69373 7ff76338baac GetCurrentDirectoryW 69358->69373 69377 7ff763317380 86 API calls 5 library calls 69358->69377 69361 7ff76335289c 69364 7ff7633527ef 69362->69364 69363 7ff763352858 ISource 69363->69335 69364->69363 69365 7ff7633686d8 _invalid_parameter_noinfo_noreturn 83 API calls 69364->69365 69365->69366 69378 7ff7632ffa60 86 API calls 2 library calls 69366->69378 69368 7ff763311650 69367->69368 69369 7ff763311635 69367->69369 69372 7ff763311662 69368->69372 69379 7ff763317380 86 API calls 5 library calls 69368->69379 69369->69358 69371 7ff7633116a3 69371->69358 69372->69358 69374 7ff76338bacd GetLastError 69373->69374 69375 7ff76338babe 69373->69375 69376 7ff76338bac2 69374->69376 69375->69374 69375->69376 69376->69358 69377->69358 69378->69361 69379->69371 69380 7ff763352950 69381 7ff763352980 69380->69381 69382 7ff76338bae8 107 API calls 69381->69382 69383 7ff763352999 69382->69383 69384 7ff763384bd0 _Strxfrm 8 API calls 69383->69384 69385 7ff7633529d6 69384->69385 69047 7ff763313236 69048 7ff76331323b ISource 69047->69048 69049 7ff763384bd0 _Strxfrm 8 API calls 69048->69049 69050 7ff76331324f 69049->69050 69051 7ff76335fd31 69052 7ff76335fd5c 69051->69052 69065 7ff76335fd47 69051->69065 69055 7ff76335fd65 69052->69055 69056 7ff76335ff2c 69052->69056 69053 7ff76335ff99 69054 7ff76335fa00 8 API calls 69053->69054 69054->69065 69061 7ff7633176b0 86 API calls 69055->69061 69062 7ff76335fdc6 memcpy_s 69055->69062 69056->69053 69059 7ff76335fa00 8 API calls 69056->69059 69057 7ff763384bd0 _Strxfrm 8 API calls 69060 7ff7633602eb 69057->69060 69058 7ff76335febe 69063 7ff76335fa00 8 API calls 69058->69063 69059->69056 69061->69062 69062->69058 69064 7ff76335fa00 8 API calls 69062->69064 69063->69065 69064->69062 69065->69057 69386 7ff763370650 69397 7ff7633704b4 69386->69397 69389 7ff7633706ad 69391 7ff7633706ed 69389->69391 69392 7ff763370676 69389->69392 69415 7ff7633751a4 83 API calls 2 library calls 69389->69415 69403 7ff7633704dc 69391->69403 69395 7ff7633706e1 69395->69391 69416 7ff763375880 11 API calls 2 library calls 69395->69416 69398 7ff7633704bd 69397->69398 69402 7ff7633704cd 69397->69402 69417 7ff76336cb7c 11 API calls _Strcoll 69398->69417 69400 7ff7633704c2 69418 7ff7633686b8 83 API calls _invalid_parameter_noinfo_noreturn 69400->69418 69402->69389 69402->69392 69414 7ff7633705d4 83 API calls _invalid_parameter_noinfo_noreturn 69402->69414 69404 7ff7633704b4 _fread_nolock 83 API calls 69403->69404 69405 7ff763370501 69404->69405 69406 7ff7633705a1 69405->69406 69407 7ff763370510 69405->69407 69428 7ff7633739cc 83 API calls 2 library calls 69406->69428 69409 7ff76337052e 69407->69409 69412 7ff76337054c 69407->69412 69427 7ff7633739cc 83 API calls 2 library calls 69409->69427 69411 7ff76337053c 69411->69392 69412->69411 69419 7ff7633764d4 69412->69419 69414->69389 69415->69395 69416->69391 69417->69400 69418->69402 69420 7ff763376504 69419->69420 69429 7ff763376300 69420->69429 69423 7ff763376543 69425 7ff763376558 69423->69425 69441 7ff763366678 83 API calls 2 library calls 69423->69441 69425->69411 69427->69411 69428->69411 69430 7ff76337632d 69429->69430 69431 7ff763376349 69429->69431 69430->69423 69440 7ff763366678 83 API calls 2 library calls 69430->69440 69432 7ff7633763d7 69431->69432 69434 7ff763376381 69431->69434 69443 7ff7633685e8 83 API calls _invalid_parameter_noinfo_noreturn 69432->69443 69442 7ff76337ba54 EnterCriticalSection 69434->69442 69440->69423 69441->69425 69443->69430
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: FileModuleName
                                              • String ID: $ --key "$" --type $APPB:$File.exe$cmd /c ""$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set$status$6
                                              • API String ID: 514040917-1525073170
                                              • Opcode ID: 5fc856a2cc2307c6d7fa37578e25aed0dccd97dc840e6619a0df3d6f05366ff4
                                              • Instruction ID: 43234b4f68dbcce1297aa978df6c85ad3a6c802a45ea733f4e4ddd3d07ef55de
                                              • Opcode Fuzzy Hash: 5fc856a2cc2307c6d7fa37578e25aed0dccd97dc840e6619a0df3d6f05366ff4
                                              • Instruction Fuzzy Hash: 6223C772A15BC5C9EBA09F29D8813EDB361FB85758F405329EA9D17B99EF38D240C310

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 519 7ff763358cc0-7ff763358e09 GetSystemMetrics * 4 GetDC GetDeviceCaps * 2 CreateCompatibleDC CreateCompatibleBitmap SelectObject BitBlt SHCreateMemStream 520 7ff763358ed3-7ff763358f5d call 7ff763351320 EnterCriticalSection LeaveCriticalSection GetObjectW 519->520 521 7ff763358e0f-7ff763358e61 SelectObject DeleteDC ReleaseDC DeleteObject 519->521 529 7ff763358fbf-7ff763358fda 520->529 530 7ff763358f5f-7ff763358fa5 520->530 523 7ff763358e63-7ff763358e74 521->523 524 7ff763358ea0-7ff763358ed2 call 7ff763384bd0 521->524 526 7ff763358e76-7ff763358e89 523->526 527 7ff763358e8f call 7ff763384bf0 523->527 526->527 531 7ff763359273-7ff763359278 call 7ff7633686d8 526->531 537 7ff763358e94-7ff763358e9b 527->537 535 7ff763358fde-7ff763359029 call 7ff7633514b0 IStream_Size IStream_Reset 529->535 530->535 536 7ff763358fa7-7ff763358fbd 530->536 541 7ff76335902b-7ff763359033 535->541 542 7ff763359035 535->542 536->535 537->524 543 7ff76335906a-7ff763359119 IStream_Read call 7ff7633875a0 call 7ff76330ffc0 call 7ff7633347b0 SelectObject DeleteDC ReleaseDC DeleteObject 541->543 542->543 544 7ff763359037-7ff763359041 542->544 559 7ff76335911b-7ff763359128 543->559 560 7ff763359148-7ff76335914a 543->560 545 7ff763359043-7ff76335904f call 7ff763363ff0 544->545 546 7ff763359051-7ff763359062 call 7ff7633875a0 544->546 553 7ff763359066 545->553 546->553 553->543 559->560 561 7ff76335912a-7ff763359146 559->561 562 7ff76335914c-7ff763359159 560->562 563 7ff763359177-7ff76335917b 560->563 565 7ff763359180-7ff763359183 561->565 562->563 564 7ff76335915b-7ff763359175 562->564 563->565 564->565 566 7ff76335918d-7ff7633591c8 call 7ff76330eb50 565->566 567 7ff763359185-7ff763359188 call 7ff7633133a0 565->567 571 7ff7633591ee-7ff763359204 call 7ff763351320 EnterCriticalSection 566->571 572 7ff7633591ca-7ff7633591e8 DeleteObject 566->572 567->566 575 7ff76335922b-7ff76335923d LeaveCriticalSection 571->575 576 7ff763359206-7ff763359216 EnterCriticalSection 571->576 572->571 575->524 577 7ff763359243-7ff763359254 575->577 578 7ff76335921e-7ff763359225 LeaveCriticalSection 576->578 579 7ff763359218 GdiplusShutdown 576->579 577->527 580 7ff76335925a-7ff76335926d 577->580 578->575 579->578 580->527 580->531
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Object$CriticalSection$Delete$MetricsSystem$CreateEnterLeaveSelectStream_$CapsCompatibleDeviceRelease$BitmapGdiplusReadResetShutdownSizeStream_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 1635401455-3916222277
                                              • Opcode ID: 3a2c9e1e0611246e604ce157a124539e6b286dd82537658a06beef2d21c92f2c
                                              • Instruction ID: a9261e48893476d7ece692920c4d630b003d1b664ac956f52e7cebb78dcbdd48
                                              • Opcode Fuzzy Hash: 3a2c9e1e0611246e604ce157a124539e6b286dd82537658a06beef2d21c92f2c
                                              • Instruction Fuzzy Hash: 73028E72A14BC1CAE750DF76D8442A9B7A1FB897A8F90423AEA5D57B98DF3CD044C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$__std_fs_convert_wide_to_narrow
                                              • String ID: cannot use push_back() with $content$directory_iterator::directory_iterator$exists$filename$recursive_directory_iterator::operator++$recursive_directory_iterator::recursive_directory_iterator$status
                                              • API String ID: 972399972-4250644884
                                              • Opcode ID: ac1c4a39928003ae646900306c94808a3542728c4d9560a95ceaf51d0f58be9e
                                              • Instruction ID: a8c6469e3d444de103ad890cfc7a06b92b308b8ced9c755bfaff491dd173b033
                                              • Opcode Fuzzy Hash: ac1c4a39928003ae646900306c94808a3542728c4d9560a95ceaf51d0f58be9e
                                              • Instruction Fuzzy Hash: 65236C72A09BC2C1EAB0AB15E4807EAB361FBC5754F80523AD69D53B99EF3CD144CB10

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1289 7ff76335b410-7ff76335b8d9 call 7ff7633598a0 call 7ff7633597d0 call 7ff763359960 call 7ff763359410 call 7ff7633594b0 call 7ff76335b100 call 7ff763359280 call 7ff7633242c0 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 call 7ff7633242c0 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 call 7ff7633242c0 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 call 7ff7633242c0 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 GlobalMemoryStatusEx 1352 7ff76335b8db-7ff76335b8e0 1289->1352 1353 7ff76335b8e2-7ff76335b8f3 1289->1353 1354 7ff76335b8f7-7ff76335bc2d call 7ff763312e00 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 call 7ff7633242c0 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 call 7ff7633242c0 call 7ff763301d20 call 7ff763310ac0 1352->1354 1353->1354 1385 7ff76335bc30-7ff76335bc38 1354->1385 1385->1385 1386 7ff76335bc3a-7ff76335bca6 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 call 7ff763358cc0 1385->1386 1395 7ff76335bcab-7ff76335bdbf call 7ff7633140b0 call 7ff763314380 call 7ff763301d20 call 7ff763310ac0 1386->1395 1396 7ff76335bca8 1386->1396 1405 7ff76335bdc0-7ff76335bdc8 1395->1405 1396->1395 1405->1405 1406 7ff76335bdca-7ff76335be23 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 1405->1406 1413 7ff76335be59-7ff76335be7b 1406->1413 1414 7ff76335be25-7ff76335be39 1406->1414 1415 7ff76335be7d-7ff76335be91 1413->1415 1416 7ff76335beb1-7ff76335c049 call 7ff763358af0 call 7ff763314380 call 7ff763301d20 call 7ff763310ac0 1413->1416 1417 7ff76335be3b-7ff76335be4e 1414->1417 1418 7ff76335be54 call 7ff763384bf0 1414->1418 1421 7ff76335beac call 7ff763384bf0 1415->1421 1422 7ff76335be93-7ff76335bea6 1415->1422 1441 7ff76335c050-7ff76335c058 1416->1441 1417->1418 1419 7ff76335cd63-7ff76335cd68 call 7ff7633686d8 1417->1419 1418->1413 1424 7ff76335cd69-7ff76335cd6e call 7ff7633686d8 1419->1424 1421->1416 1422->1421 1422->1424 1433 7ff76335cd6f-7ff76335cd74 call 7ff7633686d8 1424->1433 1439 7ff76335cd75-7ff76335cd7a call 7ff7633686d8 1433->1439 1446 7ff76335cd7b-7ff76335cd80 call 7ff7633686d8 1439->1446 1441->1441 1443 7ff76335c05a-7ff76335c0ad call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 1441->1443 1457 7ff76335c0e3-7ff76335c160 call 7ff76336f02c call 7ff76337002c call 7ff763370438 1443->1457 1458 7ff76335c0af-7ff76335c0c3 1443->1458 1452 7ff76335cd81-7ff76335cd86 call 7ff7633686d8 1446->1452 1459 7ff76335cd87-7ff76335cd8c call 7ff7633686d8 1452->1459 1475 7ff76335c163-7ff76335c16b 1457->1475 1460 7ff76335c0de call 7ff763384bf0 1458->1460 1461 7ff76335c0c5-7ff76335c0d8 1458->1461 1468 7ff76335cd8d-7ff76335cd92 call 7ff7633686d8 1459->1468 1460->1457 1461->1433 1461->1460 1474 7ff76335cd93-7ff76335cd98 call 7ff7633686d8 1468->1474 1480 7ff76335cd99-7ff76335cd9e call 7ff7633686d8 1474->1480 1475->1475 1477 7ff76335c16d-7ff76335c285 call 7ff763301d20 call 7ff763314380 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 1475->1477 1507 7ff76335c2bb-7ff76335c31d call 7ff7633875a0 GetModuleFileNameA 1477->1507 1508 7ff76335c287-7ff76335c29b 1477->1508 1486 7ff76335cd9f-7ff76335cda4 call 7ff7633686d8 1480->1486 1492 7ff76335cda5-7ff76335cdaa call 7ff7633686d8 1486->1492 1498 7ff76335cdab-7ff76335cdb0 call 7ff7633686d8 1492->1498 1504 7ff76335cdb1-7ff76335cdb6 call 7ff7633686d8 1498->1504 1512 7ff76335cdb7-7ff76335cdbf call 7ff7633686d8 1504->1512 1518 7ff76335c320-7ff76335c328 1507->1518 1510 7ff76335c29d-7ff76335c2b0 1508->1510 1511 7ff76335c2b6 call 7ff763384bf0 1508->1511 1510->1439 1510->1511 1511->1507 1518->1518 1519 7ff76335c32a-7ff76335c469 call 7ff763301d20 call 7ff7633140b0 call 7ff763314380 call 7ff763301d20 call 7ff763310ac0 1518->1519 1530 7ff76335c470-7ff76335c478 1519->1530 1530->1530 1531 7ff76335c47a-7ff76335c4db call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 1530->1531 1538 7ff76335c4dd-7ff76335c4f1 1531->1538 1539 7ff76335c511-7ff76335c539 1531->1539 1542 7ff76335c50c call 7ff763384bf0 1538->1542 1543 7ff76335c4f3-7ff76335c506 1538->1543 1540 7ff76335c56c-7ff76335c59f call 7ff76335a760 1539->1540 1541 7ff76335c53b-7ff76335c54c 1539->1541 1550 7ff76335c5a4-7ff76335c6ac call 7ff7633140b0 call 7ff763314380 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 1540->1550 1551 7ff76335c5a1 1540->1551 1545 7ff76335c54e-7ff76335c561 1541->1545 1546 7ff76335c567 call 7ff763384bf0 1541->1546 1542->1539 1543->1446 1543->1542 1545->1452 1545->1546 1546->1540 1566 7ff76335c6ae-7ff76335c6bf 1550->1566 1567 7ff76335c6df-7ff76335c6fb 1550->1567 1551->1550 1568 7ff76335c6da call 7ff763384bf0 1566->1568 1569 7ff76335c6c1-7ff76335c6d4 1566->1569 1570 7ff76335c6fd-7ff76335c711 1567->1570 1571 7ff76335c731-7ff76335c86e call 7ff7633140b0 call 7ff763314380 call 7ff763301d20 call 7ff763310ac0 1567->1571 1568->1567 1569->1459 1569->1568 1572 7ff76335c72c call 7ff763384bf0 1570->1572 1573 7ff76335c713-7ff76335c726 1570->1573 1584 7ff76335c870-7ff76335c877 1571->1584 1572->1571 1573->1468 1573->1572 1584->1584 1585 7ff76335c879-7ff76335c8ce call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 1584->1585 1592 7ff76335c8d0-7ff76335c8e1 1585->1592 1593 7ff76335c901-7ff76335c924 1585->1593 1594 7ff76335c8fc call 7ff763384bf0 1592->1594 1595 7ff76335c8e3-7ff76335c8f6 1592->1595 1596 7ff76335c9f8-7ff76335caad call 7ff763312620 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 1593->1596 1597 7ff76335c92a-7ff76335c9f3 call 7ff7633242c0 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 1593->1597 1594->1593 1595->1474 1595->1594 1619 7ff76335cab2-7ff76335cacd call 7ff763312e00 1596->1619 1597->1619 1622 7ff76335cb03-7ff76335cb27 1619->1622 1623 7ff76335cacf-7ff76335cae3 1619->1623 1626 7ff76335cb5d-7ff76335cb7f 1622->1626 1627 7ff76335cb29-7ff76335cb3d 1622->1627 1624 7ff76335cafe call 7ff763384bf0 1623->1624 1625 7ff76335cae5-7ff76335caf8 1623->1625 1624->1622 1625->1480 1625->1624 1631 7ff76335cbb5-7ff76335cbd7 1626->1631 1632 7ff76335cb81-7ff76335cb95 1626->1632 1629 7ff76335cb58 call 7ff763384bf0 1627->1629 1630 7ff76335cb3f-7ff76335cb52 1627->1630 1629->1626 1630->1486 1630->1629 1633 7ff76335cc0d-7ff76335cc2f 1631->1633 1634 7ff76335cbd9-7ff76335cbed 1631->1634 1636 7ff76335cb97-7ff76335cbaa 1632->1636 1637 7ff76335cbb0 call 7ff763384bf0 1632->1637 1640 7ff76335cc65-7ff76335cc87 1633->1640 1641 7ff76335cc31-7ff76335cc45 1633->1641 1638 7ff76335cc08 call 7ff763384bf0 1634->1638 1639 7ff76335cbef-7ff76335cc02 1634->1639 1636->1492 1636->1637 1637->1631 1638->1633 1639->1498 1639->1638 1646 7ff76335ccbd-7ff76335ccdf 1640->1646 1647 7ff76335cc89-7ff76335cc9d 1640->1647 1644 7ff76335cc47-7ff76335cc5a 1641->1644 1645 7ff76335cc60 call 7ff763384bf0 1641->1645 1644->1504 1644->1645 1645->1640 1648 7ff76335cd11-7ff76335cd5c call 7ff763384bd0 1646->1648 1649 7ff76335cce1-7ff76335ccf5 1646->1649 1651 7ff76335ccb8 call 7ff763384bf0 1647->1651 1652 7ff76335cc9f-7ff76335ccb2 1647->1652 1653 7ff76335cd0c call 7ff763384bf0 1649->1653 1654 7ff76335ccf7-7ff76335cd0a 1649->1654 1651->1646 1652->1512 1652->1651 1653->1648 1654->1653 1657 7ff76335cd5d-7ff76335cd62 call 7ff7633686d8 1654->1657 1657->1419
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Name$ComputerDevicesDisplayEnumFileGlobalMemoryModuleStatusUserValuewcsftime
                                              • String ID: %d-%m-%Y, %H:%M:%S$Meduza$computer_name$cpu$gpu$ram$system$time$timezone$user_name
                                              • API String ID: 3508509583-3212829035
                                              • Opcode ID: 2d5f15bc54f1ca29a225682702a53465a3a0fc97c076185d6b9a8703f5fd5a38
                                              • Instruction ID: fbfe0a0bdcdeef627bd8d926635ca70f7c56f1c7216eb29dfd7cb41ff421b464
                                              • Opcode Fuzzy Hash: 2d5f15bc54f1ca29a225682702a53465a3a0fc97c076185d6b9a8703f5fd5a38
                                              • Instruction Fuzzy Hash: CBE2C532A14BC5C9D761DF35D8802EDB761FB85748F80922AEA9C57B99EF38D284C710

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1662 7ff7633471a0-7ff7633471d3 1663 7ff763347205-7ff76334722a call 7ff763384bf0 1662->1663 1664 7ff7633471d5 1662->1664 1670 7ff76334722c 1663->1670 1671 7ff763347255-7ff763347279 call 7ff763384bf0 1663->1671 1665 7ff7633471e0-7ff763347203 call 7ff76334d080 call 7ff763384bf0 1664->1665 1665->1663 1674 7ff763347230-7ff763347253 call 7ff76334d080 call 7ff763384bf0 1670->1674 1678 7ff76334727b 1671->1678 1679 7ff763347295-7ff7633472b2 call 7ff763384bf0 1671->1679 1674->1671 1681 7ff763347280-7ff763347293 call 7ff763384bf0 1678->1681 1688 7ff7633472e8-7ff763347318 1679->1688 1689 7ff7633472b4-7ff7633472c5 1679->1689 1681->1679 1692 7ff76334731a 1688->1692 1693 7ff763347345-7ff763347378 call 7ff763384bf0 call 7ff763348440 * 2 1688->1693 1690 7ff7633472c7-7ff7633472da 1689->1690 1691 7ff7633472e3 call 7ff763384bf0 1689->1691 1696 7ff7633472e0 1690->1696 1697 7ff763347564-7ff763347569 call 7ff7633686d8 1690->1697 1691->1688 1694 7ff763347320-7ff763347343 call 7ff76334d080 call 7ff763384bf0 1692->1694 1713 7ff76334737a-7ff76334738b 1693->1713 1714 7ff7633473ae-7ff7633473d2 1693->1714 1694->1693 1696->1691 1707 7ff76334756a-7ff76334756f call 7ff7633686d8 1697->1707 1715 7ff763347570-7ff763347575 call 7ff7633686d8 1707->1715 1718 7ff7633473a9 call 7ff763384bf0 1713->1718 1719 7ff76334738d-7ff7633473a0 1713->1719 1716 7ff763347408-7ff763347429 1714->1716 1717 7ff7633473d4-7ff7633473e5 1714->1717 1734 7ff763347576-7ff76334757b call 7ff7633686d8 1715->1734 1724 7ff76334745c-7ff763347474 1716->1724 1725 7ff76334742b-7ff763347439 1716->1725 1722 7ff7633473e7-7ff7633473fa 1717->1722 1723 7ff763347403 call 7ff763384bf0 1717->1723 1718->1714 1719->1707 1726 7ff7633473a6 1719->1726 1722->1715 1728 7ff763347400 1722->1728 1723->1716 1732 7ff7633474a7-7ff7633474bf 1724->1732 1733 7ff763347476-7ff763347484 1724->1733 1730 7ff763347457 call 7ff763384bf0 1725->1730 1731 7ff76334743b-7ff76334744e 1725->1731 1726->1718 1728->1723 1730->1724 1731->1734 1738 7ff763347454 1731->1738 1736 7ff7633474ee-7ff763347506 1732->1736 1737 7ff7633474c1-7ff7633474cf 1732->1737 1740 7ff7633474a2 call 7ff763384bf0 1733->1740 1741 7ff763347486-7ff763347499 1733->1741 1742 7ff76334757c-7ff7633475c3 call 7ff7633686d8 call 7ff763352470 1734->1742 1748 7ff763347508-7ff763347515 1736->1748 1749 7ff763347534-7ff763347557 1736->1749 1746 7ff7633474e9 call 7ff763384bf0 1737->1746 1747 7ff7633474d1-7ff7633474e4 1737->1747 1738->1730 1740->1732 1741->1742 1743 7ff76334749f 1741->1743 1766 7ff7633475f5-7ff7633476fc call 7ff7633875a0 call 7ff763301d20 1742->1766 1767 7ff7633475c5-7ff7633475ee call 7ff7633528a0 call 7ff76335da50 call 7ff763311740 ExitProcess 1742->1767 1743->1740 1746->1736 1751 7ff763347558-7ff76334755d call 7ff7633686d8 1747->1751 1752 7ff7633474e6 1747->1752 1754 7ff763347517-7ff76334752a 1748->1754 1755 7ff76334752f call 7ff763384bf0 1748->1755 1758 7ff76334755e-7ff763347563 call 7ff7633686d8 1751->1758 1752->1746 1754->1758 1759 7ff76334752c 1754->1759 1755->1749 1758->1697 1759->1755 1776 7ff763347700-7ff763347708 1766->1776 1776->1776 1778 7ff76334770a-7ff76334778a call 7ff763301d20 call 7ff7633448a0 call 7ff76334b7f0 call 7ff76334a960 1776->1778 1788 7ff7633477be-7ff763347893 call 7ff76334b7f0 call 7ff76334b9e0 call 7ff76334ba60 call 7ff76336fad0 call 7ff76336fac8 call 7ff763344f80 call 7ff763312590 call 7ff76334bb70 1778->1788 1789 7ff76334778c-7ff76334779e 1778->1789 1819 7ff763347899-7ff7633478e2 call 7ff763311bd0 call 7ff76334bc60 call 7ff7633118c0 1788->1819 1820 7ff76334797e-7ff763347a0e call 7ff76335b100 call 7ff763334e60 1788->1820 1791 7ff7633477b9 call 7ff763384bf0 1789->1791 1792 7ff7633477a0-7ff7633477b3 1789->1792 1791->1788 1792->1791 1795 7ff763347bff-7ff763347c04 call 7ff7633686d8 1792->1795 1801 7ff763347c05-7ff763347c0a call 7ff7633686d8 1795->1801 1807 7ff763347c0b-7ff763347c10 call 7ff7633686d8 1801->1807 1838 7ff7633478e8-7ff763347910 call 7ff76333f820 call 7ff763311320 1819->1838 1839 7ff763347975-7ff763347977 ExitProcess 1819->1839 1829 7ff763347a10-7ff763347a25 1820->1829 1830 7ff763347a45-7ff763347a88 OpenMutexA 1820->1830 1832 7ff763347a27-7ff763347a3a 1829->1832 1833 7ff763347a40 call 7ff763384bf0 1829->1833 1834 7ff763347a8a-7ff763347a8f ExitProcess 1830->1834 1835 7ff763347a96-7ff763347ace CreateMutexExA call 7ff763340970 call 7ff7633529e0 1830->1835 1832->1801 1832->1833 1833->1830 1848 7ff763347adc-7ff763347b36 call 7ff76335b410 call 7ff76330d510 call 7ff76330e5a0 call 7ff76330ec50 call 7ff76330fa60 call 7ff76330c9c0 call 7ff7633314c0 call 7ff7633341a0 call 7ff763302c20 call 7ff76330ae00 call 7ff763309820 call 7ff76334ff00 call 7ff76330bee0 call 7ff763307810 call 7ff763304ad0 call 7ff763307b00 call 7ff763357bc0 1835->1848 1849 7ff763347ad0-7ff763347ad5 ExitProcess 1835->1849 1851 7ff763347968-7ff763347970 call 7ff763302b10 1838->1851 1852 7ff763347912-7ff763347967 call 7ff7633152c0 call 7ff763311300 call 7ff763341800 call 7ff7633152a0 call 7ff763311290 call 7ff763311990 1838->1852 1899 7ff763347b3b-7ff763347b4b call 7ff763342540 1848->1899 1851->1839 1852->1851 1903 7ff763347b4d-7ff763347b59 ReleaseMutex CloseHandle 1899->1903 1904 7ff763347b5f-7ff763347b66 1899->1904 1903->1904 1905 7ff763347b68-7ff763347b6d call 7ff763347c20 1904->1905 1906 7ff763347b6e-7ff763347b7a 1904->1906 1905->1906 1908 7ff763347bad-7ff763347bfe call 7ff7633471a0 call 7ff763384bd0 1906->1908 1909 7ff763347b7c-7ff763347b91 1906->1909 1912 7ff763347ba8 call 7ff763384bf0 1909->1912 1913 7ff763347b93-7ff763347ba6 1909->1913 1912->1908 1913->1807 1913->1912
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: --key$--type$1.0$APPB:
                                              • API String ID: 0-155154914
                                              • Opcode ID: f92cc1b6e4a30f8a6d2b8695ab4f0f9a510a396872d5d3fa63fd374dd7418253
                                              • Instruction ID: fe90439c4ceb88fb52e1260f62f4917403c3b23f9faa5d88bb3d5f357dcdbf4d
                                              • Opcode Fuzzy Hash: f92cc1b6e4a30f8a6d2b8695ab4f0f9a510a396872d5d3fa63fd374dd7418253
                                              • Instruction Fuzzy Hash: EF429F32A19BC6C1FA94AB26E4543EEE361FB85780F805139E69D27B96DF3CD094C310

