Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Bzw4UJiXNj.exe

Overview

General Information

Sample name:Bzw4UJiXNj.exe
renamed because original name is a hash value
Original sample name:4b61a3d79a892267bf6e76a54e188cc0.exe
Analysis ID:1528625
MD5:4b61a3d79a892267bf6e76a54e188cc0
SHA1:e1dc7ad66e65bf5ca6701eb224d11761c56b1288
SHA256:6bff92bd6fb84f1a453ead8ef017b6ae42a78b7fbbbd6414ec8a9cd669bf3b05
Tags:64exetrojan
Infos:

Detection

Metasploit
Score:96
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Metasploit Payload
Machine Learning detection for dropped file
Machine Learning detection for sample
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to communicate with device drivers
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Drops PE files
File is packed with WinRar
Found dropped PE file which has not been started or loaded
PE file contains sections with non-standard names
Sample file is different than original file name gathered from version info
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • Bzw4UJiXNj.exe (PID: 3632 cmdline: "C:\Users\user\Desktop\Bzw4UJiXNj.exe" MD5: 4B61A3D79A892267BF6E76A54E188CC0)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exeJoeSecurity_MetasploitPayload_3Yara detected Metasploit PayloadJoe Security
    C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exeJoeSecurity_MetasploitPayloadYara detected Metasploit PayloadJoe Security
      C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exeWindows_Trojan_Metasploit_24338919Identifies metasploit wininet reverse shellcode. Also used by other tools (like beacon).unknown
      • 0xac9f:$a1: 68 6E 65 74 00 68 77 69 6E 69 54 68 4C 77 26 07
      No Sigma rule has matched
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exeAvira: detection malicious, Label: TR/Patched.Gen2
      Source: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exeReversingLabs: Detection: 84%
      Source: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exeVirustotal: Detection: 81%Perma Link
      Source: Bzw4UJiXNj.exeReversingLabs: Detection: 66%
      Source: Bzw4UJiXNj.exeVirustotal: Detection: 69%Perma Link
      Source: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exeJoe Sandbox ML: detected
      Source: Bzw4UJiXNj.exeJoe Sandbox ML: detected
      Source: Bzw4UJiXNj.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
      Source: Binary string: C:\local0\asf\release\build-2.2.14\support\Release\ab.pdb source: Bzw4UJiXNj.exe, 00000000.00000003.2115529243.00000279499A2000.00000004.00000020.00020000.00000000.sdmp, Icon-https.exe.0.dr
      Source: Binary string: D:\Projects\WinRAR\sfx\build\sfxrar64\Release\sfxrar.pdb source: Bzw4UJiXNj.exe
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DAB190 EndDialog,SetDlgItemTextW,GetMessageW,IsDialogMessageW,TranslateMessage,DispatchMessageW,EndDialog,GetDlgItem,SendMessageW,SendMessageW,SetFocus,GetLastError,GetLastError,GetTickCount,GetLastError,GetCommandLineW,CreateFileMappingW,MapViewOfFile,ShellExecuteExW,Sleep,UnmapViewOfFile,CloseHandle,SetDlgItemTextW,SetWindowTextW,SetDlgItemTextW,SetWindowTextW,GetDlgItem,GetWindowLongPtrW,SetWindowLongPtrW,SetDlgItemTextW,SendMessageW,SendDlgItemMessageW,GetDlgItem,SendMessageW,GetDlgItem,SetDlgItemTextW,SetDlgItemTextW,SetForegroundWindow,DialogBoxParamW,EndDialog,EnableWindow,SendMessageW,PostMessageW,SetDlgItemTextW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SendDlgItemMessageW,FindFirstFileW,FindClose,SendDlgItemMessageW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF646DAB190
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D940BC FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF646D940BC
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DBFCA0 FindFirstFileExA,0_2_00007FF646DBFCA0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\user\AppDataJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\user\Videos\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\userJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\user\Music\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\user\OneDrive\desktop.iniJump to behavior
      Source: Icon-https.exe.0.drString found in binary or memory: http://www.apache.org/
      Source: Bzw4UJiXNj.exe, 00000000.00000003.2115529243.00000279499A2000.00000004.00000020.00020000.00000000.sdmp, Icon-https.exe.0.drString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
      Source: Icon-https.exe.0.drString found in binary or memory: http://www.zeustech.net/

      System Summary

      barindex
      Source: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exe, type: DROPPEDMatched rule: Identifies metasploit wininet reverse shellcode. Also used by other tools (like beacon). Author: unknown
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D8C2F0: CreateFileW,CloseHandle,wcscpy,wcscpy,wcscpy,wcscpy,CreateFileW,DeviceIoControl,CloseHandle,GetLastError,RemoveDirectoryW,DeleteFileW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF646D8C2F0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB07540_2_00007FF646DB0754
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D8F9300_2_00007FF646D8F930
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D949280_2_00007FF646D94928
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D9A4AC0_2_00007FF646D9A4AC
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DA34840_2_00007FF646DA3484
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DAB1900_2_00007FF646DAB190
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D85E240_2_00007FF646D85E24
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DA1F200_2_00007FF646DA1F20
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DACE880_2_00007FF646DACE88
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DBC8380_2_00007FF646DBC838
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D848400_2_00007FF646D84840
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DC25500_2_00007FF646DC2550
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D876C00_2_00007FF646D876C0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DA53F00_2_00007FF646DA53F0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D9B5340_2_00007FF646D9B534
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DA21D00_2_00007FF646DA21D0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D9F1800_2_00007FF646D9F180
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D8A3100_2_00007FF646D8A310
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D8C2F00_2_00007FF646D8C2F0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D872880_2_00007FF646D87288
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D9126C0_2_00007FF646D9126C
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DC20800_2_00007FF646DC2080
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DA8DF40_2_00007FF646DA8DF4
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB07540_2_00007FF646DB0754
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DA2D580_2_00007FF646DA2D58
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D9AF180_2_00007FF646D9AF18
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB8C1C0_2_00007FF646DB8C1C
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DA4B980_2_00007FF646DA4B98
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D9BB900_2_00007FF646D9BB90
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D95B600_2_00007FF646D95B60
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB89A00_2_00007FF646DB89A0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DA39640_2_00007FF646DA3964
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D9C96C0_2_00007FF646D9C96C
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DC5AF80_2_00007FF646DC5AF8
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D81AA40_2_00007FF646D81AA4
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DA2AB00_2_00007FF646DA2AB0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DBFA940_2_00007FF646DBFA94
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D91A480_2_00007FF646D91A48
      Source: Bzw4UJiXNj.exe, 00000000.00000003.2115529243.00000279499A2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameab.exeF vs Bzw4UJiXNj.exe
      Source: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exe, type: DROPPEDMatched rule: Windows_Trojan_Metasploit_24338919 os = windows, severity = x86, description = Identifies metasploit wininet reverse shellcode. Also used by other tools (like beacon)., creation_date = 2021-03-23, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = ac76190a84c4bdbb6927c5ad84a40e2145ca9e76369a25ac2ffd727eefef4804, id = 24338919-8efe-4cf2-a23a-a3f22095b42d, last_modified = 2021-08-23
      Source: Icon-https.exe.0.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: classification engineClassification label: mal96.troj.winEXE@1/3@0/0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D8B6D8 GetLastError,FormatMessageW,LocalFree,0_2_00007FF646D8B6D8
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DA8624 FindResourceW,SizeofResource,LoadResource,LockResource,GlobalAlloc,GlobalLock,CreateStreamOnHGlobal,GdipAlloc,GdipCreateHBITMAPFromBitmap,GlobalUnlock,GlobalFree,0_2_00007FF646DA8624
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile created: C:\Users\user\AppData\Local\Temp\RarSFX0Jump to behavior
      Source: Bzw4UJiXNj.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile read: C:\Windows\win.iniJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: Bzw4UJiXNj.exeReversingLabs: Detection: 66%
      Source: Bzw4UJiXNj.exeVirustotal: Detection: 69%
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile read: C:\Users\user\Desktop\Bzw4UJiXNj.exeJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: version.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: dxgidebug.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: sfc_os.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: rsaenh.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: dwmapi.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: riched20.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: usp10.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: msls31.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: windowscodecs.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: textshaping.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: textinputframework.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: coreuicomponents.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: ntmarta.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: propsys.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: ndfapi.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: wdi.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: duser.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: xmllite.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: atlthunk.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: windows.fileexplorer.common.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: iertutil.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: ntshrui.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: cscapi.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: netutils.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: windows.staterepositoryps.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeSection loaded: linkinfo.dllJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32Jump to behavior
      Source: Window RecorderWindow detected: More than 3 window changes detected
      Source: Bzw4UJiXNj.exeStatic PE information: Image base 0x140000000 > 0x60000000
      Source: Bzw4UJiXNj.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
      Source: Bzw4UJiXNj.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
      Source: Bzw4UJiXNj.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
      Source: Bzw4UJiXNj.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
      Source: Bzw4UJiXNj.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
      Source: Bzw4UJiXNj.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
      Source: Bzw4UJiXNj.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
      Source: Bzw4UJiXNj.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
      Source: Binary string: C:\local0\asf\release\build-2.2.14\support\Release\ab.pdb source: Bzw4UJiXNj.exe, 00000000.00000003.2115529243.00000279499A2000.00000004.00000020.00020000.00000000.sdmp, Icon-https.exe.0.dr
      Source: Binary string: D:\Projects\WinRAR\sfx\build\sfxrar64\Release\sfxrar.pdb source: Bzw4UJiXNj.exe
      Source: Bzw4UJiXNj.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
      Source: Bzw4UJiXNj.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
      Source: Bzw4UJiXNj.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
      Source: Bzw4UJiXNj.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
      Source: Bzw4UJiXNj.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile created: C:\Users\user\AppData\Local\Temp\RarSFX0\__tmp_rar_sfx_access_check_6096718Jump to behavior
      Source: Bzw4UJiXNj.exeStatic PE information: section name: .didat
      Source: Bzw4UJiXNj.exeStatic PE information: section name: _RDATA
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DC5156 push rsi; retf 0_2_00007FF646DC5157
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DC5166 push rsi; retf 0_2_00007FF646DC5167
      Source: Icon-https.exe.0.drStatic PE information: section name: .text entropy: 7.021725181628894
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile created: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exeJump to dropped file
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exeJump to dropped file
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DAB190 EndDialog,SetDlgItemTextW,GetMessageW,IsDialogMessageW,TranslateMessage,DispatchMessageW,EndDialog,GetDlgItem,SendMessageW,SendMessageW,SetFocus,GetLastError,GetLastError,GetTickCount,GetLastError,GetCommandLineW,CreateFileMappingW,MapViewOfFile,ShellExecuteExW,Sleep,UnmapViewOfFile,CloseHandle,SetDlgItemTextW,SetWindowTextW,SetDlgItemTextW,SetWindowTextW,GetDlgItem,GetWindowLongPtrW,SetWindowLongPtrW,SetDlgItemTextW,SendMessageW,SendDlgItemMessageW,GetDlgItem,SendMessageW,GetDlgItem,SetDlgItemTextW,SetDlgItemTextW,SetForegroundWindow,DialogBoxParamW,EndDialog,EnableWindow,SendMessageW,PostMessageW,SetDlgItemTextW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SendDlgItemMessageW,FindFirstFileW,FindClose,SendDlgItemMessageW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF646DAB190
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D940BC FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF646D940BC
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DBFCA0 FindFirstFileExA,0_2_00007FF646DBFCA0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB16A4 VirtualQuery,GetSystemInfo,0_2_00007FF646DB16A4
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\user\AppDataJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\user\Videos\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\userJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\user\Music\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeFile opened: C:\Users\user\OneDrive\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB76D8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF646DB76D8
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DC0D20 GetProcessHeap,0_2_00007FF646DC0D20
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB76D8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF646DB76D8
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB3354 SetUnhandledExceptionFilter,0_2_00007FF646DB3354
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB2510 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF646DB2510
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB3170 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF646DB3170
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DAB190 EndDialog,SetDlgItemTextW,GetMessageW,IsDialogMessageW,TranslateMessage,DispatchMessageW,EndDialog,GetDlgItem,SendMessageW,SendMessageW,SetFocus,GetLastError,GetLastError,GetTickCount,GetLastError,GetCommandLineW,CreateFileMappingW,MapViewOfFile,ShellExecuteExW,Sleep,UnmapViewOfFile,CloseHandle,SetDlgItemTextW,SetWindowTextW,SetDlgItemTextW,SetWindowTextW,GetDlgItem,GetWindowLongPtrW,SetWindowLongPtrW,SetDlgItemTextW,SendMessageW,SendDlgItemMessageW,GetDlgItem,SendMessageW,GetDlgItem,SetDlgItemTextW,SetDlgItemTextW,SetForegroundWindow,DialogBoxParamW,EndDialog,EnableWindow,SendMessageW,PostMessageW,SetDlgItemTextW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SendDlgItemMessageW,FindFirstFileW,FindClose,SendDlgItemMessageW,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF646DAB190
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DC58E0 cpuid 0_2_00007FF646DC58E0
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: GetLocaleInfoW,GetNumberFormatW,0_2_00007FF646DAA2CC
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646DB0754 GetCommandLineW,OpenFileMappingW,MapViewOfFile,UnmapViewOfFile,MapViewOfFile,UnmapViewOfFile,CloseHandle,SetEnvironmentVariableW,GetLocalTime,swprintf,SetEnvironmentVariableW,GetModuleHandleW,LoadIconW,DialogBoxParamW,Sleep,DeleteObject,DeleteObject,CloseHandle,OleUninitialize,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF646DB0754
      Source: C:\Users\user\Desktop\Bzw4UJiXNj.exeCode function: 0_2_00007FF646D951A4 GetVersionExW,0_2_00007FF646D951A4