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 1918 7ff76330d510-7ff76330d600 LoadLibraryA 1919 7ff76330e4b7-7ff76330e4c1 1918->1919 1920 7ff76330d606-7ff76330d9bf GetProcAddress * 6 1918->1920 1921 7ff76330e4d0-7ff76330e4d3 1919->1921 1922 7ff76330e4c3-7ff76330e4c5 1919->1922 1920->1919 1923 7ff76330d9c5-7ff76330d9c8 1920->1923 1924 7ff76330e4de-7ff76330e50d call 7ff763384bd0 1921->1924 1925 7ff76330e4d5-7ff76330e4d8 FreeLibrary 1921->1925 1922->1921 1923->1919 1926 7ff76330d9ce-7ff76330d9d1 1923->1926 1925->1924 1926->1919 1929 7ff76330d9d7-7ff76330d9da 1926->1929 1929->1919 1931 7ff76330d9e0-7ff76330d9e3 1929->1931 1931->1919 1932 7ff76330d9e9-7ff76330d9ec 1931->1932 1932->1919 1933 7ff76330d9f2-7ff76330da00 1932->1933 1934 7ff76330da04-7ff76330da06 1933->1934 1934->1919 1935 7ff76330da0c-7ff76330da18 1934->1935 1935->1919 1936 7ff76330da1e 1935->1936 1937 7ff76330da23-7ff76330da3e 1936->1937 1939 7ff76330e49e-7ff76330e4aa 1937->1939 1940 7ff76330da44-7ff76330da62 1937->1940 1939->1937 1941 7ff76330e4b0 1939->1941 1940->1939 1943 7ff76330da68-7ff76330da7a 1940->1943 1941->1919 1944 7ff76330da80 1943->1944 1945 7ff76330e485-7ff76330e497 1943->1945 1946 7ff76330da84-7ff76330dad5 call 7ff763384e90 1944->1946 1945->1939 1951 7ff76330dadb-7ff76330dae2 1946->1951 1952 7ff76330dd54 1946->1952 1951->1952 1953 7ff76330dae8-7ff76330dbdb call 7ff7633413f0 call 7ff7633140b0 call 7ff763314380 1951->1953 1954 7ff76330dd56-7ff76330dd5d 1952->1954 1979 7ff76330dbe2-7ff76330dbea 1953->1979 1956 7ff76330dd63-7ff76330dd6a 1954->1956 1957 7ff76330dfd4-7ff76330e010 1954->1957 1956->1957 1959 7ff76330dd70-7ff76330de5e call 7ff7633413f0 call 7ff7633140b0 call 7ff763314380 1956->1959 1965 7ff76330e2a7-7ff76330e2a9 1957->1965 1966 7ff76330e016-7ff76330e024 1957->1966 1992 7ff76330de65-7ff76330de6d 1959->1992 1971 7ff76330e457-7ff76330e46d call 7ff763310120 1965->1971 1972 7ff76330e2af-7ff76330e3d4 call 7ff763301d20 call 7ff763310ac0 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 call 7ff763384e90 call 7ff76332a460 1965->1972 1969 7ff76330e02a-7ff76330e031 1966->1969 1970 7ff76330e2a0-7ff76330e2a3 1966->1970 1969->1970 1977 7ff76330e037-7ff76330e12c call 7ff7633413f0 call 7ff7633140b0 call 7ff763314380 1969->1977 1970->1965 1975 7ff76330e2a5 1970->1975 1986 7ff76330da82 1971->1986 1987 7ff76330e473-7ff76330e47e 1971->1987 2065 7ff76330e3e0-7ff76330e3f9 call 7ff763312620 1972->2065 2066 7ff76330e3d6-7ff76330e3d8 1972->2066 1975->1965 2007 7ff76330e130-7ff76330e137 1977->2007 1979->1979 1984 7ff76330dbec-7ff76330dc46 call 7ff763301d20 call 7ff7633155e0 call 7ff763312e00 1979->1984 2014 7ff76330dc48-7ff76330dc59 1984->2014 2015 7ff76330dc79-7ff76330dca3 1984->2015 1986->1946 1987->1945 1992->1992 1996 7ff76330de6f-7ff76330dec8 call 7ff763301d20 call 7ff7633155e0 call 7ff763312e00 1992->1996 2028 7ff76330deca-7ff76330dedb 1996->2028 2029 7ff76330defb-7ff76330df25 1996->2029 2007->2007 2012 7ff76330e139-7ff76330e192 call 7ff763301d20 call 7ff7633155e0 call 7ff763312e00 2007->2012 2076 7ff76330e194-7ff76330e1a5 2012->2076 2077 7ff76330e1c5-7ff76330e1ee 2012->2077 2019 7ff76330dc5b-7ff76330dc6e 2014->2019 2020 7ff76330dc74 call 7ff763384bf0 2014->2020 2023 7ff76330dcdb-7ff76330dd01 2015->2023 2024 7ff76330dca5-7ff76330dcb9 2015->2024 2019->2020 2026 7ff76330e56c-7ff76330e571 call 7ff7633686d8 2019->2026 2020->2015 2034 7ff76330dd39-7ff76330dd52 2023->2034 2035 7ff76330dd03-7ff76330dd17 2023->2035 2031 7ff76330dcbb-7ff76330dcce 2024->2031 2032 7ff76330dcd4-7ff76330dcd9 call 7ff763384bf0 2024->2032 2039 7ff76330e572-7ff76330e577 call 7ff7633686d8 2026->2039 2036 7ff76330dedd-7ff76330def0 2028->2036 2037 7ff76330def6 call 7ff763384bf0 2028->2037 2040 7ff76330df27-7ff76330df3b 2029->2040 2041 7ff76330df5d-7ff76330df83 2029->2041 2031->2032 2031->2039 2032->2023 2034->1954 2045 7ff76330dd19-7ff76330dd2c 2035->2045 2046 7ff76330dd32-7ff76330dd37 call 7ff763384bf0 2035->2046 2036->2037 2047 7ff76330e57e-7ff76330e583 call 7ff7633686d8 2036->2047 2037->2029 2055 7ff76330e578-7ff76330e57d call 7ff7633686d8 2039->2055 2050 7ff76330df3d-7ff76330df50 2040->2050 2051 7ff76330df56-7ff76330df5b call 7ff763384bf0 2040->2051 2057 7ff76330dfbb-7ff76330dfcd 2041->2057 2058 7ff76330df85-7ff76330df99 2041->2058 2045->2046 2045->2055 2046->2034 2064 7ff76330e584-7ff76330e589 call 7ff7633686d8 2047->2064 2050->2051 2050->2064 2051->2041 2055->2047 2057->1957 2068 7ff76330df9b-7ff76330dfae 2058->2068 2069 7ff76330dfb4-7ff76330dfb9 call 7ff763384bf0 2058->2069 2071 7ff76330e58a-7ff76330e58f call 7ff7633686d8 2064->2071 2086 7ff76330e3fd-7ff76330e409 2065->2086 2078 7ff76330e3de 2066->2078 2079 7ff76330e514-7ff76330e565 call 7ff7633127e0 call 7ff763316310 call 7ff7633163e0 call 7ff763387db4 2066->2079 2068->2069 2068->2071 2069->2057 2097 7ff76330e590-7ff76330e595 call 7ff7633686d8 2071->2097 2083 7ff76330e1a7-7ff76330e1ba 2076->2083 2084 7ff76330e1c0 call 7ff763384bf0 2076->2084 2087 7ff76330e1f0-7ff76330e204 2077->2087 2088 7ff76330e224-7ff76330e24a 2077->2088 2078->2086 2112 7ff76330e566-7ff76330e56b call 7ff7633686d8 2079->2112 2083->2084 2083->2097 2084->2077 2092 7ff76330e40b-7ff76330e42e 2086->2092 2093 7ff76330e430-7ff76330e43a call 7ff76331b840 2086->2093 2100 7ff76330e21f call 7ff763384bf0 2087->2100 2101 7ff76330e206-7ff76330e219 2087->2101 2095 7ff76330e24c-7ff76330e260 2088->2095 2096 7ff76330e280-7ff76330e299 2088->2096 2105 7ff76330e43f-7ff76330e450 call 7ff763312e00 2092->2105 2093->2105 2108 7ff76330e27b call 7ff763384bf0 2095->2108 2109 7ff76330e262-7ff76330e275 2095->2109 2096->1970 2100->2088 2101->2100 2103 7ff76330e50e-7ff76330e513 call 7ff7633686d8 2101->2103 2103->2079 2105->1971 2108->2096 2109->2108 2109->2112 2112->2026
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$AddressProc$Library$FreeLoad
                                              • String ID: cannot use push_back() with $system$vault
                                              • API String ID: 2463004387-1741236777
                                              • Opcode ID: 2b98cdbaa1bbfeffe98e90da3d23d5e7708a7210484257f37841cb4d8938f9d5
                                              • Instruction ID: aceda159bda374435a99ddfe595b398cea077144a1d837950d5a80f5b72931a0
                                              • Opcode Fuzzy Hash: 2b98cdbaa1bbfeffe98e90da3d23d5e7708a7210484257f37841cb4d8938f9d5
                                              • Instruction Fuzzy Hash: 01925E72609BC58ADB619F29E8403EDB3B4F749798F504229DB9C5BB99EF38C654C300

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2125 7ff763331a80-7ff763332394 call 7ff7633003b0 * 2 2133 7ff76333239a-7ff76333275f call 7ff7632ff020 call 7ff7632feeb0 call 7ff763334a50 call 7ff763352540 call 7ff763302bb0 2125->2133 2134 7ff7633327a8-7ff7633327d2 call 7ff763384bd0 2125->2134 2150 7ff763332791-7ff7633327a1 2133->2150 2151 7ff763332761-7ff763332775 2133->2151 2150->2134 2152 7ff763332777-7ff76333278a 2151->2152 2153 7ff76333278c call 7ff763384bf0 2151->2153 2152->2153 2154 7ff7633327d3-7ff763332dad call 7ff7633686d8 call 7ff7633127e0 call 7ff763316310 call 7ff7633163e0 call 7ff763387db4 call 7ff7632ffb70 * 3 call 7ff7633686d8 * 4 call 7ff7632ffb70 call 7ff7633686d8 * 2 call 7ff7632fea20 call 7ff7633686d8 call 7ff7632ffb70 call 7ff7633686d8 * 2 call 7ff7632fea20 call 7ff7632ff020 call 7ff7632feeb0 2152->2154 2153->2150 2204 7ff763332db0-7ff763332db7 2154->2204 2204->2204 2205 7ff763332db9-7ff763332f79 call 7ff76331de60 call 7ff7632ff320 call 7ff7632ff3f0 2204->2205 2212 7ff763332f80-7ff763332f88 2205->2212 2212->2212 2213 7ff763332f8a-7ff76333304b call 7ff763301d20 call 7ff76331de60 call 7ff763306c10 call 7ff7632fec60 call 7ff7633518d0 2212->2213 2223 7ff763333050-7ff763333329 call 7ff7632ff3f0 * 2 call 7ff763311d90 2213->2223 2230 7ff763333330-7ff763333337 2223->2230 2230->2230 2231 7ff763333339-7ff763333362 call 7ff763316070 2230->2231 2234 7ff763333d49-7ff763333d54 2231->2234 2235 7ff763333368-7ff763333377 call 7ff763300310 2231->2235 2237 7ff763333d8e-7ff763333db1 2234->2237 2238 7ff763333d56-7ff763333d60 2234->2238 2235->2234 2244 7ff76333337d-7ff763333432 2235->2244 2239 7ff763333dd0-7ff763333e53 call 7ff763302bb0 call 7ff763311990 call 7ff7632ff3f0 call 7ff763311990 call 7ff763384bd0 2237->2239 2240 7ff763333db3-7ff763333dbc 2237->2240 2238->2237 2242 7ff763333d62-7ff763333d6a 2238->2242 2240->2239 2250 7ff763333dbe-7ff763333dcf 2240->2250 2245 7ff763333d70-7ff763333d73 2242->2245 2244->2234 2248 7ff763333e66-7ff763333ee6 call 7ff7632fea20 call 7ff7632ffbe0 call 7ff7632ffb70 call 7ff7633686d8 call 7ff763331850 2244->2248 2245->2237 2249 7ff763333d75-7ff763333d8c 2245->2249 2249->2245 2250->2239
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: Profiles$cannot use push_back() with $directory_iterator::directory_iterator$exists$prefs.js$status
                                              • API String ID: 0-1457875953
                                              • Opcode ID: 89d9a8ab5d0dbe2dbe5e81df4987dba28a8c4ea003609d94d462e5a4adcd2181
                                              • Instruction ID: 95f21914e547105f6e9dcebd450a9353caf4396edbd63e4f27969f45c6e98d7b
                                              • Opcode Fuzzy Hash: 89d9a8ab5d0dbe2dbe5e81df4987dba28a8c4ea003609d94d462e5a4adcd2181
                                              • Instruction Fuzzy Hash: 91525A32909BC5C5E6B1AB15E8813EAB3A4FBC9784F405229DACC67B59EF3CD144CB50

                                              Control-flow Graph

                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: content$directory_iterator::directory_iterator$exists$filename$status$telegram
                                              • API String ID: 0-572754909
                                              • Opcode ID: 8eaa77fff3547dcf0fa5227ed6f9769ab59cee067ab09958a86cd50c67ba0331
                                              • Instruction ID: f503c4f35146fd27855d673a30914891d40a0b2e040cf8d48b7ac6ee33094e90
                                              • Opcode Fuzzy Hash: 8eaa77fff3547dcf0fa5227ed6f9769ab59cee067ab09958a86cd50c67ba0331
                                              • Instruction Fuzzy Hash: B882B332A15BC5C9EB61AF25D8843EDB360FB85758F844239DA4D6BBA9DF38D640C310

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2303 7ff76338bae8-7ff76338bb28 2304 7ff76338bb2a-7ff76338bb31 2303->2304 2305 7ff76338bb3d-7ff76338bb46 2303->2305 2304->2305 2306 7ff76338bb33-7ff76338bb38 2304->2306 2307 7ff76338bb62-7ff76338bb64 2305->2307 2308 7ff76338bb48-7ff76338bb4b 2305->2308 2309 7ff76338bdbc-7ff76338bde2 call 7ff763384bd0 2306->2309 2311 7ff76338bdba 2307->2311 2312 7ff76338bb6a-7ff76338bb6e 2307->2312 2308->2307 2310 7ff76338bb4d-7ff76338bb55 2308->2310 2316 7ff76338bb57-7ff76338bb59 2310->2316 2317 7ff76338bb5b-7ff76338bb5e 2310->2317 2311->2309 2313 7ff76338bb74-7ff76338bb77 2312->2313 2314 7ff76338bc45-7ff76338bc6c call 7ff76338bebc 2312->2314 2318 7ff76338bb79-7ff76338bb81 2313->2318 2319 7ff76338bb8b-7ff76338bb9d GetFileAttributesExW 2313->2319 2328 7ff76338bc8e-7ff76338bc97 2314->2328 2329 7ff76338bc6e-7ff76338bc77 2314->2329 2316->2307 2316->2317 2317->2307 2318->2319 2322 7ff76338bb83-7ff76338bb85 2318->2322 2323 7ff76338bb9f-7ff76338bba8 GetLastError 2319->2323 2324 7ff76338bbf0-7ff76338bbff 2319->2324 2322->2314 2322->2319 2323->2309 2326 7ff76338bbae-7ff76338bbc0 FindFirstFileW 2323->2326 2327 7ff76338bc03-7ff76338bc05 2324->2327 2334 7ff76338bbc2-7ff76338bbc8 GetLastError 2326->2334 2335 7ff76338bbcd-7ff76338bbee FindClose 2326->2335 2336 7ff76338bc11-7ff76338bc3f 2327->2336 2337 7ff76338bc07-7ff76338bc0f 2327->2337 2332 7ff76338bd4b-7ff76338bd54 2328->2332 2333 7ff76338bc9d-7ff76338bcb5 GetFileInformationByHandleEx 2328->2333 2330 7ff76338bc87-7ff76338bc89 2329->2330 2331 7ff76338bc79-7ff76338bc81 CloseHandle 2329->2331 2330->2309 2331->2330 2338 7ff76338bdfd-7ff76338be02 call 7ff76337811c 2331->2338 2339 7ff76338bda3-7ff76338bda5 2332->2339 2340 7ff76338bd56-7ff76338bd6a GetFileInformationByHandleEx 2332->2340 2341 7ff76338bcb7-7ff76338bcc3 GetLastError 2333->2341 2342 7ff76338bcdd-7ff76338bcf6 2333->2342 2334->2309 2335->2327 2336->2311 2336->2314 2337->2314 2337->2336 2359 7ff76338be03-7ff76338be08 call 7ff76337811c 2338->2359 2348 7ff76338bde3-7ff76338bde7 2339->2348 2349 7ff76338bda7-7ff76338bdab 2339->2349 2344 7ff76338bd90-7ff76338bda0 2340->2344 2345 7ff76338bd6c-7ff76338bd78 GetLastError 2340->2345 2346 7ff76338bcc5-7ff76338bcd0 CloseHandle 2341->2346 2347 7ff76338bcd6-7ff76338bcd8 2341->2347 2342->2332 2350 7ff76338bcf8-7ff76338bcfc 2342->2350 2344->2339 2345->2347 2352 7ff76338bd7e-7ff76338bd89 CloseHandle 2345->2352 2346->2347 2353 7ff76338be0f-7ff76338be17 call 7ff76337811c 2346->2353 2347->2309 2357 7ff76338bdf6-7ff76338bdfb 2348->2357 2358 7ff76338bde9-7ff76338bdf4 CloseHandle 2348->2358 2349->2311 2354 7ff76338bdad-7ff76338bdb8 CloseHandle 2349->2354 2355 7ff76338bd44 2350->2355 2356 7ff76338bcfe-7ff76338bd18 GetFileInformationByHandleEx 2350->2356 2360 7ff76338be09-7ff76338be0e call 7ff76337811c 2352->2360 2361 7ff76338bd8b 2352->2361 2354->2311 2354->2338 2365 7ff76338bd48 2355->2365 2363 7ff76338bd1a-7ff76338bd26 GetLastError 2356->2363 2364 7ff76338bd3b-7ff76338bd42 2356->2364 2357->2309 2358->2338 2358->2357 2359->2360 2360->2353 2361->2347 2363->2347 2369 7ff76338bd28-7ff76338bd33 CloseHandle 2363->2369 2364->2365 2365->2332 2369->2359 2372 7ff76338bd39 2369->2372 2372->2347
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Close$ErrorFileFindHandleLast$AttributesFirst__std_fs_open_handle
                                              • String ID:
                                              • API String ID: 2398595512-0
                                              • Opcode ID: b0954c19c2ec1b49376cfeb0a7b9e933d87c955ad15e2e4042eb139bd7e8b443
                                              • Instruction ID: c293822cbef2207a2592b10fd7497e49df41b789de5d62dbdf587cbadc3a3390
                                              • Opcode Fuzzy Hash: b0954c19c2ec1b49376cfeb0a7b9e933d87c955ad15e2e4042eb139bd7e8b443
                                              • Instruction Fuzzy Hash: 9191B531A08A43C6E6F46B17A814679A2A0EF457B4F980738D97D6FBD4DE3CE445C720

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2482 7ff76330c9c0-7ff76330ca2a CredEnumerateA 2483 7ff76330d43a-7ff76330d469 call 7ff763384bd0 2482->2483 2484 7ff76330ca30-7ff76330ca39 2482->2484 2485 7ff76330d42d-7ff76330d434 CredFree 2484->2485 2486 7ff76330ca3f-7ff76330ca57 2484->2486 2485->2483 2488 7ff76330ca60-7ff76330cab2 call 7ff763384e90 2486->2488 2492 7ff76330cab8-7ff76330cadc 2488->2492 2493 7ff76330ccee-7ff76330ccf5 2488->2493 2494 7ff76330cae0-7ff76330cae8 2492->2494 2495 7ff76330ccfb-7ff76330cd1b 2493->2495 2496 7ff76330cf4f-7ff76330cf56 2493->2496 2494->2494 2497 7ff76330caea-7ff76330cb9d call 7ff763301d20 call 7ff7633140b0 call 7ff763314380 2494->2497 2498 7ff76330cd22-7ff76330cd2a 2495->2498 2499 7ff76330d19c-7ff76330d19f 2496->2499 2500 7ff76330cf5c-7ff76330d03e call 7ff763301d20 call 7ff7633140b0 call 7ff763314380 2496->2500 2528 7ff76330cba4-7ff76330cbac 2497->2528 2498->2498 2504 7ff76330cd2c-7ff76330cdea call 7ff763301d20 call 7ff7633140b0 call 7ff763314380 2498->2504 2501 7ff76330d411-7ff76330d427 call 7ff763310120 2499->2501 2502 7ff76330d1a5-7ff76330d229 2499->2502 2530 7ff76330d045-7ff76330d04d 2500->2530 2501->2485 2501->2488 2507 7ff76330d230-7ff76330d238 2502->2507 2534 7ff76330cdf1-7ff76330cdf9 2504->2534 2507->2507 2512 7ff76330d23a-7ff76330d2ec call 7ff763301d20 call 7ff763310ac0 2507->2512 2532 7ff76330d2f0-7ff76330d2f8 2512->2532 2528->2528 2533 7ff76330cbae-7ff76330cc07 call 7ff763301d20 call 7ff7633155e0 call 7ff763312e00 2528->2533 2530->2530 2535 7ff76330d04f-7ff76330d0a8 call 7ff763301d20 call 7ff7633155e0 call 7ff763312e00 2530->2535 2532->2532 2536 7ff76330d2fa-7ff76330d398 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 call 7ff763384e90 call 7ff76332a460 2532->2536 2561 7ff76330cc09-7ff76330cc1a 2533->2561 2562 7ff76330cc3a-7ff76330cc5d 2533->2562 2534->2534 2538 7ff76330cdfb-7ff76330ce54 call 7ff763301d20 call 7ff7633155e0 call 7ff763312e00 2534->2538 2564 7ff76330d0aa-7ff76330d0bb 2535->2564 2565 7ff76330d0db-7ff76330d0fb 2535->2565 2633 7ff76330d39a-7ff76330d39c 2536->2633 2634 7ff76330d3a4-7ff76330d3b7 call 7ff763312620 2536->2634 2569 7ff76330ce87-7ff76330cead 2538->2569 2570 7ff76330ce56-7ff76330ce67 2538->2570 2567 7ff76330cc1c-7ff76330cc2f 2561->2567 2568 7ff76330cc35 call 7ff763384bf0 2561->2568 2573 7ff76330cc5f-7ff76330cc70 2562->2573 2574 7ff76330cc90-7ff76330cca8 2562->2574 2571 7ff76330d0bd-7ff76330d0d0 2564->2571 2572 7ff76330d0d6 call 7ff763384bf0 2564->2572 2575 7ff76330d0fd-7ff76330d111 2565->2575 2576 7ff76330d131-7ff76330d153 2565->2576 2567->2568 2582 7ff76330d4c2-7ff76330d4c7 call 7ff7633686d8 2567->2582 2568->2562 2588 7ff76330ceaf-7ff76330cec3 2569->2588 2589 7ff76330cee3-7ff76330cf05 2569->2589 2583 7ff76330ce69-7ff76330ce7c 2570->2583 2584 7ff76330ce82 call 7ff763384bf0 2570->2584 2571->2572 2585 7ff76330d4e6-7ff7633157bd call 7ff7633686d8 2571->2585 2572->2565 2590 7ff76330cc8b call 7ff763384bf0 2573->2590 2591 7ff76330cc72-7ff76330cc85 2573->2591 2577 7ff76330ccaa-7ff76330ccbb 2574->2577 2578 7ff76330ccdb-7ff76330cceb 2574->2578 2592 7ff76330d12c call 7ff763384bf0 2575->2592 2593 7ff76330d113-7ff76330d126 2575->2593 2579 7ff76330d187-7ff76330d19a 2576->2579 2580 7ff76330d155-7ff76330d167 2576->2580 2601 7ff76330ccbd-7ff76330ccd0 2577->2601 2602 7ff76330ccd6 call 7ff763384bf0 2577->2602 2578->2493 2579->2502 2603 7ff76330d169-7ff76330d17c 2580->2603 2604 7ff76330d182 call 7ff763384bf0 2580->2604 2597 7ff76330d4c8-7ff76330d4cd call 7ff7633686d8 2582->2597 2583->2584 2609 7ff76330d4d4-7ff76330d4d9 call 7ff7633686d8 2583->2609 2584->2569 2637 7ff7633157bf 2585->2637 2638 7ff7633157f1-7ff763315804 2585->2638 2595 7ff76330cede call 7ff763384bf0 2588->2595 2596 7ff76330cec5-7ff76330ced8 2588->2596 2605 7ff76330cf07-7ff76330cf19 2589->2605 2606 7ff76330cf39-7ff76330cf4c 2589->2606 2590->2574 2591->2590 2591->2597 2592->2576 2593->2592 2598 7ff76330d46a-7ff76330d46f call 7ff7633686d8 2593->2598 2595->2589 2596->2595 2612 7ff76330d4da-7ff76330d4df call 7ff7633686d8 2596->2612 2615 7ff76330d4ce-7ff76330d4d3 call 7ff7633686d8 2597->2615 2641 7ff76330d470-7ff76330d4bb call 7ff7633127e0 call 7ff763316310 call 7ff7633163e0 call 7ff763387db4 2598->2641 2601->2602 2601->2615 2602->2578 2603->2604 2616 7ff76330d4bc-7ff76330d4c1 call 7ff7633686d8 2603->2616 2604->2579 2617 7ff76330cf1b-7ff76330cf2e 2605->2617 2618 7ff76330cf34 call 7ff763384bf0 2605->2618 2606->2496 2609->2612 2627 7ff76330d4e0-7ff76330d4e5 call 7ff7633686d8 2612->2627 2615->2609 2616->2582 2617->2618 2617->2627 2618->2606 2627->2585 2633->2641 2642 7ff76330d3a2 2633->2642 2649 7ff76330d3bb-7ff76330d3c7 2634->2649 2646 7ff7633157c0-7ff7633157ef call 7ff763317af0 call 7ff763321b50 call 7ff763384bf0 2637->2646 2641->2616 2642->2649 2646->2638 2650 7ff76330d3c9-7ff76330d3e8 2649->2650 2651 7ff76330d3ea-7ff76330d3f4 call 7ff76331b840 2649->2651 2654 7ff76330d3f9-7ff76330d407 call 7ff763312e00 2650->2654 2651->2654 2654->2501
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Cred$EnumerateFree
                                              • String ID: cannot use push_back() with
                                              • API String ID: 1347986415-4122110429
                                              • Opcode ID: db70fc8c7cc1e53bb913ccbf7ba85581c9265d57aaf4195650c43122afca833d
                                              • Instruction ID: d8d39d988e2983716efb1040c462e0d63942c7a28e9fa82c4acb7b6127594adf
                                              • Opcode Fuzzy Hash: db70fc8c7cc1e53bb913ccbf7ba85581c9265d57aaf4195650c43122afca833d
                                              • Instruction Fuzzy Hash: 3B628172A04BC5C9EB609F25E8403EDB761FB49798F505329EAAC1BB99DF78D184C310

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2670 7ff763361b00-7ff763361b41 2671 7ff763361e1d-7ff763361e57 call 7ff763365180 call 7ff7633621a0 2670->2671 2672 7ff763361b47-7ff763361b71 call 7ff7633875a0 2670->2672 2681 7ff763361e5c-7ff763361e62 2671->2681 2678 7ff763361b73-7ff763361b7c 2672->2678 2679 7ff763361b80-7ff763361bb9 call 7ff763335c60 call 7ff7633642e0 call 7ff7633621a0 2672->2679 2678->2679 2708 7ff763361d60-7ff763361d67 2679->2708 2709 7ff763361bbf-7ff763361c44 call 7ff763301d20 call 7ff763335dc0 call 7ff763339600 call 7ff763336340 2679->2709 2683 7ff763361e68-7ff763361ee3 call 7ff763301d20 call 7ff763335dc0 call 7ff763339600 call 7ff763336340 2681->2683 2684 7ff763361fff-7ff763362003 2681->2684 2738 7ff76336213e-7ff76336215a call 7ff763334a10 call 7ff763387db4 2683->2738 2739 7ff763361ee9-7ff763361ef1 2683->2739 2687 7ff7633620cc-7ff7633620d3 2684->2687 2688 7ff763362009-7ff763362066 call 7ff763312620 call 7ff763312e00 2684->2688 2690 7ff7633620a5-7ff7633620cb call 7ff763384bd0 2687->2690 2691 7ff7633620d5-7ff7633620ea 2687->2691 2688->2690 2717 7ff763362068-7ff76336207d 2688->2717 2695 7ff7633620ec-7ff7633620ff 2691->2695 2696 7ff763362094-7ff7633620a0 call 7ff763384bf0 2691->2696 2702 7ff763362109-7ff76336210e call 7ff7633686d8 2695->2702 2703 7ff763362101 2695->2703 2696->2690 2725 7ff76336210f-7ff76336212b call 7ff763334a10 call 7ff763387db4 2702->2725 2703->2696 2714 7ff763361d69-7ff763361daf call 7ff763312620 2708->2714 2715 7ff763361db1-7ff763361db4 2708->2715 2709->2725 2767 7ff763361c4a-7ff763361c52 2709->2767 2734 7ff763361dfc-7ff763361e0b call 7ff763312e00 2714->2734 2721 7ff763361e0c-7ff763361e18 call 7ff763335a80 2715->2721 2722 7ff763361db6-7ff763361df7 call 7ff763312620 2715->2722 2717->2696 2724 7ff76336207f-7ff763362092 2717->2724 2721->2690 2722->2734 2724->2696 2724->2702 2753 7ff76336212c-7ff763362131 call 7ff7633686d8 2725->2753 2734->2721 2754 7ff76336215b-7ff763362160 call 7ff7633686d8 2738->2754 2740 7ff763361f24-7ff763361f69 call 7ff763386ba4 * 2 2739->2740 2741 7ff763361ef3-7ff763361f04 2739->2741 2772 7ff763361f6b-7ff763361f7d 2740->2772 2773 7ff763361f9d-7ff763361fb8 2740->2773 2746 7ff763361f06-7ff763361f19 2741->2746 2747 7ff763361f1f call 7ff763384bf0 2741->2747 2746->2747 2746->2754 2747->2740 2771 7ff763362132-7ff763362137 call 7ff7633686d8 2753->2771 2770 7ff763362161-7ff763362186 call 7ff7633686d8 2754->2770 2768 7ff763361c54-7ff763361c66 2767->2768 2769 7ff763361c86-7ff763361ccc call 7ff763386ba4 * 2 2767->2769 2774 7ff763361c68-7ff763361c7b 2768->2774 2775 7ff763361c81 call 7ff763384bf0 2768->2775 2802 7ff763361cce-7ff763361cdf 2769->2802 2803 7ff763361cff-7ff763361d19 2769->2803 2792 7ff763362188-7ff76336218d call 7ff763384bf0 2770->2792 2793 7ff763362192-7ff76336219a 2770->2793 2794 7ff763362138-7ff76336213d call 7ff7633686d8 2771->2794 2779 7ff763361f98 call 7ff763384bf0 2772->2779 2780 7ff763361f7f-7ff763361f92 2772->2780 2781 7ff763361fec-7ff763361ffa 2773->2781 2782 7ff763361fba-7ff763361fcc 2773->2782 2774->2753 2774->2775 2775->2769 2779->2773 2780->2770 2780->2779 2781->2684 2788 7ff763361fce-7ff763361fe1 2782->2788 2789 7ff763361fe7 call 7ff763384bf0 2782->2789 2788->2789 2790 7ff763362103-7ff763362108 call 7ff7633686d8 2788->2790 2789->2781 2790->2702 2792->2793 2794->2738 2804 7ff763361cfa call 7ff763384bf0 2802->2804 2805 7ff763361ce1-7ff763361cf4 2802->2805 2806 7ff763361d1b-7ff763361d2d 2803->2806 2807 7ff763361d4d-7ff763361d5b 2803->2807 2804->2803 2805->2771 2805->2804 2809 7ff763361d48 call 7ff763384bf0 2806->2809 2810 7ff763361d2f-7ff763361d42 2806->2810 2807->2708 2809->2807 2810->2794 2810->2809
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_destroy
                                              • String ID: value
                                              • API String ID: 1346393832-494360628
                                              • Opcode ID: 905df17ddf5fb733e77bc0a4f9a92f8ad7025c56cba96bea3251c24b5fa3678d
                                              • Instruction ID: c9f1d0e781ac1e9cf8bddcf69e1c4bcf0e8835d4e9cfae751f3ca7a841c7e8f5
                                              • Opcode Fuzzy Hash: 905df17ddf5fb733e77bc0a4f9a92f8ad7025c56cba96bea3251c24b5fa3678d
                                              • Instruction Fuzzy Hash: 1012E622E19BC1C9EB41DB76D4403BDA761EB863A4F905235EA9D66BDADF7CD080C310

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2812 7ff763357bc0-7ff763357c1d call 7ff763385a10 call 7ff76335f620 2817 7ff763357c1f 2812->2817 2818 7ff763357c22-7ff763357c69 call 7ff7633140b0 call 7ff763313d90 2812->2818 2817->2818 2823 7ff763357c6b-7ff763357c7d 2818->2823 2824 7ff763357c9d-7ff763357cbc 2818->2824 2827 7ff763357c98 call 7ff763384bf0 2823->2827 2828 7ff763357c7f-7ff763357c92 2823->2828 2825 7ff763357cbe-7ff763357cd3 2824->2825 2826 7ff763357cf3-7ff763357d81 call 7ff763353ef0 call 7ff7633875a0 2824->2826 2831 7ff763357cee call 7ff763384bf0 2825->2831 2832 7ff763357cd5-7ff763357ce8 2825->2832 2844 7ff763357d86-7ff763357da9 recv 2826->2844 2827->2824 2828->2827 2829 7ff7633583bd-7ff7633583c2 call 7ff7633686d8 2828->2829 2835 7ff7633583c3-7ff7633583c8 call 7ff7633686d8 2829->2835 2831->2826 2832->2831 2832->2835 2843 7ff7633583c9-7ff7633583ce call 7ff7633686d8 2835->2843 2857 7ff7633583cf-7ff7633583d4 call 7ff7633686d8 2843->2857 2846 7ff763357daf-7ff763357db8 2844->2846 2847 7ff763357e80-7ff763357eae 2844->2847 2851 7ff763357df8-7ff763357e14 call 7ff763317860 2846->2851 2852 7ff763357dba-7ff763357df6 call 7ff763386ef0 2846->2852 2848 7ff763357eb4-7ff763357ec2 call 7ff76336f1b0 2847->2848 2849 7ff7633581cf-7ff7633581e7 2847->2849 2868 7ff763357ec8-7ff763357ecb 2848->2868 2869 7ff7633581c3-7ff7633581c9 2848->2869 2855 7ff7633581ed-7ff76335825a call 7ff763318e20 call 7ff763353ef0 2849->2855 2856 7ff7633583e1-7ff7633583e6 call 7ff7632fd450 2849->2856 2860 7ff763357e19-7ff763357e28 2851->2860 2852->2860 2883 7ff76335825c-7ff76335826e 2855->2883 2884 7ff76335828e-7ff7633582a1 2855->2884 2872 7ff7633583e7-7ff7633583ec call 7ff7633686d8 2856->2872 2875 7ff7633583d5-7ff7633583da call 7ff7633686d8 2857->2875 2865 7ff763357e2a-7ff763357e3a 2860->2865 2866 7ff763357e3f-7ff763357e78 2860->2866 2865->2844 2866->2847 2868->2869 2873 7ff763357ed1-7ff763357f7a call 7ff7633150b0 call 7ff763334ee0 call 7ff763312620 call 7ff763353f80 call 7ff76335f620 2868->2873 2869->2848 2869->2849 2887 7ff7633583ed-7ff7633583f2 call 7ff7633686d8 2872->2887 2921 7ff763357f7c 2873->2921 2922 7ff763357f7f-7ff763358020 call 7ff7633140b0 call 7ff763312c10 call 7ff763353ef0 2873->2922 2885 7ff7633583db-7ff7633583e0 call 7ff7633686d8 2875->2885 2889 7ff763358289 call 7ff763384bf0 2883->2889 2890 7ff763358270-7ff763358283 2883->2890 2886 7ff7633582a3-7ff7633582c9 recv 2884->2886 2885->2856 2893 7ff7633582cb closesocket 2886->2893 2894 7ff7633582d1-7ff7633582dc WSACleanup 2886->2894 2907 7ff7633583f3-7ff7633583f8 call 7ff7633686d8 2887->2907 2889->2884 2890->2872 2890->2889 2893->2894 2899 7ff7633582de-7ff7633582ec 2894->2899 2900 7ff763358310-7ff763358338 2894->2900 2903 7ff7633582ee-7ff763358302 2899->2903 2904 7ff763358308-7ff76335830b call 7ff763384bf0 2899->2904 2905 7ff76335833a-7ff76335834f 2900->2905 2906 7ff76335836f-7ff7633583bc call 7ff763384bd0 2900->2906 2903->2887 2903->2904 2904->2900 2911 7ff76335836a call 7ff763384bf0 2905->2911 2912 7ff763358351-7ff763358364 2905->2912 2911->2906 2912->2907 2912->2911 2921->2922 2929 7ff763358054-7ff76335807a 2922->2929 2930 7ff763358022-7ff763358034 2922->2930 2933 7ff76335807c-7ff763358091 2929->2933 2934 7ff7633580b1-7ff7633580d6 2929->2934 2931 7ff763358036-7ff763358049 2930->2931 2932 7ff76335804f call 7ff763384bf0 2930->2932 2931->2843 2931->2932 2932->2929 2936 7ff7633580ac call 7ff763384bf0 2933->2936 2937 7ff763358093-7ff7633580a6 2933->2937 2938 7ff76335810d-7ff76335815e call 7ff763312e00 * 2 2934->2938 2939 7ff7633580d8-7ff7633580ed 2934->2939 2936->2934 2937->2857 2937->2936 2948 7ff763358195-7ff7633581be 2938->2948 2949 7ff763358160-7ff763358175 2938->2949 2941 7ff763358108 call 7ff763384bf0 2939->2941 2942 7ff7633580ef-7ff763358102 2939->2942 2941->2938 2942->2875 2942->2941 2948->2886 2950 7ff763358177-7ff76335818a 2949->2950 2951 7ff763358190 call 7ff763384bf0 2949->2951 2950->2885 2950->2951 2951->2948
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$recv$Cleanupclosesocket
                                              • String ID:
                                              • API String ID: 3402187201-0
                                              • Opcode ID: 9064601b55afc3268a856f0008743e1efd5d557aabc0f4eb4d7f6c1238982a2f
                                              • Instruction ID: af46279b2958774f506fc5c5e4673a3787da7b60c905ec7170fadf664bd30a26
                                              • Opcode Fuzzy Hash: 9064601b55afc3268a856f0008743e1efd5d557aabc0f4eb4d7f6c1238982a2f
                                              • Instruction Fuzzy Hash: 3E12B872A187C5C1EA61AB16E4443EAE761FB893A0F904236D6DD67BE9DF7CD080C710

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 3116 7ff76330e5a0-7ff76330e616 CreateToolhelp32Snapshot call 7ff7633875a0 call 7ff76330ffc0 3121 7ff76330e61c-7ff76330e62a Process32FirstW 3116->3121 3122 7ff76330e834-7ff76330e850 call 7ff76330fee0 3116->3122 3123 7ff76330e630-7ff76330e632 3121->3123 3128 7ff76330ea98-7ff76330eaad CloseHandle 3122->3128 3129 7ff76330e856-7ff76330e880 call 7ff7633140b0 3122->3129 3123->3122 3125 7ff76330e638-7ff76330e650 call 7ff7633413f0 3123->3125 3137 7ff76330e652 3125->3137 3138 7ff76330e655-7ff76330e679 call 7ff76331ad00 call 7ff7633152c0 3125->3138 3130 7ff76330eadf-7ff76330eb33 call 7ff76330eb50 call 7ff763384bd0 3128->3130 3131 7ff76330eaaf-7ff76330eac3 3128->3131 3134 7ff76330e885-7ff76330e93c call 7ff763314380 3129->3134 3135 7ff76330eada call 7ff763384bf0 3131->3135 3136 7ff76330eac5-7ff76330ead8 3131->3136 3150 7ff76330e940-7ff76330e948 3134->3150 3135->3130 3136->3135 3141 7ff76330eb34-7ff76330eb39 call 7ff7633686d8 3136->3141 3137->3138 3156 7ff76330e680-7ff76330e6a7 3138->3156 3154 7ff76330eb3a-7ff76330eb3f call 7ff7633686d8 3141->3154 3150->3150 3155 7ff76330e94a-7ff76330e9f0 call 7ff763301d20 call 7ff763310ac0 3150->3155 3164 7ff76330eb40-7ff76330eb45 call 7ff7633686d8 3154->3164 3172 7ff76330e9f5-7ff76330e9fc 3155->3172 3156->3156 3159 7ff76330e6a9-7ff76330e6cb 3156->3159 3162 7ff76330e6e7-7ff76330e6fb call 7ff76331dd60 3159->3162 3163 7ff76330e6cd-7ff76330e6e5 3159->3163 3166 7ff76330e700-7ff76330e783 call 7ff76331ad00 call 7ff7633152c0 call 7ff763313a20 call 7ff763318c50 call 7ff763318af0 3162->3166 3163->3166 3174 7ff76330eb46-7ff76330eb4b call 7ff7633686d8 3164->3174 3196 7ff76330e7b9-7ff76330e7db 3166->3196 3197 7ff76330e785-7ff76330e799 3166->3197 3172->3172 3175 7ff76330e9fe-7ff76330ea54 call 7ff763301d20 call 7ff763310ac0 call 7ff763312e00 3172->3175 3190 7ff76330ea87-7ff76330ea94 3175->3190 3191 7ff76330ea56-7ff76330ea67 3175->3191 3190->3128 3194 7ff76330ea69-7ff76330ea7c 3191->3194 3195 7ff76330ea82 call 7ff763384bf0 3191->3195 3194->3174 3194->3195 3195->3190 3201 7ff76330e7dd-7ff76330e7ef 3196->3201 3202 7ff76330e80f-7ff76330e82f Process32NextW 3196->3202 3199 7ff76330e79b-7ff76330e7ae 3197->3199 3200 7ff76330e7b4 call 7ff763384bf0 3197->3200 3199->3154 3199->3200 3200->3196 3204 7ff76330e80a call 7ff763384bf0 3201->3204 3205 7ff76330e7f1-7ff76330e804 3201->3205 3202->3123 3204->3202 3205->3164 3205->3204
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Process32$CloseCreateFirstHandleNextSnapshotToolhelp32
                                              • String ID: [PID:
                                              • API String ID: 1946380282-2210602247
                                              • Opcode ID: 707e104124b93063194511a9bdad35d81a8a4ba7d3925c2e90c534d8c1506ad0
                                              • Instruction ID: f4e22e9c368428dfb7da164d7b738f7274aec731af3fe93a2ae7ed50a05bb133
                                              • Opcode Fuzzy Hash: 707e104124b93063194511a9bdad35d81a8a4ba7d3925c2e90c534d8c1506ad0
                                              • Instruction Fuzzy Hash: 7BE1E672618BC1C5E761DF26E8803EDB765FB857A8F805225EA9D1BB99DF38D240C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 5bf3cefcc1b12d0f908fae1d1b68f269451cfeba0dc988f38174dabf3f0848ce
                                              • Instruction ID: e1ba434fdc26f212fa97b828a580ddf09959f2268c305b16eda04215bfe47a71
                                              • Opcode Fuzzy Hash: 5bf3cefcc1b12d0f908fae1d1b68f269451cfeba0dc988f38174dabf3f0848ce
                                              • Instruction Fuzzy Hash: 94726032605BC589DB719F29E8403EDB3A4F789798F504325EADC6AB99DF38C284C714
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Internet$Query$AvailableDataHttpInfoOpen$CloseConcurrency::cancel_current_taskCriticalEnterFileHandleReadSection_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 2754876294-0
                                              • Opcode ID: 14968f1006e427f15a06223f8d08607396f5d2f295d36b78be71ae35b45849b8
                                              • Instruction ID: 8e0ec71991ec8265ce25c89dff1e92ddcd28151748422f56eb1e05944c36a9e1
                                              • Opcode Fuzzy Hash: 14968f1006e427f15a06223f8d08607396f5d2f295d36b78be71ae35b45849b8
                                              • Instruction Fuzzy Hash: 0E026132B28B95C5F740DB66E8402ADB7B4FB84798F501229EE8D67B99DF78D080C710
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: File$PointerReadSize_invalid_parameter_noinfo_noreturn
                                              • String ID: exists$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                                              • API String ID: 2478245620-15404121
                                              • Opcode ID: 5d8242099734290fb5c2cd9d0b9a4ed373f2cb241c23ad425eb2d1444e5b8d73
                                              • Instruction ID: d7b065e0c37c92f43918e7bf691654231f8bdda2c7d69a6eed9d9ed10b133476
                                              • Opcode Fuzzy Hash: 5d8242099734290fb5c2cd9d0b9a4ed373f2cb241c23ad425eb2d1444e5b8d73
                                              • Instruction Fuzzy Hash: 9B321832A15BC5C9EB60EF29D8803E9B7A0FB44758F80423ADA4D67B99EF78D544C710
                                              APIs
                                              • _get_daylight.LIBCMT ref: 00007FF7633796FD
                                                • Part of subcall function 00007FF763378D68: _invalid_parameter_noinfo.LIBCMT ref: 00007FF763378D7C
                                                • Part of subcall function 00007FF763373E04: RtlFreeHeap.NTDLL(?,?,?,00007FF76337DF72,?,?,?,00007FF76337E2EF,?,?,00000000,00007FF76337C02C,?,?,?,00007FF76337BF5F), ref: 00007FF763373E1A
                                                • Part of subcall function 00007FF763373E04: GetLastError.KERNEL32(?,?,?,00007FF76337DF72,?,?,?,00007FF76337E2EF,?,?,00000000,00007FF76337C02C,?,?,?,00007FF76337BF5F), ref: 00007FF763373E24
                                                • Part of subcall function 00007FF763368708: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF7633686B6,?,?,?,?,8000000000000000,00007FF76336859E), ref: 00007FF763368711
                                                • Part of subcall function 00007FF763368708: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF7633686B6,?,?,?,?,8000000000000000,00007FF76336859E), ref: 00007FF763368736
                                                • Part of subcall function 00007FF763381E20: _invalid_parameter_noinfo.LIBCMT ref: 00007FF763381D6B
                                              • _get_daylight.LIBCMT ref: 00007FF7633796EC
                                                • Part of subcall function 00007FF763378DC8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF763378DDC
                                              • _get_daylight.LIBCMT ref: 00007FF763379962
                                              • _get_daylight.LIBCMT ref: 00007FF763379973
                                              • _get_daylight.LIBCMT ref: 00007FF763379984
                                              • GetTimeZoneInformation.KERNEL32(00007FF763379C72), ref: 00007FF7633799AB
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureFreeHeapInformationLastPresentProcessProcessorTimeZone
                                              • String ID: Eastern Standard Time$Eastern Summer Time
                                              • API String ID: 4070488512-239921721
                                              • Opcode ID: 37a35d0dc6c7566623b794cfda2633962aacf996f92dc9f81c09c89044e56338
                                              • Instruction ID: f3f6e009921c58a01bfd061c1da5e5fc1c492815b8488bbdf6d8b8e8e6f7095a
                                              • Opcode Fuzzy Hash: 37a35d0dc6c7566623b794cfda2633962aacf996f92dc9f81c09c89044e56338
                                              • Instruction Fuzzy Hash: 4ED1D122A18242C6E7A0BF23D8415B9E7B1EF86785FC44139EA0D67B85EF3CE441C764
                                              APIs
                                                • Part of subcall function 00007FF763384D80: EnterCriticalSection.KERNEL32(?,?,0000000100000000,00007FF763301944), ref: 00007FF763384D90
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76335355E
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF763353564
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$CriticalEnterSection
                                              • String ID: Local State$exists$ios_base::badbit set$os_crypt
                                              • API String ID: 555700303-1113887999
                                              • Opcode ID: c462c773239d946173dbf18e47caa983b3ec1196ebe5b435ccb68ef175641302
                                              • Instruction ID: a3632b5dd70135c641c955a307c759f837d6f4246fdc45fafa7953a92ed48c34
                                              • Opcode Fuzzy Hash: c462c773239d946173dbf18e47caa983b3ec1196ebe5b435ccb68ef175641302
                                              • Instruction Fuzzy Hash: 5F327132A19BC2C5DAA1EB15E4903EAF364FB84754F80523ADA9D53BA9DF3CD144CB10
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 871cd596d817da1dfca138a3484f660d41bf89ec6fb81b35143c343f2ca51a0b
                                              • Instruction ID: 7fc582450ad321f89d2f4d746eba8d3a9ca70d0255f4133bd19ba94e3aeac80e
                                              • Opcode Fuzzy Hash: 871cd596d817da1dfca138a3484f660d41bf89ec6fb81b35143c343f2ca51a0b
                                              • Instruction Fuzzy Hash: 41C1D022A0C686D5EBE17B1684243BDA6B0FB82B82F85413CDA4D27792CF7DE454C724
                                              APIs
                                              • _get_daylight.LIBCMT ref: 00007FF763379962
                                                • Part of subcall function 00007FF763378DC8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF763378DDC
                                              • _get_daylight.LIBCMT ref: 00007FF763379973
                                                • Part of subcall function 00007FF763378D68: _invalid_parameter_noinfo.LIBCMT ref: 00007FF763378D7C
                                              • _get_daylight.LIBCMT ref: 00007FF763379984
                                                • Part of subcall function 00007FF763378D98: _invalid_parameter_noinfo.LIBCMT ref: 00007FF763378DAC
                                                • Part of subcall function 00007FF763373E04: RtlFreeHeap.NTDLL(?,?,?,00007FF76337DF72,?,?,?,00007FF76337E2EF,?,?,00000000,00007FF76337C02C,?,?,?,00007FF76337BF5F), ref: 00007FF763373E1A
                                                • Part of subcall function 00007FF763373E04: GetLastError.KERNEL32(?,?,?,00007FF76337DF72,?,?,?,00007FF76337E2EF,?,?,00000000,00007FF76337C02C,?,?,?,00007FF76337BF5F), ref: 00007FF763373E24
                                              • GetTimeZoneInformation.KERNEL32(00007FF763379C72), ref: 00007FF7633799AB
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
                                              • String ID: Eastern Standard Time$Eastern Summer Time
                                              • API String ID: 3458911817-239921721
                                              • Opcode ID: ac5588a5ff664b8a5f0424968954f99b69c1fbc099cb9212fbaebeac0ee85e96
                                              • Instruction ID: 079b0e4624966ecc21769db707587e1f5d616dd34280fc67d25d876e713160c0
                                              • Opcode Fuzzy Hash: ac5588a5ff664b8a5f0424968954f99b69c1fbc099cb9212fbaebeac0ee85e96
                                              • Instruction Fuzzy Hash: 8851AB32A18242C6E790FF23E9815A9E7A0FB49785F80423DEA4D67B95DF3CE401C764
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: cores
                                              • API String ID: 3668304517-2370456839
                                              • Opcode ID: a05b6d6b301fc25f31edc7bc7575b86fa9b45acb600edd5d86db558c14c5cc35
                                              • Instruction ID: a90fbcf31d97af0dba52d38938590465829d037f5d2c7739c328fd73cfa92084
                                              • Opcode Fuzzy Hash: a05b6d6b301fc25f31edc7bc7575b86fa9b45acb600edd5d86db558c14c5cc35
                                              • Instruction Fuzzy Hash: 4AB19062F14B858AF700DFB9C0413AC7762EB99368F90532ADE5C36B9ADF789185C350
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 42d69556137239d4018a4a046d5d66665d6a6635332840f1875bc2263b5e90c7
                                              • Instruction ID: 7c230bb7f49308b2bc36f257827c35ed52ac0d87316b0c57dfd08f3d0ce35d2a
                                              • Opcode Fuzzy Hash: 42d69556137239d4018a4a046d5d66665d6a6635332840f1875bc2263b5e90c7
                                              • Instruction Fuzzy Hash: 2EF16232A19F8889EB608B69E44135DB7B0F789798F505329EEDC56B99EF7CC180C700
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: bfdf69b2787f59eeaecb1f115bae47d78ddfe4f3593e2ed65244e29632c2e00d
                                              • Instruction ID: e6ed652974ef16056af56213c89d57d2a73ff9c1af3536c1b26366a4d97beb0e
                                              • Opcode Fuzzy Hash: bfdf69b2787f59eeaecb1f115bae47d78ddfe4f3593e2ed65244e29632c2e00d
                                              • Instruction Fuzzy Hash: 50F15032A19F8889EB608B69E44135DB7B0F789798F505325EEDC56B99EF3CD180C700
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$DriveLogicalStrings
                                              • String ID:
                                              • API String ID: 3916208290-0
                                              • Opcode ID: a1fca8bcaa72458f355929caee6bb519fc86481125b0adeec8b7a65b6a98e8be
                                              • Instruction ID: 04cbb80127669388d49113c3df8278e1f29ada0f5174b8481690a68ff43ff4a1
                                              • Opcode Fuzzy Hash: a1fca8bcaa72458f355929caee6bb519fc86481125b0adeec8b7a65b6a98e8be
                                              • Instruction Fuzzy Hash: 7C71A332A18B81C2E7109F25E48039EB771FB84798F505229EA9C23BA9DF7CE1D0D750
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: InformationTimeZone
                                              • String ID: [UTC
                                              • API String ID: 565725191-1715286942
                                              • Opcode ID: 212000cced222a5dc7caf820b1ec4ab89a7c66cbca98204d263862c5374b7d4e
                                              • Instruction ID: 7115b4aadc3ab484b229025460746e0d9f87c2ecd84cb72a9befd6dd2b87c6cb
                                              • Opcode Fuzzy Hash: 212000cced222a5dc7caf820b1ec4ab89a7c66cbca98204d263862c5374b7d4e
                                              • Instruction Fuzzy Hash: B091E832619FC889D7718F29E84129AB7A4F399788F105325EACD5BB58EF38D250CB00
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: CryptDataFreeLocalUnprotect
                                              • String ID:
                                              • API String ID: 1561624719-0
                                              • Opcode ID: 4e58c951b7c5e6adfc0a1d9a22f9c6bd733eaecc205548daf511c016fcdcf1dd
                                              • Instruction ID: 7676a0f38d7f350e04070689b85ff21a7ea7380aa6b4004c58560cd45f2b216f
                                              • Opcode Fuzzy Hash: 4e58c951b7c5e6adfc0a1d9a22f9c6bd733eaecc205548daf511c016fcdcf1dd
                                              • Instruction Fuzzy Hash: 3A415932A18B81CAF3209F75D5403AD77A4FB5974CF440239EA8C16E8ADF79D164C354
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: NameUser
                                              • String ID:
                                              • API String ID: 2645101109-0
                                              • Opcode ID: 0871bde2d788b78335871fd266b49462b60068c1f051bbca3e7ae24717f37f63
                                              • Instruction ID: def305175c7a6a579fb9dd0baa18013d4e527e812b922fd837c99f17e72709ae
                                              • Opcode Fuzzy Hash: 0871bde2d788b78335871fd266b49462b60068c1f051bbca3e7ae24717f37f63
                                              • Instruction Fuzzy Hash: B901527291878182E761DF15E4403AAB3A4FB98788F800135E6CD52B55DFBCD194CB40
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: \u%04x
                                              • API String ID: 0-2916071157
                                              • Opcode ID: b91eab7eddda3438d0160b701b9c771a5be05e06c21634bd1e17fd1013c12c1d
                                              • Instruction ID: 68332176a54eab3ec66036a2f53df129864d4907bbea3cbf5fb47341fabc33b7
                                              • Opcode Fuzzy Hash: b91eab7eddda3438d0160b701b9c771a5be05e06c21634bd1e17fd1013c12c1d
                                              • Instruction Fuzzy Hash: 2A81F332A0C646DAEA94EB16D1916BDA761FB86B80F855039CF4E23B91DF3CE554C320
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: ":
                                              • API String ID: 0-3662656813
                                              • Opcode ID: dbd0ed8516a4cc5c4625d639ae940563b17413e68dca520790d84e6f5753e9d8
                                              • Instruction ID: 90fba42f6b29381924017ea073e125f2d8c1b05cfd0061d6899fe43eb6d5f4a3
                                              • Opcode Fuzzy Hash: dbd0ed8516a4cc5c4625d639ae940563b17413e68dca520790d84e6f5753e9d8
                                              • Instruction Fuzzy Hash: 1D912676608A86C2DB60EF26D09466DB761FB89FC8F859026CF4E17B64CF39D158CB10
                                              Strings
                                              • ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/, xrefs: 00007FF763314139
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
                                              • API String ID: 0-1713319389
                                              • Opcode ID: 437ae662eb117c41f44ff7f9c77615c2854eafd9d66bebc79b763ab490802efe
                                              • Instruction ID: a5ed450523caf9a1e04399d808f898d415cc0cdd916677b25159e7e25190c7e2
                                              • Opcode Fuzzy Hash: 437ae662eb117c41f44ff7f9c77615c2854eafd9d66bebc79b763ab490802efe
                                              • Instruction Fuzzy Hash: 9941066361D7E089D742CB3A841127DBFB2E366F88B5CC162D7D887746CA2DD206C720