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exe, type: DROPPED
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
      DLL Side-Loading
      1
      Exploitation for Privilege Escalation
      3
      Software Packing
      OS Credential Dumping1
      System Time Discovery
      Remote Services1
      Archive Collected Data
      1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
      DLL Side-Loading
      1
      DLL Side-Loading
      LSASS Memory12
      Security Software Discovery
      Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)2
      Obfuscated Files or Information
      Security Account Manager3
      File and Directory Discovery
      SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS25
      System Information Discovery
      Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      Bzw4UJiXNj.exe67%ReversingLabsWin64.Trojan.CryptZMarte
      Bzw4UJiXNj.exe69%VirustotalBrowse
      Bzw4UJiXNj.exe100%Joe Sandbox ML
      SourceDetectionScannerLabelLink
      C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exe100%AviraTR/Patched.Gen2
      C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exe100%Joe Sandbox ML
      C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exe84%ReversingLabsWin32.Backdoor.Swrort
      C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exe82%VirustotalBrowse
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      http://www.zeustech.net/0%VirustotalBrowse
      http://www.apache.org/0%VirustotalBrowse
      http://www.apache.org/licenses/LICENSE-2.00%VirustotalBrowse
      No contacted domains info
      NameSourceMaliciousAntivirus DetectionReputation
      http://www.apache.org/licenses/LICENSE-2.0Bzw4UJiXNj.exe, 00000000.00000003.2115529243.00000279499A2000.00000004.00000020.00020000.00000000.sdmp, Icon-https.exe.0.drfalseunknown
      http://www.apache.org/Icon-https.exe.0.drfalseunknown
      http://www.zeustech.net/Icon-https.exe.0.drfalseunknown
      No contacted IP infos
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1528625
      Start date and time:2024-10-08 05:08:06 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 2m 15s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:default.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:2
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:Bzw4UJiXNj.exe
      renamed because original name is a hash value
      Original Sample Name:4b61a3d79a892267bf6e76a54e188cc0.exe
      Detection:MAL
      Classification:mal96.troj.winEXE@1/3@0/0
      EGA Information:
      • Successful, ratio: 100%
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 68
      • Number of non-executed functions: 93
      Cookbook Comments:
      • Found application associated with file extension: .exe
      • Stop behavior analysis, all processes terminated
      • Exclude process from analysis (whitelisted): dllhost.exe
      • Excluded domains from analysis (whitelisted): client.wns.windows.com, otelrules.azureedge.net
      • Report size getting too big, too many NtOpenKeyEx calls found.
      • Report size getting too big, too many NtProtectVirtualMemory calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.
      No simulations
      No context
      No context
      No context
      No context
      No context
      Process:C:\Users\user\Desktop\Bzw4UJiXNj.exe
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):73802
      Entropy (8bit):6.32292825214426
      Encrypted:false
      SSDEEP:1536:IPoaiZ2dMsk7otVGNvoBGZ063+GsWOVMb+KR0Nc8QsJq39:W1c2dZtM68063fee0Nc8QsC9
      MD5:07E1BC43F53A20F738039F5BD8D081EC
      SHA1:8F6C6DD58009C7E87BCBE565D2D1702D77E70BA2
      SHA-256:62E57F61112880D6D11D3FD7E0FB6BEA47215A5041BD66B170BCE4EF4CE8BF60
      SHA-512:E3BD6A8F983AF417E2BD67BCCD6EBCF949C36A9115EBB1179BE96BEE9C43FB4B164D55BC3A67ED471450CE58E1664938A81DFAE1BF919846BFC52056168F405A
      Malicious:true
      Yara Hits:
      • Rule: JoeSecurity_MetasploitPayload_3, Description: Yara detected Metasploit Payload, Source: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exe, Author: Joe Security
      • Rule: JoeSecurity_MetasploitPayload, Description: Yara detected Metasploit Payload, Source: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exe, Author: Joe Security
      • Rule: Windows_Trojan_Metasploit_24338919, Description: Identifies metasploit wininet reverse shellcode. Also used by other tools (like beacon)., Source: C:\Users\user\AppData\Local\Temp\RarSFX0\Icon-https.exe, Author: unknown
      Antivirus:
      • Antivirus: Avira, Detection: 100%
      • Antivirus: Joe Sandbox ML, Detection: 100%
      • Antivirus: ReversingLabs, Detection: 84%
      • Antivirus: Virustotal, Detection: 82%, Browse
      Reputation:low
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........8...Y...Y...Y...E...Y..TE...Y...F...Y...F...Y...Y...Y..TQ..Y...z...Y..._...Y..Rich.Y..................PE..L....<>J.............................?............@..........................`..............................................l...x....P...............................................................................................................text...f........................... ..`.rdata..............................@..@.data...\p.......@..................@....rsrc........P......................@..@........................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Users\user\Desktop\Bzw4UJiXNj.exe
      File Type:MS Windows icon resource - 1 icon, -128x-128, 32 bits/pixel
      Category:dropped
      Size (bytes):67646
      Entropy (8bit):4.599798862733515
      Encrypted:false
      SSDEEP:384:J55555555555555555555555555555555555555555555555555555555555555V:/vmmmmmuRb+PtPdOvJ
      MD5:26C3AA5599218EB4B32C5A042F099320
      SHA1:5443FDA4FEC6F022B46DC54A73CAC835ECFD1B87
      SHA-256:17C8F8D74D73C1106E25CE25AEDE9408BEA3766E9B05B333DC3EA3DBCEB03C5C
      SHA-512:C90A9204749EC0C234E7DFEA93D12F199BFA275C11E55B2EACA23195E240E552DA1E085518C4025B0233A09640A870B3F0A051DF6CBF760DA910154982325CE1
      Malicious:false
      Reputation:low
      Preview:............ .(.......(............. ..........;...;....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Users\user\Desktop\Bzw4UJiXNj.exe
      File Type:PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
      Category:dropped
      Size (bytes):10713
      Entropy (8bit):7.50179523733628
      Encrypted:false
      SSDEEP:192:YzQMA0Eh3B9aSl7Kq+ZmpImcQORPMJ6aUbbRMQMzwySd5mIOumCU4B:YcN9j7KqNljJ5Ujmib
      MD5:1304E793E5FFC4A9508DD9D334F45BE4
      SHA1:05ABC3179625C6863828A5CFA5AD2A19AAE372D2
      SHA-256:E6C42A78E2A0A76DA607F8A3338A779670336B56100B92A618896D4209ED7DD8
      SHA-512:2A62FDA3ACA049E6A7C1ED31FA0A858D6B0F12F1F840E2D51CF75F3312B1421F7EFC02E32FF034E7DAB07BDC9A772820E685215AA42240F16241D26ECA9001A9
      Malicious:false
      Reputation:low
      Preview:.PNG........IHDR..............x....).IDATx...i.\.y..........g_8...k42d$H.........X....;.a... . o.....A...A..B6X......9+.}.....k.'...7{z....{...>...]o..y.:.=.......................................................Q.....3....&.v).}../.nI.].....R.qE:.PGMd.......:../L...~..v.T.g....M...............d+_...I....#.1.#.B......I.+S..._X.~3.......e........z..-...7.~..}~.H#....g.w.. ......k....|.....W.../d..S.~g.KA..&....'."..>..._Z....<.....m...%.\....]..}....[.."..<..wo|.(.S.u.....7^..U_.....g.3. ...w..Ed.>...W...?.....|... ,.%..u-..D.)..x......Az.<.3.7. ,|O<...G=..o...;......T.~U......8...w...?.\............u-...n........K...^[{.W.... .U.K.M... .~.........@:...:..@.....OK....@jl|e..3.. .L..u].. ]..>'.........M..)......l,D:...@..5........t].. ..R... ...u].. ...}....M..u...t2&XM..)..^.5......%..W........u...........................................................................................................................................................
      File type:PE32+ executable (GUI) x86-64, for MS Windows
      Entropy (8bit):6.694905962044059
      TrID:
      • Win64 Executable GUI (202006/5) 92.65%
      • Win64 Executable (generic) (12005/4) 5.51%
      • Generic Win/DOS Executable (2004/3) 0.92%
      • DOS Executable Generic (2002/1) 0.92%
      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
      File name:Bzw4UJiXNj.exe
      File size:536'027 bytes
      MD5:4b61a3d79a892267bf6e76a54e188cc0
      SHA1:e1dc7ad66e65bf5ca6701eb224d11761c56b1288
      SHA256:6bff92bd6fb84f1a453ead8ef017b6ae42a78b7fbbbd6414ec8a9cd669bf3b05
      SHA512:4970d37d95accc39709886f45125a3059e58c4dc91dee46591737ad0279efb8f395625fff67a0daa30a6f8b29f79af13aeadf71c2b9f18844a2883e004b06884
      SSDEEP:12288:wyveQB/fTHIGaPkKEYzURNAwbAg6c0tY0BfYM:wuDXTIGaPhEYzUzA0L0thBfV
      TLSH:95B44A35EA9414B5F3FAD538945A8503E27D3C0DC228766A12F022661FF7B778B2B319
      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......$.2.`.\.`.\.`.\..y..h.\..y....\..y..m.\.....b.\...X.r.\..._.j.\...Y.Y.\.i...i.\.i...b.\.i...g.\.`.].C.\...Y.R.\...\.a.\.....a.\
      Icon Hash:0b03084c4e4e0383
      Entrypoint:0x140032ee0
      Entrypoint Section:.text
      Digitally signed:false
      Imagebase:0x140000000
      Subsystem:windows gui
      Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
      DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
      Time Stamp:0x66409723 [Sun May 12 10:17:07 2024 UTC]
      TLS Callbacks:
      CLR (.Net) Version:
      OS Version Major:5
      OS Version Minor:2
      File Version Major:5
      File Version Minor:2
      Subsystem Version Major:5
      Subsystem Version Minor:2
      Import Hash:b1c5b1beabd90d9fdabd1df0779ea832
      Instruction
      dec eax
      sub esp, 28h
      call 00007FAE50B99F78h
      dec eax
      add esp, 28h
      jmp 00007FAE50B9990Fh
      int3
      int3
      dec eax
      mov eax, esp
      dec eax
      mov dword ptr [eax+08h], ebx
      dec eax
      mov dword ptr [eax+10h], ebp
      dec eax
      mov dword ptr [eax+18h], esi
      dec eax
      mov dword ptr [eax+20h], edi
      inc ecx
      push esi
      dec eax
      sub esp, 20h
      dec ebp
      mov edx, dword ptr [ecx+38h]
      dec eax
      mov esi, edx
      dec ebp
      mov esi, eax
      dec eax
      mov ebp, ecx
      dec ecx
      mov edx, ecx
      dec eax
      mov ecx, esi
      dec ecx
      mov edi, ecx
      inc ecx
      mov ebx, dword ptr [edx]
      dec eax
      shl ebx, 04h
      dec ecx
      add ebx, edx
      dec esp
      lea eax, dword ptr [ebx+04h]
      call 00007FAE50B98D93h
      mov eax, dword ptr [ebp+04h]
      and al, 66h
      neg al
      mov eax, 00000001h
      sbb edx, edx
      neg edx
      add edx, eax
      test dword ptr [ebx+04h], edx
      je 00007FAE50B99AA3h
      dec esp
      mov ecx, edi
      dec ebp
      mov eax, esi
      dec eax
      mov edx, esi
      dec eax
      mov ecx, ebp
      call 00007FAE50B9BAB7h
      dec eax
      mov ebx, dword ptr [esp+30h]
      dec eax
      mov ebp, dword ptr [esp+38h]
      dec eax
      mov esi, dword ptr [esp+40h]
      dec eax
      mov edi, dword ptr [esp+48h]
      dec eax
      add esp, 20h
      inc ecx
      pop esi
      ret
      int3
      int3
      int3
      dec eax
      sub esp, 48h
      dec eax
      lea ecx, dword ptr [esp+20h]
      call 00007FAE50B88323h
      dec eax
      lea edx, dword ptr [00025747h]
      dec eax
      lea ecx, dword ptr [esp+20h]
      call 00007FAE50B9AB72h
      int3
      jmp 00007FAE50BA0D54h
      int3
      int3
      int3
      int3
      int3
      int3
      Programming Language:
      • [ C ] VS2008 SP1 build 30729
      • [IMP] VS2008 SP1 build 30729
      NameVirtual AddressVirtual Size Is in Section
      IMAGE_DIRECTORY_ENTRY_EXPORT0x597a00x34.rdata
      IMAGE_DIRECTORY_ENTRY_IMPORT0x597d40x50.rdata
      IMAGE_DIRECTORY_ENTRY_RESOURCE0x700000x154f4.rsrc
      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x6a0000x306c.pdata
      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
      IMAGE_DIRECTORY_ENTRY_BASERELOC0x860000x970.reloc
      IMAGE_DIRECTORY_ENTRY_DEBUG0x536c00x54.rdata
      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
      IMAGE_DIRECTORY_ENTRY_TLS0x537800x28.rdata
      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x4b3f00x140.rdata
      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
      IMAGE_DIRECTORY_ENTRY_IAT0x480000x508.rdata
      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x588bc0x120.rdata
      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
      .text0x10000x4676e0x46800f06bb06e02377ae8b223122e53be35c2False0.5372340425531915data6.47079645411382IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      .rdata0x480000x128c40x12a002de06d4a6920a6911e64ff20000ea72fFalse0.4499003775167785data5.273999097784603IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .data0x5b0000xe75c0x1a000dbdb901a7d477980097e42e511a94fbFalse0.28275240384615385data3.2571023907881185IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .pdata0x6a0000x306c0x3200b0ce0f057741ad2a4ef4717079fa34e9False0.483359375data5.501810413666288IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .didat0x6e0000x3600x4001fcc7b1d7a02443319f8fcc2be4ca936False0.2578125data3.0459938492946015IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      _RDATA0x6f0000x15c0x2003f331ec50f09ba861beaf955b33712d5False0.408203125data3.3356393424384843IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .rsrc0x700000x154f40x156003fc741d3ed0e5cdaebe6cc1c5f34a0a3False0.1883109466374269data5.3514803031072535IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .reloc0x860000x9700xa0077a9ddfc47a5650d6eebbcc823e39532False0.52421875data5.336289720085303IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
      NameRVASizeTypeLanguageCountryZLIB Complexity
      PNG0x705540xb45PNG image data, 93 x 302, 8-bit/color RGB, non-interlacedEnglishUnited States1.0027729636048528
      PNG0x7109c0x15a9PNG image data, 186 x 604, 8-bit/color RGB, non-interlacedEnglishUnited States0.9363390441839495
      RT_ICON0x726480x10828Device independent bitmap graphic, 128 x 256 x 32, image size 65536, resolution 15118 x 15118 px/m0.06374955637051934
      RT_DIALOG0x82e700x286dataEnglishUnited States0.5092879256965944
      RT_DIALOG0x830f80x13adataEnglishUnited States0.60828025477707
      RT_DIALOG0x832340xecdataEnglishUnited States0.6991525423728814
      RT_DIALOG0x833200x12edataEnglishUnited States0.5927152317880795
      RT_DIALOG0x834500x338dataEnglishUnited States0.45145631067961167
      RT_DIALOG0x837880x252dataEnglishUnited States0.5757575757575758
      RT_STRING0x839dc0x1e2dataEnglishUnited States0.3900414937759336
      RT_STRING0x83bc00x1ccdataEnglishUnited States0.4282608695652174
      RT_STRING0x83d8c0x1b8dataEnglishUnited States0.45681818181818185
      RT_STRING0x83f440x146dataEnglishUnited States0.5153374233128835
      RT_STRING0x8408c0x46cdataEnglishUnited States0.3454063604240283
      RT_STRING0x844f80x166dataEnglishUnited States0.49162011173184356
      RT_STRING0x846600x152dataEnglishUnited States0.5059171597633136
      RT_STRING0x847b40x10adataEnglishUnited States0.49624060150375937
      RT_STRING0x848c00xbcdataEnglishUnited States0.6329787234042553
      RT_STRING0x8497c0x1c0dataEnglishUnited States0.5178571428571429
      RT_STRING0x84b3c0x250dataEnglishUnited States0.44256756756756754
      RT_GROUP_ICON0x84d8c0x14data1.15
      RT_MANIFEST0x84da00x753XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.3957333333333333
      DLLImport
      KERNEL32.dllLocalFree, GetLastError, SetLastError, FormatMessageW, GetCurrentProcess, DeviceIoControl, SetFileTime, CloseHandle, RemoveDirectoryW, CreateFileW, DeleteFileW, CreateHardLinkW, GetShortPathNameW, GetLongPathNameW, MoveFileW, GetFileType, GetStdHandle, WriteFile, ReadFile, FlushFileBuffers, SetEndOfFile, SetFilePointer, GetCurrentProcessId, CreateDirectoryW, SetFileAttributesW, GetFileAttributesW, FindClose, FindFirstFileW, FindNextFileW, GetVersionExW, GetModuleFileNameW, SetCurrentDirectoryW, GetCurrentDirectoryW, GetFullPathNameW, FoldStringW, GetModuleHandleW, FindResourceW, FreeLibrary, GetProcAddress, ExpandEnvironmentStringsW, ExitProcess, SetThreadExecutionState, Sleep, LoadLibraryW, GetSystemDirectoryW, CompareStringW, AllocConsole, FreeConsole, AttachConsole, WriteConsoleW, GetProcessAffinityMask, CreateThread, SetThreadPriority, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, SetEvent, ResetEvent, ReleaseSemaphore, WaitForSingleObject, CreateEventW, CreateSemaphoreW, GetSystemTime, SystemTimeToTzSpecificLocalTime, TzSpecificLocalTimeToSystemTime, SystemTimeToFileTime, FileTimeToLocalFileTime, LocalFileTimeToFileTime, FileTimeToSystemTime, GetCPInfo, IsDBCSLeadByte, MultiByteToWideChar, WideCharToMultiByte, GlobalAlloc, LockResource, GlobalLock, GlobalUnlock, GlobalFree, GlobalMemoryStatusEx, LoadResource, SizeofResource, GetTimeFormatW, GetDateFormatW, GetExitCodeProcess, GetLocalTime, GetTickCount, MapViewOfFile, UnmapViewOfFile, CreateFileMappingW, OpenFileMappingW, GetCommandLineW, SetEnvironmentVariableW, GetTempPathW, MoveFileExW, GetLocaleInfoW, GetNumberFormatW, SetFilePointerEx, GetConsoleMode, GetConsoleCP, HeapSize, SetStdHandle, GetProcessHeap, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, GetOEMCP, IsValidCodePage, FindNextFileA, RaiseException, GetSystemInfo, VirtualProtect, VirtualQuery, LoadLibraryExA, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, InitializeCriticalSectionAndSpinCount, WaitForSingleObjectEx, IsDebuggerPresent, GetStartupInfoW, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, RtlPcToFileHeader, RtlUnwindEx, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, LoadLibraryExW, QueryPerformanceFrequency, GetModuleHandleExW, GetModuleFileNameA, GetACP, HeapFree, HeapAlloc, GetStringTypeW, HeapReAlloc, LCMapStringW, FindFirstFileExA
      OLEAUT32.dllSysAllocString, SysFreeString, VariantClear
      gdiplus.dllGdipCloneImage, GdipFree, GdipDisposeImage, GdipCreateBitmapFromStream, GdipCreateHBITMAPFromBitmap, GdiplusStartup, GdiplusShutdown, GdipAlloc
      Language of compilation systemCountry where language is spokenMap
      EnglishUnited States
      No network behavior found

      Click to jump to process

      Click to jump to process

      Click to dive into process behavior distribution

      Target ID:0
      Start time:23:08:55
      Start date:07/10/2024
      Path:C:\Users\user\Desktop\Bzw4UJiXNj.exe
      Wow64 process (32bit):false
      Commandline:"C:\Users\user\Desktop\Bzw4UJiXNj.exe"
      Imagebase:0x7ff646d80000
      File size:536'027 bytes
      MD5 hash:4B61A3D79A892267BF6E76A54E188CC0
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      Reset < >