                                              Control-flow Graph

                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Info$CleanupStartupUserclosesocketconnecthtonsinet_ptonsocket
                                              • String ID: 176.124.204.206$geo$system
                                              • API String ID: 2440148987-2101002029
                                              • Opcode ID: e7f163373f1f68074f436349328a7394993a0486a9352bfce74b1ccfe7400599
                                              • Instruction ID: 9034120cf678de0a81f6db0cdf764a86975459e7e8027d6ac0bcefb193e61342
                                              • Opcode Fuzzy Hash: e7f163373f1f68074f436349328a7394993a0486a9352bfce74b1ccfe7400599
                                              • Instruction Fuzzy Hash: 77919262F08A42C9FB40EF76E4502ACB371EF44358F80563ADA5D66BA9EE3C9145C320

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2429 7ff7633514b0-7ff7633514eb call 7ff763351320 2432 7ff76335152c 2429->2432 2433 7ff7633514ed-7ff7633514fc EnterCriticalSection 2429->2433 2436 7ff763351531-7ff76335154f call 7ff763384bd0 2432->2436 2434 7ff7633514fe-7ff763351520 GdiplusStartup 2433->2434 2435 7ff763351550-7ff76335156a LeaveCriticalSection GdipGetImageEncodersSize 2433->2435 2434->2435 2438 7ff763351522-7ff763351526 LeaveCriticalSection 2434->2438 2435->2432 2437 7ff76335156c-7ff76335157f 2435->2437 2440 7ff7633515bb-7ff7633515c9 call 7ff763370454 2437->2440 2441 7ff763351581-7ff76335158a call 7ff7633510b0 2437->2441 2438->2432 2449 7ff7633515cb-7ff7633515ce 2440->2449 2450 7ff7633515d0-7ff7633515da 2440->2450 2447 7ff76335158c-7ff763351596 2441->2447 2448 7ff7633515b8 2441->2448 2451 7ff763351598 2447->2451 2452 7ff7633515a2-7ff7633515b6 call 7ff763385a10 2447->2452 2448->2440 2453 7ff7633515de-7ff7633515e1 2449->2453 2450->2453 2451->2452 2452->2453 2454 7ff7633515ed-7ff7633515fe GdipGetImageEncoders 2453->2454 2455 7ff7633515e3-7ff7633515e8 2453->2455 2458 7ff763351743-7ff763351748 2454->2458 2459 7ff763351604-7ff76335160d 2454->2459 2457 7ff763351758-7ff76335175b 2455->2457 2463 7ff76335175d 2457->2463 2464 7ff763351774-7ff763351776 2457->2464 2458->2457 2461 7ff76335163f 2459->2461 2462 7ff76335160f-7ff76335161d 2459->2462 2467 7ff763351646-7ff763351656 2461->2467 2465 7ff763351620-7ff76335162b 2462->2465 2466 7ff763351760-7ff763351772 call 7ff763367ac0 2463->2466 2464->2436 2468 7ff76335162d-7ff763351632 2465->2468 2469 7ff763351638-7ff76335163d 2465->2469 2466->2464 2471 7ff763351658-7ff763351663 2467->2471 2472 7ff763351669-7ff763351685 2467->2472 2468->2469 2473 7ff7633516e7-7ff7633516eb 2468->2473 2469->2461 2469->2465 2471->2458 2471->2472 2475 7ff763351687-7ff7633516e0 GdipCreateBitmapFromScan0 GdipSaveImageToStream 2472->2475 2476 7ff7633516f2-7ff763351731 GdipCreateBitmapFromHBITMAP GdipSaveImageToStream 2472->2476 2473->2467 2479 7ff7633516f0 2475->2479 2480 7ff7633516e2-7ff7633516e5 2475->2480 2477 7ff76335174a-7ff763351757 GdipDisposeImage 2476->2477 2478 7ff763351733 2476->2478 2477->2457 2481 7ff763351736-7ff76335173d GdipDisposeImage 2478->2481 2479->2477 2480->2481 2481->2458
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Gdip$Image$CriticalSection$DisposeEncodersLeave$BitmapCreateEnterErrorFromGdiplusInitializeLastSaveScan0SizeStartupStream
                                              • String ID: &
                                              • API String ID: 1703174404-3042966939
                                              • Opcode ID: 258f57589f733d9db5dd03cd69d3f576a81e6c4f73ba0decaf4fabaadf714bfa
                                              • Instruction ID: cb55345593617f7ddab6b1b7b889d8dfbcb863cdb907f56a6b69348bbedf713a
                                              • Opcode Fuzzy Hash: 258f57589f733d9db5dd03cd69d3f576a81e6c4f73ba0decaf4fabaadf714bfa
                                              • Instruction Fuzzy Hash: CC910B32E04B42C9EB90EF32D8405A8BBA4FB547A8F85453AEA5E67B94DF3CD541C350

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 2953 7ff763340390-7ff7633403ad 2954 7ff7633403af-7ff7633403c0 2953->2954 2955 7ff7633403e3-7ff763340409 2953->2955 2956 7ff7633403de call 7ff763384bf0 2954->2956 2957 7ff7633403c2-7ff7633403d5 2954->2957 2958 7ff76334040b-7ff76334041c 2955->2958 2959 7ff76334043f-7ff763340463 2955->2959 2956->2955 2960 7ff763340559-7ff76334055e call 7ff7633686d8 2957->2960 2961 7ff7633403db 2957->2961 2963 7ff76334043a call 7ff763384bf0 2958->2963 2964 7ff76334041e-7ff763340431 2958->2964 2965 7ff763340496-7ff7633404be call 7ff763312590 2959->2965 2966 7ff763340465-7ff763340473 2959->2966 2970 7ff76334055f-7ff763340564 call 7ff7633686d8 2960->2970 2961->2956 2963->2959 2969 7ff763340437 2964->2969 2964->2970 2980 7ff7633404ed-7ff763340505 2965->2980 2981 7ff7633404c0-7ff7633404ce 2965->2981 2972 7ff763340491 call 7ff763384bf0 2966->2972 2973 7ff763340475-7ff763340488 2966->2973 2969->2963 2975 7ff763340565-7ff76334056a call 7ff7633686d8 2970->2975 2972->2965 2974 7ff76334048e 2973->2974 2973->2975 2974->2972 2987 7ff763340507-7ff763340514 2980->2987 2988 7ff763340533-7ff76334054c 2980->2988 2985 7ff7633404e8 call 7ff763384bf0 2981->2985 2986 7ff7633404d0-7ff7633404e3 2981->2986 2985->2980 2989 7ff76334054d-7ff763340552 call 7ff7633686d8 2986->2989 2990 7ff7633404e5 2986->2990 2992 7ff76334052e call 7ff763384bf0 2987->2992 2993 7ff763340516-7ff763340529 2987->2993 2997 7ff763340553-7ff763340558 call 7ff7633686d8 2989->2997 2990->2985 2992->2988 2996 7ff76334052b 2993->2996 2993->2997 2996->2992 2997->2960
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: 176.124.204.206$5FbeQM3x+58/nMpdia7AF5DyhKEXonXRJTycAVdLKzI=$QhoUvbB5PEQ=$port$type must be number, but is
                                              • API String ID: 3668304517-3327423027
                                              • Opcode ID: c89d9505c1229be2380f663996fda926188632ac9c16584dfc2abe87fb9fa606
                                              • Instruction ID: 65ddf7d140ad7a53bf2ab9c6e80c5af1e2069c972e533a875d5b38c8e485e019
                                              • Opcode Fuzzy Hash: c89d9505c1229be2380f663996fda926188632ac9c16584dfc2abe87fb9fa606
                                              • Instruction Fuzzy Hash: 914193A2709685C5FB44EB2AD4583BDA356EB11F88FD04439DA4C2A7ABDF78C4C4C360

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 3001 7ff76335aae6-7ff76335ab4e call 7ff763312c10 call 7ff763311850 3006 7ff76335ab50-7ff76335ab61 3001->3006 3007 7ff76335ab81-7ff76335ab9a 3001->3007 3010 7ff76335ab7c call 7ff763384bf0 3006->3010 3011 7ff76335ab63-7ff76335ab76 3006->3011 3008 7ff76335ab9c-7ff76335abad 3007->3008 3009 7ff76335abcd-7ff76335ac18 call 7ff763350870 call 7ff76334d4d0 3007->3009 3013 7ff76335abc8 call 7ff763384bf0 3008->3013 3014 7ff76335abaf-7ff76335abc2 3008->3014 3027 7ff76335ac1a-7ff76335ac29 3009->3027 3028 7ff76335ac36-7ff76335ac47 call 7ff763317540 3009->3028 3010->3007 3011->3010 3016 7ff76335b0b6-7ff76335b0bb call 7ff7633686d8 3011->3016 3013->3009 3014->3013 3017 7ff76335b0bc-7ff76335b0c1 call 7ff7633686d8 3014->3017 3016->3017 3026 7ff76335b0c2-7ff76335b0c7 call 7ff7633686d8 3017->3026 3036 7ff76335b0c8-7ff76335b0cd call 7ff7633686d8 3026->3036 3030 7ff76335ac2b 3027->3030 3031 7ff76335ac2e-7ff76335ac34 3027->3031 3033 7ff76335ac4c-7ff76335ad64 call 7ff763312c10 * 3 3028->3033 3030->3031 3031->3033 3047 7ff76335ad97-7ff76335adb8 3033->3047 3048 7ff76335ad66-7ff76335ad77 3033->3048 3042 7ff76335b0ce-7ff76335b0d3 call 7ff7633686d8 3036->3042 3049 7ff76335b0d4-7ff76335b0d9 call 7ff7633686d8 3042->3049 3052 7ff76335adec-7ff76335ae0f 3047->3052 3053 7ff76335adba-7ff76335adcc 3047->3053 3050 7ff76335ad79-7ff76335ad8c 3048->3050 3051 7ff76335ad92 call 7ff763384bf0 3048->3051 3066 7ff76335b0da-7ff76335b0df call 7ff7633686d8 3049->3066 3050->3026 3050->3051 3051->3047 3055 7ff76335ae43-7ff76335ae5e 3052->3055 3056 7ff76335ae11-7ff76335ae23 3052->3056 3058 7ff76335adce-7ff76335ade1 3053->3058 3059 7ff76335ade7 call 7ff763384bf0 3053->3059 3063 7ff76335ae60-7ff76335ae71 3055->3063 3064 7ff76335ae91-7ff76335aeaa 3055->3064 3061 7ff76335ae3e call 7ff763384bf0 3056->3061 3062 7ff76335ae25-7ff76335ae38 3056->3062 3058->3036 3058->3059 3059->3052 3061->3055 3062->3042 3062->3061 3069 7ff76335ae8c call 7ff763384bf0 3063->3069 3070 7ff76335ae73-7ff76335ae86 3063->3070 3071 7ff76335aeac-7ff76335aebd 3064->3071 3072 7ff76335aedd-7ff76335af07 call 7ff763359e70 3064->3072 3079 7ff76335b0e0-7ff76335b0e5 call 7ff7633686d8 3066->3079 3069->3064 3070->3049 3070->3069 3076 7ff76335aed8 call 7ff763384bf0 3071->3076 3077 7ff76335aebf-7ff76335aed2 3071->3077 3078 7ff76335af0c-7ff76335af36 call 7ff763312c10 3072->3078 3076->3072 3077->3066 3077->3076 3085 7ff76335af38-7ff76335af49 3078->3085 3086 7ff76335af69-7ff76335af87 3078->3086 3087 7ff76335b0e6-7ff76335b0eb call 7ff7633686d8 3079->3087 3088 7ff76335af4b-7ff76335af5e 3085->3088 3089 7ff76335af64 call 7ff763384bf0 3085->3089 3091 7ff76335afbd-7ff76335afe1 3086->3091 3092 7ff76335af89-7ff76335af9d 3086->3092 3101 7ff76335b0ec-7ff76335b0f1 call 7ff7633686d8 3087->3101 3088->3079 3088->3089 3089->3086 3097 7ff76335b017-7ff76335b039 3091->3097 3098 7ff76335afe3-7ff76335aff7 3091->3098 3095 7ff76335afb8 call 7ff763384bf0 3092->3095 3096 7ff76335af9f-7ff76335afb2 3092->3096 3095->3091 3096->3087 3096->3095 3099 7ff76335b06b-7ff76335b0af call 7ff763384bd0 3097->3099 3100 7ff76335b03b-7ff76335b04f 3097->3100 3103 7ff76335aff9-7ff76335b00c 3098->3103 3104 7ff76335b012 call 7ff763384bf0 3098->3104 3106 7ff76335b066 call 7ff763384bf0 3100->3106 3107 7ff76335b051-7ff76335b064 3100->3107 3103->3101 3103->3104 3104->3097 3106->3099 3107->3106 3110 7ff76335b0b0-7ff76335b0b5 call 7ff7633686d8 3107->3110 3110->3016
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 3e862abfc831c003ca9250d5e42bb48159188533bdbc1e907ac646608f375d00
                                              • Instruction ID: f581fb801b6af10a8364c0c3a142f0a5d7db26f46d6f7ea74935ed5262a04d77
                                              • Opcode Fuzzy Hash: 3e862abfc831c003ca9250d5e42bb48159188533bdbc1e907ac646608f375d00
                                              • Instruction Fuzzy Hash: DFF12963E187C5C5EB419B3AD4043ACA711EB857A4F909326DAAC26BEADF7CD1C0C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: chrome_key$directory_iterator::directory_iterator$exists$key$status
                                              • API String ID: 3668304517-2866355200
                                              • Opcode ID: 842b569f3b3d82af19ab9c615f90c268fcf32daf0aa98b27de6a646b5b05b21f
                                              • Instruction ID: aa5dd28378ab1a6b63594ec805fbfcfa39b345d651dc713491cefe17ffe280bc
                                              • Opcode Fuzzy Hash: 842b569f3b3d82af19ab9c615f90c268fcf32daf0aa98b27de6a646b5b05b21f
                                              • Instruction Fuzzy Hash: DBA1D672A04B86C6EB40EF65E8443ADB361FB44798F909639EA5D27BA9DF3CD141C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type_get_daylight
                                              • String ID:
                                              • API String ID: 1330151763-0
                                              • Opcode ID: 6285118774f749e8d84d89f3fc9727a5f198784a2c206228c38fa5836f6e4f91
                                              • Instruction ID: c6203a132998269db418f714769b7134b763a82b86c7e797929377ea1076eaa1
                                              • Opcode Fuzzy Hash: 6285118774f749e8d84d89f3fc9727a5f198784a2c206228c38fa5836f6e4f91
                                              • Instruction Fuzzy Hash: 48C1B377B28A41C5EB50EF6AC8902AC7771FB49BA8B410229DE2E6B7D4DF38D451C350
                                              APIs
                                                • Part of subcall function 00007FF763384D80: EnterCriticalSection.KERNEL32(?,?,0000000100000000,00007FF763301944), ref: 00007FF763384D90
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF763353E0A
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF763353E10
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$CriticalEnterSection
                                              • String ID: Local State$encrypted_key$exists$ios_base::badbit set$os_crypt
                                              • API String ID: 555700303-529672285
                                              • Opcode ID: be5313ba20d33fb6dee1c416b809d7ef15849b19d8d71b149d6cd3c7f336037c
                                              • Instruction ID: 76763ab455edee8a78e7a95fd9037c578f0519f74781b21cbca0a89f4af3810f
                                              • Opcode Fuzzy Hash: be5313ba20d33fb6dee1c416b809d7ef15849b19d8d71b149d6cd3c7f336037c
                                              • Instruction Fuzzy Hash: 5A228632A19BC6D1DAA1EB15E4803EAF760FB84754F80423ADA9D53BA5DF7CD144CB10
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: Wallets$content$directory_iterator::directory_iterator$exists$filename$status
                                              • API String ID: 3668304517-331726099
                                              • Opcode ID: 9d88c9dd596880f603f0a42a7411af62108ce0df9fd998f57afb9c91781c7df9
                                              • Instruction ID: 5dd7fa038cebd1949f8e633c0693795f60767546dbc5c9868b3e243704d46efd
                                              • Opcode Fuzzy Hash: 9d88c9dd596880f603f0a42a7411af62108ce0df9fd998f57afb9c91781c7df9
                                              • Instruction Fuzzy Hash: 50F0B4A2A1468581FB58AB69D00836DA351E705F89F944438C78C1E7D6DF7DC4C1C350
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$CloseEnumOpen
                                              • String ID:
                                              • API String ID: 2177193445-0
                                              • Opcode ID: 3615f07cb8ff19c576fd6b4f946d3be5ef4fe89864409f7535f8990a94e47d16
                                              • Instruction ID: 5ab87da252a58efac24c24426bbcc3a9a4f1667948e0f543ad8bcc0f38c5978a
                                              • Opcode Fuzzy Hash: 3615f07cb8ff19c576fd6b4f946d3be5ef4fe89864409f7535f8990a94e47d16
                                              • Instruction Fuzzy Hash: 40718272A08B8585FB519B65E44436DA761FB453A8F90022AEBAC27BD5DF7CD0C0D710
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: exists
                                              • API String ID: 3668304517-2996790960
                                              • Opcode ID: 5c1235b651781e4c8b750f994b384f3eee359d1db4b594c28ea417f73e0f61af
                                              • Instruction ID: 2d9bb5381f2133c853b42cfc7e568a4b46cc0a387e64b8b71ecddd62241c4fc0
                                              • Opcode Fuzzy Hash: 5c1235b651781e4c8b750f994b384f3eee359d1db4b594c28ea417f73e0f61af
                                              • Instruction Fuzzy Hash: 28A1B672A08B86C6EB50DF65E8443ADB361FB44798F905239EA5D27BA9DF3CD181C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$DriveFileFindFirstLogicalStrings
                                              • String ID: Grabber$content$filename
                                              • API String ID: 3820383557-1559270721
                                              • Opcode ID: ce80dbb2ecc2378fce3f1c0631002e6034e706b01a79afe46905bdef6ab37b26
                                              • Instruction ID: 3845819bca2222ae6455a3bd7ebbc313f74ff65e0ce9b6a750e0d3e5c472033d
                                              • Opcode Fuzzy Hash: ce80dbb2ecc2378fce3f1c0631002e6034e706b01a79afe46905bdef6ab37b26
                                              • Instruction Fuzzy Hash: A0419562E08645C1EE60AB16E44026AE761EBC57F4F980336E6AD27BE9DF7CD180C710
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: EnumOpen
                                              • String ID:
                                              • API String ID: 3231578192-0
                                              • Opcode ID: a36913a9e4c3cb3fa547cbb311b3305daa72d015cf49b5d665d464c797954e1f
                                              • Instruction ID: d461c6f19501426bd17953b32cf92bd43be0e25eac6cde599b2045536dc10670
                                              • Opcode Fuzzy Hash: a36913a9e4c3cb3fa547cbb311b3305daa72d015cf49b5d665d464c797954e1f
                                              • Instruction Fuzzy Hash: D531B332A04B85C5E761DFA2E8446AEB774FB447A8F600229DE9D27B54DF7CD091C710
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Value
                                              • String ID: --type$ProductName$SOFTWARE\Microsoft\Windows NT\CurrentVersion
                                              • API String ID: 3702945584-3762788641
                                              • Opcode ID: 9b274ce6bb4d4cdcd3e36ea76c9f110c81100d9485de4f81a8863b0b7cf813e5
                                              • Instruction ID: 5bcefc86b9c83b98ca72b4cbe6ad4f5bb3baa6b59f5279d79927128b8296d780
                                              • Opcode Fuzzy Hash: 9b274ce6bb4d4cdcd3e36ea76c9f110c81100d9485de4f81a8863b0b7cf813e5
                                              • Instruction Fuzzy Hash: 4E113D32908B85C2D7609F22F4413AAF3A4FB99798F900239EADC16B58DFBCD154CB50
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ProcessToken$CloseCurrentHandleInformationOpen
                                              • String ID:
                                              • API String ID: 215268677-0
                                              • Opcode ID: 843c4e881ea1c955be678229682ad12d7f62d781caae3c893c8b4e9352b10c93
                                              • Instruction ID: 49204a6c8cc589194423599bbadfbf5f5a20ec760964737fd81cf6072d66b054
                                              • Opcode Fuzzy Hash: 843c4e881ea1c955be678229682ad12d7f62d781caae3c893c8b4e9352b10c93
                                              • Instruction Fuzzy Hash: 24114A32618B82C6E7909F12F84035AF7A0FB84B84F844139EA8D57B18DF3CD415CB50
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: os_crypt
                                              • API String ID: 0-1885529964
                                              • Opcode ID: 6cd1e62ccbf59bc056a7ee45604afab4ca7d3205a5ef0a59b9cdf789acb3c30a
                                              • Instruction ID: fd0792b363405f4a37f5ba4d40d49f2b451d91c236fb4856ddd90dd4016d249f
                                              • Opcode Fuzzy Hash: 6cd1e62ccbf59bc056a7ee45604afab4ca7d3205a5ef0a59b9cdf789acb3c30a
                                              • Instruction Fuzzy Hash: 65A1B132A04B81C6EB50DF26D8443ADB7A0F789BA8F58823ADA8D57795DF3CD480C710
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$CloseOpen
                                              • String ID: Profiles
                                              • API String ID: 3087652857-1917249382
                                              • Opcode ID: 2afd084996fb65d7d85bc09335c39a156f65583df812ce05f705afe239c96caa
                                              • Instruction ID: fd8334aa3137f812e368a44cb2b0faf89b8d2784839fb22b579de25351c5419e
                                              • Opcode Fuzzy Hash: 2afd084996fb65d7d85bc09335c39a156f65583df812ce05f705afe239c96caa
                                              • Instruction Fuzzy Hash: 0271F532A18BC5C5EB50DB66E4403ADB7A1F789798F904236EA9C27BA9DF3CC140C710
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID: cannot use operator[] with a numeric argument with
                                              • API String ID: 73155330-485864652
                                              • Opcode ID: 47af27a4396b31f4ca52b67e984e374f80d468a776c57d5f4d7245d4691a4da7
                                              • Instruction ID: 31d08744aeb921d0bb73ceec397e3985f3bb53698d76acd0378bbd0dfafdd6fb
                                              • Opcode Fuzzy Hash: 47af27a4396b31f4ca52b67e984e374f80d468a776c57d5f4d7245d4691a4da7
                                              • Instruction Fuzzy Hash: D331E221719782C9EE55BB1BE5042A8E356AB04BE4F980738DE6D1BBD6DE7CE051C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: CurrentProfile
                                              • String ID: --type$Unknown
                                              • API String ID: 2104809126-2669863112
                                              • Opcode ID: 69ff7fa0b78fb07a03e9d6b68d909bad007d1af503b55ac48648ab31583b2781
                                              • Instruction ID: 561b9dff88eaba51aba6fe73ec73b88fff37b3674b32f0816d11287097a0f95c
                                              • Opcode Fuzzy Hash: 69ff7fa0b78fb07a03e9d6b68d909bad007d1af503b55ac48648ab31583b2781
                                              • Instruction Fuzzy Hash: 7C31C322A2CBC1C6E660DF15F4402AAF760FB99784F94122AEBCD12A56DF7DD184CB10
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: CloseOpen
                                              • String ID: Profiles
                                              • API String ID: 47109696-1917249382
                                              • Opcode ID: 5829549960449d947faf1de599e7bedf2171007a48caf413cec529ae16cd6429
                                              • Instruction ID: 8e5b93e394f62b6fb7d4b9316b7dc97b9d34af0cc9d85da966feafd6a6d784cc
                                              • Opcode Fuzzy Hash: 5829549960449d947faf1de599e7bedf2171007a48caf413cec529ae16cd6429
                                              • Instruction Fuzzy Hash: 6C21DB21B18A41C5FE90AB23F8403AAE760EF54BD8F840135EE4D13B95DF2DD081C710
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: FolderFreeKnownPathTask_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 2444108017-0
                                              • Opcode ID: 90aa186b4265c15d4056cd557437e1a9e26daa12c30c1e3e649755021e69193c
                                              • Instruction ID: 2af0adbb855c8607ae3da95b62273a967ee8a60205843e81192f4123fa8a9e49
                                              • Opcode Fuzzy Hash: 90aa186b4265c15d4056cd557437e1a9e26daa12c30c1e3e649755021e69193c
                                              • Instruction Fuzzy Hash: 64319772D1878181E6609F2AE44025AB761FB997F4F50532AFAEC17B95DF7CD180CB00
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo$_local_unwind
                                              • String ID:
                                              • API String ID: 1677304287-0
                                              • Opcode ID: 3b153441c32461bfb0eb759f9cc7ec2d93a122d6959f07e27f40eb8d54cdee1f
                                              • Instruction ID: 7950f8dca8dc3d622675d61cc270c84f6829c87345456e60b6bb74731c45c8a4
                                              • Opcode Fuzzy Hash: 3b153441c32461bfb0eb759f9cc7ec2d93a122d6959f07e27f40eb8d54cdee1f
                                              • Instruction Fuzzy Hash: 5121D731A18646C9EA80FB16E4501B9A360EF96B84FD6013AE60E773E2DE3CE114C730
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: CloseOpenQueryValue
                                              • String ID:
                                              • API String ID: 3677997916-0
                                              • Opcode ID: 8d517d52458f60790962c1463bba805df80deba335e50ef2807d8efda91b40ea
                                              • Instruction ID: 3c0e405e493b8bc07ef1e2145ae1438008ed40a4f55e7d518b8b40c87d67ca0e
                                              • Opcode Fuzzy Hash: 8d517d52458f60790962c1463bba805df80deba335e50ef2807d8efda91b40ea
                                              • Instruction Fuzzy Hash: 7121C772A18785C1EA90DF26E08036AE751EBD57E4F805236EA9D52B95DE2CD084C710
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Info$User
                                              • String ID:
                                              • API String ID: 2017065092-0
                                              • Opcode ID: abc5036c296a8e57beceb74fdc647dcfa0ac5a3609073149a4a7ea06c52c9197
                                              • Instruction ID: 51290938f2e0eca423b8f92b49698769215723d2904c6d32f8373488a1be9a68
                                              • Opcode Fuzzy Hash: abc5036c296a8e57beceb74fdc647dcfa0ac5a3609073149a4a7ea06c52c9197
                                              • Instruction Fuzzy Hash: 7E11BE33A28785C6D7109F62E41065AB761FB90BC8F445138EF8917B49DF7CE150CB80
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: ios_base::badbit set
                                              • API String ID: 3668304517-3882152299
                                              • Opcode ID: 11c821e4b43dbdbc588919d5dc4f424958b90f249a81ad1a8528aeea595e2633
                                              • Instruction ID: 385f4d5df23762402a866b5378980d247487ec160846ac7780c33ad99b8fe147
                                              • Opcode Fuzzy Hash: 11c821e4b43dbdbc588919d5dc4f424958b90f249a81ad1a8528aeea595e2633
                                              • Instruction Fuzzy Hash: 1761CD22B0CA80CAFB419B7A94413FCA371AF5674CF449228DE8D37B95DF38A595C354
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: cd8fd92580dba8edd5d65f986a70d68b0eab73f238eba0f6b0a242237305781b
                                              • Instruction ID: 60dcee9354ea3923b26977997f2c11425ee4e0cbb7fab33573c4e64314395427
                                              • Opcode Fuzzy Hash: cd8fd92580dba8edd5d65f986a70d68b0eab73f238eba0f6b0a242237305781b
                                              • Instruction Fuzzy Hash: 2861D222B08B8581E951EB17A50457AB754FB44BE4F948739EEAD2BBD4CF3CE052C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: 1d6cb4d2482f1ef68bdbd1e68424630939e04501563cd5773f019a30d898e9ac
                                              • Instruction ID: 0bd2bec4282ef62fe8af41cae7112047955a9ad9f35f2bc661a67fe3176fbec2
                                              • Opcode Fuzzy Hash: 1d6cb4d2482f1ef68bdbd1e68424630939e04501563cd5773f019a30d898e9ac
                                              • Instruction Fuzzy Hash: 7B61C222609A41C9EAA0AF57D00427DA761EB06FD4F964639CF6E377D2DE3CE481C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: 046e9d51f2ddea1f7b180091d63b122fa3468643ba29a49ef74c8abe375ff798
                                              • Instruction ID: 12694fdbc21fc4ac0aa5f882f5d77c6f57ac294770b2ee93fb725d31afe7532f
                                              • Opcode Fuzzy Hash: 046e9d51f2ddea1f7b180091d63b122fa3468643ba29a49ef74c8abe375ff798
                                              • Instruction Fuzzy Hash: AC519B32A08B46C5EB96AF2AD4542ACB3A1FB58FE4F944139CE1D633A5DE3CD441C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: InformationVolume__std_fs_get_current_path_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3375085511-0
                                              • Opcode ID: 667e95a111ccc9308dced16a7d399f257838173fc00192af7fc5ce8a679a4a3e
                                              • Instruction ID: 550c1a55a1454add6af7e4248802bc542c9041f1e392f18f29c9fe4e63cdcb82
                                              • Opcode Fuzzy Hash: 667e95a111ccc9308dced16a7d399f257838173fc00192af7fc5ce8a679a4a3e
                                              • Instruction Fuzzy Hash: A4719F32A18B81C9E710DF75E8802ED7774F788758F90422AEA8D67B59EF78D184C750
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: 975f2292ed3ab7cd8cb3798530030509bef457a3fbaa49436a981110db01395f
                                              • Instruction ID: d146de86ced6d73e0ce05604d3a16161dabc7b6682d10a809ffe5a7881e5b5e2
                                              • Opcode Fuzzy Hash: 975f2292ed3ab7cd8cb3798530030509bef457a3fbaa49436a981110db01395f
                                              • Instruction Fuzzy Hash: 63410322B08781C1EAA1AB16E10426AF755FB44BD4F980639EFAD17BD9DF7CE040C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: b67eeb4d8761d791fde975bd1e9a88dcc517fb5f84569c5d75c8d82ec9108bc3
                                              • Instruction ID: f13dfe76aff816cc14ea17b64ad0c6a8966bbd8251472769f527fc4d430cb50c
                                              • Opcode Fuzzy Hash: b67eeb4d8761d791fde975bd1e9a88dcc517fb5f84569c5d75c8d82ec9108bc3
                                              • Instruction Fuzzy Hash: B841D222609B85C1EA64EF16E44427AE3A4FB48BD0FA48639DBAD17B95CF3CD050C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: __std_fs_directory_iterator_open
                                              • String ID:
                                              • API String ID: 4007087469-0
                                              • Opcode ID: 94b04f1cb2cf3656ee73b5c6c15997d5b3bfe66093c08fb928735d05e49a60f6
                                              • Instruction ID: 8bd4ee409ac49a5981b955924734d1f8e39f4dccf7a0597bcdb9a35d8ff5aedd
                                              • Opcode Fuzzy Hash: 94b04f1cb2cf3656ee73b5c6c15997d5b3bfe66093c08fb928735d05e49a60f6
                                              • Instruction Fuzzy Hash: FA412663A48642D5EA50AB15E4402BAA391EF857F8F880339EE6C577E5EF3CD0C1C720
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: ffe440de61b82e5f398e9f0ac531d7edb89aedd7f1e7035129276699f07fd964
                                              • Instruction ID: 6e93214485ffb00106eaecbb1a8fe0b8a04971be0890f772130c1339ae342abe
                                              • Opcode Fuzzy Hash: ffe440de61b82e5f398e9f0ac531d7edb89aedd7f1e7035129276699f07fd964
                                              • Instruction Fuzzy Hash: 8D31B062718685C1E995EA57A8041BAF750FB44BE4F948A39EEAD2BBD5CF3CE041C310
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: f156c46424bb9a348111ed454f692e5fcaf150f18fa80458846ed35b1bb3665e
                                              • Instruction ID: 48931ebe1bbe0ac8200e4395c6ef0f926fcb2243403f4008b986ec82f96d5100
                                              • Opcode Fuzzy Hash: f156c46424bb9a348111ed454f692e5fcaf150f18fa80458846ed35b1bb3665e
                                              • Instruction Fuzzy Hash: 7631B131709641C5EEA5AB56E2042B9F256AF48BE0F880639DF5D1BBD5DE3CE081C320
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 262b5e8506a9a074d62926610c2e51101e4d88319338fccb5df5ad85ac35eb22
                                              • Instruction ID: 850385d78e72b6b8a12a409fd631a01c359504ef6ac1571eece9e509ea41c870
                                              • Opcode Fuzzy Hash: 262b5e8506a9a074d62926610c2e51101e4d88319338fccb5df5ad85ac35eb22
                                              • Instruction Fuzzy Hash: B741EB62A187C5C6FA50AB2AE44536AF750FB857A4F900339E6EC567D5DF3CD080CB10
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 73155330-0
                                              • Opcode ID: f9c8b5776e2933e5e990604a8b11885257ddd64a82d55928efbbbe774be918d6
                                              • Instruction ID: c8ee30b895addbba0b515635a71480b181ac14b76f836a6ab72f26e671c58745
                                              • Opcode Fuzzy Hash: f9c8b5776e2933e5e990604a8b11885257ddd64a82d55928efbbbe774be918d6
                                              • Instruction Fuzzy Hash: 2121F632E05A4185EE99AB16A5002B9A351AF54BB4F648735DA3C13BD5FE7CE4D2C340
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: CloseCreateCredEnumerateFirstHandleMutexProcess32ReleaseSnapshotToolhelp32recv
                                              • String ID:
                                              • API String ID: 420082584-0
                                              • Opcode ID: 984f70c47e4c59795d457a7adcd0c7a85abdb293d432f429c0564b5387438e4d
                                              • Instruction ID: 7ca1b0db02018f8258c7c02f604b481fe68bd2e3406ee8178927e086b9d34bed
                                              • Opcode Fuzzy Hash: 984f70c47e4c59795d457a7adcd0c7a85abdb293d432f429c0564b5387438e4d
                                              • Instruction Fuzzy Hash: 24219D21E0C682C0FAD1BB67A8463FDD215AF45790FC45539E96D3A7D79E2CE484C231
                                              APIs
                                              • SetFilePointerEx.KERNEL32(?,?,?,?,?,00007FF7633763C8,?,?,?,?,?,?,?,00007FF76337651D), ref: 00007FF763376474
                                              • GetLastError.KERNEL32(?,?,?,?,?,00007FF7633763C8,?,?,?,?,?,?,?,00007FF76337651D), ref: 00007FF76337647E
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ErrorFileLastPointer
                                              • String ID:
                                              • API String ID: 2976181284-0
                                              • Opcode ID: 0b289e67f3315a15b91e6abf967764529b2485836cde0f12dbfa8971809dfebb
                                              • Instruction ID: bec260c16f26658d84828a3dab8baa7c561b7fe263c95a6723af8c77beb4194d
                                              • Opcode Fuzzy Hash: 0b289e67f3315a15b91e6abf967764529b2485836cde0f12dbfa8971809dfebb
                                              • Instruction Fuzzy Hash: FE110171A08B81C1DAA0AB26E414169A371EB41FF4F940339EE7D1B7E9CE3CD080C740
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task$std::bad_alloc::bad_alloc
                                              • String ID:
                                              • API String ID: 1173176844-0
                                              • Opcode ID: 405008cc01b437d6d1913cc62f306b0ce1d640e415570274eed73f872d5e1b18
                                              • Instruction ID: d8e45352831d520374b67b20dc3a53fac2d92f123afdcc82ed8fb5b4d72c94aa
                                              • Opcode Fuzzy Hash: 405008cc01b437d6d1913cc62f306b0ce1d640e415570274eed73f872d5e1b18
                                              • Instruction Fuzzy Hash: 75E0EC40E1A207C9FDE976A314160B985480F59774EAC1738E93D287D3AD3CB495C630
                                              APIs
                                              • RtlFreeHeap.NTDLL(?,?,?,00007FF76337DF72,?,?,?,00007FF76337E2EF,?,?,00000000,00007FF76337C02C,?,?,?,00007FF76337BF5F), ref: 00007FF763373E1A
                                              • GetLastError.KERNEL32(?,?,?,00007FF76337DF72,?,?,?,00007FF76337E2EF,?,?,00000000,00007FF76337C02C,?,?,?,00007FF76337BF5F), ref: 00007FF763373E24
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ErrorFreeHeapLast
                                              • String ID:
                                              • API String ID: 485612231-0
                                              • Opcode ID: 24c1c0facc83508872a16f71c5f3085ae3b42767224b6ebf063ad29e43c36eb2
                                              • Instruction ID: 6b339e0ccc035a4d4b6b86d24ac3bc0e89c686c187fdede18f3d8171c6e5473a
                                              • Opcode Fuzzy Hash: 24c1c0facc83508872a16f71c5f3085ae3b42767224b6ebf063ad29e43c36eb2
                                              • Instruction Fuzzy Hash: 79E08C51F19682C2FF887BF39844078A2609F8A741BC4003CC91EB7761DE3CA891C334
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: ac5a6e8f024a9f482d4cff9144b48fab1265b49d531ab5f92d373b99ba19e449
                                              • Instruction ID: ad051c7594e40fd3c000aeda83b576844d50a59a4822ecc4a6c0973e3f41fdff
                                              • Opcode Fuzzy Hash: ac5a6e8f024a9f482d4cff9144b48fab1265b49d531ab5f92d373b99ba19e449
                                              • Instruction Fuzzy Hash: E5B18D32F18A41C4EB92EB66D9442ADB761FB04B98F85413ACF4D27B99DF38D491C360
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 64d94acb7bf0318463c15645241ce2c0a0a4af76723e704df93724cb5bdf734c
                                              • Instruction ID: 4375bc825503aacda77b92e07a3e1751d8d506d63d99fc4f3c79ca94001729cd
                                              • Opcode Fuzzy Hash: 64d94acb7bf0318463c15645241ce2c0a0a4af76723e704df93724cb5bdf734c
                                              • Instruction Fuzzy Hash: 52B1AE32704A41CADB609F3AD4907ACB3A1FB48B68F845636EB5E53B99CF39D455C320
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 112835adffac4f3a2811c593af6f4198d7fcde7becbd26983c8a17c7eba33d23
                                              • Instruction ID: a7d4a432564409efb55d72081b7704458632a68392638918a1ff26f972f092b0
                                              • Opcode Fuzzy Hash: 112835adffac4f3a2811c593af6f4198d7fcde7becbd26983c8a17c7eba33d23
                                              • Instruction Fuzzy Hash: E191CF22E18BC585E751DB79E4403ADA7A0FB99398F541329EADC26B99DF3CD180C710
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: af97434640a838a5f551ed2e2dfffd87e7f6ff24c5d315330158e50efae3ec73
                                              • Instruction ID: 9a5aefa42075962fadc0cbe85dc90ea925343ad5d1a72f718092e196d996f195
                                              • Opcode Fuzzy Hash: af97434640a838a5f551ed2e2dfffd87e7f6ff24c5d315330158e50efae3ec73
                                              • Instruction Fuzzy Hash: AD41D332908205C7EAB4AB1AE440279F3B0EB56B42F900139DB9EA7791CF7DF442C764
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: eb959c3f41324018dc16cf4a52fbf3dfdc0a984b8be5d43a60f9f1cd1ee1a301
                                              • Instruction ID: 14f04fe1b72c9fb07c0daa9142dc34bc549fc2b57dd8fd2e661a27a72e6ee06d
                                              • Opcode Fuzzy Hash: eb959c3f41324018dc16cf4a52fbf3dfdc0a984b8be5d43a60f9f1cd1ee1a301
                                              • Instruction Fuzzy Hash: E6413872B15B48CDE7408FB9E4403AC73B6E74979CF005625DE9C66B89EE348164C394
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 118556049-0