        Execution Graph

        Execution Coverage:12%
        Dynamic/Decrypted Code Coverage:0%
        Signature Coverage:28.2%
        Total number of Nodes:2000
        Total number of Limit Nodes:26
        execution_graph 26522 7ff646dbbf2c 26529 7ff646dbbc34 26522->26529 26534 7ff646dbd440 35 API calls 3 library calls 26529->26534 26533 7ff646dbbc3f 26535 7ff646dbd068 35 API calls abort 26533->26535 26534->26533 25511 7ff646db03e0 25512 7ff646db041f 25511->25512 25513 7ff646db0497 25511->25513 25544 7ff646d9aae0 25512->25544 25515 7ff646d9aae0 48 API calls 25513->25515 25517 7ff646db04ab 25515->25517 25519 7ff646d9da98 48 API calls 25517->25519 25523 7ff646db0442 BuildCatchObjectHelperInternal 25519->25523 25521 7ff646db0541 25541 7ff646d8250c 25521->25541 25522 7ff646db05cc 25527 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 25522->25527 25523->25522 25524 7ff646db05c6 25523->25524 25536 7ff646d81fa0 25523->25536 25554 7ff646db7904 25524->25554 25529 7ff646db05d2 25527->25529 25537 7ff646d81fb3 25536->25537 25538 7ff646d81fdc 25536->25538 25537->25538 25539 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 25537->25539 25538->25521 25540 7ff646d82000 25539->25540 25542 7ff646d82516 SetDlgItemTextW 25541->25542 25543 7ff646d82513 25541->25543 25543->25542 25545 7ff646d9aaf3 25544->25545 25559 7ff646d99774 25545->25559 25548 7ff646d9ab86 25551 7ff646d9da98 25548->25551 25549 7ff646d9ab58 LoadStringW 25549->25548 25550 7ff646d9ab71 LoadStringW 25549->25550 25550->25548 25596 7ff646d9d874 25551->25596 25689 7ff646db783c 31 API calls 2 library calls 25554->25689 25556 7ff646db791d 25690 7ff646db7934 16 API calls abort 25556->25690 25566 7ff646d99638 25559->25566 25562 7ff646d997d9 25576 7ff646db2320 25562->25576 25567 7ff646d99692 25566->25567 25575 7ff646d99730 25566->25575 25571 7ff646d996c0 25567->25571 25589 7ff646da0f68 WideCharToMultiByte 25567->25589 25569 7ff646db2320 _handle_error 8 API calls 25570 7ff646d99764 25569->25570 25570->25562 25585 7ff646d99800 25570->25585 25574 7ff646d996ef 25571->25574 25591 7ff646d9aa88 45 API calls 2 library calls 25571->25591 25592 7ff646dba270 31 API calls 2 library calls 25574->25592 25575->25569 25578 7ff646db2329 25576->25578 25577 7ff646d997f2 25577->25548 25577->25549 25578->25577 25579 7ff646db2550 IsProcessorFeaturePresent 25578->25579 25580 7ff646db2568 25579->25580 25593 7ff646db2744 RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind 25580->25593 25582 7ff646db257b 25594 7ff646db2510 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 25582->25594 25586 7ff646d99840 25585->25586 25588 7ff646d99869 25585->25588 25595 7ff646dba270 31 API calls 2 library calls 25586->25595 25588->25562 25590 7ff646da0faa 25589->25590 25590->25571 25591->25574 25592->25575 25593->25582 25595->25588 25612 7ff646d9d4d0 25596->25612 25600 7ff646d9d8e5 swprintf 25608 7ff646d9d974 25600->25608 25626 7ff646db9ef0 25600->25626 25653 7ff646d89d78 33 API calls 25600->25653 25603 7ff646d9da17 25604 7ff646db2320 _handle_error 8 API calls 25603->25604 25606 7ff646d9da2b 25604->25606 25605 7ff646d9da3f 25607 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 25605->25607 25606->25523 25609 7ff646d9da44 25607->25609 25610 7ff646d9d9a3 25608->25610 25654 7ff646d89d78 33 API calls 25608->25654 25610->25603 25610->25605 25613 7ff646d9d665 25612->25613 25614 7ff646d9d502 25612->25614 25616 7ff646d9cb80 25613->25616 25614->25613 25615 7ff646d81744 33 API calls 25614->25615 25615->25614 25617 7ff646d9cc80 25616->25617 25618 7ff646d9cbb6 25616->25618 25665 7ff646d82004 33 API calls std::_Xinvalid_argument 25617->25665 25621 7ff646d9cc20 25618->25621 25622 7ff646d9cc7b 25618->25622 25624 7ff646d9cbc6 25618->25624 25621->25624 25655 7ff646db21d0 25621->25655 25664 7ff646d81f80 33 API calls 3 library calls 25622->25664 25624->25600 25627 7ff646db9f4e 25626->25627 25628 7ff646db9f36 25626->25628 25627->25628 25630 7ff646db9f58 25627->25630 25677 7ff646dbd69c 15 API calls _set_errno_from_matherr 25628->25677 25679 7ff646db7ef0 35 API calls 2 library calls 25630->25679 25632 7ff646db9f3b 25678 7ff646db78e4 31 API calls _invalid_parameter_noinfo_noreturn 25632->25678 25634 7ff646db9f69 __scrt_get_show_window_mode 25680 7ff646db7e70 15 API calls _set_errno_from_matherr 25634->25680 25635 7ff646db2320 _handle_error 8 API calls 25636 7ff646dba10b 25635->25636 25636->25600 25638 7ff646db9fd4 25681 7ff646db82f8 46 API calls 3 library calls 25638->25681 25640 7ff646db9fdd 25641 7ff646db9fe5 25640->25641 25642 7ff646dba014 25640->25642 25682 7ff646dbd90c 25641->25682 25644 7ff646dba06c 25642->25644 25645 7ff646dba092 25642->25645 25648 7ff646dba01a 25642->25648 25651 7ff646dba023 25642->25651 25649 7ff646dbd90c __free_lconv_num 15 API calls 25644->25649 25645->25644 25646 7ff646dba09c 25645->25646 25650 7ff646dbd90c __free_lconv_num 15 API calls 25646->25650 25647 7ff646dbd90c __free_lconv_num 15 API calls 25652 7ff646db9f46 25647->25652 25648->25644 25648->25651 25649->25652 25650->25652 25651->25647 25652->25635 25653->25600 25654->25610 25656 7ff646db21db 25655->25656 25657 7ff646db21f4 25656->25657 25659 7ff646db21fa 25656->25659 25666 7ff646dbbbc0 25656->25666 25657->25624 25660 7ff646db2205 25659->25660 25669 7ff646db2f7c RtlPcToFileHeader RaiseException std::bad_alloc::bad_alloc std::_Xinvalid_argument 25659->25669 25670 7ff646d81f80 33 API calls 3 library calls 25660->25670 25663 7ff646db220b 25664->25617 25671 7ff646dbbc00 25666->25671 25669->25660 25670->25663 25676 7ff646dbf398 EnterCriticalSection 25671->25676 25677->25632 25678->25652 25679->25634 25680->25638 25681->25640 25683 7ff646dbd911 RtlFreeHeap 25682->25683 25684 7ff646dbd941 __free_lconv_num 25682->25684 25683->25684 25685 7ff646dbd92c 25683->25685 25684->25652 25688 7ff646dbd69c 15 API calls _set_errno_from_matherr 25685->25688 25687 7ff646dbd931 GetLastError 25687->25684 25688->25687 25689->25556 25697 7ff646db20f0 25698 7ff646db2106 _com_error::_com_error 25697->25698 25703 7ff646db4078 25698->25703 25700 7ff646db2117 25708 7ff646db1900 25700->25708 25704 7ff646db40b4 RtlPcToFileHeader 25703->25704 25705 7ff646db4097 25703->25705 25706 7ff646db40cc 25704->25706 25707 7ff646db40db RaiseException 25704->25707 25705->25704 25706->25707 25707->25700 25734 7ff646db1558 25708->25734 25711 7ff646db198b 25712 7ff646db1868 DloadReleaseSectionWriteAccess 6 API calls 25711->25712 25713 7ff646db1998 RaiseException 25712->25713 25726 7ff646db1bb5 25713->25726 25714 7ff646db1abd 25716 7ff646db1b85 25714->25716 25721 7ff646db1b1b GetProcAddress 25714->25721 25715 7ff646db1a3d LoadLibraryExA 25717 7ff646db1a54 GetLastError 25715->25717 25718 7ff646db1aa9 25715->25718 25742 7ff646db1868 25716->25742 25722 7ff646db1a7e 25717->25722 25729 7ff646db1a69 25717->25729 25718->25714 25719 7ff646db1ab4 FreeLibrary 25718->25719 25719->25714 25720 7ff646db19b4 25720->25714 25720->25715 25720->25716 25720->25718 25721->25716 25724 7ff646db1b30 GetLastError 25721->25724 25723 7ff646db1868 DloadReleaseSectionWriteAccess 6 API calls 25722->25723 25727 7ff646db1a8b RaiseException 25723->25727 25728 7ff646db1b45 25724->25728 25727->25726 25728->25716 25730 7ff646db1868 DloadReleaseSectionWriteAccess 6 API calls 25728->25730 25729->25718 25729->25722 25731 7ff646db1b67 RaiseException 25730->25731 25732 7ff646db1558 _com_raise_error 6 API calls 25731->25732 25733 7ff646db1b81 25732->25733 25733->25716 25735 7ff646db156e 25734->25735 25741 7ff646db15d3 25734->25741 25750 7ff646db1604 25735->25750 25738 7ff646db15ce 25740 7ff646db1604 DloadReleaseSectionWriteAccess 3 API calls 25738->25740 25740->25741 25741->25711 25741->25720 25743 7ff646db1878 25742->25743 25749 7ff646db18d1 25742->25749 25744 7ff646db1604 DloadReleaseSectionWriteAccess 3 API calls 25743->25744 25745 7ff646db187d 25744->25745 25746 7ff646db18cc 25745->25746 25747 7ff646db17d8 DloadProtectSection 3 API calls 25745->25747 25748 7ff646db1604 DloadReleaseSectionWriteAccess 3 API calls 25746->25748 25747->25746 25748->25749 25749->25726 25751 7ff646db161f 25750->25751 25752 7ff646db1573 25750->25752 25751->25752 25753 7ff646db1624 GetModuleHandleW 25751->25753 25752->25738 25757 7ff646db17d8 25752->25757 25754 7ff646db163e GetProcAddress 25753->25754 25755 7ff646db1639 25753->25755 25754->25755 25756 7ff646db1653 GetProcAddress 25754->25756 25755->25752 25756->25755 25759 7ff646db17fa DloadProtectSection 25757->25759 25758 7ff646db1802 25758->25738 25759->25758 25760 7ff646db183a VirtualProtect 25759->25760 25762 7ff646db16a4 VirtualQuery GetSystemInfo 25759->25762 25760->25758 25762->25760 28482 7ff646db11cf 28483 7ff646db1102 28482->28483 28484 7ff646db1900 _com_raise_error 14 API calls 28483->28484 28485 7ff646db1141 28484->28485 26547 7ff646dab190 26893 7ff646d8255c 26547->26893 26549 7ff646dab1db 26550 7ff646dab1ef 26549->26550 26551 7ff646dabe93 26549->26551 26600 7ff646dab20c 26549->26600 26553 7ff646dab1ff 26550->26553 26554 7ff646dab2db 26550->26554 26550->26600 27134 7ff646daf390 26551->27134 26557 7ff646dab2a9 26553->26557 26558 7ff646dab207 26553->26558 26559 7ff646dab391 26554->26559 26566 7ff646dab2f5 26554->26566 26555 7ff646db2320 _handle_error 8 API calls 26560 7ff646dac350 26555->26560 26565 7ff646dab2cb EndDialog 26557->26565 26557->26600 26570 7ff646d9aae0 48 API calls 26558->26570 26558->26600 26901 7ff646d822bc GetDlgItem 26559->26901 26561 7ff646dabec9 26563 7ff646dabef0 GetDlgItem SendMessageW 26561->26563 26564 7ff646dabed5 SendDlgItemMessageW 26561->26564 26562 7ff646dabeba SendMessageW 26562->26561 26569 7ff646d962dc 35 API calls 26563->26569 26564->26563 26565->26600 26571 7ff646d9aae0 48 API calls 26566->26571 26573 7ff646dabf47 GetDlgItem 26569->26573 26574 7ff646dab236 26570->26574 26575 7ff646dab313 SetDlgItemTextW 26571->26575 26572 7ff646dab3b1 EndDialog 26757 7ff646dab3da 26572->26757 27153 7ff646d82520 26573->27153 27157 7ff646d81ec4 34 API calls _handle_error 26574->27157 26579 7ff646dab326 26575->26579 26578 7ff646dab408 GetDlgItem 26583 7ff646dab44f SetFocus 26578->26583 26584 7ff646dab422 SendMessageW SendMessageW 26578->26584 26587 7ff646dab340 GetMessageW 26579->26587 26579->26600 26582 7ff646dab246 26586 7ff646dab25c 26582->26586 26592 7ff646d8250c SetDlgItemTextW 26582->26592 26588 7ff646dab465 26583->26588 26589 7ff646dab4f2 26583->26589 26584->26583 26586->26600 26606 7ff646dac363 26586->26606 26594 7ff646dab35e IsDialogMessageW 26587->26594 26587->26600 26595 7ff646d9aae0 48 API calls 26588->26595 26593 7ff646d88d04 33 API calls 26589->26593 26590 7ff646d81fa0 31 API calls 26590->26600 26592->26586 26599 7ff646dab52c 26593->26599 26594->26579 26601 7ff646dab373 TranslateMessage DispatchMessageW 26594->26601 26602 7ff646dab46f 26595->26602 26596 7ff646dabcc5 26597 7ff646d9aae0 48 API calls 26596->26597 26603 7ff646dabcd6 SetDlgItemTextW 26597->26603 27158 7ff646daef80 33 API calls 2 library calls 26599->27158 26600->26555 26601->26579 26612 7ff646d8129c 33 API calls 26602->26612 26608 7ff646d9aae0 48 API calls 26603->26608 26607 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26606->26607 26611 7ff646dac368 26607->26611 26613 7ff646dabd08 26608->26613 26610 7ff646dab537 26616 7ff646d9aae0 48 API calls 26610->26616 26622 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26611->26622 26618 7ff646dab498 26612->26618 26630 7ff646d8129c 33 API calls 26613->26630 26617 7ff646dab555 26616->26617 26621 7ff646d9da98 48 API calls 26617->26621 26915 7ff646daf0a4 26618->26915 26627 7ff646dab568 26621->26627 26628 7ff646dac36e 26622->26628 26635 7ff646daf0a4 24 API calls 26627->26635 26640 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26628->26640 26666 7ff646dabd31 26630->26666 26639 7ff646dab578 26635->26639 26636 7ff646dab4e8 26655 7ff646dab5ec 26636->26655 27159 7ff646dafa80 33 API calls 2 library calls 26636->27159 26653 7ff646d81fa0 31 API calls 26639->26653 26647 7ff646dac374 26640->26647 26641 7ff646dabdda 26649 7ff646d9aae0 48 API calls 26641->26649 26671 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26647->26671 26658 7ff646dabde4 26649->26658 26664 7ff646dab586 26653->26664 26668 7ff646dab61a 26655->26668 27160 7ff646d932a8 26655->27160 26684 7ff646d8129c 33 API calls 26658->26684 26664->26628 26664->26636 26666->26641 26677 7ff646d8129c 33 API calls 26666->26677 26929 7ff646d92f58 26668->26929 26683 7ff646dac37a 26671->26683 26685 7ff646dabd7f 26677->26685 26681 7ff646dab634 GetLastError 26682 7ff646dab64c 26681->26682 26694 7ff646d97fc4 SetCurrentDirectoryW 26682->26694 26688 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26683->26688 26689 7ff646dabe0d 26684->26689 26691 7ff646d9aae0 48 API calls 26685->26691 26687 7ff646dab60e 27163 7ff646da9d90 12 API calls _handle_error 26687->27163 26695 7ff646dac380 26688->26695 26704 7ff646d8129c 33 API calls 26689->26704 26696 7ff646dabd8a 26691->26696 26698 7ff646dab65e 26694->26698 26703 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26695->26703 26697 7ff646d81150 33 API calls 26696->26697 26700 7ff646dabda2 26697->26700 26701 7ff646dab674 26698->26701 26702 7ff646dab665 GetLastError 26698->26702 26710 7ff646d82034 33 API calls 26700->26710 26705 7ff646dab71c 26701->26705 26709 7ff646dab72b 26701->26709 26711 7ff646dab68b GetTickCount 26701->26711 26702->26701 26706 7ff646dac386 26703->26706 26707 7ff646dabe4e 26704->26707 26705->26709 26728 7ff646dabb79 26705->26728 26712 7ff646d8255c 61 API calls 26706->26712 26722 7ff646d81fa0 31 API calls 26707->26722 26713 7ff646daba50 26709->26713 26717 7ff646d96454 34 API calls 26709->26717 26714 7ff646dabdbe 26710->26714 26941 7ff646d84228 26711->26941 26716 7ff646dac3e4 26712->26716 26713->26572 27172 7ff646d8bd0c 33 API calls 26713->27172 26718 7ff646d81fa0 31 API calls 26714->26718 26720 7ff646dac3e8 26716->26720 26727 7ff646dac489 GetDlgItem SetFocus 26716->26727 26754 7ff646dac3fd 26716->26754 26724 7ff646dab74e 26717->26724 26725 7ff646dabdcc 26718->26725 26737 7ff646db2320 _handle_error 8 API calls 26720->26737 26730 7ff646dabe78 26722->26730 27164 7ff646d9b914 102 API calls 26724->27164 26733 7ff646d81fa0 31 API calls 26725->26733 26732 7ff646dac4ba 26727->26732 26740 7ff646d9aae0 48 API calls 26728->26740 26729 7ff646daba75 27173 7ff646d81150 26729->27173 26736 7ff646d81fa0 31 API calls 26730->26736 26746 7ff646d8129c 33 API calls 26732->26746 26733->26641 26734 7ff646dab6ba 26739 7ff646d81fa0 31 API calls 26734->26739 26742 7ff646dabe83 26736->26742 26743 7ff646daca97 26737->26743 26738 7ff646dab768 26745 7ff646d9da98 48 API calls 26738->26745 26747 7ff646dab6c8 26739->26747 26748 7ff646dabba7 SetDlgItemTextW 26740->26748 26741 7ff646daba8a 26749 7ff646d9aae0 48 API calls 26741->26749 26750 7ff646d81fa0 31 API calls 26742->26750 26752 7ff646dab7aa GetCommandLineW 26745->26752 26753 7ff646dac4cc 26746->26753 26951 7ff646d92134 26747->26951 26755 7ff646d82534 26748->26755 26756 7ff646daba97 26749->26756 26750->26757 26751 7ff646dac434 SendDlgItemMessageW 26758 7ff646dac454 26751->26758 26759 7ff646dac45d EndDialog 26751->26759 26760 7ff646dab84f 26752->26760 26761 7ff646dab869 26752->26761 27178 7ff646d980d8 33 API calls 26753->27178 26754->26720 26754->26751 26763 7ff646dabbc5 SetDlgItemTextW GetDlgItem 26755->26763 26764 7ff646d81150 33 API calls 26756->26764 26757->26590 26758->26759 26759->26720 26776 7ff646d820b0 33 API calls 26760->26776 27165 7ff646daab54 33 API calls _handle_error 26761->27165 26768 7ff646dabbf0 GetWindowLongPtrW SetWindowLongPtrW 26763->26768 26769 7ff646dabc13 26763->26769 26770 7ff646dabaaa 26764->26770 26765 7ff646dac4e0 26771 7ff646d8250c SetDlgItemTextW 26765->26771 26768->26769 26967 7ff646dace88 26769->26967 26775 7ff646d81fa0 31 API calls 26770->26775 26777 7ff646dac4f4 26771->26777 26772 7ff646dab87a 27166 7ff646daab54 33 API calls _handle_error 26772->27166 26782 7ff646dabab5 26775->26782 26776->26761 26789 7ff646dac526 SendDlgItemMessageW FindFirstFileW 26777->26789 26779 7ff646dab704 26786 7ff646d9204c 100 API calls 26779->26786 26780 7ff646dab6f5 GetLastError 26780->26779 26784 7ff646d81fa0 31 API calls 26782->26784 26783 7ff646dace88 161 API calls 26787 7ff646dabc3c 26783->26787 26788 7ff646dabac3 26784->26788 26785 7ff646dab88b 27167 7ff646daab54 33 API calls _handle_error 26785->27167 26791 7ff646dab711 26786->26791 27120 7ff646daf974 26787->27120 26799 7ff646d9aae0 48 API calls 26788->26799 26793 7ff646dac57b 26789->26793 26885 7ff646daca04 26789->26885 26795 7ff646d81fa0 31 API calls 26791->26795 26803 7ff646d9aae0 48 API calls 26793->26803 26794 7ff646dab89c 27168 7ff646d9b9b4 102 API calls 26794->27168 26795->26705 26798 7ff646dace88 161 API calls 26814 7ff646dabc6a 26798->26814 26802 7ff646dabadb 26799->26802 26800 7ff646daca81 26800->26720 26801 7ff646dab8b3 27169 7ff646dafbdc 33 API calls 26801->27169 26815 7ff646d8129c 33 API calls 26802->26815 26807 7ff646dac59e 26803->26807 26804 7ff646dacaa9 26809 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26804->26809 26806 7ff646dabc96 27177 7ff646d82298 GetDlgItem EnableWindow 26806->27177 26820 7ff646d8129c 33 API calls 26807->26820 26808 7ff646dab8d2 CreateFileMappingW 26812 7ff646dab911 MapViewOfFile 26808->26812 26813 7ff646dab953 ShellExecuteExW 26808->26813 26810 7ff646dacaae 26809->26810 26818 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26810->26818 27170 7ff646db3640 26812->27170 26832 7ff646dab974 26813->26832 26814->26806 26819 7ff646dace88 161 API calls 26814->26819 26827 7ff646dabb04 26815->26827 26816 7ff646dab3f5 26816->26572 26816->26596 26821 7ff646dacab4 26818->26821 26819->26806 26822 7ff646dac5cd 26820->26822 26825 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26821->26825 26823 7ff646d81150 33 API calls 26822->26823 26828 7ff646dac5e8 26823->26828 26824 7ff646dab9c3 26833 7ff646dab9ef 26824->26833 26834 7ff646dab9dc UnmapViewOfFile CloseHandle 26824->26834 26829 7ff646dacaba 26825->26829 26826 7ff646dabb5a 26830 7ff646d81fa0 31 API calls 26826->26830 26827->26683 26827->26826 26831 7ff646d8e164 33 API calls 26828->26831 26836 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26829->26836 26830->26572 26835 7ff646dac5ff 26831->26835 26832->26824 26839 7ff646dab9b1 Sleep 26832->26839 26833->26647 26837 7ff646daba25 26833->26837 26834->26833 26838 7ff646d81fa0 31 API calls 26835->26838 26840 7ff646dacac0 26836->26840 26841 7ff646d81fa0 31 API calls 26837->26841 26842 7ff646dac60c 26838->26842 26839->26824 26839->26832 26845 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26840->26845 26843 7ff646daba42 26841->26843 26842->26810 26844 7ff646d81fa0 31 API calls 26842->26844 26846 7ff646d81fa0 31 API calls 26843->26846 26847 7ff646dac673 26844->26847 26848 7ff646dacac6 26845->26848 26846->26713 26849 7ff646d8250c SetDlgItemTextW 26847->26849 26851 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26848->26851 26850 7ff646dac687 FindClose 26849->26850 26852 7ff646dac6a3 26850->26852 26853 7ff646dac797 SendDlgItemMessageW 26850->26853 26854 7ff646dacacc 26851->26854 27179 7ff646daa2cc 10 API calls _handle_error 26852->27179 26856 7ff646dac7cb 26853->26856 26859 7ff646d9aae0 48 API calls 26856->26859 26857 7ff646dac6c6 26858 7ff646d9aae0 48 API calls 26857->26858 26861 7ff646dac6cf 26858->26861 26860 7ff646dac7d8 26859->26860 26863 7ff646d8129c 33 API calls 26860->26863 26862 7ff646d9da98 48 API calls 26861->26862 26867 7ff646dac6ec BuildCatchObjectHelperInternal 26862->26867 26864 7ff646dac807 26863->26864 26866 7ff646d81150 33 API calls 26864->26866 26865 7ff646d81fa0 31 API calls 26868 7ff646dac783 26865->26868 26869 7ff646dac822 26866->26869 26867->26821 26867->26865 26870 7ff646d8250c SetDlgItemTextW 26868->26870 26871 7ff646d8e164 33 API calls 26869->26871 26870->26853 26872 7ff646dac839 26871->26872 26873 7ff646d81fa0 31 API calls 26872->26873 26874 7ff646dac845 BuildCatchObjectHelperInternal 26873->26874 26875 7ff646d81fa0 31 API calls 26874->26875 26876 7ff646dac87f 26875->26876 26877 7ff646d81fa0 31 API calls 26876->26877 26878 7ff646dac88c 26877->26878 26878->26829 26879 7ff646d81fa0 31 API calls 26878->26879 26880 7ff646dac8f3 26879->26880 26881 7ff646d8250c SetDlgItemTextW 26880->26881 26882 7ff646dac907 26881->26882 26882->26885 27180 7ff646daa2cc 10 API calls _handle_error 26882->27180 26884 7ff646dac932 26886 7ff646d9aae0 48 API calls 26884->26886 26885->26720 26885->26800 26885->26804 26885->26848 26887 7ff646dac93c 26886->26887 26888 7ff646d9da98 48 API calls 26887->26888 26890 7ff646dac959 BuildCatchObjectHelperInternal 26888->26890 26889 7ff646d81fa0 31 API calls 26891 7ff646dac9f0 26889->26891 26890->26840 26890->26889 26892 7ff646d8250c SetDlgItemTextW 26891->26892 26892->26885 26894 7ff646d8256a 26893->26894 26895 7ff646d825d0 26893->26895 26894->26895 27181 7ff646d9a4ac 26894->27181 26895->26549 26897 7ff646d8258f 26897->26895 26898 7ff646d825a4 GetDlgItem 26897->26898 26898->26895 26899 7ff646d825b7 26898->26899 26899->26895 26900 7ff646d825be SetWindowTextW 26899->26900 26900->26895 26902 7ff646d82334 26901->26902 26903 7ff646d822fc 26901->26903 27230 7ff646d823f8 GetWindowTextLengthW 26902->27230 26905 7ff646d8129c 33 API calls 26903->26905 26906 7ff646d8232a BuildCatchObjectHelperInternal 26905->26906 26907 7ff646d81fa0 31 API calls 26906->26907 26910 7ff646d82389 26906->26910 26907->26910 26908 7ff646d823c8 26909 7ff646db2320 _handle_error 8 API calls 26908->26909 26911 7ff646d823dd 26909->26911 26910->26908 26912 7ff646d823f0 26910->26912 26911->26572 26911->26578 26911->26816 26913 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26912->26913 26914 7ff646d823f5 26913->26914 27242 7ff646daae1c PeekMessageW 26915->27242 26918 7ff646daf0f5 26922 7ff646daf101 ShowWindow SendMessageW SendMessageW 26918->26922 26919 7ff646daf143 SendMessageW SendMessageW 26920 7ff646daf1a4 SendMessageW 26919->26920 26921 7ff646daf189 26919->26921 26923 7ff646daf1c3 26920->26923 26924 7ff646daf1c6 SendMessageW SendMessageW 26920->26924 26921->26920 26922->26919 26923->26924 26925 7ff646daf1f3 SendMessageW 26924->26925 26926 7ff646daf218 SendMessageW 26924->26926 26925->26926 26927 7ff646db2320 _handle_error 8 API calls 26926->26927 26928 7ff646dab4a5 26927->26928 26928->26611 26928->26636 26932 7ff646d9309d 26929->26932 26937 7ff646d92f8e 26929->26937 26930 7ff646db2320 _handle_error 8 API calls 26931 7ff646d930b3 26930->26931 26931->26681 26931->26682 26932->26930 26933 7ff646d93077 26933->26932 26934 7ff646d93684 56 API calls 26933->26934 26934->26932 26935 7ff646d8129c 33 API calls 26935->26937 26937->26933 26937->26935 26938 7ff646d930c8 26937->26938 27247 7ff646d93684 26937->27247 26939 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26938->26939 26940 7ff646d930cd 26939->26940 26942 7ff646d84255 26941->26942 26943 7ff646d8426a 26942->26943 26944 7ff646d8129c 33 API calls 26942->26944 26945 7ff646db2320 _handle_error 8 API calls 26943->26945 26944->26943 26946 7ff646d842a1 26945->26946 26947 7ff646d83c84 26946->26947 26948 7ff646d83cab 26947->26948 27281 7ff646d8710c 26948->27281 26950 7ff646d83cbb BuildCatchObjectHelperInternal 26950->26734 26953 7ff646d9216a 26951->26953 26952 7ff646d9219e 26956 7ff646d96a0c 49 API calls 26952->26956 26963 7ff646d9227f 26952->26963 26953->26952 26954 7ff646d921b1 CreateFileW 26953->26954 26954->26952 26955 7ff646d922af 26957 7ff646db2320 _handle_error 8 API calls 26955->26957 26958 7ff646d92209 26956->26958 26960 7ff646d922c4 26957->26960 26961 7ff646d92246 26958->26961 26962 7ff646d9220d CreateFileW 26958->26962 26959 7ff646d820b0 33 API calls 26959->26955 26960->26779 26960->26780 26961->26963 26964 7ff646d922d8 26961->26964 26962->26961 26963->26955 26963->26959 26965 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26964->26965 26966 7ff646d922dd 26965->26966 27293 7ff646daaa08 26967->27293 26969 7ff646dad1ee 26970 7ff646d81fa0 31 API calls 26969->26970 26971 7ff646dad1f7 26970->26971 26972 7ff646db2320 _handle_error 8 API calls 26971->26972 26974 7ff646dabc2b 26972->26974 26973 7ff646d9d22c 33 API calls 27116 7ff646dacf03 BuildCatchObjectHelperInternal 26973->27116 26974->26783 26975 7ff646daeefa 27382 7ff646d8704c 47 API calls BuildCatchObjectHelperInternal 26975->27382 26978 7ff646daef00 27383 7ff646d8704c 47 API calls BuildCatchObjectHelperInternal 26978->27383 26981 7ff646daeeee 26983 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26981->26983 26982 7ff646daef06 26985 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26982->26985 26984 7ff646daeef4 26983->26984 27381 7ff646d8704c 47 API calls BuildCatchObjectHelperInternal 26984->27381 26987 7ff646daef0c 26985->26987 26989 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26987->26989 26990 7ff646daef12 26989->26990 26995 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26990->26995 26991 7ff646daee4a 26992 7ff646daeed2 26991->26992 26996 7ff646d820b0 33 API calls 26991->26996 27379 7ff646d81f80 33 API calls 3 library calls 26992->27379 26993 7ff646d813a4 33 API calls 26997 7ff646dadc3a GetTempPathW 26993->26997 26994 7ff646daeee8 27380 7ff646d82004 33 API calls std::_Xinvalid_argument 26994->27380 26998 7ff646daef18 26995->26998 27001 7ff646daee77 26996->27001 26997->27116 27005 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26998->27005 26999 7ff646d962dc 35 API calls 26999->27116 27378 7ff646daabe8 33 API calls 3 library calls 27001->27378 27004 7ff646daee8d 27012 7ff646d81fa0 31 API calls 27004->27012 27015 7ff646daeea4 BuildCatchObjectHelperInternal 27004->27015 27010 7ff646daef1e 27005->27010 27006 7ff646d82520 SetWindowTextW 27006->27116 27009 7ff646dbbb8c 43 API calls 27009->27116 27016 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27010->27016 27012->27015 27013 7ff646d81fa0 31 API calls 27013->26992 27014 7ff646dae7f3 27014->26992 27014->26994 27017 7ff646db21d0 33 API calls 27014->27017 27025 7ff646dae83b BuildCatchObjectHelperInternal 27014->27025 27015->27013 27018 7ff646daef24 27016->27018 27017->27025 27024 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27018->27024 27020 7ff646daaa08 33 API calls 27020->27116 27021 7ff646daef6c 27386 7ff646d82004 33 API calls std::_Xinvalid_argument 27021->27386 27022 7ff646d820b0 33 API calls 27022->27116 27023 7ff646daef78 27388 7ff646d82004 33 API calls std::_Xinvalid_argument 27023->27388 27028 7ff646daef2a 27024->27028 27033 7ff646d820b0 33 API calls 27025->27033 27075 7ff646daeb8f 27025->27075 27027 7ff646d81fa0 31 API calls 27027->26991 27039 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27028->27039 27029 7ff646daef72 27387 7ff646d81f80 33 API calls 3 library calls 27029->27387 27030 7ff646d820b0 33 API calls 27113 7ff646dad489 27030->27113 27032 7ff646daef66 27385 7ff646d81f80 33 API calls 3 library calls 27032->27385 27040 7ff646dae963 27033->27040 27036 7ff646daed40 27036->27023 27036->27029 27055 7ff646daed3b BuildCatchObjectHelperInternal 27036->27055 27060 7ff646db21d0 33 API calls 27036->27060 27038 7ff646daec2a 27038->27021 27038->27032 27047 7ff646daec72 BuildCatchObjectHelperInternal 27038->27047 27038->27055 27057 7ff646db21d0 33 API calls 27038->27057 27046 7ff646daef30 27039->27046 27048 7ff646daef60 27040->27048 27056 7ff646d8129c 33 API calls 27040->27056 27041 7ff646d82674 31 API calls 27041->27116 27044 7ff646da99c8 31 API calls 27044->27116 27045 7ff646d8e164 33 API calls 27045->27116 27061 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27046->27061 27298 7ff646daf4e0 27047->27298 27384 7ff646d8704c 47 API calls BuildCatchObjectHelperInternal 27048->27384 27049 7ff646d93d34 51 API calls 27049->27116 27051 7ff646dad5e9 GetDlgItem 27059 7ff646d82520 SetWindowTextW 27051->27059 27053 7ff646d9dc2c 33 API calls 27053->27116 27055->27027 27062 7ff646dae9a6 27056->27062 27057->27047 27063 7ff646dad608 SendMessageW 27059->27063 27060->27055 27064 7ff646daef36 27061->27064 27374 7ff646d9d22c 27062->27374 27063->27113 27068 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27064->27068 27067 7ff646d95b60 53 API calls 27067->27116 27074 7ff646daef3c 27068->27074 27069 7ff646dad63c SendMessageW 27069->27113 27070 7ff646d95aa8 33 API calls 27070->27116 27073 7ff646d93f30 54 API calls 27073->27116 27077 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27074->27077 27075->27036 27075->27038 27079 7ff646daef54 27075->27079 27080 7ff646daef5a 27075->27080 27083 7ff646daef42 27077->27083 27081 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27079->27081 27086 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27080->27086 27081->27080 27082 7ff646d88d04 33 API calls 27082->27116 27088 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27083->27088 27084 7ff646dad95e SHFileOperationW 27084->27116 27086->27048 27087 7ff646d84228 33 API calls 27087->27116 27091 7ff646daef48 27088->27091 27089 7ff646d95820 33 API calls 27089->27116 27090 7ff646d932a8 51 API calls 27090->27116 27092 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27091->27092 27093 7ff646daef4e 27092->27093 27098 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27093->27098 27094 7ff646d8250c SetDlgItemTextW 27094->27116 27096 7ff646d97df4 47 API calls 27096->27116 27097 7ff646d81150 33 API calls 27097->27116 27098->27079 27099 7ff646da13c4 CompareStringW 27108 7ff646dae9d1 27099->27108 27101 7ff646d81fa0 31 API calls 27101->27108 27102 7ff646d82034 33 API calls 27102->27116 27103 7ff646d8129c 33 API calls 27103->27108 27106 7ff646d8129c 33 API calls 27106->27116 27107 7ff646d932bc 51 API calls 27107->27116 27108->27075 27108->27091 27108->27093 27108->27099 27108->27101 27108->27103 27111 7ff646d9d22c 33 API calls 27108->27111 27109 7ff646dadf99 EndDialog 27109->27116 27111->27108 27112 7ff646dadb21 MoveFileW 27112->27113 27114 7ff646dadb55 MoveFileExW 27112->27114 27113->26982 27113->27030 27113->27069 27115 7ff646d81fa0 31 API calls 27113->27115 27113->27116 27339 7ff646d8df4c 47 API calls BuildCatchObjectHelperInternal 27113->27339 27342 7ff646d82674 31 API calls _invalid_parameter_noinfo_noreturn 27113->27342 27343 7ff646daa440 116 API calls 2 library calls 27113->27343 27114->27113 27115->27113 27116->26969 27116->26973 27116->26975 27116->26978 27116->26981 27116->26984 27116->26987 27116->26990 27116->26991 27116->26993 27116->26998 27116->26999 27116->27006 27116->27009 27116->27010 27116->27014 27116->27018 27116->27020 27116->27022 27116->27028 27116->27041 27116->27044 27116->27045 27116->27046 27116->27049 27116->27053 27116->27064 27116->27067 27116->27070 27116->27073 27116->27074 27116->27082 27116->27083 27116->27084 27116->27087 27116->27089 27116->27090 27116->27094 27116->27096 27116->27097 27116->27102 27116->27106 27116->27107 27116->27109 27116->27112 27116->27113 27117 7ff646d92f58 56 API calls 27116->27117 27119 7ff646d81fa0 31 API calls 27116->27119 27297 7ff646da13c4 CompareStringW 27116->27297 27336 7ff646d9cfa4 35 API calls _invalid_parameter_noinfo_noreturn 27116->27336 27337 7ff646da95b4 33 API calls Concurrency::cancel_current_task 27116->27337 27338 7ff646db0684 31 API calls _invalid_parameter_noinfo_noreturn 27116->27338 27340 7ff646daa834 33 API calls _invalid_parameter_noinfo_noreturn 27116->27340 27341 7ff646da9518 33 API calls 27116->27341 27344 7ff646daabe8 33 API calls 3 library calls 27116->27344 27345 7ff646d97368 33 API calls 2 library calls 27116->27345 27346 7ff646d94088 33 API calls 27116->27346 27347 7ff646d965b0 33 API calls 3 library calls 27116->27347 27348 7ff646d972cc 27116->27348 27352 7ff646d81744 33 API calls 4 library calls 27116->27352 27353 7ff646d931bc 27116->27353 27367 7ff646d93ea0 FindClose 27116->27367 27368 7ff646da13f4 CompareStringW 27116->27368 27369 7ff646da9cd0 47 API calls 27116->27369 27370 7ff646da87d8 51 API calls 3 library calls 27116->27370 27371 7ff646daab54 33 API calls _handle_error 27116->27371 27372 7ff646d95b08 CompareStringW 27116->27372 27373 7ff646d97eb0 47 API calls 27116->27373 27117->27116 27119->27116 27121 7ff646daf9a3 27120->27121 27122 7ff646d820b0 33 API calls 27121->27122 27124 7ff646daf9b9 27122->27124 27123 7ff646daf9ee 27398 7ff646d8e34c 27123->27398 27124->27123 27125 7ff646d820b0 33 API calls 27124->27125 27125->27123 27127 7ff646dafa4b 27418 7ff646d8e7a8 27127->27418 27131 7ff646dafa61 27132 7ff646db2320 _handle_error 8 API calls 27131->27132 27133 7ff646dabc52 27132->27133 27133->26798 27135 7ff646da849c 4 API calls 27134->27135 27136 7ff646daf3bf 27135->27136 27137 7ff646daf4b7 27136->27137 27138 7ff646daf3c7 GetWindow 27136->27138 27140 7ff646db2320 _handle_error 8 API calls 27137->27140 27139 7ff646daf3e2 27138->27139 27139->27137 27142 7ff646daf3ee GetClassNameW 27139->27142 27144 7ff646daf496 GetWindow 27139->27144 27145 7ff646daf417 GetWindowLongPtrW 27139->27145 27141 7ff646dabe9b 27140->27141 27141->26561 27141->26562 28474 7ff646da13c4 CompareStringW 27142->28474 27144->27137 27144->27139 27145->27144 27146 7ff646daf429 SendMessageW 27145->27146 27146->27144 27147 7ff646daf445 GetObjectW 27146->27147 28475 7ff646da8504 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 27147->28475 27149 7ff646daf461 27150 7ff646da84cc 4 API calls 27149->27150 28476 7ff646da8df4 16 API calls _handle_error 27149->28476 27150->27149 27152 7ff646daf479 SendMessageW DeleteObject 27152->27144 27154 7ff646d8252a SetWindowTextW 27153->27154 27155 7ff646d82527 27153->27155 27156 7ff646dee2e0 27154->27156 27155->27154 27157->26582 27158->26610 27159->26655 27161 7ff646d932bc 51 API calls 27160->27161 27162 7ff646d932b1 27161->27162 27162->26668 27162->26687 27163->26668 27164->26738 27165->26772 27166->26785 27167->26794 27168->26801 27169->26808 27171 7ff646db3620 27170->27171 27171->26813 27171->27171 27172->26729 27174 7ff646d81177 27173->27174 27175 7ff646d82034 33 API calls 27174->27175 27176 7ff646d81185 BuildCatchObjectHelperInternal 27175->27176 27176->26741 27178->26765 27179->26857 27180->26884 27182 7ff646d93e28 swprintf 46 API calls 27181->27182 27183 7ff646d9a509 27182->27183 27184 7ff646da0f68 WideCharToMultiByte 27183->27184 27185 7ff646d9a519 27184->27185 27186 7ff646d9a589 27185->27186 27200 7ff646d99800 31 API calls 27185->27200 27203 7ff646d9a56a SetDlgItemTextW 27185->27203 27206 7ff646d99408 27186->27206 27189 7ff646d9a603 27191 7ff646d9a6c2 27189->27191 27192 7ff646d9a60c GetWindowLongPtrW 27189->27192 27190 7ff646d9a6f2 GetSystemMetrics GetWindow 27193 7ff646d9a821 27190->27193 27204 7ff646d9a71d 27190->27204 27221 7ff646d995a8 27191->27221 27195 7ff646dee2c0 27192->27195 27194 7ff646db2320 _handle_error 8 API calls 27193->27194 27197 7ff646d9a830 27194->27197 27198 7ff646d9a6aa GetWindowRect 27195->27198 27197->26897 27198->27191 27200->27185 27201 7ff646d9a6e5 SetWindowTextW 27201->27190 27202 7ff646d9a73e GetWindowRect 27202->27204 27203->27185 27204->27193 27204->27202 27205 7ff646d9a800 GetWindow 27204->27205 27205->27193 27205->27204 27207 7ff646d995a8 47 API calls 27206->27207 27209 7ff646d9944f 27207->27209 27208 7ff646db2320 _handle_error 8 API calls 27210 7ff646d9958e GetWindowRect GetClientRect 27208->27210 27211 7ff646d8129c 33 API calls 27209->27211 27219 7ff646d9955a 27209->27219 27210->27189 27210->27190 27212 7ff646d9949c 27211->27212 27213 7ff646d995a1 27212->27213 27214 7ff646d8129c 33 API calls 27212->27214 27215 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27213->27215 27217 7ff646d99514 27214->27217 27216 7ff646d995a7 27215->27216 27218 7ff646d9959c 27217->27218 27217->27219 27220 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27218->27220 27219->27208 27220->27213 27222 7ff646d93e28 swprintf 46 API calls 27221->27222 27223 7ff646d995eb 27222->27223 27224 7ff646da0f68 WideCharToMultiByte 27223->27224 27225 7ff646d99603 27224->27225 27226 7ff646d99800 31 API calls 27225->27226 27227 7ff646d9961b 27226->27227 27228 7ff646db2320 _handle_error 8 API calls 27227->27228 27229 7ff646d9962b 27228->27229 27229->27190 27229->27201 27231 7ff646d813a4 33 API calls 27230->27231 27232 7ff646d82462 GetWindowTextW 27231->27232 27233 7ff646d82494 27232->27233 27234 7ff646d8129c 33 API calls 27233->27234 27235 7ff646d824a2 27234->27235 27237 7ff646d82505 27235->27237 27240 7ff646d824dd 27235->27240 27236 7ff646db2320 _handle_error 8 API calls 27238 7ff646d824f3 27236->27238 27239 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27237->27239 27238->26906 27241 7ff646d8250a 27239->27241 27240->27236 27243 7ff646daae80 GetDlgItem 27242->27243 27244 7ff646daae3c GetMessageW 27242->27244 27243->26918 27243->26919 27245 7ff646daae6a TranslateMessage DispatchMessageW 27244->27245 27246 7ff646daae5b IsDialogMessageW 27244->27246 27245->27243 27246->27243 27246->27245 27249 7ff646d936b3 27247->27249 27248 7ff646d936e0 27251 7ff646d932bc 51 API calls 27248->27251 27249->27248 27250 7ff646d936cc CreateDirectoryW 27249->27250 27250->27248 27252 7ff646d9377d 27250->27252 27253 7ff646d936ee 27251->27253 27254 7ff646d9378d 27252->27254 27267 7ff646d93d34 27252->27267 27255 7ff646d93791 GetLastError 27253->27255 27257 7ff646d96a0c 49 API calls 27253->27257 27258 7ff646db2320 _handle_error 8 API calls 27254->27258 27255->27254 27259 7ff646d9371c 27257->27259 27260 7ff646d937b9 27258->27260 27261 7ff646d93720 CreateDirectoryW 27259->27261 27262 7ff646d9373b 27259->27262 27260->26937 27261->27262 27263 7ff646d93774 27262->27263 27264 7ff646d937ce 27262->27264 27263->27252 27263->27255 27265 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27264->27265 27266 7ff646d937d3 27265->27266 27268 7ff646d93d5e SetFileAttributesW 27267->27268 27269 7ff646d93d5b 27267->27269 27270 7ff646d93d74 27268->27270 27277 7ff646d93df5 27268->27277 27269->27268 27271 7ff646d96a0c 49 API calls 27270->27271 27273 7ff646d93d99 27271->27273 27272 7ff646db2320 _handle_error 8 API calls 27274 7ff646d93e0a 27272->27274 27275 7ff646d93dbc 27273->27275 27276 7ff646d93d9d SetFileAttributesW 27273->27276 27274->27254 27275->27277 27278 7ff646d93e1a 27275->27278 27276->27275 27277->27272 27279 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27278->27279 27280 7ff646d93e1f 27279->27280 27282 7ff646d8713b 27281->27282 27283 7ff646d87206 27281->27283 27285 7ff646d8714b BuildCatchObjectHelperInternal 27282->27285 27290 7ff646d83f48 33 API calls 2 library calls 27282->27290 27291 7ff646d8704c 47 API calls BuildCatchObjectHelperInternal 27283->27291 27285->26950 27287 7ff646d87273 27287->26950 27288 7ff646d8720b 27288->27287 27292 7ff646d8889c 8 API calls BuildCatchObjectHelperInternal 27288->27292 27290->27285 27291->27288 27292->27288 27294 7ff646daaa2f 27293->27294 27295 7ff646daaa36 27293->27295 27294->27116 27295->27294 27389 7ff646d81744 33 API calls 4 library calls 27295->27389 27297->27116 27303 7ff646daf529 __scrt_get_show_window_mode 27298->27303 27314 7ff646daf87d 27298->27314 27299 7ff646d81fa0 31 API calls 27300 7ff646daf89c 27299->27300 27301 7ff646db2320 _handle_error 8 API calls 27300->27301 27302 7ff646daf8a8 27301->27302 27302->27055 27305 7ff646daf684 27303->27305 27390 7ff646da13c4 CompareStringW 27303->27390 27306 7ff646d8129c 33 API calls 27305->27306 27307 7ff646daf6c0 27306->27307 27308 7ff646d932a8 51 API calls 27307->27308 27309 7ff646daf6ca 27308->27309 27310 7ff646d81fa0 31 API calls 27309->27310 27313 7ff646daf6d5 27310->27313 27311 7ff646daf742 ShellExecuteExW 27312 7ff646daf846 27311->27312 27320 7ff646daf755 27311->27320 27312->27314 27318 7ff646daf8fb 27312->27318 27313->27311 27315 7ff646d8129c 33 API calls 27313->27315 27314->27299 27317 7ff646daf717 27315->27317 27316 7ff646daf78e 27392 7ff646dafe24 PeekMessageW GetMessageW TranslateMessage DispatchMessageW WaitForSingleObject 27316->27392 27391 7ff646d95b60 53 API calls 2 library calls 27317->27391 27322 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27318->27322 27319 7ff646daf7e3 CloseHandle 27323 7ff646daf801 27319->27323 27324 7ff646daf7f2 27319->27324 27320->27316 27320->27319 27325 7ff646daf781 ShowWindow 27320->27325 27328 7ff646daf900 27322->27328 27323->27312 27332 7ff646daf837 ShowWindow 27323->27332 27393 7ff646da13c4 CompareStringW 27324->27393 27325->27316 27327 7ff646daf725 27331 7ff646d81fa0 31 API calls 27327->27331 27330 7ff646daf7a6 27330->27319 27334 7ff646daf7b4 GetExitCodeProcess 27330->27334 27333 7ff646daf72f 27331->27333 27332->27312 27333->27311 27334->27319 27335 7ff646daf7c7 27334->27335 27335->27319 27336->27116 27337->27116 27338->27116 27339->27113 27340->27116 27341->27116 27343->27051 27344->27116 27345->27116 27346->27116 27347->27116 27349 7ff646d972ea 27348->27349 27394 7ff646d8b3a8 27349->27394 27352->27084 27354 7ff646d931e4 27353->27354 27355 7ff646d931e7 DeleteFileW 27353->27355 27354->27355 27356 7ff646d931fd 27355->27356 27363 7ff646d9327c 27355->27363 27357 7ff646d96a0c 49 API calls 27356->27357 27359 7ff646d93222 27357->27359 27358 7ff646db2320 _handle_error 8 API calls 27360 7ff646d93291 27358->27360 27361 7ff646d93243 27359->27361 27362 7ff646d93226 DeleteFileW 27359->27362 27360->27116 27361->27363 27364 7ff646d932a1 27361->27364 27362->27361 27363->27358 27365 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27364->27365 27366 7ff646d932a6 27365->27366 27368->27116 27369->27116 27370->27116 27371->27116 27372->27116 27373->27116 27377 7ff646d9d25e 27374->27377 27375 7ff646d9d292 27375->27108 27376 7ff646d81744 33 API calls 27376->27377 27377->27375 27377->27376 27378->27004 27379->26994 27381->26975 27382->26978 27383->26982 27384->27032 27385->27021 27387->27023 27389->27295 27390->27305 27391->27327 27392->27330 27393->27323 27397 7ff646d8b3f2 __scrt_get_show_window_mode 27394->27397 27395 7ff646db2320 _handle_error 8 API calls 27396 7ff646d8b4b6 27395->27396 27396->27116 27397->27395 27454 7ff646d986ec 27398->27454 27400 7ff646d8e3c4 27460 7ff646d8e600 27400->27460 27402 7ff646d8e4d4 27405 7ff646db21d0 33 API calls 27402->27405 27403 7ff646d8e549 27406 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27403->27406 27404 7ff646d8e454 27404->27402 27404->27403 27407 7ff646d8e4f0 27405->27407 27415 7ff646d8e54e 27406->27415 27466 7ff646da3148 102 API calls 27407->27466 27409 7ff646d8e51d 27410 7ff646db2320 _handle_error 8 API calls 27409->27410 27411 7ff646d8e52d 27410->27411 27411->27127 27412 7ff646d918c2 27413 7ff646d9190d 27412->27413 27416 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27412->27416 27413->27127 27414 7ff646d81fa0 31 API calls 27414->27415 27415->27412 27415->27413 27415->27414 27417 7ff646d9193b 27416->27417 27420 7ff646d8e7ea 27418->27420 27419 7ff646d8e8a1 27430 7ff646d8e900 27419->27430 27474 7ff646d8f578 27419->27474 27420->27419 27422 7ff646d8e864 27420->27422 27467 7ff646d93ec8 27420->27467 27422->27419 27423 7ff646d8e993 27422->27423 27424 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27423->27424 27426 7ff646d8e998 27424->27426 27425 7ff646d8e955 27428 7ff646db2320 _handle_error 8 API calls 27425->27428 27429 7ff646d8e97e 27428->27429 27432 7ff646d8e578 27429->27432 27430->27425 27510 7ff646d828a4 82 API calls 2 library calls 27430->27510 28460 7ff646d915d8 27432->28460 27435 7ff646d8e59e 27437 7ff646d81fa0 31 API calls 27435->27437 27436 7ff646da1870 108 API calls 27436->27435 27438 7ff646d8e5b7 27437->27438 27439 7ff646d81fa0 31 API calls 27438->27439 27440 7ff646d8e5c3 27439->27440 27441 7ff646d81fa0 31 API calls 27440->27441 27442 7ff646d8e5cf 27441->27442 27443 7ff646d9878c 108 API calls 27442->27443 27444 7ff646d8e5db 27443->27444 27445 7ff646d81fa0 31 API calls 27444->27445 27446 7ff646d8e5e4 27445->27446 27447 7ff646d81fa0 31 API calls 27446->27447 27450 7ff646d8e5ed 27447->27450 27448 7ff646d918c2 27449 7ff646d9190d 27448->27449 27452 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27448->27452 27449->27131 27450->27448 27450->27449 27451 7ff646d81fa0 31 API calls 27450->27451 27451->27450 27453 7ff646d9193b 27452->27453 27455 7ff646d9870a 27454->27455 27456 7ff646db21d0 33 API calls 27455->27456 27457 7ff646d9872f 27456->27457 27458 7ff646db21d0 33 API calls 27457->27458 27459 7ff646d98759 27458->27459 27459->27400 27461 7ff646d8e627 27460->27461 27463 7ff646d8e62c BuildCatchObjectHelperInternal 27460->27463 27462 7ff646d81fa0 31 API calls 27461->27462 27462->27463 27464 7ff646d81fa0 31 API calls 27463->27464 27465 7ff646d8e668 BuildCatchObjectHelperInternal 27463->27465 27464->27465 27465->27404 27466->27409 27468 7ff646d972cc 8 API calls 27467->27468 27469 7ff646d93ee1 27468->27469 27470 7ff646d93f0f 27469->27470 27511 7ff646d940bc 27469->27511 27470->27420 27473 7ff646d93efa FindClose 27473->27470 27475 7ff646d8f598 _snwprintf 27474->27475 27537 7ff646d82950 27475->27537 27478 7ff646d8f5cc 27482 7ff646d8f5fc 27478->27482 27552 7ff646d833e4 27478->27552 27481 7ff646d8f5f8 27481->27482 27584 7ff646d83ad8 27481->27584 27803 7ff646d82c54 27482->27803 27489 7ff646d8f7cb 27594 7ff646d8f8a4 27489->27594 27491 7ff646d88d04 33 API calls 27492 7ff646d8f662 27491->27492 27823 7ff646d97918 48 API calls 2 library calls 27492->27823 27494 7ff646d8f677 27496 7ff646d93ec8 55 API calls 27494->27496 27504 7ff646d8f6ad 27496->27504 27497 7ff646d8f842 27497->27482 27615 7ff646d869f8 27497->27615 27626 7ff646d8f930 27497->27626 27502 7ff646d8f89a 27505 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27502->27505 27503 7ff646d8f74d 27503->27489 27503->27502 27506 7ff646d8f895 27503->27506 27504->27502 27504->27503 27507 7ff646d93ec8 55 API calls 27504->27507 27824 7ff646d97918 48 API calls 2 library calls 27504->27824 27509 7ff646d8f8a0 27505->27509 27508 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27506->27508 27507->27504 27508->27502 27510->27425 27512 7ff646d941d2 FindNextFileW 27511->27512 27513 7ff646d940f9 FindFirstFileW 27511->27513 27515 7ff646d941e1 GetLastError 27512->27515 27516 7ff646d941f3 27512->27516 27513->27516 27517 7ff646d9411e 27513->27517 27536 7ff646d941c0 27515->27536 27518 7ff646d94211 27516->27518 27520 7ff646d820b0 33 API calls 27516->27520 27519 7ff646d96a0c 49 API calls 27517->27519 27523 7ff646d8129c 33 API calls 27518->27523 27522 7ff646d94144 27519->27522 27520->27518 27521 7ff646db2320 _handle_error 8 API calls 27524 7ff646d93ef4 27521->27524 27525 7ff646d94148 FindFirstFileW 27522->27525 27526 7ff646d94167 27522->27526 27527 7ff646d9423b 27523->27527 27524->27470 27524->27473 27525->27526 27526->27516 27528 7ff646d941af GetLastError 27526->27528 27530 7ff646d94314 27526->27530 27529 7ff646d98090 47 API calls 27527->27529 27528->27536 27531 7ff646d94249 27529->27531 27532 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27530->27532 27534 7ff646d9430f 27531->27534 27531->27536 27533 7ff646d9431a 27532->27533 27535 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27534->27535 27535->27530 27536->27521 27538 7ff646d8296c 27537->27538 27539 7ff646d986ec 33 API calls 27538->27539 27540 7ff646d8298d 27539->27540 27541 7ff646db21d0 33 API calls 27540->27541 27544 7ff646d82ac2 27540->27544 27542 7ff646d82ab0 27541->27542 