                                              • Opcode ID: a13861e00e590468816802660cd1da83d972d62d9d49e287459ee2df58605774
                                              • Instruction ID: 42ee880bac96837e16d73998681bb950d5bc4763f03acc9815306ea7f0fd3e8b
                                              • Opcode Fuzzy Hash: a13861e00e590468816802660cd1da83d972d62d9d49e287459ee2df58605774
                                              • Instruction Fuzzy Hash: 38415A73908B41C6DB54DF16E440128B7B0F798F44B558629DB8D57355DF38D8A0C7A4
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 6f786347a37d4684b13f6cf6e78b2ce699f61a5fd7bf47ee94c93a2a041324e2
                                              • Instruction ID: 66f6cd9028851c3a79cf1a50d0eafbdca9afe74747eb3fdfb46deef91e73cd56
                                              • Opcode Fuzzy Hash: 6f786347a37d4684b13f6cf6e78b2ce699f61a5fd7bf47ee94c93a2a041324e2
                                              • Instruction Fuzzy Hash: 56316F32E18601CAF7957F1694412BCB661AB8ABA2FD1023DD91D277E2CF7CA441C739
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 2e4d518ac2133c9683ed8c698cd18f3f674434f9c9dba20d80f23c38ac4b812f
                                              • Instruction ID: af44ed575b8c63bec43486b6b3d775afff14e6d6f0300e0f8bc8d856cabf394f
                                              • Opcode Fuzzy Hash: 2e4d518ac2133c9683ed8c698cd18f3f674434f9c9dba20d80f23c38ac4b812f
                                              • Instruction Fuzzy Hash: 08112876705B49C6DB459F6EE09422C7361FB89F99B918026DF4D57368DF38C890C350
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 4f9b2f8469ee7c7c2fa910a4f0b010034c9d4173bbd88a1f33b49acec34b0f12
                                              • Instruction ID: 2704e5d634201b6730000234f9d8e112ca1e36e24639a0babc6b7fdd3a367f6c
                                              • Opcode Fuzzy Hash: 4f9b2f8469ee7c7c2fa910a4f0b010034c9d4173bbd88a1f33b49acec34b0f12
                                              • Instruction Fuzzy Hash: DC21D772A08641C7DBA1AF1AE840379B7A0FB85B64F944238DA5D577D9EF3CD840CB10
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 071eab0d2ddb6d97d7b7232e2de0088f1d155ba52ad6f2216ba9fc5c62e5c193
                                              • Instruction ID: c9902ff7a47f809489581e1bde540671e914f8bc0dc2abf29e16b45e60d15f2d
                                              • Opcode Fuzzy Hash: 071eab0d2ddb6d97d7b7232e2de0088f1d155ba52ad6f2216ba9fc5c62e5c193
                                              • Instruction Fuzzy Hash: 6B118C22A1C742C5EAE0BF53940027DE2A0BF86B80F945439EA8D67B96DF7CE441C760
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: send
                                              • String ID:
                                              • API String ID: 2809346765-0
                                              • Opcode ID: 4e306829149e169d4783c267f1d2206ea130793025a9a04d510cabbcf64490f0
                                              • Instruction ID: 21fcae5e169f651089b6f201b37e95f6306abc433fef8b3c0b324303ce26282b
                                              • Opcode Fuzzy Hash: 4e306829149e169d4783c267f1d2206ea130793025a9a04d510cabbcf64490f0
                                              • Instruction Fuzzy Hash: 3A01A221B18A85C1EB909F1BB940229E7A0FB88FE4F885235EF5E53F58DF28D8518740
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: FileFindNext
                                              • String ID:
                                              • API String ID: 2029273394-0
                                              • Opcode ID: d66c6789144ba1e35efb442882a242fd38313b147d2b64ebd79fbcf9248c3a46
                                              • Instruction ID: 5a99979b51ce858c9dc638f841512e428e737d6d8d93f83d5d44de94d9a1e082
                                              • Opcode Fuzzy Hash: d66c6789144ba1e35efb442882a242fd38313b147d2b64ebd79fbcf9248c3a46
                                              • Instruction Fuzzy Hash: A5014F26608AC2C1DAB0DB56F4542ABB364FB88B94F804036DE8D57B58DF3CD886CB00
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: e3199247b15e626e1ff80a5878ee6ff274038b46c14856a595a092b0a0f0e46b
                                              • Instruction ID: 553c2f22ea15c79d9f2e0f08955d4c2a267e2a18e1a09798f81c1fc5ed49308e
                                              • Opcode Fuzzy Hash: e3199247b15e626e1ff80a5878ee6ff274038b46c14856a595a092b0a0f0e46b
                                              • Instruction Fuzzy Hash: 39E0E531A09642C9EB943A6A9141078A1609F067F0FD15338EA3C263C1DE289860C620
                                              APIs
                                              • FindNextFileW.KERNELBASE(?,?,?,?,00007FF7632FFD7B,?,?,?,?,00000000,00000000,FFFFFFFF,?,?,00007FF763313F5F), ref: 00007FF76338B9FC
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: FileFindNext
                                              • String ID:
                                              • API String ID: 2029273394-0
                                              • Opcode ID: 021893cd2ed339d1065ce6c5a318dc70dc0859a0caadd9e5077c2889b17622f9
                                              • Instruction ID: d2d99e0513f062509818580fb076a2b8519af1a3e1224a943d205d54318f6fae
                                              • Opcode Fuzzy Hash: 021893cd2ed339d1065ce6c5a318dc70dc0859a0caadd9e5077c2889b17622f9
                                              • Instruction Fuzzy Hash: 72C04C15F59983C1E69437635C861A25590AB44740FD08538C52C98750DD2C91A7C631
                                              APIs
                                              • GetNativeSystemInfo.KERNEL32(?,?,?,?,?,?,?,?,?,?,00007FF763359AC8), ref: 00007FF76338D529
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: InfoNativeSystem
                                              • String ID:
                                              • API String ID: 1721193555-0
                                              • Opcode ID: 7625abf66e5e969e873e9ca9c619bb3736778813dbd6fa0c580d282ca7e19459
                                              • Instruction ID: d87567d2c84937c4eb22ae2e7199d8207a53125f4a15b56b9140040ad30872ab
                                              • Opcode Fuzzy Hash: 7625abf66e5e969e873e9ca9c619bb3736778813dbd6fa0c580d282ca7e19459
                                              • Instruction Fuzzy Hash: 18B09226E288C0C3C611FB04E842019B731FB94B08FD00420E28D42B24DE2CDA2ACF00
                                              APIs
                                              • HeapAlloc.KERNEL32(?,?,00000000,00007FF763370C66,?,?,8000000000000000,00007FF76336CB85,?,?,?,?,00007FF7633767F4,?,?,?), ref: 00007FF7633744C1
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: AllocHeap
                                              • String ID:
                                              • API String ID: 4292702814-0
                                              • Opcode ID: ce6335797a4eddad822b84f0a1549a88b3ca4cbb4f04ff5d221c521cf26faf27
                                              • Instruction ID: f5caa91989b5df68786871332d9fa13c9872698b10150c97703eff0fcfa3f3cb
                                              • Opcode Fuzzy Hash: ce6335797a4eddad822b84f0a1549a88b3ca4cbb4f04ff5d221c521cf26faf27
                                              • Instruction Fuzzy Hash: EFF06D54B0A206C1FED577A394052B4D2A41F4AB81F9C553CDD0EA67D1EE2CF4C0E238
                                              APIs
                                              • HeapAlloc.KERNEL32(?,?,?,00007FF763386B53,?,?,?,?,?,?,?,?,0000000100000000,00007FF76338C815), ref: 00007FF7633767E2
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: AllocHeap
                                              • String ID:
                                              • API String ID: 4292702814-0
                                              • Opcode ID: b406b7f263db90f071041f31ea6e7ee73d4bc305731f5b88ce6b24a3c5683e1f
                                              • Instruction ID: cbd353f29a23e9e9d364b3c66c0c0ba384b72e9affec6b664cb2c3f39660f2a6
                                              • Opcode Fuzzy Hash: b406b7f263db90f071041f31ea6e7ee73d4bc305731f5b88ce6b24a3c5683e1f
                                              • Instruction Fuzzy Hash: D0F05E24A0D286C4FAD536A399216B992905F46BF1FC8063CED2EA57C1EE2CE440C234
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$ExceptionFileHeaderRaise__std_exception_copy
                                              • String ID: "$#base$#include$*$/$No closed word$Unexpected eof$conditional not closed$key declared, but no value$key opened, but never closed$object is not closed with '}'$quote was opened but not closed.$unexpected '}'$unexpected key without object$word wasnt properly ended
                                              • API String ID: 1861853482-2258937249
                                              • Opcode ID: 6f46a390516381455ed3b7e9f1244a7de4cac0cfaa7f0e95f4cd53533bb37532
                                              • Instruction ID: eaeec783c7c01513cce5e91727d896601c3f4b1ae9dfac5d544853068e18baef
                                              • Opcode Fuzzy Hash: 6f46a390516381455ed3b7e9f1244a7de4cac0cfaa7f0e95f4cd53533bb37532
                                              • Instruction Fuzzy Hash: FFE29272A08BC6C5EBA1AF26D8403F9B761FB44788F845135DA4D2BB99DF78D185C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                              • String ID: "$#base$#include$No closed word$key declared, but no value$key opened, but never closed$quote was opened but not closed.$unexpected '}'$unexpected key without object$word wasnt properly ended
                                              • API String ID: 3936042273-2543107223
                                              • Opcode ID: 18d965921196ec1df1f610757faf78c66ad73ab177f07b132fe41238fd1ce982
                                              • Instruction ID: 9ed52ee0c1c1ec363b1c53afb3da607c09dbe65e4c0cd8a74eb09782ebb08ff1
                                              • Opcode Fuzzy Hash: 18d965921196ec1df1f610757faf78c66ad73ab177f07b132fe41238fd1ce982
                                              • Instruction Fuzzy Hash: 81A2C572A08BC6C5EBA1AF26C8507FDA761FB44788F844139DA4D2BB99DF78D185C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_fs_convert_wide_to_narrow
                                              • String ID: !$content$filename$status$users
                                              • API String ID: 1223724100-3795777748
                                              • Opcode ID: 8fe4d0a50f7d0f48ac4d1d61496dbe7c14bcf77aac862f92058017f3301ea0f4
                                              • Instruction ID: 899e98b2d6d3507f8c57d3c5961fdfabc01fc2b615dbc69514d5674ed992e6c3
                                              • Opcode Fuzzy Hash: 8fe4d0a50f7d0f48ac4d1d61496dbe7c14bcf77aac862f92058017f3301ea0f4
                                              • Instruction Fuzzy Hash: A1B2A062A14BC5C9DB61AF35D8403EDB365FB45788F805239EA9D6BB99EF38D240C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: String$Free$Byte$AllocInitialize$BlanketCreateInstanceProxySecurity_invalid_parameter_noinfo_noreturn
                                              • String ID: @
                                              • API String ID: 4083794144-2766056989
                                              • Opcode ID: 251b227ba7a1fb980a489014036dc5f27b097793efe4a60789f7e685506b82bc
                                              • Instruction ID: ec58cccc5ac61810ee79bcc9b7d387a7bd2c62b9dc37fd90807058514b155682
                                              • Opcode Fuzzy Hash: 251b227ba7a1fb980a489014036dc5f27b097793efe4a60789f7e685506b82bc
                                              • Instruction Fuzzy Hash: 52D1B022F08781CAF740AF7AD4543ADA3A1EB49798F808639DE9D66B95DF3CE144C310
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: Email$HTTP Server URL$HTTP User$HTTPMail Server$IMAP Password$IMAP Password2$IMAP Server$IMAP User$IMAP User Name$NNTP Password$NNTP Password2$NNTP Server$NNTP User$NNTP User Name$POP3 Password$POP3 Password2$POP3 Server$POP3 User$POP3 User Name$SMTP Password$SMTP Password2$SMTP Server$SMTP User$SMTP User Name
                                              • API String ID: 0-560833949
                                              • Opcode ID: 88317e2a70de5c5ec0c64bc131c99f8842114f81e22e42028fa3f3b6b1b907df
                                              • Instruction ID: f1fb65655527805aea1b968ad913ae4de7f6a49f77bc885ecf83caea233568cd
                                              • Opcode Fuzzy Hash: 88317e2a70de5c5ec0c64bc131c99f8842114f81e22e42028fa3f3b6b1b907df
                                              • Instruction Fuzzy Hash: E8D2B532919BC989D7768F35AC413EA73A8F75978CF505229EB8C2AB19EF749354C300
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID: BOOTNXT$autorun.inf$boot.ini$boot.sdi$bootfont.bin$bootmgfw.efi$bootmgr$bootsect.bak$bootstat.dat$d3d9caps.dat$desktop.ini$gdipfontcachev1.dat$iconcache.db$indexervolumeguid$mib.bin$ntldr$ntuser.dat$ntuser.dat.log$ntuser.ini$reagent.xml$thumbs.db$winre.wim$winsipolicy.p7b$wpsettings.dat
                                              • API String ID: 73155330-850610325
                                              • Opcode ID: a96eecc44e3043773db0e883680fe3aa9f097c62710d358845abfe4b3a443794
                                              • Instruction ID: ffdff67d072f066eef13221ee16fd262800392d603596df93ef10dc28dfd066c
                                              • Opcode Fuzzy Hash: a96eecc44e3043773db0e883680fe3aa9f097c62710d358845abfe4b3a443794
                                              • Instruction Fuzzy Hash: 03C16952D64BCA84E711DB35C8813F5A361FFEA384F90632AA58C7595AEF68B3C4C350
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: lstrcpy$lstrcat$AllocateInitLockMemoryObjectStringUnicodeVirtual$AcquireEnumerateFolderFreeInitializeKnownLoadedModulesPathReleaseTaskUninitialize_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 2979746431-0
                                              • Opcode ID: 69eeff7077457ebd5f2efa87dbda7386d0aa3d989cbf95d9af8d4e1f52a335ba
                                              • Instruction ID: 441de36127112348bb45c41663b2ce74ac51c81703da224812dd9599caa64b6d
                                              • Opcode Fuzzy Hash: 69eeff7077457ebd5f2efa87dbda7386d0aa3d989cbf95d9af8d4e1f52a335ba
                                              • Instruction Fuzzy Hash: 64D2AA36629FC58AD7918F29E88169EB3B4F788788F505229EECD57B18EF38C154C740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID: #recycle$$recycle.bin$$windows.~bt$$windows.~ws$$winreagent$All users$AppData$Application Data$Boot$PerfLogs$Program Files$Program Files (x86)$ProgramData$System Volume Information$Windows$Windows.old$Windows.~bt$bootmgr$config.msi$ntldr
                                              • API String ID: 73155330-2722463023
                                              • Opcode ID: ff761d91631aa3f9502625d79d5292476573348136f5d4a02a43359ddd108f2a
                                              • Instruction ID: 16496f84c4c6b438869a3dab5f498da0a5868493981b2c21728c5121f60ae210
                                              • Opcode Fuzzy Hash: ff761d91631aa3f9502625d79d5292476573348136f5d4a02a43359ddd108f2a
                                              • Instruction Fuzzy Hash: 39A18852D64BCAC4E751EB35C8413F5A361FBEA344FA0632AA58C7595ADF68B3C4C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
                                              • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                                              • API String ID: 808467561-2761157908
                                              • Opcode ID: 529c51e133bdec29678d87a85c3d83eb1136f2ce27c70c96b191372ce4db736a
                                              • Instruction ID: a4445080ba6a27c9dd4cc24406b7274d009c69c51c141eb93020234926a9fc4f
                                              • Opcode Fuzzy Hash: 529c51e133bdec29678d87a85c3d83eb1136f2ce27c70c96b191372ce4db736a
                                              • Instruction Fuzzy Hash: 61B2D272E19282CBE7A59F66D4407FDB6A1FB44388F905139DA1E77B84DB3CA600CB50
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: or more] $[default: $[nargs: $[nargs=$[required]
                                              • API String ID: 3668304517-2670406794
                                              • Opcode ID: 29bfa332825ff32d88e04e8b8cb11d07638d852fed181530fe04ea65f0815f08
                                              • Instruction ID: f67d3a9a6f4200fd1638135aa5b4ae15669cb52b218889f49e3e30874ba71d00
                                              • Opcode Fuzzy Hash: 29bfa332825ff32d88e04e8b8cb11d07638d852fed181530fe04ea65f0815f08
                                              • Instruction Fuzzy Hash: 9352B562A08B81C1FB54EB6AD8443ADB761FB457A4F90423ADA9D277D6DF3CE184C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_destroy
                                              • String ID: value
                                              • API String ID: 1346393832-494360628
                                              • Opcode ID: 88271e93bfd314610f364f837937c401ec86a8887a5d0b179968ee98ae76f929
                                              • Instruction ID: 63a7607d01529265e5aa6a05a07bd9b5422cb9a9f8c5b14e1dd20cdb0fe82709
                                              • Opcode Fuzzy Hash: 88271e93bfd314610f364f837937c401ec86a8887a5d0b179968ee98ae76f929
                                              • Instruction Fuzzy Hash: 7502E622A19BC1C5FB41DB76D4403ADA761EB853A4F905239FA9D26BDADF7CD180C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                              • String ID: parse_error$value
                                              • API String ID: 1944019136-1739288027
                                              • Opcode ID: 2fc5d3fea41350fa17fc3e1aa00e37ccfaf1c2611c6308e52872b775bad0d304
                                              • Instruction ID: 37fba8bb4a99e3cc562a527f053949265003a2e9bade2c9820c833402cd5c6d9
                                              • Opcode Fuzzy Hash: 2fc5d3fea41350fa17fc3e1aa00e37ccfaf1c2611c6308e52872b775bad0d304
                                              • Instruction Fuzzy Hash: C3F1B062F18A86C5FB40EB66D4413FDA321EB55398F809235EA5D26BDAEF3CD184C350
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: lstrcatlstrcpy$Object$AcquireAllocateInitializeLockMemoryUninitializeVirtual
                                              • String ID:
                                              • API String ID: 3636535045-0
                                              • Opcode ID: 33125db565dc998c7adbbacb9267a4c4f1f59afe7db5753b15395ce550f5eb4b
                                              • Instruction ID: aa7fdb3e254fd24412c2e5f6fe243c97397d5fb384735e004d8c343996abb021
                                              • Opcode Fuzzy Hash: 33125db565dc998c7adbbacb9267a4c4f1f59afe7db5753b15395ce550f5eb4b
                                              • Instruction Fuzzy Hash: 19B2893652AFC58AD7A18F29E88169AB3A4F388784F106215FFCD57B18EF78C254C740
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                              • String ID: --help$--version$prints version information and exits$shows help message and exits
                                              • API String ID: 3936042273-1172229024
                                              • Opcode ID: e1b930c1560d9a6ca6b2243aba9ac1992d77844dccab8e61e6a5c5b464e5c1e2
                                              • Instruction ID: b04ebf3a2ea94fd50c66a466c656eb003385941920b38b690d77c6e62dd20085
                                              • Opcode Fuzzy Hash: e1b930c1560d9a6ca6b2243aba9ac1992d77844dccab8e61e6a5c5b464e5c1e2
                                              • Instruction Fuzzy Hash: A022CC32A08B81C5E750DF25E8407ADB3A4FB98748F959239DE8D27766EF78D199C300
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$ExecuteFileModuleNameShell
                                              • String ID: --type
                                              • API String ID: 3435646932-2654721227
                                              • Opcode ID: ec6db7150de02d8e9b2120cf22d57e4aa77cda58c9333c21951039a7757e3f81
                                              • Instruction ID: b358beac6d0654929a595a8818080e49f471ba533c005f5220dfac9051db6137
                                              • Opcode Fuzzy Hash: ec6db7150de02d8e9b2120cf22d57e4aa77cda58c9333c21951039a7757e3f81
                                              • Instruction Fuzzy Hash: 56223C32A29FC48AE7808F29E88169DB3A4F788784F505229FEDD57B59EF38D154C740
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ErrorLastNameTranslate$CodePageValidValue
                                              • String ID: utf8
                                              • API String ID: 1791977518-905460609
                                              • Opcode ID: c639ea29ff2223611d1607500ef9607e403d74a87a68d05e1ae74b1fb23a3b06
                                              • Instruction ID: fe8a659ced081868a6fc13b8f25a6e7269f3eebfac85e3ea81f4b96f8f939bc8
                                              • Opcode Fuzzy Hash: c639ea29ff2223611d1607500ef9607e403d74a87a68d05e1ae74b1fb23a3b06
                                              • Instruction Fuzzy Hash: 1E91AA36A08742C6EBA4BF22D4412B9A3B0FB86B81F844139DE5C67785DF3CE541C728
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Value$Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
                                              • String ID:
                                              • API String ID: 2591520935-0
                                              • Opcode ID: 8fe74223d010cdf23bbaed2293233460185b379beb42cca2b39d3ff693acabf0
                                              • Instruction ID: 85203184a89d8d46a0362cd42b5a0d2fee4442f99cd6c81c107a5912774a5174
                                              • Opcode Fuzzy Hash: 8fe74223d010cdf23bbaed2293233460185b379beb42cca2b39d3ff693acabf0
                                              • Instruction Fuzzy Hash: 12715D22B08656C9FB90AB62D4506B8B3F0BF4A745F84403ACE1D677D5EF3CA545C364
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
                                              • String ID:
                                              • API String ID: 1239891234-0
                                              • Opcode ID: a0623ba61f08f5fe629988ead490c086d0c0d6930e11c71ea404e3dd4b904fa3
                                              • Instruction ID: fb328c5e23097b6f97d09e9d171713b7748af530b2ba9d6e1c4696aa4dc3edd5
                                              • Opcode Fuzzy Hash: a0623ba61f08f5fe629988ead490c086d0c0d6930e11c71ea404e3dd4b904fa3
                                              • Instruction Fuzzy Hash: CC31B332608F81C6EBA0DF26E8402AEB7A4FB89754F940139EA9D57B54DF3CC555CB10
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: memcpy_s
                                              • String ID:
                                              • API String ID: 1502251526-3916222277
                                              • Opcode ID: c10be92ccd777733aec77242fd83f6c250c9f7e3d5896467feec955041489aac
                                              • Instruction ID: 25f789854ade177eed50ab9fc6d835a2df43c4044f8159ddb65eabdd5a5e7c7f
                                              • Opcode Fuzzy Hash: c10be92ccd777733aec77242fd83f6c250c9f7e3d5896467feec955041489aac
                                              • Instruction Fuzzy Hash: B1C1E372A18286CBD7A0DF17E048A6AF795F785784F858139EB4E6B744DB3CE901CB10
                                              APIs
                                              Strings
                                              • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 00007FF76338DCE3
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: DebugDebuggerErrorLastOutputPresentString
                                              • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
                                              • API String ID: 389471666-631824599
                                              • Opcode ID: 5c7395dc388ac93676d6db0d40de6010577d7fa9f7f31d3abeba2b9718ad71c6
                                              • Instruction ID: b8c196b9016eee457b415a5e814920376c58e0ae991e06af03d60b65081b5e00
                                              • Opcode Fuzzy Hash: 5c7395dc388ac93676d6db0d40de6010577d7fa9f7f31d3abeba2b9718ad71c6
                                              • Instruction Fuzzy Hash: D2113D32A14B82D7E784AB23E5443B9B2A4FF04745F804139CA5D56B50EF7CE0B4C720
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Virtual$AllocInfoProtectQuerySystem
                                              • String ID:
                                              • API String ID: 3562403962-0
                                              • Opcode ID: d8d05873cc0ad23a6227d848cec7d083f47c87653e05dd80255be0592c12f254
                                              • Instruction ID: 86531829cc259a241517c6401c16c1ae439fcbc37ac7362e1381778e85b958bb
                                              • Opcode Fuzzy Hash: d8d05873cc0ad23a6227d848cec7d083f47c87653e05dd80255be0592c12f254
                                              • Instruction Fuzzy Hash: B2314B32714A81CEEB50EF36D8407E867A5FB09B88F84403ADA0D9BB44DE3CE645C750
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                              • String ID:
                                              • API String ID: 2933794660-0
                                              • Opcode ID: 2ac89b5fea08dda77e100734bc6dd1b2318c7a5e5bcdef592d09e1a64040e310
                                              • Instruction ID: ce513b824cda728e5bc83819392f98994c1f75248e90ca8965a3f72355432702
                                              • Opcode Fuzzy Hash: 2ac89b5fea08dda77e100734bc6dd1b2318c7a5e5bcdef592d09e1a64040e310
                                              • Instruction Fuzzy Hash: 09117026B14F02C9EB40DF61E8542B873A4F718758F840E35DAAD56BA4DF7CD194C350
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: %
                                              • API String ID: 3668304517-2567322570
                                              • Opcode ID: e3bf12713740de0f426eb16773a4e3a8c56b7ca0e6a832e220c648acd7c70913
                                              • Instruction ID: c6cd87fb2fc4d7569ccdd67e4752d9012dbb5a148ad5b6386b549a1bf8e62b9d
                                              • Opcode Fuzzy Hash: e3bf12713740de0f426eb16773a4e3a8c56b7ca0e6a832e220c648acd7c70913
                                              • Instruction Fuzzy Hash: C5123522B08685C9F7559B66D8103FDB761AB55788F844139DE4D3BB8ADF3CD448C3A0
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: FormatInfoLocaleMessage
                                              • String ID: !x-sys-default-locale
                                              • API String ID: 4235545615-2729719199
                                              • Opcode ID: 524e3a65a531c01bd4bfd41e549e365538079e1841d07b699c799e17f4840897
                                              • Instruction ID: 82446de39af939416c9dc49626a91b600dafb68bbe1aa96fa8bf947555094177
                                              • Opcode Fuzzy Hash: 524e3a65a531c01bd4bfd41e549e365538079e1841d07b699c799e17f4840897
                                              • Instruction Fuzzy Hash: E2019E72B0878282EB609B12F4407B9BBA2FB88794F844139EA5D66B89CF3CD445C710
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: e26a54fae50cf6d0c152cbd76e3d92c0e3f1b924993c3f9af7ddc82fa085cf11
                                              • Instruction ID: 5279654d144af7963c60aebc9f40da30e017355f72ed98cb1142ee1d4cbd4de4
                                              • Opcode Fuzzy Hash: e26a54fae50cf6d0c152cbd76e3d92c0e3f1b924993c3f9af7ddc82fa085cf11
                                              • Instruction Fuzzy Hash: DE91E072B19B89C1EE54EB1AE4505A9F3A4FB58BC0B94403AEE8D57758DF3CD191C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: CryptDataFreeLocalUnprotect_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 2610421622-0
                                              • Opcode ID: 77944de7a45d9015c2a24ca5dd6cb00f6c331963efd3e3576b95a0ce3d995bb6
                                              • Instruction ID: 7d1dbaedd091d403b9f5605fd1ce2135385f033eaa0a8a0aa04820525ca51348
                                              • Opcode Fuzzy Hash: 77944de7a45d9015c2a24ca5dd6cb00f6c331963efd3e3576b95a0ce3d995bb6
                                              • Instruction Fuzzy Hash: A5616A32B14B81CAF750AF75D4403ADB3A1EB5878CF404239EA8D26B99DF78D594C350
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: -
                                              • API String ID: 3668304517-2547889144
                                              • Opcode ID: f9a4a7eb24ca7097e4a03f9841305f6c701a90c6d8e525e9717dd9b3478dda0d
                                              • Instruction ID: 3cb8ec5f366af48b8f2c376adbe7dda7cf2ec3afcba5fca8cc4d01bf5da43945
                                              • Opcode Fuzzy Hash: f9a4a7eb24ca7097e4a03f9841305f6c701a90c6d8e525e9717dd9b3478dda0d
                                              • Instruction Fuzzy Hash: A822C522A08B91C6FB50DF26D8402ADB7A1FB45798F904539EF9D27B9ADF38D484C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: InfoLocale
                                              • String ID: GetLocaleInfoEx
                                              • API String ID: 2299586839-2904428671
                                              • Opcode ID: 48c8ba2ab909c589d8f3a54eaaeee6d023891dddf4428f91815a6c587b1413cc
                                              • Instruction ID: 235aa7083ddbd1a072105702bb7a24af45cd94f9ae38f335f846727c3a0da593
                                              • Opcode Fuzzy Hash: 48c8ba2ab909c589d8f3a54eaaeee6d023891dddf4428f91815a6c587b1413cc
                                              • Instruction Fuzzy Hash: 7401A721B08A81C5E7C4AB57B8000A6E760FF89BD1F944139EE5D27B95CE3CE541C754
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 70cd9e7d658119a16aaf4246b5890b4d52ec64eaa5aaf6a012302e172bd4e19b
                                              • Instruction ID: f668d9e4e9e9f1ad18f909b1984fd4c368572841f23d271a3d71cfd9744c403b
                                              • Opcode Fuzzy Hash: 70cd9e7d658119a16aaf4246b5890b4d52ec64eaa5aaf6a012302e172bd4e19b
                                              • Instruction Fuzzy Hash: E8E1B322A08B91C1FB90AF26D84436DA761FB45B94F844239DE9D23BDADF7CE485C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ExceptionRaise_clrfp
                                              • String ID:
                                              • API String ID: 15204871-0
                                              • Opcode ID: d3f8887b7b8b3517747a6c22ca831dda960a01a1d0f15fe4b7d9d18be4f800f7
                                              • Instruction ID: 82b09c9c400f180e0cbbfb4ab1af6d091e6546b8a1f7e45edce4e6851fbe9e14
                                              • Opcode Fuzzy Hash: d3f8887b7b8b3517747a6c22ca831dda960a01a1d0f15fe4b7d9d18be4f800f7
                                              • Instruction Fuzzy Hash: 34B18B77600B88CBEB55CF2AC882368B7B0F745B89F488829DB5D8B7A4CB39D411C710
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: CriticalEnterSection