27542->27544 27546 7ff646d891c8 35 API calls 27542->27546 27825 7ff646d94d04 27544->27825 27546->27544 27547 7ff646d92ca8 27551 7ff646d924c0 54 API calls 27547->27551 27548 7ff646d92cc1 27549 7ff646d92cc5 27548->27549 27839 7ff646d8b7e8 99 API calls 2 library calls 27548->27839 27549->27478 27551->27548 27580 7ff646d928d0 104 API calls 27552->27580 27553 7ff646d83431 __scrt_get_show_window_mode 27561 7ff646d83601 27553->27561 27563 7ff646d8344e 27553->27563 27577 7ff646d92bb0 101 API calls 27553->27577 27554 7ff646d83674 27840 7ff646d828a4 82 API calls 2 library calls 27554->27840 27556 7ff646d869f8 141 API calls 27558 7ff646d83682 27556->27558 27557 7ff646d834cc 27581 7ff646d928d0 104 API calls 27557->27581 27558->27556 27559 7ff646d8370c 27558->27559 27558->27561 27582 7ff646d92aa0 101 API calls 27558->27582 27559->27561 27564 7ff646d83740 27559->27564 27841 7ff646d828a4 82 API calls 2 library calls 27559->27841 27561->27481 27562 7ff646d835cb 27562->27563 27565 7ff646d835d7 27562->27565 27563->27554 27563->27558 27564->27561 27568 7ff646d8384d 27564->27568 27583 7ff646d92bb0 101 API calls 27564->27583 27565->27561 27566 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27565->27566 27569 7ff646d83891 27566->27569 27567 7ff646d834eb 27567->27562 27579 7ff646d92aa0 101 API calls 27567->27579 27568->27561 27570 7ff646d820b0 33 API calls 27568->27570 27569->27481 27570->27561 27571 7ff646d869f8 141 API calls 27573 7ff646d8378e 27571->27573 27572 7ff646d835a7 27572->27562 27575 7ff646d928d0 104 API calls 27572->27575 27573->27571 27574 7ff646d83803 27573->27574 27576 7ff646d92aa0 101 API calls 27573->27576 27578 7ff646d92aa0 101 API calls 27574->27578 27575->27562 27576->27573 27577->27557 27578->27568 27579->27572 27580->27553 27581->27567 27582->27558 27583->27573 27585 7ff646d83af9 27584->27585 27590 7ff646d83b55 27584->27590 27842 7ff646d83378 27585->27842 27587 7ff646db2320 _handle_error 8 API calls 27588 7ff646d83b67 27587->27588 27588->27489 27588->27491 27590->27587 27591 7ff646d83b6c 27592 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27591->27592 27593 7ff646d83b71 27592->27593 28075 7ff646d9886c 27594->28075 27596 7ff646d8f8ba 28079 7ff646d9ef60 GetSystemTime SystemTimeToFileTime 27596->28079 27599 7ff646da0994 27600 7ff646db0340 27599->27600 27601 7ff646d97df4 47 API calls 27600->27601 27602 7ff646db0373 27601->27602 27603 7ff646d9aae0 48 API calls 27602->27603 27604 7ff646db0387 27603->27604 27605 7ff646d9da98 48 API calls 27604->27605 27606 7ff646db0397 27605->27606 27607 7ff646d81fa0 31 API calls 27606->27607 27608 7ff646db03a2 27607->27608 28088 7ff646dafc68 27608->28088 27616 7ff646d86a0e 27615->27616 27622 7ff646d86a0a 27615->27622 27625 7ff646d92bb0 101 API calls 27616->27625 27617 7ff646d86a1b 27618 7ff646d86a2f 27617->27618 27619 7ff646d86a3e 27617->27619 27618->27622 28100 7ff646d85e24 27618->28100 28183 7ff646d85130 130 API calls 2 library calls 27619->28183 27621 7ff646d86a3c 27621->27622 28184 7ff646d8466c 82 API calls 27621->28184 27622->27497 27625->27617 27627 7ff646d8f978 27626->27627 27631 7ff646d8f9b0 27627->27631 27686 7ff646d8fa34 27627->27686 28300 7ff646da612c 146 API calls 3 library calls 27627->28300 27629 7ff646d91189 27632 7ff646d9118e 27629->27632 27633 7ff646d911e1 27629->27633 27630 7ff646db2320 _handle_error 8 API calls 27634 7ff646d911c4 27630->27634 27631->27629 27636 7ff646d8f9d0 27631->27636 27631->27686 27632->27686 28352 7ff646d8dd08 179 API calls 27632->28352 27633->27686 28353 7ff646da612c 146 API calls 3 library calls 27633->28353 27634->27497 27636->27686 28221 7ff646d89bb0 27636->28221 27639 7ff646d8fad6 28234 7ff646d95ef8 27639->28234 27642 7ff646d8fb7a 27686->27630 27804 7ff646d82c88 27803->27804 27805 7ff646d82c74 27803->27805 27806 7ff646d81fa0 31 API calls 27804->27806 27805->27804 28439 7ff646d82d80 108 API calls _invalid_parameter_noinfo_noreturn 27805->28439 27808 7ff646d82ca1 27806->27808 27810 7ff646d82d64 27808->27810 28440 7ff646d83090 31 API calls _invalid_parameter_noinfo_noreturn 27808->28440 27812 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27810->27812 27811 7ff646d82d08 28441 7ff646d83090 31 API calls _invalid_parameter_noinfo_noreturn 27811->28441 27814 7ff646d82d7c 27812->27814 27815 7ff646d82d14 27816 7ff646d81fa0 31 API calls 27815->27816 27817 7ff646d82d20 27816->27817 28442 7ff646d9878c 27817->28442 27823->27494 27824->27504 27826 7ff646d94d32 __scrt_get_show_window_mode 27825->27826 27835 7ff646d94bac 27826->27835 27828 7ff646d94d54 27829 7ff646d94d90 27828->27829 27831 7ff646d94dae 27828->27831 27830 7ff646db2320 _handle_error 8 API calls 27829->27830 27832 7ff646d82b32 27830->27832 27833 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27831->27833 27832->27478 27832->27547 27834 7ff646d94db3 27833->27834 27836 7ff646d94c2f BuildCatchObjectHelperInternal 27835->27836 27837 7ff646d94c27 27835->27837 27836->27828 27838 7ff646d81fa0 31 API calls 27837->27838 27838->27836 27839->27549 27840->27561 27841->27564 27843 7ff646d8339a 27842->27843 27844 7ff646d83396 27842->27844 27848 7ff646d83294 27843->27848 27844->27590 27844->27591 27847 7ff646d92aa0 101 API calls 27847->27844 27849 7ff646d832bb 27848->27849 27851 7ff646d832f6 27848->27851 27850 7ff646d869f8 141 API calls 27849->27850 27855 7ff646d832db 27850->27855 27856 7ff646d86e74 27851->27856 27855->27847 27860 7ff646d86e95 27856->27860 27857 7ff646d869f8 141 API calls 27857->27860 27858 7ff646d8331d 27858->27855 27861 7ff646d83904 27858->27861 27860->27857 27860->27858 27888 7ff646d9e808 27860->27888 27896 7ff646d86a7c 27861->27896 27864 7ff646d8396a 27867 7ff646d8399a 27864->27867 27868 7ff646d83989 27864->27868 27866 7ff646d83a8a 27869 7ff646db2320 _handle_error 8 API calls 27866->27869 27873 7ff646d839a3 27867->27873 27876 7ff646d839ec 27867->27876 27937 7ff646da0d54 33 API calls 27868->27937 27872 7ff646d83a9e 27869->27872 27870 7ff646d83ab3 27874 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27870->27874 27872->27855 27938 7ff646da0c80 33 API calls 27873->27938 27877 7ff646d83ab8 27874->27877 27939 7ff646d826b4 33 API calls BuildCatchObjectHelperInternal 27876->27939 27881 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27877->27881 27878 7ff646d839b0 27882 7ff646d81fa0 31 API calls 27878->27882 27886 7ff646d839c0 BuildCatchObjectHelperInternal 27878->27886 27880 7ff646d83a13 27940 7ff646da0ae8 34 API calls _invalid_parameter_noinfo_noreturn 27880->27940 27885 7ff646d83abe 27881->27885 27882->27886 27883 7ff646d81fa0 31 API calls 27887 7ff646d8394f 27883->27887 27886->27883 27887->27866 27887->27870 27887->27877 27889 7ff646d9e811 27888->27889 27890 7ff646d9e82b 27889->27890 27894 7ff646d8b664 RtlPcToFileHeader RaiseException std::_Xinvalid_argument 27889->27894 27892 7ff646d9e845 SetThreadExecutionState 27890->27892 27895 7ff646d8b664 RtlPcToFileHeader RaiseException std::_Xinvalid_argument 27890->27895 27894->27890 27895->27892 27897 7ff646d86a96 _snwprintf 27896->27897 27898 7ff646d86ae4 27897->27898 27899 7ff646d86ac4 27897->27899 27901 7ff646d86d4d 27898->27901 27904 7ff646d86b0f 27898->27904 27979 7ff646d828a4 82 API calls 2 library calls 27899->27979 28008 7ff646d828a4 82 API calls 2 library calls 27901->28008 27903 7ff646d86ad0 27905 7ff646db2320 _handle_error 8 API calls 27903->27905 27904->27903 27941 7ff646da1f94 27904->27941 27906 7ff646d8394b 27905->27906 27906->27864 27906->27887 27928 7ff646d82794 27906->27928 27909 7ff646d86b85 27910 7ff646d86c2a 27909->27910 27927 7ff646d86b7b 27909->27927 27985 7ff646d98968 109 API calls 27909->27985 27950 7ff646d94760 27910->27950 27911 7ff646d86b80 27911->27909 27981 7ff646d840b0 27911->27981 27912 7ff646d86b6e 27980 7ff646d828a4 82 API calls 2 library calls 27912->27980 27918 7ff646d86c52 27919 7ff646d86cc7 27918->27919 27920 7ff646d86cd1 27918->27920 27954 7ff646d91794 27919->27954 27986 7ff646da1f20 27920->27986 27923 7ff646d86ccf 28006 7ff646d94700 8 API calls _handle_error 27923->28006 27925 7ff646d86cfd 27925->27927 27969 7ff646da1870 27927->27969 27929 7ff646d8289b 27928->27929 27932 7ff646d827d1 27928->27932 28074 7ff646d82018 33 API calls std::_Xinvalid_argument 27929->28074 27933 7ff646db21d0 33 API calls 27932->27933 27934 7ff646d827ed __std_swap_ranges_trivially_swappable 27932->27934 27933->27934 28073 7ff646d83bc0 31 API calls _invalid_parameter_noinfo_noreturn 27934->28073 27936 7ff646d82888 27936->27864 27937->27887 27938->27878 27939->27880 27940->27887 27942 7ff646da2056 std::bad_alloc::bad_alloc 27941->27942 27944 7ff646da1fc5 std::bad_alloc::bad_alloc 27941->27944 27943 7ff646db4078 std::_Xinvalid_argument 2 API calls 27942->27943 27943->27944 27945 7ff646db4078 std::_Xinvalid_argument 2 API calls 27944->27945 27946 7ff646da200f std::bad_alloc::bad_alloc 27944->27946 27947 7ff646d86b59 27944->27947 27945->27946 27946->27947 27948 7ff646db4078 std::_Xinvalid_argument 2 API calls 27946->27948 27947->27909 27947->27911 27947->27912 27949 7ff646da20a9 27948->27949 27951 7ff646d94780 27950->27951 27953 7ff646d9478a 27950->27953 27952 7ff646db21d0 33 API calls 27951->27952 27952->27953 27953->27918 27955 7ff646d917be __scrt_get_show_window_mode 27954->27955 28009 7ff646d98a48 27955->28009 27957 7ff646d917f2 27970 7ff646da188e 27969->27970 27972 7ff646da18a1 27970->27972 28025 7ff646d9e948 27970->28025 27976 7ff646da18d8 27972->27976 28032 7ff646db236c 27972->28032 27974 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 27975 7ff646da1ad0 27974->27975 27978 7ff646da1a37 27976->27978 28036 7ff646d9a984 31 API calls _invalid_parameter_noinfo_noreturn 27976->28036 27978->27974 27979->27903 27980->27927 27982 7ff646d840dd 27981->27982 27984 7ff646d840d7 __scrt_get_show_window_mode 27981->27984 27982->27984 28037 7ff646d84120 27982->28037 27984->27909 27985->27910 27987 7ff646da1f29 27986->27987 27988 7ff646da1f5d 27987->27988 27989 7ff646da1f55 27987->27989 27990 7ff646da1f49 27987->27990 27988->27923 28064 7ff646da3964 156 API calls 27989->28064 28043 7ff646da20ac 27990->28043 28006->27925 28008->27903 28011 7ff646d98bcd 28009->28011 28015 7ff646d98a91 BuildCatchObjectHelperInternal 28009->28015 28010 7ff646d98c1a 28012 7ff646d9e808 SetThreadExecutionState RtlPcToFileHeader RaiseException 28010->28012 28011->28010 28013 7ff646d8a174 8 API calls 28011->28013 28016 7ff646d98c1f 28012->28016 28013->28010 28014 7ff646da612c 146 API calls 28014->28015 28015->28011 28015->28014 28015->28016 28017 7ff646d94888 108 API calls 28015->28017 28018 7ff646d928d0 104 API calls 28015->28018 28016->27957 28017->28015 28018->28015 28026 7ff646d9ecd8 103 API calls 28025->28026 28027 7ff646d9e95f ReleaseSemaphore 28026->28027 28028 7ff646d9e9a3 DeleteCriticalSection CloseHandle CloseHandle 28027->28028 28029 7ff646d9e984 28027->28029 28030 7ff646d9ea5c 101 API calls 28029->28030 28031 7ff646d9e98e CloseHandle 28030->28031 28031->28028 28031->28029 28033 7ff646db239f 28032->28033 28034 7ff646db23c8 28033->28034 28035 7ff646da1870 108 API calls 28033->28035 28034->27976 28035->28033 28036->27978 28040 7ff646d84149 28037->28040 28042 7ff646d84168 __std_swap_ranges_trivially_swappable __scrt_get_show_window_mode 28037->28042 28038 7ff646d82018 33 API calls 28039 7ff646d841eb 28038->28039 28041 7ff646db21d0 33 API calls 28040->28041 28040->28042 28041->28042 28042->28038 28045 7ff646da20c8 __scrt_get_show_window_mode 28043->28045 28044 7ff646da21ba 28045->28044 28046 7ff646d8b75c 82 API calls 28045->28046 28046->28045 28064->27988 28073->27936 28076 7ff646d98882 28075->28076 28077 7ff646d98892 28075->28077 28082 7ff646d923f0 28076->28082 28077->27596 28080 7ff646db2320 _handle_error 8 API calls 28079->28080 28081 7ff646d8f7dc 28080->28081 28081->27497 28081->27599 28083 7ff646d9240f 28082->28083 28086 7ff646d92aa0 101 API calls 28083->28086 28084 7ff646d92428 28087 7ff646d92bb0 101 API calls 28084->28087 28085 7ff646d92438 28085->28077 28086->28084 28087->28085 28089 7ff646dafc94 28088->28089 28090 7ff646d8129c 33 API calls 28089->28090 28091 7ff646dafca4 28090->28091 28092 7ff646daf0a4 24 API calls 28091->28092 28093 7ff646dafcb1 28092->28093 28094 7ff646dafceb 28093->28094 28096 7ff646dafd03 28093->28096 28098 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 28096->28098 28101 7ff646d85e67 28100->28101 28103 7ff646d85ea5 28101->28103 28107 7ff646d85eb7 28101->28107 28131 7ff646d86084 28101->28131 28195 7ff646d828a4 82 API calls 2 library calls 28103->28195 28105 7ff646d86134 28202 7ff646d86fcc 82 API calls 28105->28202 28107->28105 28108 7ff646d85f44 28107->28108 28196 7ff646d86f38 33 API calls BuildCatchObjectHelperInternal 28107->28196 28197 7ff646d86d88 82 API calls 28108->28197 28109 7ff646d869af 28111 7ff646db2320 _handle_error 8 API calls 28109->28111 28114 7ff646d869c3 28111->28114 28113 7ff646d869e4 28116 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 28113->28116 28114->27621 28115 7ff646d86973 28179 7ff646d85eb2 28115->28179 28215 7ff646d8466c 82 API calls 28115->28215 28118 7ff646d869e9 28116->28118 28117 7ff646d8612e 28117->28105 28117->28115 28123 7ff646d985f0 104 API calls 28117->28123 28121 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 28118->28121 28124 7ff646d869ef 28121->28124 28122 7ff646d86034 28126 7ff646db236c 108 API calls 28122->28126 28122->28131 28125 7ff646d861a4 28123->28125 28127 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 28124->28127 28125->28105 28136 7ff646d861ac 28125->28136 28128 7ff646d8606e 28126->28128 28129 7ff646d869f5 28127->28129 28130 7ff646db236c 108 API calls 28128->28130 28130->28131 28185 7ff646d985f0 28131->28185 28132 7ff646d86097 28201 7ff646d8433c 82 API calls 2 library calls 28132->28201 28135 7ff646d85f5d 28135->28122 28135->28132 28198 7ff646d8433c 82 API calls 2 library calls 28135->28198 28199 7ff646d86d88 82 API calls 28135->28199 28200 7ff646d8a1a0 109 API calls _handle_error 28135->28200 28137 7ff646d8623f 28136->28137 28203 7ff646d8466c 82 API calls 28136->28203 28137->28115 28139 7ff646d860a1 28141 7ff646db236c 108 API calls 28139->28141 28139->28179 28142 7ff646d860f4 28141->28142 28179->28109 28179->28113 28179->28124 28183->27621 28186 7ff646d98614 28185->28186 28187 7ff646d9869a 28185->28187 28188 7ff646d9867c 28186->28188 28189 7ff646d840b0 33 API calls 28186->28189 28187->28188 28190 7ff646d840b0 33 API calls 28187->28190 28188->28117 28191 7ff646d9864d 28189->28191 28192 7ff646d986b3 28190->28192 28216 7ff646d8a174 28191->28216 28194 7ff646d928d0 104 API calls 28192->28194 28194->28188 28195->28179 28197->28135 28198->28135 28199->28135 28200->28135 28201->28139 28202->28179 28217 7ff646d8a185 28216->28217 28219 7ff646d8a19a 28217->28219 28220 7ff646d9af18 8 API calls 2 library calls 28217->28220 28219->28188 28220->28219 28229 7ff646d89be7 28221->28229 28222 7ff646d89c1b 28223 7ff646db2320 _handle_error 8 API calls 28222->28223 28224 7ff646d89c9d 28223->28224 28224->27639 28226 7ff646d89c83 28228 7ff646d81fa0 31 API calls 28226->28228 28228->28222 28229->28222 28229->28226 28230 7ff646d89cae 28229->28230 28354 7ff646d95294 28229->28354 28372 7ff646d9db60 28229->28372 28231 7ff646d89cbf 28230->28231 28376 7ff646d9da48 CompareStringW 28230->28376 28231->28226 28233 7ff646d820b0 33 API calls 28231->28233 28233->28226 28245 7ff646d95f3a 28234->28245 28235 7ff646d9619b 28236 7ff646db2320 _handle_error 8 API calls 28235->28236 28238 7ff646d8fb29 28236->28238 28237 7ff646d961ce 28380 7ff646d8704c 47 API calls BuildCatchObjectHelperInternal 28237->28380 28238->27642 28301 7ff646d97c94 47 API calls 2 library calls 28238->28301 28240 7ff646d8129c 33 API calls 28242 7ff646d96129 28240->28242 28241 7ff646d961d4 28243 7ff646d81fa0 31 API calls 28242->28243 28244 7ff646d9613b BuildCatchObjectHelperInternal 28242->28244 28243->28244 28244->28235 28246 7ff646d961c9 28244->28246 28245->28235 28245->28237 28245->28240 28300->27631 28352->27686 28353->27686 28355 7ff646d952d4 28354->28355 28359 7ff646d95339 __vcrt_InitializeCriticalSectionEx 28355->28359 28360 7ff646d95312 __vcrt_InitializeCriticalSectionEx 28355->28360 28377 7ff646da13f4 CompareStringW 28355->28377 28356 7ff646db2320 _handle_error 8 API calls 28357 7ff646d95503 28356->28357 28357->28229 28359->28356 28360->28359 28361 7ff646d95382 __vcrt_InitializeCriticalSectionEx 28360->28361 28378 7ff646da13f4 CompareStringW 28360->28378 28361->28359 28363 7ff646d95439 28361->28363 28364 7ff646d8129c 33 API calls 28361->28364 28366 7ff646d9551b 28363->28366 28367 7ff646d95489 28363->28367 28365 7ff646d95426 28364->28365 28368 7ff646d972cc 8 API calls 28365->28368 28369 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 28366->28369 28367->28359 28379 7ff646da13f4 CompareStringW 28367->28379 28368->28363 28371 7ff646d95520 28369->28371 28374 7ff646d9db73 28372->28374 28373 7ff646d9db91 28373->28229 28374->28373 28375 7ff646d820b0 33 API calls 28374->28375 28375->28373 28376->28231 28377->28360 28378->28361 28379->28359 28380->28241 28439->27804 28440->27811 28441->27815 28443 7ff646d987af 28442->28443 28453 7ff646d987df 28442->28453 28444 7ff646db236c 108 API calls 28443->28444 28447 7ff646d987ca 28444->28447 28445 7ff646db236c 108 API calls 28448 7ff646d98814 28445->28448 28450 7ff646db236c 108 API calls 28447->28450 28451 7ff646db236c 108 API calls 28448->28451 28449 7ff646d98845 28452 7ff646d9461c 108 API calls 28449->28452 28450->28453 28454 7ff646d9882b 28451->28454 28455 7ff646d98851 28452->28455 28453->28445 28453->28454 28456 7ff646d9461c 28454->28456 28457 7ff646d94632 28456->28457 28459 7ff646d9463a 28456->28459 28458 7ff646d9e948 108 API calls 28457->28458 28458->28459 28459->28449 28461 7ff646d9163e 28460->28461 28467 7ff646d91681 28460->28467 28463 7ff646d931bc 51 API calls 28461->28463 28461->28467 28462 7ff646d8e600 31 API calls 28466 7ff646d916de 28462->28466 28463->28461 28464 7ff646d81fa0 31 API calls 28464->28467 28465 7ff646d9175b 28470 7ff646db2320 _handle_error 8 API calls 28465->28470 28466->28465 28469 7ff646d9178d 28466->28469 28467->28464 28468 7ff646d916a0 28467->28468 28468->28462 28471 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 28469->28471 28472 7ff646d8e58a 28470->28472 28473 7ff646d91792 28471->28473 28472->27435 28472->27436 28474->27139 28475->27149 28476->27152 25763 7ff646db0df5 14 API calls _com_raise_error 25768 7ff646db2d6c 25793 7ff646db27fc 25768->25793 25771 7ff646db2eb8 25892 7ff646db3170 7 API calls 2 library calls 25771->25892 25772 7ff646db2d88 __scrt_acquire_startup_lock 25774 7ff646db2ec2 25772->25774 25776 7ff646db2da6 25772->25776 25893 7ff646db3170 7 API calls 2 library calls 25774->25893 25777 7ff646db2dcb 25776->25777 25781 7ff646db2de8 __scrt_release_startup_lock 25776->25781 25801 7ff646dbcd90 25776->25801 25778 7ff646db2ecd abort 25780 7ff646db2e51 25805 7ff646db32bc 25780->25805 25781->25780 25889 7ff646dbc050 35 API calls __GSHandlerCheck_EH 25781->25889 25783 7ff646db2e56 25808 7ff646dbcd20 25783->25808 25894 7ff646db2fb0 25793->25894 25796 7ff646db2827 25796->25771 25796->25772 25797 7ff646db282b 25896 7ff646dbcc50 25797->25896 25802 7ff646dbcdeb 25801->25802 25803 7ff646dbcdcc 25801->25803 25802->25781 25803->25802 25913 7ff646d81120 25803->25913 25956 7ff646db3cf0 25805->25956 25958 7ff646dc0730 25808->25958 25810 7ff646dbcd2f 25812 7ff646db2e5e 25810->25812 25962 7ff646dc0ac0 35 API calls _snwprintf 25810->25962 25813 7ff646db0754 25812->25813 25964 7ff646d9dfd0 25813->25964 25817 7ff646db079a 26051 7ff646da946c 25817->26051 25819 7ff646db07a4 __scrt_get_show_window_mode 26056 7ff646da9a14 25819->26056 25821 7ff646db0ddc 25822 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 25821->25822 25824 7ff646db0de2 25822->25824 25823 7ff646db096e GetCommandLineW 25825 7ff646db0980 25823->25825 25826 7ff646db0b42 25823->25826 25829 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 25824->25829 26139 7ff646d8129c 25825->26139 26066 7ff646d96454 25826->26066 25827 7ff646db0819 25827->25821 25827->25823 25831 7ff646db0de8 25829->25831 25830 7ff646db0b51 25835 7ff646d81fa0 31 API calls 25830->25835 25839 7ff646db0b68 BuildCatchObjectHelperInternal 25830->25839 25837 7ff646db1900 _com_raise_error 14 API calls 25831->25837 25833 7ff646d81fa0 31 API calls 25836 7ff646db0b93 SetEnvironmentVariableW GetLocalTime 25833->25836 25834 7ff646db09a5 26149 7ff646dacad0 102 API calls 3 library calls 25834->26149 25835->25839 26078 7ff646d93e28 25836->26078 25841 7ff646db0e34 25837->25841 25839->25833 25842 7ff646db09af 25842->25824 25845 7ff646db09f9 OpenFileMappingW 25842->25845 25846 7ff646db0adb 25842->25846 25847 7ff646db0ad0 CloseHandle 25845->25847 25848 7ff646db0a19 MapViewOfFile 25845->25848 25852 7ff646d8129c 33 API calls 25846->25852 25847->25826 25848->25847 25850 7ff646db0a3f UnmapViewOfFile MapViewOfFile 25848->25850 25850->25847 25853 7ff646db0a71 25850->25853 25855 7ff646db0b00 25852->25855 26150 7ff646daa190 33 API calls 2 library calls 25853->26150 25854 7ff646db0c75 26106 7ff646da67b4 25854->26106 26154 7ff646dafd0c 35 API calls 2 library calls 25855->26154 25859 7ff646db0a81 26151 7ff646dafd0c 35 API calls 2 library calls 25859->26151 25861 7ff646db0b0a 25861->25826 25867 7ff646db0dd7 25861->25867 25863 7ff646da67b4 33 API calls 25865 7ff646db0c87 DialogBoxParamW 25863->25865 25864 7ff646db0a90 26152 7ff646d9b9b4 102 API calls 25864->26152 25871 7ff646db0cd3 25865->25871 25870 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 25867->25870 25868 7ff646db0aa5 26153 7ff646d9bb00 102 API calls 25868->26153 25870->25821 25872 7ff646db0ce6 Sleep 25871->25872 25873 7ff646db0cec 25871->25873 25872->25873 25875 7ff646db0cfa 25873->25875 26109 7ff646da9f4c 25873->26109 25874 7ff646db0ab8 25876 7ff646db0ac7 UnmapViewOfFile 25874->25876 25878 7ff646db0d06 DeleteObject 25875->25878 25876->25847 25879 7ff646db0d1f DeleteObject 25878->25879 25880 7ff646db0d25 25878->25880 25879->25880 25881 7ff646db0d6d 25880->25881 25882 7ff646db0d5b 25880->25882 26135 7ff646da94e4 25881->26135 26155 7ff646dafe24 PeekMessageW GetMessageW TranslateMessage DispatchMessageW WaitForSingleObject 25882->26155 25884 7ff646db0d60 CloseHandle 25884->25881 25889->25780 25892->25774 25893->25778 25895 7ff646db281e __scrt_dllmain_crt_thread_attach 25894->25895 25895->25796 25895->25797 25897 7ff646dc0d4c 25896->25897 25898 7ff646db2830 25897->25898 25901 7ff646dbec00 25897->25901 25898->25796 25900 7ff646db51a0 7 API calls 2 library calls 25898->25900 25900->25796 25912 7ff646dbf398 EnterCriticalSection 25901->25912 25918 7ff646d891c8 25913->25918 25917 7ff646db2a01 25917->25803 25926 7ff646d956a4 25918->25926 25920 7ff646d891df 25929 7ff646d9b788 25920->25929 25924 7ff646d81130 25925 7ff646db29bc 34 API calls 25924->25925 25925->25917 25935 7ff646d956e8 25926->25935 25944 7ff646d813a4 25929->25944 25932 7ff646d89a28 25933 7ff646d956e8 2 API calls 25932->25933 25934 7ff646d89a36 25933->25934 25934->25924 25936 7ff646d956fe __scrt_get_show_window_mode 25935->25936 25939 7ff646d9eba4 25936->25939 25942 7ff646d9eb58 GetCurrentProcess GetProcessAffinityMask 25939->25942 25943 7ff646d956de 25942->25943 25943->25920 25945 7ff646d813ad 25944->25945 25946 7ff646d8142d 25944->25946 25947 7ff646d8143d 25945->25947 25948 7ff646d813ce 25945->25948 25946->25932 25955 7ff646d82018 33 API calls std::_Xinvalid_argument 25947->25955 25951 7ff646db21d0 33 API calls 25948->25951 25952 7ff646d813db __scrt_get_show_window_mode 25948->25952 25951->25952 25954 7ff646d8197c 31 API calls _invalid_parameter_noinfo_noreturn 25952->25954 25954->25946 25957 7ff646db32d3 GetStartupInfoW 25956->25957 25957->25783 25959 7ff646dc0749 25958->25959 25960 7ff646dc073d 25958->25960 25959->25810 25963 7ff646dc0570 48 API calls 4 library calls 25960->25963 25962->25810 25963->25959 26156 7ff646db2450 25964->26156 25967 7ff646d9e026 GetProcAddress 25969 7ff646d9e053 GetProcAddress 25967->25969 25970 7ff646d9e03b 25967->25970 25968 7ff646d9e07b 25971 7ff646d9e503 25968->25971 26189 7ff646dbb788 39 API calls 2 library calls 25968->26189 25969->25968 25973 7ff646d9e068 25969->25973 25970->25969 25972 7ff646d96454 34 API calls 25971->25972 25975 7ff646d9e50c 25972->25975 25973->25968 26158 7ff646d97df4 25975->26158 25976 7ff646d9e3b0 25976->25971 25978 7ff646d9e3ba 25976->25978 25979 7ff646d96454 34 API calls 25978->25979 25980 7ff646d9e3c3 CreateFileW 25979->25980 25981 7ff646d9e4f0 CloseHandle 25980->25981 25982 7ff646d9e403 SetFilePointer 25980->25982 25985 7ff646d81fa0 31 API calls 25981->25985 25982->25981 25984 7ff646d9e41c ReadFile 25982->25984 25984->25981 25986 7ff646d9e444 25984->25986 25985->25971 25987 7ff646d9e800 25986->25987 25988 7ff646d9e458 25986->25988 26195 7ff646db2624 8 API calls 25987->26195 25993 7ff646d8129c 33 API calls 25988->25993 25990 7ff646d8129c 33 API calls 26007 7ff646d9e51a 25990->26007 25991 7ff646d9e805 25992 7ff646d9e53e CompareStringW 25992->26007 25998 7ff646d9e48f 25993->25998 25995 7ff646d81fa0 31 API calls 25995->26007 25997 7ff646d9e63a 25999 7ff646d9e7c2 25997->25999 26000 7ff646d9e648 25997->26000 26004 7ff646d9e4db 25998->26004 26190 7ff646d9d0a0 33 API calls 25998->26190 26002 7ff646d81fa0 31 API calls 25999->26002 26191 7ff646d97eb0 47 API calls 26000->26191 26006 7ff646d9e7cb 26002->26006 26008 7ff646d81fa0 31 API calls 26004->26008 26005 7ff646d9e651 26009 7ff646d951a4 9 API calls 26005->26009 26011 7ff646d81fa0 31 API calls 26006->26011 26007->25990 26007->25992 26007->25995 26025 7ff646d9e5cc 26007->26025 26166 7ff646d951a4 26007->26166 26171 7ff646d98090 26007->26171 26175 7ff646d932bc 26007->26175 26012 7ff646d9e4e5 26008->26012 26014 7ff646d9e656 26009->26014 26010 7ff646d8129c 33 API calls 26010->26025 26015 7ff646d9e7d5 26011->26015 26013 7ff646d81fa0 31 API calls 26012->26013 26013->25981 26016 7ff646d9e706 26014->26016 26023 7ff646d9e661 26014->26023 26018 7ff646db2320 _handle_error 8 API calls 26015->26018 26019 7ff646d9da98 48 API calls 26016->26019 26017 7ff646d98090 47 API calls 26017->26025 26020 7ff646d9e7e4 26018->26020 26021 7ff646d9e74b AllocConsole 26019->26021 26041 7ff646d962dc GetCurrentDirectoryW 26020->26041 26024 7ff646d9e755 GetCurrentProcessId AttachConsole 26021->26024 26040 7ff646d9e6fb 26021->26040 26022 7ff646d81fa0 31 API calls 26022->26025 26028 7ff646d9aae0 48 API calls 26023->26028 26026 7ff646d9e76c 26024->26026 26025->25997 26025->26010 26025->26017 26025->26022 26027 7ff646d932bc 51 API calls 26025->26027 26033 7ff646d9e778 GetStdHandle WriteConsoleW Sleep FreeConsole 26026->26033 26027->26025 26031 7ff646d9e6a5 26028->26031 26030 7ff646d9e7b9 ExitProcess 26032 7ff646d9da98 48 API calls 26031->26032 26034 7ff646d9e6c3 26032->26034 26033->26040 26035 7ff646d9aae0 48 API calls 26034->26035 26036 7ff646d9e6ce 26035->26036 26192 7ff646d9dc2c 33 API calls 26036->26192 26038 7ff646d9e6da 26193 7ff646d819e0 31 API calls _invalid_parameter_noinfo_noreturn 26038->26193 26194 7ff646d819e0 31 API calls _invalid_parameter_noinfo_noreturn 26040->26194 26042 7ff646d96300 26041->26042 26047 7ff646d9638d 26041->26047 26043 7ff646d813a4 33 API calls 26042->26043 26044 7ff646d9631b GetCurrentDirectoryW 26043->26044 26045 7ff646d96341 26044->26045 26321 7ff646d820b0 26045->26321 26047->25817 26048 7ff646d9634f 26048->26047 26049 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26048->26049 26050 7ff646d963a9 26049->26050 26052 7ff646d9dd88 26051->26052 26053 7ff646da9481 OleInitialize 26052->26053 26054 7ff646da94a7 26053->26054 26055 7ff646da94cd SHGetMalloc 26054->26055 26055->25819 26057 7ff646da9a49 26056->26057 26059 7ff646da9a4e BuildCatchObjectHelperInternal 26056->26059 26058 7ff646d81fa0 31 API calls 26057->26058 26058->26059 26060 7ff646da9a7d BuildCatchObjectHelperInternal 26059->26060 26061 7ff646d81fa0 31 API calls 26059->26061 26062 7ff646d81fa0 31 API calls 26060->26062 26063 7ff646da9aac BuildCatchObjectHelperInternal 26060->26063 26061->26060 26062->26063 26064 7ff646d81fa0 31 API calls 26063->26064 26065 7ff646da9adb BuildCatchObjectHelperInternal 26063->26065 26064->26065 26065->25827 26067 7ff646d813a4 33 API calls 26066->26067 26068 7ff646d96489 26067->26068 26069 7ff646d9648c GetModuleFileNameW 26068->26069 26072 7ff646d964dc 26068->26072 26070 7ff646d964de 26069->26070 26071 7ff646d964a7 26069->26071 26070->26072 26071->26068 26073 7ff646d8129c 33 API calls 26072->26073 26075 7ff646d96506 26073->26075 26074 7ff646d9653e 26074->25830 26075->26074 26076 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26075->26076 26077 7ff646d96560 26076->26077 26079 7ff646d93e4d swprintf 26078->26079 26080 7ff646db9ef0 swprintf 46 API calls 26079->26080 26081 7ff646d93e69 SetEnvironmentVariableW GetModuleHandleW LoadIconW 26080->26081 26082 7ff646dab014 LoadBitmapW 26081->26082 26083 7ff646dab03e 26082->26083 26084 7ff646dab046 26082->26084 26326 7ff646da8624 FindResourceW 26083->26326 26086 7ff646dab04e GetObjectW 26084->26086 26087 7ff646dab063 26084->26087 26086->26087 26341 7ff646da849c 26087->26341 26090 7ff646dab0ce 26101 7ff646d998ac 26090->26101 26091 7ff646dab09e 26346 7ff646da8504 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 26091->26346 26092 7ff646da8624 11 API calls 26094 7ff646dab08a 26092->26094 26094->26091 26096 7ff646dab092 DeleteObject 26094->26096 26095 7ff646dab0a7 26347 7ff646da84cc 26095->26347 26096->26091 26100 7ff646dab0bf DeleteObject 26100->26090 26354 7ff646d998dc 26101->26354 26103 7ff646d998ba 26421 7ff646d9a43c GetModuleHandleW FindResourceW 26103->26421 26105 7ff646d998c2 26105->25854 26107 7ff646db21d0 33 API calls 26106->26107 26108 7ff646da67fa 26107->26108 26108->25863 26110 7ff646da9ffe 26109->26110 26111 7ff646da9f92 26109->26111 26112 7ff646d81fa0 31 API calls 26110->26112 26116 7ff646daa019 26110->26116 26113 7ff646d8129c 33 API calls 26111->26113 26112->26116 26114 7ff646da9fbc 26113->26114 26117 7ff646d97df4 47 API calls 26114->26117 26115 7ff646daa156 26118 7ff646db2320 _handle_error 8 API calls 26115->26118 26116->26115 26121 7ff646daa189 26116->26121 26503 7ff646d97fc4 26116->26503 26122 7ff646da9fd0 26117->26122 26123 7ff646daa167 26118->26123 26120 7ff646daa074 26506 7ff646d88d04 26120->26506 26125 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26121->26125 26516 7ff646da13f4 CompareStringW 26122->26516 26123->25875 26128 7ff646daa18f 26125->26128 26127 7ff646daa0a3 26129 7ff646daa0ae 26127->26129 26517 7ff646d81744 33 API calls 4 library calls 26127->26517 26130 7ff646daa0dd SHFileOperationW 26129->26130 26130->26115 26132 7ff646daa129 26130->26132 26132->26115 26133 7ff646daa184 26132->26133 26134 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26133->26134 26134->26121 26136 7ff646da9501 26135->26136 26137 7ff646da950a OleUninitialize 26136->26137 26138 7ff646dee330 26137->26138 26140 7ff646d8139b 26139->26140 26141 7ff646d812d0 26139->26141 26521 7ff646d82004 33 API calls std::_Xinvalid_argument 26140->26521 26144 7ff646d812de BuildCatchObjectHelperInternal 26141->26144 26145 7ff646d81338 26141->26145 26146 7ff646d81396 26141->26146 26144->25834 26145->26144 26148 7ff646db21d0 33 API calls 26145->26148 26520 7ff646d81f80 33 API calls 3 library calls 26146->26520 26148->26144 26149->25842 26150->25859 26151->25864 26152->25868 26153->25874 26154->25861 26155->25884 26157 7ff646d9dff4 GetModuleHandleW 26156->26157 26157->25967 26157->25968 26159 7ff646d97e0c 26158->26159 26160 7ff646d97e23 26159->26160 26161 7ff646d97e55 26159->26161 26163 7ff646d8129c 33 API calls 26160->26163 26196 7ff646d8704c 47 API calls BuildCatchObjectHelperInternal 26161->26196 26165 7ff646d97e47 26163->26165 26164 7ff646d97e5a 26165->26007 26167 7ff646d951c8 GetVersionExW 26166->26167 26168 7ff646d951fb 26166->26168 26167->26168 26169 7ff646db2320 _handle_error 8 API calls 26168->26169 26170 7ff646d95228 26169->26170 26170->26007 26172 7ff646d980a5 26171->26172 26197 7ff646d98188 26172->26197 26174 7ff646d980ca 26174->26007 26176 7ff646d932e4 26175->26176 26177 7ff646d932e7 GetFileAttributesW 26175->26177 26176->26177 26178 7ff646d932f8 26177->26178 26179 7ff646d93375 26177->26179 26206 7ff646d96a0c 26178->26206 26181 7ff646db2320 _handle_error 8 API calls 26179->26181 26183 7ff646d93389 26181->26183 26183->26007 26184 7ff646d93323 GetFileAttributesW 26185 7ff646d9333c 26184->26185 26185->26179 26186 7ff646d93399 26185->26186 26187 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26186->26187 26188 7ff646d9339e 26187->26188 26189->25976 26190->25998 26191->26005 26192->26038 26193->26040 26194->26030 26195->25991 26196->26164 26198 7ff646d98326 26197->26198 26201 7ff646d981ba 26197->26201 26205 7ff646d8704c 47 API calls BuildCatchObjectHelperInternal 26198->26205 26200 7ff646d9832b 26203 7ff646d981d4 BuildCatchObjectHelperInternal 26201->26203 26204 7ff646d958a4 33 API calls 2 library calls 26201->26204 26203->26174 26204->26203 26205->26200 26207 7ff646d96a4b 26206->26207 26221 7ff646d96a44 26206->26221 26209 7ff646d8129c 33 API calls 26207->26209 26208 7ff646db2320 _handle_error 8 API calls 26210 7ff646d9331f 26208->26210 26211 7ff646d96a76 26209->26211 26210->26184 26210->26185 26212 7ff646d96cc7 26211->26212 26213 7ff646d96a96 26211->26213 26214 7ff646d962dc 35 API calls 26212->26214 26215 7ff646d96ab0 26213->26215 26238 7ff646d96b49 26213->26238 26219 7ff646d96ce6 26214->26219 26216 7ff646d970ab 26215->26216 26279 7ff646d8c098 26215->26279 26312 7ff646d82004 33 API calls std::_Xinvalid_argument 26216->26312 26218 7ff646d96eef 26223 7ff646d970cf 26218->26223 26228 7ff646d8c098 33 API calls 26218->26228 26219->26218 26224 7ff646d96d1b 26219->26224 26277 7ff646d96b44 26219->26277 26220 7ff646d970b1 26230 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26220->26230 26221->26208 26315 7ff646d82004 33 API calls std::_Xinvalid_argument 26223->26315 26229 7ff646d970bd 26224->26229 26235 7ff646d8c098 33 API calls 26224->26235 26225 7ff646d970d5 26231 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26225->26231 26227 7ff646d96b03 26239 7ff646d81fa0 31 API calls 26227->26239 26245 7ff646d96b15 BuildCatchObjectHelperInternal 26227->26245 26233 7ff646d96f56 26228->26233 26313 7ff646d82004 33 API calls std::_Xinvalid_argument 26229->26313 26236 7ff646d970b7 26230->26236 26237 7ff646d970db 26231->26237 26232 7ff646d970a6 26243 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26232->26243 26310 7ff646d811cc 33 API calls BuildCatchObjectHelperInternal 26233->26310 26253 7ff646d96d76 BuildCatchObjectHelperInternal 26235->26253 26247 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26236->26247 26249 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26237->26249 26244 7ff646d8129c 33 API calls 26238->26244 26238->26277 26239->26245 26241 7ff646d970c3 26252 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26241->26252 26242 7ff646d81fa0 31 API calls 26242->26277 26243->26216 26250 7ff646d96bbe 26244->26250 26245->26242 26246 7ff646d96f69 26311 7ff646d957ac 33 API calls BuildCatchObjectHelperInternal 26246->26311 26247->26229 26248 7ff646d81fa0 31 API calls 26263 7ff646d96df5 26248->26263 26254 7ff646d970e1 26249->26254 26287 7ff646d95820 26250->26287 26256 7ff646d970c9 26252->26256 26253->26241 26253->26248 26314 7ff646d8704c 47 API calls BuildCatchObjectHelperInternal 26256->26314 26259 7ff646d81fa0 31 API calls 26262 7ff646d96fec 26259->26262 26261 7ff646d96f79 BuildCatchObjectHelperInternal 26261->26237 26261->26259 26264 7ff646d81fa0 31 API calls 26262->26264 26268 7ff646d96e21 26263->26268 26305 7ff646d81744 33 API calls 4 library calls 26263->26305 26267 7ff646d96ff6 26264->26267 26266 7ff646d81fa0 31 API calls 26271 7ff646d96c6d 26266->26271 26272 7ff646d81fa0 31 API calls 26267->26272 26268->26256 26269 7ff646d8129c 33 API calls 26268->26269 26273 7ff646d96ec2 26269->26273 26270 7ff646d96be9 BuildCatchObjectHelperInternal 26270->26236 26270->26266 26274 7ff646d81fa0 31 API calls 26271->26274 26272->26277 26306 7ff646d82034 26273->26306 26274->26277 26276 7ff646d96edf 26278 7ff646d81fa0 31 API calls 26276->26278 26277->26220 26277->26221 26277->26225 26277->26232 26278->26277 26280 7ff646d8c0e5 26279->26280 26281 7ff646d8c0fa BuildCatchObjectHelperInternal 26279->26281 26280->26281 26282 7ff646d8c1a5 26280->26282 26284 7ff646d8c12c 26280->26284 26281->26227 26316 7ff646d81f80 33 API calls 3 library calls 26282->26316 26284->26281 26286 7ff646db21d0 33 API calls 26284->26286 26285 7ff646d8c1aa 26286->26281 26288 7ff646d95849 26287->26288 26289 7ff646d9589e 26288->26289 26291 7ff646d9585b 26288->26291 26317 7ff646d82004 33 API calls std::_Xinvalid_argument 26289->26317 26293 7ff646d8c098 33 API calls 26291->26293 26294 7ff646d95886 26293->26294 26295 7ff646d8e164 26294->26295 26297 7ff646d8e1b2 26295->26297 26296 7ff646d8e1b8 BuildCatchObjectHelperInternal 26296->26270 26297->26296 26299 7ff646d8e340 26297->26299 26302 7ff646d8e345 26297->26302 26303 7ff646d8e2bc 26297->26303 26318 7ff646d81f80 33 API calls 3 library calls 26299->26318 26319 7ff646d82004 33 API calls std::_Xinvalid_argument 26302->26319 26303->26296 26304 7ff646db21d0 33 API calls 26303->26304 26304->26296 26305->26268 26307 7ff646d82085 26306->26307 26309 7ff646d82059 BuildCatchObjectHelperInternal 26306->26309 26320 7ff646d815b8 33 API calls 3 library calls 26307->26320 26309->26276 26310->26246 26311->26261 26314->26223 26316->26285 26318->26302 26320->26309 26322 7ff646d820f6 26321->26322 26324 7ff646d820cb BuildCatchObjectHelperInternal 26321->26324 26325 7ff646d81474 33 API calls 3 library calls 26322->26325 26324->26048 26325->26324 26327 7ff646da864f SizeofResource 26326->26327 26328 7ff646da879b 26326->26328 26327->26328 26329 7ff646da8669 LoadResource 26327->26329 26328->26084 26329->26328 26330 7ff646da8682 LockResource 26329->26330 26330->26328 26331 7ff646da8697 GlobalAlloc 26330->26331 26331->26328 26332 7ff646da86b8 GlobalLock 26331->26332 26333 7ff646da8792 GlobalFree 26332->26333 26334 7ff646da86ca BuildCatchObjectHelperInternal 26332->26334 26333->26328 26335 7ff646da86d8 CreateStreamOnHGlobal 26334->26335 26336 7ff646da8789 GlobalUnlock 26335->26336 26337 7ff646da86f6 GdipAlloc 26335->26337 26336->26333 26338 7ff646da870b 26337->26338 26338->26336 26339 7ff646da8772 26338->26339 26340 7ff646da875a GdipCreateHBITMAPFromBitmap 26338->26340 26339->26336 26340->26339 26342 7ff646da84cc 4 API calls 26341->26342 26343 7ff646da84aa 26342->26343 26345 7ff646da84b9 26343->26345 26352 7ff646da8504 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 26343->26352 26345->26090 26345->26091 26345->26092 26346->26095 26348 7ff646da84de 26347->26348 26349 7ff646da84e3 26347->26349 26353 7ff646da8590 GetDC GetDeviceCaps GetDeviceCaps ReleaseDC 26348->26353 26351 7ff646da8df4 16 API calls _handle_error 26349->26351 26351->26100 26352->26345 26353->26349 26357 7ff646d998fe _snwprintf 26354->26357 26355 7ff646d99973 26472 7ff646d968b0 48 API calls 26355->26472 26357->26355 26359 7ff646d99a89 26357->26359 26358 7ff646d81fa0 31 API calls 26361 7ff646d999fd 26358->26361 26359->26361 26363 7ff646d820b0 33 API calls 26359->26363 26360 7ff646d9997d BuildCatchObjectHelperInternal 26360->26358 26362 7ff646d9a42e 26360->26362 26423 7ff646d924c0 26361->26423 26364 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26362->26364 26363->26361 26366 7ff646d9a434 26364->26366 26369 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26366->26369 26368 7ff646d99a22 26370 7ff646d9204c 100 API calls 26368->26370 26372 7ff646d9a43a 26369->26372 26373 7ff646d99a2b 26370->26373 26371 7ff646d99b17 26441 7ff646dba450 26371->26441 26373->26366 26375 7ff646d99a66 26373->26375 26378 7ff646db2320 _handle_error 8 API calls 26375->26378 26376 7ff646d99aad 26376->26371 26381 7ff646d98e58 33 API calls 26376->26381 26380 7ff646d9a40e 26378->26380 26379 7ff646dba450 31 API calls 26392 7ff646d99b57 __vcrt_InitializeCriticalSectionEx 26379->26392 26380->26103 26381->26376 26382 7ff646d99c89 26383 7ff646d92aa0 101 API calls 26382->26383 26395 7ff646d99d5c 26382->26395 26386 7ff646d99ca1 26383->26386 26387 7ff646d928d0 104 API calls 26386->26387 26386->26395 26393 7ff646d99cc9 26387->26393 26392->26382 26392->26395 26449 7ff646d92bb0 26392->26449 26458 7ff646d928d0 26392->26458 26463 7ff646d92aa0 26392->26463 26393->26395 26416 7ff646d99cd7 __vcrt_InitializeCriticalSectionEx 26393->26416 26473 7ff646da0bbc MultiByteToWideChar 26393->26473 26468 7ff646d9204c 26395->26468 26396 7ff646d9a1ec 26409 7ff646d9a2c2 26396->26409 26479 7ff646dbcf90 31 API calls 2 library calls 26396->26479 26398 7ff646d9a157 26398->26396 26476 7ff646dbcf90 31 API calls 2 library calls 26398->26476 26401 7ff646d9a14b 26401->26103 26402 7ff646d9a2ae 26402->26409 26481 7ff646d98cd0 33 API calls 2 library calls 26402->26481 26403 7ff646d9a3a2 26405 7ff646dba450 31 API calls 26403->26405 26404 7ff646d9a249 26480 7ff646dbb7bc 31 API calls _invalid_parameter_noinfo_noreturn 26404->26480 26408 7ff646d9a3cb 26405->26408 26406 7ff646d98e58 33 API calls 26406->26409 26411 7ff646dba450 31 API calls 26408->26411 26409->26403 26409->26406 26410 7ff646d9a16d 26477 7ff646dbb7bc 31 API calls _invalid_parameter_noinfo_noreturn 26410->26477 26411->26395 26413 7ff646d9a1d8 26413->26396 26478 7ff646d98cd0 33 API calls 2 library calls 26413->26478 26414 7ff646da0f68 WideCharToMultiByte 26414->26416 26416->26395 26416->26396 26416->26398 26416->26401 26416->26414 26417 7ff646d9a429 26416->26417 26474 7ff646d9aa88 45 API calls 2 library calls 26416->26474 26475 7ff646dba270 31 API calls 2 library calls 26416->26475 26482 7ff646db2624 8 API calls 26417->26482 26422 7ff646d9a468 26421->26422 26422->26105 26424 7ff646d924fd CreateFileW 26423->26424 26426 7ff646d925ae GetLastError 26424->26426 26434 7ff646d9266e 26424->26434 26427 7ff646d96a0c 49 API calls 26426->26427 26428 7ff646d925dc 26427->26428 26429 7ff646d925e0 CreateFileW GetLastError 26428->26429 26435 7ff646d9262c 26428->26435 26429->26435 26430 7ff646d92708 26432 7ff646db2320 _handle_error 8 API calls 26430->26432 26431 7ff646d926b1 SetFileTime 26433 7ff646d926cf 26431->26433 26436 7ff646d9271b 26432->26436 26433->26430 26437 7ff646d820b0 33 API calls 26433->26437 26434->26431 26434->26433 26435->26434 26438 7ff646d92736 26435->26438 26436->26368 26436->26376 26437->26430 26439 7ff646db7904 _invalid_parameter_noinfo_noreturn 31 API calls 26438->26439 26440 7ff646d9273b 26439->26440 26442 7ff646dba47d 26441->26442 26448 7ff646dba492 26442->26448 26483 7ff646dbd69c 15 API calls _set_errno_from_matherr 26442->26483 26444 7ff646dba487 26484 7ff646db78e4 31 API calls _invalid_parameter_noinfo_noreturn 26444->26484 26445 7ff646db2320 _handle_error 8 API calls 26447 7ff646d99b37 26445->26447 26447->26379 26448->26445 26450 7ff646d92bcd 26449->26450 26452 7ff646d92be9 26449->26452 26451 7ff646d92bfb 26450->26451 26485 7ff646d8b9c4 99 API calls std::_Xinvalid_argument 26450->26485 26451->26392 26452->26451 26454 7ff646d92c01 SetFilePointer 26452->26454 26454->26451 26455 7ff646d92c1e GetLastError 26454->26455 26455->26451 26456 7ff646d92c28 26455->26456 26456->26451 26486 7ff646d8b9c4 99 API calls std::_Xinvalid_argument 26456->26486 26459 7ff646d928fd 26458->26459 26460 7ff646d928f6 26458->26460 26459->26460 26462 7ff646d92320 GetStdHandle ReadFile GetLastError GetLastError GetFileType 26459->26462 26487 7ff646d8b8a4 99 API calls std::_Xinvalid_argument 26459->26487 26460->26392 26462->26459 26488 7ff646d92778 26463->26488 26466 7ff646d92ac7 26466->26392 26469 7ff646d92072 26468->26469 26470 7ff646d92066 26468->26470 26470->26469 26496 7ff646d920d0 26470->26496 26472->26360 26473->26416 26474->26416 26475->26416 26476->26410 26477->26413 26478->26396 26479->26404 26480->26402 26481->26409 26482->26362 26483->26444 26484->26448 26494 7ff646d92789 _snwprintf 26488->26494 26489 7ff646d927b5 26491 7ff646db2320 _handle_error 8 API calls 26489->26491 26490 7ff646d92890 SetFilePointer 26490->26489 26493 7ff646d928b8 GetLastError 26490->26493 26492 7ff646d9281d 26491->26492 26492->26466 26495 7ff646d8b9c4 99 API calls std::_Xinvalid_argument 26492->26495 26493->26489 26494->26489 26494->26490 26498 7ff646d920ea 26496->26498 26499 7ff646d92102 26496->26499 26497 7ff646d92126 26497->26469 26498->26499 26500 7ff646d920f6 CloseHandle 26498->26500 26499->26497 26502 7ff646d8b544 99 API calls 26499->26502 26500->26499 26502->26497 26504 7ff646d97fcf 26503->26504 26505 7ff646d97fd2 SetCurrentDirectoryW 26503->26505 26504->26505 26505->26120 26508 7ff646d88d34 26506->26508 26514 7ff646d88de8 26506->26514 26510 7ff646d88d91 26508->26510 26511 7ff646d88de3 26508->26511 26512 7ff646d88d42 BuildCatchObjectHelperInternal 26508->26512 26510->26512 26515 7ff646db21d0 33 API calls 26510->26515 26518 7ff646d81f80 33 API calls 3 library calls 26511->26518 26512->26127 26519 7ff646d82004 33 API calls std::_Xinvalid_argument 26514->26519 26515->26512 26516->26110 26517->26130 26518->26514 26520->26140 28493 7ff646dbd94c 28494 7ff646dbd997 28493->28494 28498 7ff646dbd95b _set_errno_from_matherr 28493->28498 28500 7ff646dbd69c 15 API calls _set_errno_from_matherr 28494->28500 28496 7ff646dbd97e HeapAlloc 28497 7ff646dbd995 28496->28497 28496->28498 28498->28494 28498->28496 28499 7ff646dbbbc0 _set_errno_from_matherr 2 API calls 28498->28499 28499->28498 28500->28497 28502 7ff646db154b 28503 7ff646db14a2 28502->28503 28504 7ff646db1900 _com_raise_error 14 API calls 28503->28504 28504->28503
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ItemMessage$_invalid_parameter_noinfo_noreturn$Send$DialogText$File$ErrorLastWindow$CloseFindFocusLoadStringView$CommandConcurrency::cancel_current_taskCountCreateDispatchEnableExecuteFirstForegroundHandleLineMappingParamPostShellSleepTickTranslateUnmap
        • String ID: %s %s$-el -s2 "-d%s" "-sp%s"$@$LICENSEDLG$REPLACEFILEDLG$STARTDLG$__tmp_rar_sfx_access_check_$p$runas$winrarsfxmappingfile.tmp
        • API String ID: 2406191690-2702805183
        • Opcode ID: 0c64e270eeb3cc0a242973fa26eae57dde3a5bf8809ed376eda01980870d8d08
        • Instruction ID: c783de94e3bd34a1d5f53e3d28053065be745cd42654e3882ac7b1b5ff873350
        • Opcode Fuzzy Hash: 0c64e270eeb3cc0a242973fa26eae57dde3a5bf8809ed376eda01980870d8d08
        • Instruction Fuzzy Hash: 47D2BF62A0CA8381EB20FB25E8542FAE361EFD5794F404335D95D876AADF3EE549C700
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_taskFile$MessageMoveSend$DialogItemOperationPathTemp
        • String ID: .lnk$.tmp$<br>$@set:user$HIDE$MAX$MIN$ProgramFilesDir$Software\Microsoft\Windows\CurrentVersion$lnk
        • API String ID: 2933078328-3916287355
        • Opcode ID: c0b2aa49ad2b0acab997a33698ebcc2e952028e2f40aaddae65ee8a390eaee56
        • Instruction ID: 724e2a4bcd23ac5e6aec95367db283d753fb5558e56250739bcaab0325595989
        • Opcode Fuzzy Hash: c0b2aa49ad2b0acab997a33698ebcc2e952028e2f40aaddae65ee8a390eaee56
        • Instruction Fuzzy Hash: B213B062B0CB8289EB10FF64D8442FCA7B1EB44798F401636DA5D97AE9DF79E584C340