                                              • String ID: dumps$emoji
                                              • API String ID: 1904992153-2873254224
                                              • Opcode ID: 092ff418cf0c40e3f20b61d1c30a2f04bd5a03ef75a1f2bccf0fc08b948617e8
                                              • Instruction ID: 8b306f4803e956dba1abe39ba97155dafcbe0616082633e4d8b2e0602bd29247
                                              • Opcode Fuzzy Hash: 092ff418cf0c40e3f20b61d1c30a2f04bd5a03ef75a1f2bccf0fc08b948617e8
                                              • Instruction Fuzzy Hash: E4C17C32E15F85C9E740DF36E9811A8B3B1FB59788B405279EE8C26B59EF38E160C354
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 118556049-0
                                              • Opcode ID: ce6420c4d04a0fe96625aeb9a715c5e061a1ef034888a1cb16f3a0d50e60645b
                                              • Instruction ID: 195fb2c0c4a7f6c648b5fca463262c6bc05cdce256aa9906aad362e5804d5b28
                                              • Opcode Fuzzy Hash: ce6420c4d04a0fe96625aeb9a715c5e061a1ef034888a1cb16f3a0d50e60645b
                                              • Instruction Fuzzy Hash: 3AA16822A19B99C9FB41CB6AD4803AC7B70BB19748F94842ADF8D67B55DF3CD091C360
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 118556049-0
                                              • Opcode ID: 3385634120feb312b940f20433d6ccba510a8324adb36212ce1dd2450b4516d7
                                              • Instruction ID: 70cb07f88fb1b7812aafda9fdda625cfb0120fd37bbca9249b19b02fd66e90bd
                                              • Opcode Fuzzy Hash: 3385634120feb312b940f20433d6ccba510a8324adb36212ce1dd2450b4516d7
                                              • Instruction Fuzzy Hash: 4BA15822A19B99C9FB40DB6AD4803ACB770FB59748F94842ACB8D67755DF3CD091C360
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 118556049-0
                                              • Opcode ID: befd39ce9c16a882e63783290c6ed6883a33189ba1b74a57d8bcd32ab303fc76
                                              • Instruction ID: 7436171b67a120781e37b34a9fcaea61a449062c33d082af37ced5ee961ca409
                                              • Opcode Fuzzy Hash: befd39ce9c16a882e63783290c6ed6883a33189ba1b74a57d8bcd32ab303fc76
                                              • Instruction Fuzzy Hash: 44A18A22A08B95C9FB40DB6AD4803ACA770FB59748F94842ADF8D67755DF3CE091C360
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task
                                              • String ID:
                                              • API String ID: 118556049-0
                                              • Opcode ID: 6984bc12ee70109b5625062afeaa56f6819c6c30e71561ed82d7f8c24550cf89
                                              • Instruction ID: da8a395990678e8460f42b62f9660dd839384563591226eaac6f73b9943a17dc
                                              • Opcode Fuzzy Hash: 6984bc12ee70109b5625062afeaa56f6819c6c30e71561ed82d7f8c24550cf89
                                              • Instruction Fuzzy Hash: BFA18C22A18B95C9FB41CBAAD4803ACB771FB59748F94812ADF8D67755DF38E091C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _get_daylight_invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 474895018-0
                                              • Opcode ID: 0f622ff60f30d3780f80892d390401e18fc4cc141069fbff87909c5ebbf4c4d7
                                              • Instruction ID: 258355ff17c710b54af0a8bb6fbbc9b9f4bc022addaf958f56ceca082d5dd267
                                              • Opcode Fuzzy Hash: 0f622ff60f30d3780f80892d390401e18fc4cc141069fbff87909c5ebbf4c4d7
                                              • Instruction Fuzzy Hash: 4361A5A2F08192C5F6E0A92A8C40779E3A19F51770F95023DE92DA67C5FE7DEC40CA21
                                              APIs
                                                • Part of subcall function 00007FF763370A8C: GetLastError.KERNEL32 ref: 00007FF763370A9B
                                                • Part of subcall function 00007FF763370A8C: FlsGetValue.KERNEL32 ref: 00007FF763370AB0
                                                • Part of subcall function 00007FF763370A8C: SetLastError.KERNEL32 ref: 00007FF763370B3B
                                              • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF76337FC7F,?,00000000,00000092,?,?,00000000,?,00007FF763371675), ref: 00007FF76337F532
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ErrorLast$EnumLocalesSystemValue
                                              • String ID:
                                              • API String ID: 3029459697-0
                                              • Opcode ID: cc2bc9e5fcae19234eddfb96daa48b4922628108c99e4c85fcc2e58e09fc0afd
                                              • Instruction ID: fa3e7892875e08bc60d4699e8eeb25c44c3106f8a0e612d7c72f720f0da132f3
                                              • Opcode Fuzzy Hash: cc2bc9e5fcae19234eddfb96daa48b4922628108c99e4c85fcc2e58e09fc0afd
                                              • Instruction Fuzzy Hash: AF11D267A08645CAEB95AF26E4406B8BBF0FB81BE1F848139C66D533C0DA38D5D1C750
                                              APIs
                                                • Part of subcall function 00007FF763370A8C: GetLastError.KERNEL32 ref: 00007FF763370A9B
                                                • Part of subcall function 00007FF763370A8C: FlsGetValue.KERNEL32 ref: 00007FF763370AB0
                                                • Part of subcall function 00007FF763370A8C: SetLastError.KERNEL32 ref: 00007FF763370B3B
                                              • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF76337FC3B,?,00000000,00000092,?,?,00000000,?,00007FF763371675), ref: 00007FF76337F5E2
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ErrorLast$EnumLocalesSystemValue
                                              • String ID:
                                              • API String ID: 3029459697-0
                                              • Opcode ID: 2d81400be64530b408a616b22bdcfe61cbf2ce0941f0ce553624850de7d5f966
                                              • Instruction ID: 1a9c22a2f0728d4d399e2d19d54115a334b2e172773e1d217f1a6de776c3ddc4
                                              • Opcode Fuzzy Hash: 2d81400be64530b408a616b22bdcfe61cbf2ce0941f0ce553624850de7d5f966
                                              • Instruction Fuzzy Hash: 4B01F562E08282C6E7906F17E4407B9B6F1FB41BA6F84833AC22D573C4CF789884C714
                                              APIs
                                              • EnumSystemLocalesW.KERNEL32(?,?,00000000,00007FF76337496B,?,?,?,?,?,?,?,?,00000000,00007FF76337EAE0), ref: 00007FF763374567
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: EnumLocalesSystem
                                              • String ID:
                                              • API String ID: 2099609381-0
                                              • Opcode ID: 01640a15c2b896cce9415d7a2c1ad7323f2ceef46adc31f8481a253780bbeb1f
                                              • Instruction ID: 6eb2aa20b2bfcc406bf5d384c92c304886c1d64a93ce9955fdb62c40c3aef6f9
                                              • Opcode Fuzzy Hash: 01640a15c2b896cce9415d7a2c1ad7323f2ceef46adc31f8481a253780bbeb1f
                                              • Instruction Fuzzy Hash: 4EF08C76B08B41C2E740EB66F9501A9B371FB99B80F848139EA4DA3365CF3CD461C350
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: gfffffff
                                              • API String ID: 0-1523873471
                                              • Opcode ID: 47307880288f6578f87132817073c4c2bb16437997dd627ef4aa9327bb89f433
                                              • Instruction ID: e61eb801fcca94e68633a63b970522c0254182abefa0ab2e7fc630457fd9ab00
                                              • Opcode Fuzzy Hash: 47307880288f6578f87132817073c4c2bb16437997dd627ef4aa9327bb89f433
                                              • Instruction Fuzzy Hash: D0A18862B183C6C6EBA1DB26D0207A9BBA1EB527C4F448039DE4D67785DE3DE405C710
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID: 0-3916222277
                                              • Opcode ID: 3fac53d13e13ef411f149e61d5ad2ea6a8a0273fbc02724b4dee553905c8a803
                                              • Instruction ID: eacae8de9f60e8826bebf6764c908f8b3a95d9b6150968a2b64cda9934ff34aa
                                              • Opcode Fuzzy Hash: 3fac53d13e13ef411f149e61d5ad2ea6a8a0273fbc02724b4dee553905c8a803
                                              • Instruction Fuzzy Hash: 3BB18372908785C9E7A4AF2A805013CBBA0EF46B48F76013DCA4E77395CF79D451C765
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 3782ae6a6e8d34298428d3b5efb726587602eb5fff82e6c6db1d75094522a651
                                              • Instruction ID: fc06f4355eabbd893124fc4c15d3ad9369125d469c4b4769720248717277e5c2
                                              • Opcode Fuzzy Hash: 3782ae6a6e8d34298428d3b5efb726587602eb5fff82e6c6db1d75094522a651
                                              • Instruction Fuzzy Hash: 84A2F972919FC88AD7718F25E8412EAB7A4F799788F505325EACC26B19EF38D250C704
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 5652fc21f92205e3397b4ebf23249a0e7dc57028e4a0d7b597c479a727f4e2f8
                                              • Instruction ID: 604a9eeb9aa376803f2a8f7186d26a588a755b18b01849de459e370565d6cc8e
                                              • Opcode Fuzzy Hash: 5652fc21f92205e3397b4ebf23249a0e7dc57028e4a0d7b597c479a727f4e2f8
                                              • Instruction Fuzzy Hash: 75B26E36515FC88ED7B68F29AC813DA73A8F75978CF105229EB8C5AB1CEB7483549340
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d0e83b2c12586f32b34f0b2b20e852511e092ff61738f276ade5db4b6a1ceeeb
                                              • Instruction ID: 010f825ce2f2d4154f9d0ea9d7b8ecd5669049ca8bebb353d30cacd3bbb5b284
                                              • Opcode Fuzzy Hash: d0e83b2c12586f32b34f0b2b20e852511e092ff61738f276ade5db4b6a1ceeeb
                                              • Instruction Fuzzy Hash: B9727332A08BC5C9EB719F25D8403EDB7A4F749798F50522AEA9C17B99DF38D284C710
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: a0f25b8a4d92c5fa5d2cac86c3aff33542094981f9b9ad47e7ea64c26f801b3b
                                              • Instruction ID: 1aef90d87031a603213e339acb7cc9f4bbae110f2619804bbb418fe7ea2638b1
                                              • Opcode Fuzzy Hash: a0f25b8a4d92c5fa5d2cac86c3aff33542094981f9b9ad47e7ea64c26f801b3b
                                              • Instruction Fuzzy Hash: 6D727332A08BC5C9EB719F25D8403EDB7A4F749798F50522AEA9C17B99DF38D284C710
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: c4ab6b828ca45922997960b2700f7132280dcbffacc02f99c9a46b6be60a2307
                                              • Instruction ID: 7fba045635e90cc10bc38fbd756d61dc13d542dacb09d357fdcf0a695a8ee5d2
                                              • Opcode Fuzzy Hash: c4ab6b828ca45922997960b2700f7132280dcbffacc02f99c9a46b6be60a2307
                                              • Instruction Fuzzy Hash: 0E624921A29E56C9E6D3AF36B811575B364BF623C4F81933BE80F76750DF2CA452C224
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 63c9611f5ec2cf19800016a450332124f1d1da1461b84474040347cf4381edbc
                                              • Instruction ID: 5338e0cecaebde9468c7118101b8290b95062f5d56fbe4e14ed6f0fdd73c98f1
                                              • Opcode Fuzzy Hash: 63c9611f5ec2cf19800016a450332124f1d1da1461b84474040347cf4381edbc
                                              • Instruction Fuzzy Hash: DC02B212E08A81C2FB50AF269A002B9A391FB55B84F489238DE5D67787DF3CF5D9C350
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 8eda6f4ab24618311ef03193c99234cfc266977fc96978999a787211a08f7182
                                              • Instruction ID: 97d70635ff6131454263fae7cc02e340545a87aab5a4182326c2e237de6fe8c4
                                              • Opcode Fuzzy Hash: 8eda6f4ab24618311ef03193c99234cfc266977fc96978999a787211a08f7182
                                              • Instruction Fuzzy Hash: 9712DA32919FC889D7618F29E84129AB3B4F79D788F505325EACC67B19EF78C254CB04
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6afb11fbea0f3916862026fdb511c2e9d803eb103ce8752adc1e091b9953803e
                                              • Instruction ID: b28af956e36cc234f2faa5606247c442907d138c2d5d61e9bbad2ab364af57b0
                                              • Opcode Fuzzy Hash: 6afb11fbea0f3916862026fdb511c2e9d803eb103ce8752adc1e091b9953803e
                                              • Instruction Fuzzy Hash: E5D10C32908746CEEBA59B278A0427DA761EB06B48F92213DDE4D373D5DF39D44AC360
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ErrorLastNameTranslate$CodePageValidValue_invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 4023145424-0
                                              • Opcode ID: 2744c6d5af2e148c940694a86325be99c976764b5396e4f305d568d4486a8bfd
                                              • Instruction ID: 7b22d473a4470f6adc1a14d44084abaee64c9889622e4e7a7a11e6809b4b1238
                                              • Opcode Fuzzy Hash: 2744c6d5af2e148c940694a86325be99c976764b5396e4f305d568d4486a8bfd
                                              • Instruction Fuzzy Hash: 9DC1B576E08682C5EBA0AB6394207FAA6B0FB86789F804039DE8D67785DF3CD545C714
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d384bc7a73bb8619b0f00c52a6659bd27eca7cc72f7d44130b50e2775f9d9d63
                                              • Instruction ID: 8753454ec8875a6ea0328e7122a9c988455626457c57bd2bc24f6f37a7b2fa5a
                                              • Opcode Fuzzy Hash: d384bc7a73bb8619b0f00c52a6659bd27eca7cc72f7d44130b50e2775f9d9d63
                                              • Instruction Fuzzy Hash: DD02E532915FC48DE7628F79EC512E9B7B4F75D788F105229EB9C2AB19EB349250C340
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID:
                                              • API String ID: 3215553584-0
                                              • Opcode ID: 07cc6fefc29fc39819f6dfbc5ef23e0de4d22eab3ae9e4ba09169b375475775c
                                              • Instruction ID: 83f1fc22f38adf840d1140a4396a6e973cdfaadb1c44ba8ca95390336d48484a
                                              • Opcode Fuzzy Hash: 07cc6fefc29fc39819f6dfbc5ef23e0de4d22eab3ae9e4ba09169b375475775c
                                              • Instruction Fuzzy Hash: 3E81D472A04B51C6EBA0EF26C4813BDA360FB44B98F94463AEE5EA7794DF38D541C350
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 832f80e29b9e7b1fab9976971e49bf3aecb105820688ae36005b75dbd0afb97c
                                              • Instruction ID: 344aca032847c7f7cf1f22eff1391710fcf6f61a694e2b74318aaa4d280174f7
                                              • Opcode Fuzzy Hash: 832f80e29b9e7b1fab9976971e49bf3aecb105820688ae36005b75dbd0afb97c
                                              • Instruction Fuzzy Hash: 3681F472A08781C5E7B4DB1A94803BABAA1FB47795F90423DEA8D57B99CF3CD400CB14
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 5ec938e2278b14a04dbb626e947d484f460c30e86730ef98d8f8e7ce8a528cec
                                              • Instruction ID: 0e50ba1961e1fa6df25ca0d40d17a477582979c7da8455e0a3e676a4809fd4bf
                                              • Opcode Fuzzy Hash: 5ec938e2278b14a04dbb626e947d484f460c30e86730ef98d8f8e7ce8a528cec
                                              • Instruction Fuzzy Hash: 1E61F462F18A89C2EE629F5ED0455B8B321FB54BD4F858235DB5E27784EE3CE581C310
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 8597c923cbaa6151206fd998e97a6f96e981866a793e387065817f7198bd7c65
                                              • Instruction ID: 1c16c2f6cd241b7395b2432300d2261b0ab31cd61fbc807adc4d7fd47387d3bb
                                              • Opcode Fuzzy Hash: 8597c923cbaa6151206fd998e97a6f96e981866a793e387065817f7198bd7c65
                                              • Instruction Fuzzy Hash: 3061B02321E2C48BD30EDF7C589106D7F61D6A7908388469DEAC5EBB4BC518C51ACBA6
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: bef6abadc817b508d6bbbbf98975d24f3a94a3958f4abd85a63e9a006dc83d4b
                                              • Instruction ID: 9cb0a75769d14c1ba817103d0c8a9f25d39d684bd084df68345cb0b03e493b28
                                              • Opcode Fuzzy Hash: bef6abadc817b508d6bbbbf98975d24f3a94a3958f4abd85a63e9a006dc83d4b
                                              • Instruction Fuzzy Hash: AF51E4A3B0568443DB248B49FC42796F7A5FB987C5F00A12AEE8D57B68EB3CD581C700
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 65988544bd8c51d46c1f2ecd44d2c2020be5c6c9d2ff497e3ff94f9df2993759
                                              • Instruction ID: 108502fe400681e2729227d391dd38db8a59f1e1e4692a161e252c314e24764a
                                              • Opcode Fuzzy Hash: 65988544bd8c51d46c1f2ecd44d2c2020be5c6c9d2ff497e3ff94f9df2993759
                                              • Instruction Fuzzy Hash: 1B51A672A08551CAE7A96F2A815433CA760EF56B58FA60138CB4D37799CF29FC81C760
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 09a4a0272fcb28be4f4c2347f47eb615663c13edcd1074745415d1c72bb9a049
                                              • Instruction ID: 32ea0ec8a7e2f15dea4915700a3814a64920cb1fa73fa88ac4bb2b9952b6617d
                                              • Opcode Fuzzy Hash: 09a4a0272fcb28be4f4c2347f47eb615663c13edcd1074745415d1c72bb9a049
                                              • Instruction Fuzzy Hash: 0F519672A08551CAE7A95E2AC05423CA760EF56B58FB64139CE4D37799CF28EC41C750
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: No closed word$Unexpected eof$key declared, but no value$key opened, but never closed$object is not closed with '}'$quote was opened but not closed.$unexpected '}'$unexpected key without object$word wasnt properly ended
                                              • API String ID: 0-2490624340
                                              • Opcode ID: 6e442b9db12aa2e477e113b4631858d19b1954e2c4f6a276777f69f5c4e9f2e3
                                              • Instruction ID: f41fd830e40b70c4c15b31ff27155e2c7b85ca2cfa1fb09a822dd5d8cc596267
                                              • Opcode Fuzzy Hash: 6e442b9db12aa2e477e113b4631858d19b1954e2c4f6a276777f69f5c4e9f2e3
                                              • Instruction Fuzzy Hash: 3AF15431A086C6D5EBA0EF25E8943F9A364FF54348FC05539E64D2A7AADF78D285C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: .exe$.exe$176.124.204.206$abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+=-&^%$#@!(){}[},.;'$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set$open$runas$temp_directory_path
                                              • API String ID: 3668304517-2844431255
                                              • Opcode ID: 91b5ab2732b57d1d8dc5f3f95d571925291a1f8e7ab52d9d206aea0a8b1b84f0
                                              • Instruction ID: 0a43db1fb8e0e713e1c01b7ff596d34ece940e40babfd812d881d3958fea2365
                                              • Opcode Fuzzy Hash: 91b5ab2732b57d1d8dc5f3f95d571925291a1f8e7ab52d9d206aea0a8b1b84f0
                                              • Instruction Fuzzy Hash: E551B122F14A41C4FB40EB66D9402BCA770AF48794FA45639DA5CB3B9ADE78E081C320
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Value$ErrorLast$Heap$AllocFree
                                              • String ID:
                                              • API String ID: 570795689-0
                                              • Opcode ID: b170fd9b733dbfbd61b4f36eded9b017c2a9bba8f47560a3642fe2208258a6e2
                                              • Instruction ID: f46c7f3d795774b4849d4873816f631dba7d887d0638df0a7a486f55fb135dd1
                                              • Opcode Fuzzy Hash: b170fd9b733dbfbd61b4f36eded9b017c2a9bba8f47560a3642fe2208258a6e2
                                              • Instruction Fuzzy Hash: 70415E10A0C202C1F9E8B7735955179E2614F8677AF94473CE83D367D2DE2EF841C628
                                              APIs
                                                • Part of subcall function 00007FF76338B798: AreFileApisANSI.KERNEL32(?,?,?,?,00007FF76331DE88,?,?,?,?,?,00000000,FFFFFFFF,?,?,00007FF763301F0A), ref: 00007FF76338B7AA
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF7632FF8F0
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF7632FF8F6
                                              • __std_exception_destroy.LIBVCRUNTIME ref: 00007FF7632FF987
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$ApisFile__std_exception_destroy
                                              • String ID: ", "$: "
                                              • API String ID: 397665139-747220369
                                              • Opcode ID: 73161b4caaefcfca97d3b04a702d7d6b1a43d9a3d8ca13878a9d8e66b467e628
                                              • Instruction ID: c2ec1200a01fd5dea37c27b047748b9cfa7a47ba1166272b49c03f3ef616b5bf
                                              • Opcode Fuzzy Hash: 73161b4caaefcfca97d3b04a702d7d6b1a43d9a3d8ca13878a9d8e66b467e628
                                              • Instruction Fuzzy Hash: FEA1E272B08B41D9EB40EF6AE0543ADB3A1EB44B88F944539DE4C27B9ADF38D491C350
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task$std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                              • String ID: bad locale name$false$true
                                              • API String ID: 164343898-1062449267
                                              • Opcode ID: b682e21b76faa0e9b2ceb8f90ded097b089d78ac5436e76cdf2da4560fe96314
                                              • Instruction ID: 0110ff9a9f4d6ff3822a69af4075b6e00ae87b44530f9cfca356ccf9e6ae352a
                                              • Opcode Fuzzy Hash: b682e21b76faa0e9b2ceb8f90ded097b089d78ac5436e76cdf2da4560fe96314
                                              • Instruction Fuzzy Hash: 31717C22A09B41DAF751EF62E8402ACB7B5EF85744F840139EA4D33B66DF38E419C364
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                              • String ID: No such argument:
                                              • API String ID: 3936042273-4085609673
                                              • Opcode ID: 81ada8103e0608db26079092ba504511297ded9be713ae7fafad3c01f6729b77
                                              • Instruction ID: ba1b2b5ac1d8280da3561a88c69a27478263cef04d1ffb96ecdfd7998f65fcda
                                              • Opcode Fuzzy Hash: 81ada8103e0608db26079092ba504511297ded9be713ae7fafad3c01f6729b77
                                              • Instruction Fuzzy Hash: 6C12D622F18785C5FB50AB66D4043BDA762EB087E8F844639DE6C27BDADE38D185C350
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: $...$VAR
                                              • API String ID: 3668304517-4000803252
                                              • Opcode ID: 22e919e0398963de0248bc354a9110d66931714f6c9a72f807b2d81d13a41b15
                                              • Instruction ID: 1e4f5b5b48d87483370b6d83d14c0e96c81c3554c2be9012763e2f099a6af6a4
                                              • Opcode Fuzzy Hash: 22e919e0398963de0248bc354a9110d66931714f6c9a72f807b2d81d13a41b15
                                              • Instruction Fuzzy Hash: 5DD1A462A18B81C5FB50DB6AD8803EDB761FB447A8F904239DA5D27B9ADF3CD184C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                              • String ID: os_crypt$out_of_range
                                              • API String ID: 1944019136-3828104817
                                              • Opcode ID: dfcd86d5255ace1054003753d28c1c71d1ad339682b270d75bcae9ef11badd04
                                              • Instruction ID: b1556db5170c2606112a98ade14b166a77f346757aa70e62e440f0e0d900fcee
                                              • Opcode Fuzzy Hash: dfcd86d5255ace1054003753d28c1c71d1ad339682b270d75bcae9ef11badd04
                                              • Instruction Fuzzy Hash: DF71C272F19B85C9FB40DF7AD4403ACA361EB55398F809235EA6D36BD9EE389184C310
                                              APIs
                                              • FreeLibrary.KERNEL32(?,00000000,00007FF763374C42,?,?,00000030,00007FF76337B900,?,?,?,?,?,?,?), ref: 00007FF763374713
                                              • GetProcAddress.KERNEL32(?,00000000,00007FF763374C42,?,?,00000030,00007FF76337B900,?,?,?,?,?,?,?), ref: 00007FF76337471F
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: AddressFreeLibraryProc
                                              • String ID: api-ms-$ext-ms-
                                              • API String ID: 3013587201-537541572
                                              • Opcode ID: fe487ba48e8b98e8da8f078ca9b00621851933d19320e8d2a4f77f7db0a80c87
                                              • Instruction ID: a191d956a7f2128842efd7e19cdea8d9e695c34b04bbfe4c5fe33821af734065
                                              • Opcode Fuzzy Hash: fe487ba48e8b98e8da8f078ca9b00621851933d19320e8d2a4f77f7db0a80c87
                                              • Instruction Fuzzy Hash: 9D412662B19B42C1FAA1EB07A8001B5A3A5BF46BD1F88413DDD1D6B794EE3CF045C364
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Internet$CloseFileHandleOpenRead
                                              • String ID: File Downloader
                                              • API String ID: 4038090926-3631955488
                                              • Opcode ID: 5f5cd5d1c3033a71f9d02e819e7c0d70b6054f3e9fde37668af81b5883abe968
                                              • Instruction ID: 93f843ce24e1575c5358e6b3f4747e25efeae3b0f298f2fa6161dd193ae16531
                                              • Opcode Fuzzy Hash: 5f5cd5d1c3033a71f9d02e819e7c0d70b6054f3e9fde37668af81b5883abe968
                                              • Instruction Fuzzy Hash: 78319032A18B81C2E7609F16E8507AAB760FB88BC4F844039EE8D53B49DF7CE554CB10
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                              • String ID: invalid_iterator
                                              • API String ID: 1944019136-2508626007
                                              • Opcode ID: fcd8f1feac9935c04b98c58f3e9524c4f9a3caa8148790d92cbd3a21410ff3b8
                                              • Instruction ID: 684c6c75ae15dc3bf8690186e6df482946a57dec91ea979decc21d1b2766ba0c
                                              • Opcode Fuzzy Hash: fcd8f1feac9935c04b98c58f3e9524c4f9a3caa8148790d92cbd3a21410ff3b8
                                              • Instruction Fuzzy Hash: 9B71B463F19B85C9FB00AB7AD4503ACA361EB59798F809235DA5C36BD5EE3CA185C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                              • String ID: out_of_range
                                              • API String ID: 1944019136-3053435996
                                              • Opcode ID: 6bec659f902b6012995f022ffc9c67b9058c71b4fbab2b8ec1208bb593e3d8bf
                                              • Instruction ID: 54663700832ec81b58d475740877750d6e8cb7ec8983510479c19d1dcdb0a265
                                              • Opcode Fuzzy Hash: 6bec659f902b6012995f022ffc9c67b9058c71b4fbab2b8ec1208bb593e3d8bf
                                              • Instruction Fuzzy Hash: 9C71B362F19B85C9FB00DF7AD4503ADA361EB55398F809335EA9C26BD9EE3C9185C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy
                                              • String ID: type_error
                                              • API String ID: 1944019136-1406221190
                                              • Opcode ID: ace33a89193a6d81226a23815234692fbdf049d2eceae4adab298d777822cdcb
                                              • Instruction ID: 972935822f767b25ef0eee01245e11ea05858af8bc9674109dc14525806037cd
                                              • Opcode Fuzzy Hash: ace33a89193a6d81226a23815234692fbdf049d2eceae4adab298d777822cdcb
                                              • Instruction Fuzzy Hash: E071C472F19B85C9FB019BBAD4543AC7321AB55398F809335DE5C36BD9EE38A185C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: __std_exception_destroy_invalid_parameter_noinfo_noreturn
                                              • String ID: at line $, column
                                              • API String ID: 729085983-191570568
                                              • Opcode ID: a088cdb21d385d6c215dffb2299ae5a961850f82b6d2bd90c36d50670c4f4dad
                                              • Instruction ID: 4aca04bc094bf92ecfde8beb19666a1d4e8a71420c548f317b7b428fca0ff12b
                                              • Opcode Fuzzy Hash: a088cdb21d385d6c215dffb2299ae5a961850f82b6d2bd90c36d50670c4f4dad
                                              • Instruction Fuzzy Hash: 1E51B372A08781C2EA54AB1AE58436EB721FB85BD0F904639EB9D17BD6DF3CD081C750
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                                              • String ID: CONOUT$
                                              • API String ID: 3230265001-3130406586
                                              • Opcode ID: 48b56def838186f0977933ffc9ee02d4886a42ddb0d3b73b1937c479b359ff6f
                                              • Instruction ID: c4581de836af36cb75a273a51c6aab0d768e939e2092b6588e70240fe513c1be
                                              • Opcode Fuzzy Hash: 48b56def838186f0977933ffc9ee02d4886a42ddb0d3b73b1937c479b359ff6f
                                              • Instruction Fuzzy Hash: 69118421A18A41C6E7909B57E854325A6A0FB58FE4F404238E96D97B94CF7CD814C754
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$CriticalEnterSection
                                              • String ID:
                                              • API String ID: 555700303-0
                                              • Opcode ID: 8e4279a93eda603b7049288216fcf0f6ac8e472970434ea1cd186c916dc80b8e
                                              • Instruction ID: 6300ee05c7d3fa527897de2da8254457f755fe58bdd62b88249e0cc2243872cc
                                              • Opcode Fuzzy Hash: 8e4279a93eda603b7049288216fcf0f6ac8e472970434ea1cd186c916dc80b8e
                                              • Instruction Fuzzy Hash: 1ED1F562F18682C5FB50AB66D4503BDA361EB45798F805639EE5D2BBD9DF3CE081C320
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ByteCharMultiWide$CompareInfoString
                                              • String ID:
                                              • API String ID: 2984826149-0
                                              • Opcode ID: f347c8f43b91741fdc9810cacbf809b241c8952251077899aabcdba9b25bb8ea
                                              • Instruction ID: 9f36744f53759c9efd8a84e350ee686357333f323c95fc3f68ea3b9df06650d8
                                              • Opcode Fuzzy Hash: f347c8f43b91741fdc9810cacbf809b241c8952251077899aabcdba9b25bb8ea