        Control-flow Graph

        • Executed
        • Not Executed
        control_flow_graph 1461 7ff646db0754-7ff646db0829 call 7ff646d9dfd0 call 7ff646d962dc call 7ff646da946c call 7ff646db3cf0 call 7ff646da9a14 1472 7ff646db0860-7ff646db0883 1461->1472 1473 7ff646db082b-7ff646db0840 1461->1473 1476 7ff646db0885-7ff646db089a 1472->1476 1477 7ff646db08ba-7ff646db08dd 1472->1477 1474 7ff646db0842-7ff646db0855 1473->1474 1475 7ff646db085b call 7ff646db220c 1473->1475 1474->1475 1478 7ff646db0ddd-7ff646db0de2 call 7ff646db7904 1474->1478 1475->1472 1480 7ff646db08b5 call 7ff646db220c 1476->1480 1481 7ff646db089c-7ff646db08af 1476->1481 1482 7ff646db08df-7ff646db08f4 1477->1482 1483 7ff646db0914-7ff646db0937 1477->1483 1497 7ff646db0de3-7ff646db0e2f call 7ff646db7904 call 7ff646db1900 1478->1497 1480->1477 1481->1478 1481->1480 1486 7ff646db090f call 7ff646db220c 1482->1486 1487 7ff646db08f6-7ff646db0909 1482->1487 1488 7ff646db096e-7ff646db097a GetCommandLineW 1483->1488 1489 7ff646db0939-7ff646db094e 1483->1489 1486->1483 1487->1478 1487->1486 1491 7ff646db0980-7ff646db09b7 call 7ff646db797c call 7ff646d8129c call 7ff646dacad0 1488->1491 1492 7ff646db0b47-7ff646db0b5e call 7ff646d96454 1488->1492 1494 7ff646db0950-7ff646db0963 1489->1494 1495 7ff646db0969 call 7ff646db220c 1489->1495 1522 7ff646db09b9-7ff646db09cc 1491->1522 1523 7ff646db09ec-7ff646db09f3 1491->1523 1505 7ff646db0b60-7ff646db0b85 call 7ff646d81fa0 call 7ff646db3640 1492->1505 1506 7ff646db0b89-7ff646db0ce4 call 7ff646d81fa0 SetEnvironmentVariableW GetLocalTime call 7ff646d93e28 SetEnvironmentVariableW GetModuleHandleW LoadIconW call 7ff646dab014 call 7ff646d998ac call 7ff646da67b4 * 2 DialogBoxParamW call 7ff646da68a8 * 2 1492->1506 1494->1478 1494->1495 1495->1488 1516 7ff646db0e34-7ff646db0e6a 1497->1516 1505->1506 1566 7ff646db0ce6 Sleep 1506->1566 1567 7ff646db0cec-7ff646db0cf3 1506->1567 1521 7ff646db0e6c 1516->1521 1521->1521 1525 7ff646db09ce-7ff646db09e1 1522->1525 1526 7ff646db09e7 call 7ff646db220c 1522->1526 1527 7ff646db09f9-7ff646db0a13 OpenFileMappingW 1523->1527 1528 7ff646db0adb-7ff646db0b12 call 7ff646db797c call 7ff646d8129c call 7ff646dafd0c 1523->1528 1525->1497 1525->1526 1526->1523 1529 7ff646db0ad0-7ff646db0ad9 CloseHandle 1527->1529 1530 7ff646db0a19-7ff646db0a39 MapViewOfFile 1527->1530 1528->1492 1549 7ff646db0b14-7ff646db0b27 1528->1549 1529->1492 1530->1529 1535 7ff646db0a3f-7ff646db0a6f UnmapViewOfFile MapViewOfFile 1530->1535 1535->1529 1538 7ff646db0a71-7ff646db0aca call 7ff646daa190 call 7ff646dafd0c call 7ff646d9b9b4 call 7ff646d9bb00 call 7ff646d9bb70 UnmapViewOfFile 1535->1538 1538->1529 1552 7ff646db0b42 call 7ff646db220c 1549->1552 1553 7ff646db0b29-7ff646db0b3c 1549->1553 1552->1492 1553->1552 1556 7ff646db0dd7-7ff646db0ddc call 7ff646db7904 1553->1556 1556->1478 1566->1567 1569 7ff646db0cf5 call 7ff646da9f4c 1567->1569 1570 7ff646db0cfa-7ff646db0d1d call 7ff646d9b8e0 DeleteObject 1567->1570 1569->1570 1575 7ff646db0d1f DeleteObject 1570->1575 1576 7ff646db0d25-7ff646db0d2c 1570->1576 1575->1576 1577 7ff646db0d2e-7ff646db0d35 1576->1577 1578 7ff646db0d48-7ff646db0d59 1576->1578 1577->1578 1579 7ff646db0d37-7ff646db0d43 call 7ff646d8ba0c 1577->1579 1580 7ff646db0d6d-7ff646db0d7a 1578->1580 1581 7ff646db0d5b-7ff646db0d67 call 7ff646dafe24 CloseHandle 1578->1581 1579->1578 1583 7ff646db0d9f-7ff646db0da4 call 7ff646da94e4 1580->1583 1584 7ff646db0d7c-7ff646db0d89 1580->1584 1581->1580 1592 7ff646db0da9-7ff646db0dd6 call 7ff646db2320 1583->1592 1587 7ff646db0d99-7ff646db0d9b 1584->1587 1588 7ff646db0d8b-7ff646db0d93 1584->1588 1587->1583 1591 7ff646db0d9d 1587->1591 1588->1583 1590 7ff646db0d95-7ff646db0d97 1588->1590 1590->1583 1591->1583
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: File$EnvironmentHandleVariableView$_invalid_parameter_noinfo_noreturn$AddressCloseCurrentDeleteDirectoryModuleObjectProcUnmap$CommandDialogIconInitializeLineLoadLocalMallocMappingOpenParamSleepTimeswprintf
        • String ID: %4d-%02d-%02d-%02d-%02d-%02d-%03d$STARTDLG$sfxname$sfxstime$winrarsfxmappingfile.tmp
        • API String ID: 1048086575-3710569615
        • Opcode ID: 698fae3a653e1b7d4e45f88450a095eb1b46b52804e719b722bb591d7123fd6d
        • Instruction ID: 37ec9365b9ae4422134de4535e9ab78eaa9c15e0da9e4cc3c3a2ec224033e4cd
        • Opcode Fuzzy Hash: 698fae3a653e1b7d4e45f88450a095eb1b46b52804e719b722bb591d7123fd6d
        • Instruction Fuzzy Hash: EE128E61A1CB8685FB10FB25E8552BDE361FF84B84F404335DA9D86AA9EF3EE144C700

        Control-flow Graph

        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Window$Rect$Text$ByteCharClientItemLongMetricsMultiSystemWideswprintf
        • String ID: $%s:$CAPTION
        • API String ID: 2100155373-404845831
        • Opcode ID: 1224945cd41bf140f0dcf37f1b002595631e4f701a4b658f84a72e9da714e3d9
        • Instruction ID: 1a2d3bffbfde37a75b5ac1dac8fea2563c9537b9a628824d8c4f1c8f558eef1d
        • Opcode Fuzzy Hash: 1224945cd41bf140f0dcf37f1b002595631e4f701a4b658f84a72e9da714e3d9
        • Instruction Fuzzy Hash: 8B91D732B1C64286E758FF29E81066AE7A1FB94788F445635EE4D97B58CF3DE805CB00

        Control-flow Graph

        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Global$Resource$AllocCreateGdipLock$BitmapFindFreeFromLoadSizeofStreamUnlock
        • String ID: PNG
        • API String ID: 211097158-364855578
        • Opcode ID: c8606208415c3a11eb94d5df8c8f8595ea54109f2541637b646828bce78d4013
        • Instruction ID: d22cab4f53b2359fc91435a4ae5cd5f3258ab031d96d4a0fdb66fc76ddcf6534
        • Opcode Fuzzy Hash: c8606208415c3a11eb94d5df8c8f8595ea54109f2541637b646828bce78d4013
        • Instruction Fuzzy Hash: 46411B25B1DA0681FB14BF56D854779E7A0AF88B94F084635CE0E877A4EF7EE449C700
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID: __tmp_reference_source_
        • API String ID: 3668304517-685763994
        • Opcode ID: 7118f36cc522cb397597310d0b68a6e51953c9a10550f0bb30b278ed57268a12
        • Instruction ID: 31d945e22db56fa84ea59206da3601cfaf9df617b47519794bdc5c3a561ce325
        • Opcode Fuzzy Hash: 7118f36cc522cb397597310d0b68a6e51953c9a10550f0bb30b278ed57268a12
        • Instruction Fuzzy Hash: 71E2B462A0C6C292EA64FB25E4543FEE761FB85784F405236DB9D836A5CF3EE458C700
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID: CMT
        • API String ID: 3668304517-2756464174
        • Opcode ID: 8d25fd63a65332c14761dec60f90f7e536d3e8df42b0a807d38d0572dc703df0
        • Instruction ID: dca8f14c83de281cac75258222f4168716e79b21c449e0fa7daf943449f1d079
        • Opcode Fuzzy Hash: 8d25fd63a65332c14761dec60f90f7e536d3e8df42b0a807d38d0572dc703df0
        • Instruction Fuzzy Hash: B6E2E022B0C68286EB58FB75D4542FEA7A1FB44788F401635DA6E877A6DF3EE454C300