                                              • Instruction Fuzzy Hash: 80A1D622A0C682C6FBB1AF2A94503B9A691EF457E4FD4063AD96D277C5DF7CE405C320
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ByteCharMultiStringWide
                                              • String ID:
                                              • API String ID: 2829165498-0
                                              • Opcode ID: e4fa22a710c47188b55bda09a09fdc9265209128699d57c18ff63feec2b297ff
                                              • Instruction ID: ce07933ee48f69651476d04ceae38efaa8de861a43c9aee87565fb6d2f271e1b
                                              • Opcode Fuzzy Hash: e4fa22a710c47188b55bda09a09fdc9265209128699d57c18ff63feec2b297ff
                                              • Instruction Fuzzy Hash: 60818432A08781C6EBA09F16D440779A6A1FF447A8F94063AFA5D6BBD8DF3CD445C710
                                              APIs
                                              • GetLastError.KERNEL32(?,?,8000000000000000,00007FF76336CB85,?,?,?,?,00007FF7633767F4,?,?,?,00007FF763386B53), ref: 00007FF763370C13
                                              • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF76336CB85,?,?,?,?,00007FF7633767F4,?,?,?,00007FF763386B53), ref: 00007FF763370C49
                                              • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF76336CB85,?,?,?,?,00007FF7633767F4,?,?,?,00007FF763386B53), ref: 00007FF763370C76
                                              • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF76336CB85,?,?,?,?,00007FF7633767F4,?,?,?,00007FF763386B53), ref: 00007FF763370C87
                                              • FlsSetValue.KERNEL32(?,?,8000000000000000,00007FF76336CB85,?,?,?,?,00007FF7633767F4,?,?,?,00007FF763386B53), ref: 00007FF763370C98
                                              • SetLastError.KERNEL32(?,?,8000000000000000,00007FF76336CB85,?,?,?,?,00007FF7633767F4,?,?,?,00007FF763386B53), ref: 00007FF763370CB3
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Value$ErrorLast
                                              • String ID:
                                              • API String ID: 2506987500-0
                                              • Opcode ID: 9b02ecda8c9321b70e6f8dbaea4320c136822b080a8063a1e62e2224ce17cf87
                                              • Instruction ID: 1426216392efcea15171208e5ea9eed795687bda1fdd2278c64c7457bccec0b8
                                              • Opcode Fuzzy Hash: 9b02ecda8c9321b70e6f8dbaea4320c136822b080a8063a1e62e2224ce17cf87
                                              • Instruction Fuzzy Hash: 5C114F20A0C653C1F9D4B7339A51179E2625F867B1F94473CE83E2A7D6DE2DF441C628
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: CriticalSection$EnterLeave$DeleteGdiplusObjectShutdown
                                              • String ID:
                                              • API String ID: 4268643673-0
                                              • Opcode ID: 0a87981d0a80b61d410f48e8fae8d3740545c0e7c6c855c0ede7b6a07225b7b0
                                              • Instruction ID: 75b987030d1caf33591bf0aa4191c701c8cc5a83777d51d0d31077d270d510f3
                                              • Opcode Fuzzy Hash: 0a87981d0a80b61d410f48e8fae8d3740545c0e7c6c855c0ede7b6a07225b7b0
                                              • Instruction Fuzzy Hash: D7113D32915B81C5EB90AF26E844068B774FB44FA4794423AD66D16BA4CF3CD897C350
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: std::_$GetcollLocinfo::_Locinfo_ctorLockitLockit::__invalid_parameter_noinfo_noreturn
                                              • String ID: bad locale name
                                              • API String ID: 818938248-1405518554
                                              • Opcode ID: 5b0cc82087ff888185ed91558a79811088a631f56eb9a38591b3ac36c5d332c3
                                              • Instruction ID: 202c2619e22919591abf635f619cbe6aa770214aa0f633f11dd890587d71a699
                                              • Opcode Fuzzy Hash: 5b0cc82087ff888185ed91558a79811088a631f56eb9a38591b3ac36c5d332c3
                                              • Instruction Fuzzy Hash: C771AB22B05B41CAFB41EFB6D8503ACB362AF45748F844139DE4D3BB99DE389051C398
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$__std_fs_convert_wide_to_narrow
                                              • String ID: Default$Profile
                                              • API String ID: 1223724100-3314577806
                                              • Opcode ID: 18dcfc186105d23553a757cefb7f49d57c4382a713a082528fb4d2c9da5b29fd
                                              • Instruction ID: cd860e185ebc1d913fb874de29c22b36f10d6230b836b023c6cbefd16799a4b7
                                              • Opcode Fuzzy Hash: 18dcfc186105d23553a757cefb7f49d57c4382a713a082528fb4d2c9da5b29fd
                                              • Instruction Fuzzy Hash: A451D972E58782C0EE90AB5AE05437AA761EF853D0FD05239D69D667E6DF7CE080C720
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturnstd::_$Concurrency::cancel_current_taskLocinfo::_Locinfo_ctorLockitLockit::_
                                              • String ID:
                                              • API String ID: 2759874623-0
                                              • Opcode ID: 37b89fb55ac7f4aff6fb1a2045dc17a5810c7324f954e6e6aba4783d232a85c5
                                              • Instruction ID: 66bd77396eef36b39c7573e71420367bcc268011927adee1f75d0d6855779e98
                                              • Opcode Fuzzy Hash: 37b89fb55ac7f4aff6fb1a2045dc17a5810c7324f954e6e6aba4783d232a85c5
                                              • Instruction Fuzzy Hash: 00919F32A05B41C9EB90EF62E4507BDB3A4EF44B98F884538EA9D23B95DE38D451C364
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _set_statfp
                                              • String ID:
                                              • API String ID: 1156100317-0
                                              • Opcode ID: 2dc6c4848308a8d27669eaf884ecdce81165a9b514e10212270fde563d0270b3
                                              • Instruction ID: bacb33f09a9e47cc50afa8ade45c74c45520f6f088b30bea16b6ed9b0d12c695
                                              • Opcode Fuzzy Hash: 2dc6c4848308a8d27669eaf884ecdce81165a9b514e10212270fde563d0270b3
                                              • Instruction Fuzzy Hash: E981EA12908A46C5F7B1AE3AA44137AE6B0FF46795F844239E95D3E790DF3CE481C624
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: EnvironmentInitStringStringsUnicode$Free_invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 1868271193-0
                                              • Opcode ID: 89e40d07247d39b222b600047b7a03d7dfbce0c35fc4c74367115637af50fa2a
                                              • Instruction ID: 98f888f2e847e7e0f74401d46304663aaf7c6ea7ff50dca7602dc08416c52c7c
                                              • Opcode Fuzzy Hash: 89e40d07247d39b222b600047b7a03d7dfbce0c35fc4c74367115637af50fa2a
                                              • Instruction Fuzzy Hash: 8F51C432A08B85C2EB50AF16E44036DB760FB95B94F94922ADB9C17B95DF7CE1E1C310
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Window$DesktopRect
                                              • String ID:
                                              • API String ID: 1991322523-0
                                              • Opcode ID: abca54bb5888cfaf8a049de51b5164587558f78cf8c2c4ee4b12a9726f285fb6
                                              • Instruction ID: e0c2cda22f67ef8e69fc161419bb847950808c32fde3e4b1c4d281d3abb653a3
                                              • Opcode Fuzzy Hash: abca54bb5888cfaf8a049de51b5164587558f78cf8c2c4ee4b12a9726f285fb6
                                              • Instruction Fuzzy Hash: E4410A62B197C5C1EA50AB1AE44436EF750EB857E4F904339EAEC66BE9DE3CD080C710
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _set_statfp
                                              • String ID:
                                              • API String ID: 1156100317-0
                                              • Opcode ID: 025d23688907853b564ca8c27b0d165eda471880a57ba5485be5edd5abf68226
                                              • Instruction ID: 1a184f77a32f25a92f3afee7d8feae20227b8ee1742fa798137be9422a85a6df
                                              • Opcode Fuzzy Hash: 025d23688907853b564ca8c27b0d165eda471880a57ba5485be5edd5abf68226
                                              • Instruction Fuzzy Hash: 9A11276AE0DA8381FBE9312ED912379D050AF51370FD40A3CE92E2A3D68EBC6840C130
                                              APIs
                                              • FlsGetValue.KERNEL32(?,?,?,00007FF763368377,?,?,00000000,00007FF763368612,?,?,?,?,8000000000000000,00007FF76336859E), ref: 00007FF763370CEB
                                              • FlsSetValue.KERNEL32(?,?,?,00007FF763368377,?,?,00000000,00007FF763368612,?,?,?,?,8000000000000000,00007FF76336859E), ref: 00007FF763370D0A
                                              • FlsSetValue.KERNEL32(?,?,?,00007FF763368377,?,?,00000000,00007FF763368612,?,?,?,?,8000000000000000,00007FF76336859E), ref: 00007FF763370D32
                                              • FlsSetValue.KERNEL32(?,?,?,00007FF763368377,?,?,00000000,00007FF763368612,?,?,?,?,8000000000000000,00007FF76336859E), ref: 00007FF763370D43
                                              • FlsSetValue.KERNEL32(?,?,?,00007FF763368377,?,?,00000000,00007FF763368612,?,?,?,?,8000000000000000,00007FF76336859E), ref: 00007FF763370D54
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Value
                                              • String ID:
                                              • API String ID: 3702945584-0
                                              • Opcode ID: fd0f37bcc45467137d82f0e0dcc3ee8bbc0f864e39e2bb63432d6b55f891ddc3
                                              • Instruction ID: ff01f97461e80b4e21159836b53f03acee3fd6c21fcadac797de70bb61405183
                                              • Opcode Fuzzy Hash: fd0f37bcc45467137d82f0e0dcc3ee8bbc0f864e39e2bb63432d6b55f891ddc3
                                              • Instruction Fuzzy Hash: D2116A20A0C342C1FAE8B7236A51279E2615F867B1F84573CE83D267D6DE2DF801C728
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
                                              • String ID: 0:
                                              • API String ID: 3936042273-4252728285
                                              • Opcode ID: 9559178d12138e3d5957b55b8f0d68c73b3a9370bd433dfad6ae6941c881546b
                                              • Instruction ID: d853627ebb370fecff5459d72fe48f56a26d2a89a057c2dc5b96a68a73ac9fa7
                                              • Opcode Fuzzy Hash: 9559178d12138e3d5957b55b8f0d68c73b3a9370bd433dfad6ae6941c881546b
                                              • Instruction Fuzzy Hash: 81C19C33A14B858AE751DF65E4402ADB3B4FB49798F445629DF8D23B59EF38E0A4C310
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                                              • API String ID: 0-1866435925
                                              • Opcode ID: 801592ebc0b75ed27a2787abaf85358e96dd858f17e9b0b99e8ab0efd60c1114
                                              • Instruction ID: 645fbea9f08eaa399a8670c4100458a332a2bb088352164afc17ee30f868e1ee
                                              • Opcode Fuzzy Hash: 801592ebc0b75ed27a2787abaf85358e96dd858f17e9b0b99e8ab0efd60c1114
                                              • Instruction Fuzzy Hash: 6C91CD72608B85C2EB94DB06E444B6DB365FB48BC4FA4803AEA9E53B95DF3CD481C350
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo
                                              • String ID: UTF-16LEUNICODE$UTF-8$ccs
                                              • API String ID: 3215553584-1196891531
                                              • Opcode ID: ef430759b7b447c0057831311c08b99cca63ded7db4fb998a2454816ebe11f35
                                              • Instruction ID: a7407019676c9a49c223b81533df0f36fca7580eb7859f96a04fd296becc77da
                                              • Opcode Fuzzy Hash: ef430759b7b447c0057831311c08b99cca63ded7db4fb998a2454816ebe11f35
                                              • Instruction Fuzzy Hash: A181B132D19A0BC5F7E46E2B8350278A6A0AB15748FD59039CA0DF73D5EB2DED81D221
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: Optional arguments:$Positional arguments:$Subcommands:
                                              • API String ID: 3668304517-2031040180
                                              • Opcode ID: 72086f7e9649a31c5b59655ff8af8d49c12a651bd44c2d07f3ae0c9f5cd50249
                                              • Instruction ID: 379d9c3e626d32a0ba18fd01611f4738a23f2902df8f7bfe6da54ecffc3a1fcb
                                              • Opcode Fuzzy Hash: 72086f7e9649a31c5b59655ff8af8d49c12a651bd44c2d07f3ae0c9f5cd50249
                                              • Instruction Fuzzy Hash: 33A17162A08A41C1FB95AB17D8803ADB7A1EB45FC4FC4843ADA0E27796DF7CD589C350
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: [json.exception.
                                              • API String ID: 0-791563284
                                              • Opcode ID: a51db3372fd15447ad9884ff31321145c1f95cf3c9ec73f87d3cde700041bf2b
                                              • Instruction ID: d14480d0f5d95a143407935d5019d8d0236809e2e4b4b6640071b60b7cc7d69d
                                              • Opcode Fuzzy Hash: a51db3372fd15447ad9884ff31321145c1f95cf3c9ec73f87d3cde700041bf2b
                                              • Instruction Fuzzy Hash: 3971EF62F14B8185F700EF7AD8402ADB761EB95B94F904239DE9D2BB9ADF78D081C350
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: CurrentDirectory__std_exception_copy__std_fs_get_current_path_invalid_parameter_noinfo_noreturn
                                              • String ID: --type$current_path()
                                              • API String ID: 2526998938-584980331
                                              • Opcode ID: 2e5e51b2a3e4999380e4a6033a9d9baaa221e04dab71b21e32a4ffa39bc7f9e3
                                              • Instruction ID: ece8b26f9fab35cc840e4655505931cbaba033c3c4f5c6c71f7a6db3efce377a
                                              • Opcode Fuzzy Hash: 2e5e51b2a3e4999380e4a6033a9d9baaa221e04dab71b21e32a4ffa39bc7f9e3
                                              • Instruction Fuzzy Hash: 0A519F62F10751C9EB50DBB5D8406AC7BB1FB48798F90422AEE5D67B98DF389481C320
                                              APIs
                                                • Part of subcall function 00007FF76331DD8E: __std_fs_convert_narrow_to_wide.LIBCPMT ref: 00007FF76331DEDD
                                                • Part of subcall function 00007FF76331DD8E: __std_fs_convert_narrow_to_wide.LIBCPMT ref: 00007FF76331DF15
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76332B741
                                              • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF76332B747
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: __std_fs_convert_narrow_to_wide_invalid_parameter_noinfo_noreturn
                                              • String ID: User Data$exists
                                              • API String ID: 522447391-1382609090
                                              • Opcode ID: 962ce83529798b44ec9cb2f329974acb72f6b2e5cf64a685e3c48d71ff55658b
                                              • Instruction ID: 8fd0789193d0982484e3dd6ac4d2c24e97a25f8548ca5da49fed73394f5f637b
                                              • Opcode Fuzzy Hash: 962ce83529798b44ec9cb2f329974acb72f6b2e5cf64a685e3c48d71ff55658b
                                              • Instruction Fuzzy Hash: 36518072B14B42C9EF40EF6AD4452AC7332EB45798F805639EA5C3BB99EE38D145C360
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: std::_$GetctypeLocinfo::_Locinfo_ctorLockitLockit::_
                                              • String ID: bad locale name
                                              • API String ID: 1612978173-1405518554
                                              • Opcode ID: 795a358b199044d064d161f202aa8d36907fafd946ce211341e9f69cef004bf1
                                              • Instruction ID: 188e564e6c2f34ad659323d34af7446cee20cf16108f7f46ba5f8dd8d955e3db
                                              • Opcode Fuzzy Hash: 795a358b199044d064d161f202aa8d36907fafd946ce211341e9f69cef004bf1
                                              • Instruction Fuzzy Hash: 6A518A22B09B41CAEB81EF61D8902BCB3A5AF40748F884539DA4E37B95DF38D521C364
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ExitProcess$InitializeMutexOpen
                                              • String ID: --key$--type$APPB:
                                              • API String ID: 3710457153-2541764812
                                              • Opcode ID: da639d6e5cdad483fb40bed12fd4e3d8ae707f3430990bcd0b73f7d76dea2ddd
                                              • Instruction ID: 8e4033a337c4ee61c9abf8bc63729e22b215adc63150af352a88181c8a15803e
                                              • Opcode Fuzzy Hash: da639d6e5cdad483fb40bed12fd4e3d8ae707f3430990bcd0b73f7d76dea2ddd
                                              • Instruction Fuzzy Hash: AD213231A0DAC7D0EAA1BB62D8553FAE360EF91380FC05039D58D667AAEE2CD549C750
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: AddressHandleModuleProc
                                              • String ID: GetTempPath2W$kernel32.dll
                                              • API String ID: 1646373207-1846531799
                                              • Opcode ID: c3f39c1016d9644655c5748e6247c669a6b28aee860c03fb307b0288e1ef9cb8
                                              • Instruction ID: ac72d0943856cc6056ba55cb52c0a1cf37399a22f7820f55c1ea9fd3c02c9ce6
                                              • Opcode Fuzzy Hash: c3f39c1016d9644655c5748e6247c669a6b28aee860c03fb307b0288e1ef9cb8
                                              • Instruction Fuzzy Hash: FCE01271E18A82D2EB456B06F945075B761FF487C0B98803DD91E5B734DE3CD495C720
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn$FreeString
                                              • String ID:
                                              • API String ID: 1965679434-0
                                              • Opcode ID: 12f2343ec10ebc4beab690ef4b10ae46424fb8a7ec555726e2b20f3022e7268b
                                              • Instruction ID: 26bbadf6f80aea709c764e959d46702e56f6bfcb23f463b42cfa644b3c2c9a43
                                              • Opcode Fuzzy Hash: 12f2343ec10ebc4beab690ef4b10ae46424fb8a7ec555726e2b20f3022e7268b
                                              • Instruction Fuzzy Hash: 6CF1A162B18B81C6FB40EB66D4503EDA762EB457A8F80453ADE5E27BDADF38D044C350
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: FileWrite$ConsoleErrorLastOutput
                                              • String ID:
                                              • API String ID: 2718003287-0
                                              • Opcode ID: fb9ce0a8caca549bef5a8e8e1920a8c6df41992dac4b542e2e2b5d99276d3802
                                              • Instruction ID: 7078a4f7d037be327cdda6bc7af6ec4c99c1d5b1bf4b37df91fad6d5c4991033
                                              • Opcode Fuzzy Hash: fb9ce0a8caca549bef5a8e8e1920a8c6df41992dac4b542e2e2b5d99276d3802
                                              • Instruction Fuzzy Hash: 60D13732B08A81C9E751DF7AD8401ACB7B1FB067E9B944239CE4DA7B99CE38D406C354
                                              APIs
                                              • GetConsoleMode.KERNEL32(?,?,?,?,00000000,?,?,00000000,00000000,?,00000000,00000000,00007FF763373A94), ref: 00007FF763373C17
                                              • GetLastError.KERNEL32(?,?,?,?,00000000,?,?,00000000,00000000,?,00000000,00000000,00007FF763373A94), ref: 00007FF763373CA1
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ConsoleErrorLastMode
                                              • String ID:
                                              • API String ID: 953036326-0
                                              • Opcode ID: 71047c117e1be3189cb89e5b74bfb6f25562d693c831f8dfb3e4c4496a6ca128
                                              • Instruction ID: 8713bf973e6f4e374e798b2c20355fa73f9b28b8b553df57881efd12c29b393c
                                              • Opcode Fuzzy Hash: 71047c117e1be3189cb89e5b74bfb6f25562d693c831f8dfb3e4c4496a6ca128
                                              • Instruction Fuzzy Hash: F391D572F18652C5FB90AB6698806BCA7B0FB06BA9F844139DE0E77784CF38D441C764
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo$_get_daylight
                                              • String ID:
                                              • API String ID: 72036449-0
                                              • Opcode ID: cf49e0592d0c650ec1e2f0b893b1cf8e88f8ffad24bae71d226c790b617eba14
                                              • Instruction ID: e7a50bc2ad653bca4b6a85319ad6c8535486196db6c9b85b5b16ac91b0149de8
                                              • Opcode Fuzzy Hash: cf49e0592d0c650ec1e2f0b893b1cf8e88f8ffad24bae71d226c790b617eba14
                                              • Instruction Fuzzy Hash: 8A51BEB2E0C606C6F7E8392A9805379E790AB41724F99403DDA5D773D6EA7CEC40C762
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID:
                                              • API String ID: 3668304517-0
                                              • Opcode ID: 80187849b2c3fc5827b9f9af02b94922c6536b1bb9af376066dece0b9a70b459
                                              • Instruction ID: ecbbc085fd5087e5b718ed681d63d92976e378a3d28be48098e40c46fecdd5e9
                                              • Opcode Fuzzy Hash: 80187849b2c3fc5827b9f9af02b94922c6536b1bb9af376066dece0b9a70b459
                                              • Instruction Fuzzy Hash: CD51AE72715B8581FA449F2AE05426DB3A5FB44F94F90863ADB9C27B99DF3CD4A0C340
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_Locinfo::_Locinfo_ctorRegister
                                              • String ID:
                                              • API String ID: 4181401918-0
                                              • Opcode ID: 0ef2616fcc5399cb645ad342650983371f86b31a6cf8c916be02572b1d7a6817
                                              • Instruction ID: ed1093fa1c9ff3955068c9dc867d24c0ae7aa075db1bd6f4c09bf60a52a8a83e
                                              • Opcode Fuzzy Hash: 0ef2616fcc5399cb645ad342650983371f86b31a6cf8c916be02572b1d7a6817
                                              • Instruction Fuzzy Hash: 8541A621A18B45C0FB95EB17E440679E360FB44B94F880639EA8D677A9DF3CE581C720
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_Register
                                              • String ID:
                                              • API String ID: 1168246061-0
                                              • Opcode ID: d73785c31b51268aaaa81e722761cd05a3bd9e846c840b8156701ed2f3cb5d06
                                              • Instruction ID: 4c7eb8c5ce0a50c4bc7d3286eb510db429b704c9add48885f294af509fc0f35a
                                              • Opcode Fuzzy Hash: d73785c31b51268aaaa81e722761cd05a3bd9e846c840b8156701ed2f3cb5d06
                                              • Instruction Fuzzy Hash: 14419C22B08B41C1EA95FB17E850379F760FB44BA4F980639DA8D177A5DE3CD441C760
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ByteCharErrorLastMultiWide
                                              • String ID:
                                              • API String ID: 203985260-0
                                              • Opcode ID: 9a4dc4f044481010f46556346e16a03dcc3346a8b305f7bba19c8a1af1585fcb
                                              • Instruction ID: ec9ba770cc2d60a4f59675cd944e151f7f9b578dda1fd26e1b18993192ea1f90
                                              • Opcode Fuzzy Hash: 9a4dc4f044481010f46556346e16a03dcc3346a8b305f7bba19c8a1af1585fcb
                                              • Instruction Fuzzy Hash: 4B212C72A18B86C6E7509F12E44432EBAB4FB98B94F640139DB8D67B54DF3CD411CB10
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ErrorFileHandleInformationLast
                                              • String ID:
                                              • API String ID: 275135790-0
                                              • Opcode ID: 4d562f91c227975d487e9ca190528b3c563a83711315297d7f69586703ffb772
                                              • Instruction ID: ee45d217652692c77580d725fbad6c3916e95953b9154bf55801c58775de273c
                                              • Opcode Fuzzy Hash: 4d562f91c227975d487e9ca190528b3c563a83711315297d7f69586703ffb772
                                              • Instruction Fuzzy Hash: 99F0D631A08283C2F7D47B66D4586B5AA90EF44740F940038F55E6EB94DE3DE584C330
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                              • String ID: conditional not closed
                                              • API String ID: 73155330-2481790218
                                              • Opcode ID: 7e3dec843d3c2bdfcd9b88ea5898acdebe44c933704b2a18e631af7654d1b92d
                                              • Instruction ID: 4e96b38a8807801a67e6d1db33d684e73f85e839412a5c6672239ceb9ed9d538
                                              • Opcode Fuzzy Hash: 7e3dec843d3c2bdfcd9b88ea5898acdebe44c933704b2a18e631af7654d1b92d
                                              • Instruction Fuzzy Hash: 8851F773E08A86C1FA90EB1AD5405BDE761EF947C4F945136EA8E273A5DE3DD084C320
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                              • String ID: bad locale name
                                              • API String ID: 3988782225-1405518554
                                              • Opcode ID: ab8ba62c3cd29999f6b0c8d15e8c73ab141a4a8ccc7404b4129a8aa97d70c633
                                              • Instruction ID: e0b9b76cd4c83cf5857bbc24089521118e2ace63acf4150ce647ed65f65d4978
                                              • Opcode Fuzzy Hash: ab8ba62c3cd29999f6b0c8d15e8c73ab141a4a8ccc7404b4129a8aa97d70c633
                                              • Instruction Fuzzy Hash: 04516F32B09A01D9FB90EF62D8902BCB3A4EF54748F880439DA4E77B56DE38D559C354
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                                              • String ID: bad locale name
                                              • API String ID: 3988782225-1405518554
                                              • Opcode ID: 5c6dfc6788a541a7de62cbe8aa76ccea44fa1d3a9b5437bfa697362aa3e33669
                                              • Instruction ID: 6a1f7e2a53f03a81d1158fc4d67c7002a8c0233495ae1987903c46dcf40537de
                                              • Opcode Fuzzy Hash: 5c6dfc6788a541a7de62cbe8aa76ccea44fa1d3a9b5437bfa697362aa3e33669
                                              • Instruction Fuzzy Hash: 36518E32B09A01D9EB90EF72D8506BCB3A4EF54748F880439EA8E73B55DE38D551C364
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _get_daylight$_invalid_parameter_noinfo
                                              • String ID: ?
                                              • API String ID: 1286766494-1684325040
                                              • Opcode ID: 948ea5093c49672d9cebe17e78a03e5ff2ff35b94c226735abaeefd0b52bf2dd
                                              • Instruction ID: c73559cd7ab7a8a40f5963e8be872925da0c376a5eb2fec276351ab66eb8bf17
                                              • Opcode Fuzzy Hash: 948ea5093c49672d9cebe17e78a03e5ff2ff35b94c226735abaeefd0b52bf2dd
                                              • Instruction Fuzzy Hash: F7412712A08682C5FBA0AF2794017BAD670EF82BA5F904339EE5C16BD5DE3CD441CB14
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: ErrorFileLastWrite
                                              • String ID: U
                                              • API String ID: 442123175-4171548499
                                              • Opcode ID: 3efb29d34a756b785a65299427448dbee74b57ff388e52a10932dd82dc16598c
                                              • Instruction ID: e5eca9ffd4c9aa4c412fd99882f268dcd91458a8a33c38f48f1a48ce413f7e71
                                              • Opcode Fuzzy Hash: 3efb29d34a756b785a65299427448dbee74b57ff388e52a10932dd82dc16598c
                                              • Instruction Fuzzy Hash: 3D41E332B18A81D1DB60AF26E8443A9B7A0FB89B95F804039EE4D97788DF3CD405C764
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _invalid_parameter_noinfo_noreturn
                                              • String ID: false$true
                                              • API String ID: 3668304517-2658103896
                                              • Opcode ID: 06af256300836894cd400fb88b33984ac3fe2ce9c156be931ae753f98a0f9e29
                                              • Instruction ID: b6a8a2a5f05fe8696d877fc8feb25325be7b89a3568de083b494b7411e069b0a
                                              • Opcode Fuzzy Hash: 06af256300836894cd400fb88b33984ac3fe2ce9c156be931ae753f98a0f9e29
                                              • Instruction Fuzzy Hash: 12419163E18B85D9FB00DB76C8403EC6371EB59398F805335DAAD2679AEF689199C310
                                              APIs
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.2605406653.00007FF7632D1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7632D0000, based on PE: true
                                              • Associated: 00000000.00000002.2605379700.00007FF7632D0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605486651.00007FF7633A8000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605516766.00007FF7633D4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605537973.00007FF7633D6000.00000008.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605557309.00007FF7633D9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                              • Associated: 00000000.00000002.2605583383.00007FF7633DD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ff7632d0000_file.jbxd
                                              Similarity
                                              • API ID: _set_errno_from_matherr
                                              • String ID: exp
                                              • API String ID: 1187470696-113136155
                                              • Opcode ID: 49f0d078269b54412d4ab26495e5ae6b104b468a2a1f1e9b5f5a5d1d2e07f27f
                                              • Instruction ID: 55bebd00ac4526f8a8e00958afa0b3ee83b294297ab35963812ff44638a94d19
                                              • Opcode Fuzzy Hash: 49f0d078269b54412d4ab26495e5ae6b104b468a2a1f1e9b5f5a5d1d2e07f27f
                                              • Instruction Fuzzy Hash: C4212836E14615CEE790EF79C4416AD77B0FB4A348B801539EA0DAAB4ADF38E540CB54