        Control-flow Graph

        • Executed
        • Not Executed
        control_flow_graph 3471 7ff646d940bc-7ff646d940f3 3472 7ff646d941d2-7ff646d941df FindNextFileW 3471->3472 3473 7ff646d940f9-7ff646d94101 3471->3473 3476 7ff646d941e1-7ff646d941f1 GetLastError 3472->3476 3477 7ff646d941f3-7ff646d941f6 3472->3477 3474 7ff646d94103 3473->3474 3475 7ff646d94106-7ff646d94118 FindFirstFileW 3473->3475 3474->3475 3475->3477 3478 7ff646d9411e-7ff646d94146 call 7ff646d96a0c 3475->3478 3479 7ff646d941ca-7ff646d941cd 3476->3479 3480 7ff646d94211-7ff646d94253 call 7ff646db797c call 7ff646d8129c call 7ff646d98090 3477->3480 3481 7ff646d941f8-7ff646d94200 3477->3481 3493 7ff646d94167-7ff646d94170 3478->3493 3494 7ff646d94148-7ff646d94164 FindFirstFileW 3478->3494 3483 7ff646d942eb-7ff646d9430e call 7ff646db2320 3479->3483 3507 7ff646d94255-7ff646d9426c 3480->3507 3508 7ff646d9428c-7ff646d942e6 call 7ff646d9f168 * 3 3480->3508 3485 7ff646d94202 3481->3485 3486 7ff646d94205-7ff646d9420c call 7ff646d820b0 3481->3486 3485->3486 3486->3480 3495 7ff646d94172-7ff646d94189 3493->3495 3496 7ff646d941a9-7ff646d941ad 3493->3496 3494->3493 3498 7ff646d941a4 call 7ff646db220c 3495->3498 3499 7ff646d9418b-7ff646d9419e 3495->3499 3496->3477 3500 7ff646d941af-7ff646d941be GetLastError 3496->3500 3498->3496 3499->3498 3502 7ff646d94315-7ff646d9431b call 7ff646db7904 3499->3502 3504 7ff646d941c0-7ff646d941c6 3500->3504 3505 7ff646d941c8 3500->3505 3504->3479 3504->3505 3505->3479 3510 7ff646d9426e-7ff646d94281 3507->3510 3511 7ff646d94287 call 7ff646db220c 3507->3511 3508->3483 3510->3511 3514 7ff646d9430f-7ff646d94314 call 7ff646db7904 3510->3514 3511->3508 3514->3502
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: FileFind$ErrorFirstLast_invalid_parameter_noinfo_noreturn$Next
        • String ID:
        • API String ID: 474548282-0
        • Opcode ID: ee5b8a3817742aa34bf8fe6f457784b4fe5053db0f5ec5b81f22969634733f46
        • Instruction ID: 4db9a74b2ada35561020af245834a9aa19ac7d3e780092b98f8645639b45fd82
        • Opcode Fuzzy Hash: ee5b8a3817742aa34bf8fe6f457784b4fe5053db0f5ec5b81f22969634733f46
        • Instruction Fuzzy Hash: 3461A362A0CB4681EA10BF25E85027DA361FB85BA8F105331EABD937D9DF3DD558C700
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID: CMT
        • API String ID: 0-2756464174
        • Opcode ID: e58ea5d07e30f29eaf86f68642e1cb38961aa44a7661b56cd2ad864dc5164ece
        • Instruction ID: 5f7dea329760d462429c629e3c3cf860492619477cc565b28c20fd795b9eec47
        • Opcode Fuzzy Hash: e58ea5d07e30f29eaf86f68642e1cb38961aa44a7661b56cd2ad864dc5164ece
        • Instruction Fuzzy Hash: 0142EF22B0C6C296EB18FB74C5552FDA7A0EB41758F401A36DB2E936E6DF39E518C700
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 00cc9b5d49baee892d39d1da46008d2b4229947a5b0a2c39888c4d08721f4c94
        • Instruction ID: aac4ba4d34f6f58a39dcc0d47b6ee83ba1a7f68b524a16eca7d40df42a25dc86
        • Opcode Fuzzy Hash: 00cc9b5d49baee892d39d1da46008d2b4229947a5b0a2c39888c4d08721f4c94
        • Instruction Fuzzy Hash: 68E1D422A0D3828AEB64FF29A5442BDB791FB48748F054239DB4EC7B85DF3EE5418704
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 26af858850e4daafc6f2970d44d6bc4b8aba49acee0196899845173dc4538b23
        • Instruction ID: 66d49d331732d44b83a4b4487c6d073576f8a5e3db6c680bba821b34ad2275d4
        • Opcode Fuzzy Hash: 26af858850e4daafc6f2970d44d6bc4b8aba49acee0196899845173dc4538b23
        • Instruction Fuzzy Hash: F9B1CEA2B0CBC993DE58EA669608BE9A392BB45FC4F498132DE1D87741DF3DE155C300
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Create$CriticalEventInitializeSectionSemaphore
        • String ID:
        • API String ID: 3340455307-0
        • Opcode ID: da87a57a9ac39f65141c41a007b89939efb02abc0997ac81e55b16170c34fd38
        • Instruction ID: 90e6da457ef9872792c2bf7e9de2476f8a522f8b67cf9d7e221208c501b3b3a0
        • Opcode Fuzzy Hash: da87a57a9ac39f65141c41a007b89939efb02abc0997ac81e55b16170c34fd38
        • Instruction Fuzzy Hash: 28410822B19756C6FA64FF11A92076AA252FBC478CF044234DE4D87795DE3DE44AC704

        Control-flow Graph

        • Executed
        • Not Executed
        control_flow_graph 0 7ff646d9dfd0-7ff646d9e024 call 7ff646db2450 GetModuleHandleW 3 7ff646d9e026-7ff646d9e039 GetProcAddress 0->3 4 7ff646d9e07b-7ff646d9e3a5 0->4 5 7ff646d9e053-7ff646d9e066 GetProcAddress 3->5 6 7ff646d9e03b-7ff646d9e04a 3->6 7 7ff646d9e503-7ff646d9e521 call 7ff646d96454 call 7ff646d97df4 4->7 8 7ff646d9e3ab-7ff646d9e3b4 call 7ff646dbb788 4->8 5->4 10 7ff646d9e068-7ff646d9e078 5->10 6->5 19 7ff646d9e525-7ff646d9e52f call 7ff646d951a4 7->19 8->7 16 7ff646d9e3ba-7ff646d9e3fd call 7ff646d96454 CreateFileW 8->16 10->4 21 7ff646d9e4f0-7ff646d9e4fe CloseHandle call 7ff646d81fa0 16->21 22 7ff646d9e403-7ff646d9e416 SetFilePointer 16->22 28 7ff646d9e531-7ff646d9e53c call 7ff646d9dd88 19->28 29 7ff646d9e564-7ff646d9e5ac call 7ff646db797c call 7ff646d8129c call 7ff646d98090 call 7ff646d81fa0 call 7ff646d932bc 19->29 21->7 22->21 24 7ff646d9e41c-7ff646d9e43e ReadFile 22->24 24->21 27 7ff646d9e444-7ff646d9e452 24->27 31 7ff646d9e800-7ff646d9e807 call 7ff646db2624 27->31 32 7ff646d9e458-7ff646d9e4ac call 7ff646db797c call 7ff646d8129c 27->32 28->29 41 7ff646d9e53e-7ff646d9e562 CompareStringW 28->41 69 7ff646d9e5b1-7ff646d9e5b4 29->69 49 7ff646d9e4c3-7ff646d9e4d9 call 7ff646d9d0a0 32->49 41->29 44 7ff646d9e5bd-7ff646d9e5c6 41->44 44->19 47 7ff646d9e5cc 44->47 50 7ff646d9e5d1-7ff646d9e5d4 47->50 64 7ff646d9e4ae-7ff646d9e4be call 7ff646d9dd88 49->64 65 7ff646d9e4db-7ff646d9e4eb call 7ff646d81fa0 * 2 49->65 53 7ff646d9e63f-7ff646d9e642 50->53 54 7ff646d9e5d6-7ff646d9e5d9 50->54 58 7ff646d9e7c2-7ff646d9e7ff call 7ff646d81fa0 * 2 call 7ff646db2320 53->58 59 7ff646d9e648-7ff646d9e65b call 7ff646d97eb0 call 7ff646d951a4 53->59 55 7ff646d9e5dd-7ff646d9e62d call 7ff646db797c call 7ff646d8129c call 7ff646d98090 call 7ff646d81fa0 call 7ff646d932bc 54->55 108 7ff646d9e62f-7ff646d9e638 55->108 109 7ff646d9e63c 55->109 82 7ff646d9e661-7ff646d9e701 call 7ff646d9dd88 * 2 call 7ff646d9aae0 call 7ff646d9da98 call 7ff646d9aae0 call 7ff646d9dc2c call 7ff646da87ac call 7ff646d819e0 59->82 83 7ff646d9e706-7ff646d9e753 call 7ff646d9da98 AllocConsole 59->83 64->49 65->21 75 7ff646d9e5ce 69->75 76 7ff646d9e5b6 69->76 75->50 76->44 100 7ff646d9e7b4-7ff646d9e7bb call 7ff646d819e0 ExitProcess 82->100 94 7ff646d9e7b0 83->94 95 7ff646d9e755-7ff646d9e7aa GetCurrentProcessId AttachConsole call 7ff646d9e868 call 7ff646d9e858 GetStdHandle WriteConsoleW Sleep FreeConsole 83->95 94->100 95->94 108->55 112 7ff646d9e63a 108->112 109->53 112->53
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$Console$FileHandle$AddressProcProcess$AllocAttachCloseCompareCreateCurrentDirectoryExitFreeLibraryLoadModulePointerReadSleepStringSystemVersionWrite
        • String ID: DXGIDebug.dll$Please remove %s from %s folder. It is unsecure to run %s until it is done.$RpcRtRemote.dll$SSPICLI.DLL$SetDefaultDllDirectories$SetDllDirectoryW$UXTheme.dll$WINNSI.DLL$WindowsCodecs.dll$XmlLite.dll$aclui.dll$apphelp.dll$atl.dll$browcli.dll$cabinet.dll$clbcatq.dll$comres.dll$crypt32.dll$cryptbase.dll$cryptsp.dll$cryptui.dll$cscapi.dll$devrtl.dll$dfscli.dll$dhcpcsvc.dll$dhcpcsvc6.dll$dnsapi.DLL$dsrole.dll$dwmapi.dll$ieframe.dll$imageres.dll$iphlpapi.DLL$kernel32$linkinfo.dll$lpk.dll$mlang.dll$mpr.dll$msasn1.dll$netapi32.dll$netutils.dll$ntmarta.dll$ntshrui.dll$oleaccrc.dll$peerdist.dll$profapi.dll$propsys.dll$psapi.dll$rasadhlp.dll$rsaenh.dll$samcli.dll$samlib.dll$secur32.dll$setupapi.dll$sfc_os.dll$shdocvw.dll$shell32.dll$slc.dll$srvcli.dll$userenv.dll$usp10.dll$uxtheme.dll$version.dll$wintrust.dll$wkscli.dll$ws2_32.dll$ws2help.dll
        • API String ID: 1496594111-2013832382
        • Opcode ID: 729aa0bc78a87cf64f47f55ad2113f2e0944a5e52d0d2a48ebf2ce523c5df02a
        • Instruction ID: 89d99c2dde96fd30a881cf3f58345a95c3dc4ec84560a4d7a7540578fa73056e
        • Opcode Fuzzy Hash: 729aa0bc78a87cf64f47f55ad2113f2e0944a5e52d0d2a48ebf2ce523c5df02a
        • Instruction Fuzzy Hash: A6321B31A0DB8699EB11BF60E8501E9B3A4FF44358F501336DA4E867A9EF3ED259C740
        APIs
          • Part of subcall function 00007FF646D98E58: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF646D98F8D
        • _snwprintf.LEGACY_STDIO_DEFINITIONS ref: 00007FF646D99F75
        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646D9A42F
        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646D9A435
          • Part of subcall function 00007FF646DA0BBC: MultiByteToWideChar.KERNEL32(?,?,?,?,?,00007FF646DA0B44), ref: 00007FF646DA0BE9
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$ByteCharConcurrency::cancel_current_taskMultiWide_snwprintf
        • String ID: $ ,$$%s:$*messages***$*messages***$@%s:$DIALOG$DIRECTION$MENU$RTL$STRINGS
        • API String ID: 3629253777-3268106645
        • Opcode ID: a0ca64e2e6ce2865254327ea7649ce479d77a76cd71c28d6026bad56dc47627e
        • Instruction ID: 1f377cb6ca40d2a0136a5b63a999c1bfb3bbd1b21b6cfd9d3e36ffab832f4ccd
        • Opcode Fuzzy Hash: a0ca64e2e6ce2865254327ea7649ce479d77a76cd71c28d6026bad56dc47627e
        • Instruction Fuzzy Hash: E362B122B1D682D5EB20FF65C4642BDA361FB44788F845232DA4D8B6D9EF3EE549C340

        Control-flow Graph

        • Executed
        • Not Executed
        control_flow_graph 1905 7ff646db1900-7ff646db1989 call 7ff646db1558 1908 7ff646db19b4-7ff646db19d1 1905->1908 1909 7ff646db198b-7ff646db19af call 7ff646db1868 RaiseException 1905->1909 1911 7ff646db19d3-7ff646db19e4 1908->1911 1912 7ff646db19e6-7ff646db19ea 1908->1912 1917 7ff646db1bb8-7ff646db1bd5 1909->1917 1913 7ff646db19ed-7ff646db19f9 1911->1913 1912->1913 1915 7ff646db1a1a-7ff646db1a1d 1913->1915 1916 7ff646db19fb-7ff646db1a0d 1913->1916 1918 7ff646db1ac4-7ff646db1acb 1915->1918 1919 7ff646db1a23-7ff646db1a26 1915->1919 1925 7ff646db1a13 1916->1925 1926 7ff646db1b89-7ff646db1b93 1916->1926 1921 7ff646db1adf-7ff646db1ae2 1918->1921 1922 7ff646db1acd-7ff646db1adc 1918->1922 1923 7ff646db1a28-7ff646db1a3b 1919->1923 1924 7ff646db1a3d-7ff646db1a52 LoadLibraryExA 1919->1924 1927 7ff646db1b85 1921->1927 1928 7ff646db1ae8-7ff646db1aec 1921->1928 1922->1921 1923->1924 1930 7ff646db1aa9-7ff646db1ab2 1923->1930 1929 7ff646db1a54-7ff646db1a67 GetLastError 1924->1929 1924->1930 1925->1915 1937 7ff646db1bb0 call 7ff646db1868 1926->1937 1938 7ff646db1b95-7ff646db1ba6 1926->1938 1927->1926 1935 7ff646db1aee-7ff646db1af2 1928->1935 1936 7ff646db1b1b-7ff646db1b2e GetProcAddress 1928->1936 1939 7ff646db1a7e-7ff646db1aa4 call 7ff646db1868 RaiseException 1929->1939 1940 7ff646db1a69-7ff646db1a7c 1929->1940 1931 7ff646db1ab4-7ff646db1ab7 FreeLibrary 1930->1931 1932 7ff646db1abd 1930->1932 1931->1932 1932->1918 1935->1936 1943 7ff646db1af4-7ff646db1aff 1935->1943 1936->1927 1942 7ff646db1b30-7ff646db1b43 GetLastError 1936->1942 1945 7ff646db1bb5 1937->1945 1938->1937 1939->1917 1940->1930 1940->1939 1947 7ff646db1b45-7ff646db1b58 1942->1947 1948 7ff646db1b5a-7ff646db1b81 call 7ff646db1868 RaiseException call 7ff646db1558 1942->1948 1943->1936 1949 7ff646db1b01-7ff646db1b08 1943->1949 1945->1917 1947->1927 1947->1948 1948->1927 1949->1936 1952 7ff646db1b0a-7ff646db1b0f 1949->1952 1952->1936 1955 7ff646db1b11-7ff646db1b19 1952->1955 1955->1927 1955->1936
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: DloadSection$AccessExceptionProtectRaiseReleaseWrite$ErrorLastLibraryLoad
        • String ID: H
        • API String ID: 3432403771-2852464175
        • Opcode ID: cf3fc932a6b7fb7fc9ef8320b4dd67bfc8d7ec91281715f792326570f1d4a57f
        • Instruction ID: f9cbf4a552f3d364b3d08fd9b22b2798b0512748b5cfe66d2ef2a1cc092a83b4
        • Opcode Fuzzy Hash: cf3fc932a6b7fb7fc9ef8320b4dd67bfc8d7ec91281715f792326570f1d4a57f
        • Instruction Fuzzy Hash: F9915A32A19B568AEB00EFA5D8406ACB3B5FB09B98F444635DE0E97758EF39E445C700

        Control-flow Graph

        • Executed
        • Not Executed
        control_flow_graph 1983 7ff646daf4e0-7ff646daf523 1984 7ff646daf894-7ff646daf8b9 call 7ff646d81fa0 call 7ff646db2320 1983->1984 1985 7ff646daf529-7ff646daf565 call 7ff646db3cf0 1983->1985 1991 7ff646daf567 1985->1991 1992 7ff646daf56a-7ff646daf571 1985->1992 1991->1992 1993 7ff646daf582-7ff646daf586 1992->1993 1994 7ff646daf573-7ff646daf577 1992->1994 1998 7ff646daf588 1993->1998 1999 7ff646daf58b-7ff646daf596 1993->1999 1996 7ff646daf579 1994->1996 1997 7ff646daf57c-7ff646daf580 1994->1997 1996->1997 1997->1999 1998->1999 2000 7ff646daf628 1999->2000 2001 7ff646daf59c 1999->2001 2003 7ff646daf62c-7ff646daf62f 2000->2003 2002 7ff646daf5a2-7ff646daf5a9 2001->2002 2004 7ff646daf5ae-7ff646daf5b3 2002->2004 2005 7ff646daf5ab 2002->2005 2006 7ff646daf631-7ff646daf635 2003->2006 2007 7ff646daf637-7ff646daf63a 2003->2007 2008 7ff646daf5e5-7ff646daf5f0 2004->2008 2009 7ff646daf5b5 2004->2009 2005->2004 2006->2007 2010 7ff646daf660-7ff646daf673 call 7ff646d963ac 2006->2010 2007->2010 2011 7ff646daf63c-7ff646daf643 2007->2011 2014 7ff646daf5f5-7ff646daf5fa 2008->2014 2015 7ff646daf5f2 2008->2015 2016 7ff646daf5ca-7ff646daf5d0 2009->2016 2024 7ff646daf675-7ff646daf693 call 7ff646da13c4 2010->2024 2025 7ff646daf698-7ff646daf6ed call 7ff646db797c call 7ff646d8129c call 7ff646d932a8 call 7ff646d81fa0 2010->2025 2011->2010 2012 7ff646daf645-7ff646daf65c 2011->2012 2012->2010 2020 7ff646daf600-7ff646daf607 2014->2020 2021 7ff646daf8ba-7ff646daf8c1 2014->2021 2015->2014 2017 7ff646daf5d2 2016->2017 2018 7ff646daf5b7-7ff646daf5be 2016->2018 2017->2008 2028 7ff646daf5c0 2018->2028 2029 7ff646daf5c3-7ff646daf5c8 2018->2029 2026 7ff646daf609 2020->2026 2027 7ff646daf60c-7ff646daf612 2020->2027 2022 7ff646daf8c3 2021->2022 2023 7ff646daf8c6-7ff646daf8cb 2021->2023 2022->2023 2030 7ff646daf8de-7ff646daf8e6 2023->2030 2031 7ff646daf8cd-7ff646daf8d4 2023->2031 2024->2025 2050 7ff646daf6ef-7ff646daf73d call 7ff646db797c call 7ff646d8129c call 7ff646d95b60 call 7ff646d81fa0 2025->2050 2051 7ff646daf742-7ff646daf74f ShellExecuteExW 2025->2051 2026->2027 2027->2021 2034 7ff646daf618-7ff646daf622 2027->2034 2028->2029 2029->2016 2035 7ff646daf5d4-7ff646daf5db 2029->2035 2040 7ff646daf8e8 2030->2040 2041 7ff646daf8eb-7ff646daf8f6 2030->2041 2038 7ff646daf8d9 2031->2038 2039 7ff646daf8d6 2031->2039 2034->2000 2034->2002 2036 7ff646daf5e0 2035->2036 2037 7ff646daf5dd 2035->2037 2036->2008 2037->2036 2038->2030 2039->2038 2040->2041 2041->2003 2050->2051 2053 7ff646daf755-7ff646daf75f 2051->2053 2054 7ff646daf846-7ff646daf84e 2051->2054 2058 7ff646daf761-7ff646daf764 2053->2058 2059 7ff646daf76f-7ff646daf772 2053->2059 2056 7ff646daf850-7ff646daf866 2054->2056 2057 7ff646daf882-7ff646daf88f 2054->2057 2061 7ff646daf868-7ff646daf87b 2056->2061 2062 7ff646daf87d call 7ff646db220c 2056->2062 2057->1984 2058->2059 2063 7ff646daf766-7ff646daf76d 2058->2063 2064 7ff646daf78e-7ff646daf7ad call 7ff646dee1b8 call 7ff646dafe24 2059->2064 2065 7ff646daf774-7ff646daf77f call 7ff646dee188 2059->2065 2061->2062 2068 7ff646daf8fb-7ff646daf903 call 7ff646db7904 2061->2068 2062->2057 2063->2059 2070 7ff646daf7e3-7ff646daf7f0 CloseHandle 2063->2070 2064->2070 2091 7ff646daf7af-7ff646daf7b2 2064->2091 2065->2064 2078 7ff646daf781-7ff646daf78c ShowWindow 2065->2078 2076 7ff646daf805-7ff646daf80c 2070->2076 2077 7ff646daf7f2-7ff646daf803 call 7ff646da13c4 2070->2077 2083 7ff646daf82e-7ff646daf830 2076->2083 2084 7ff646daf80e-7ff646daf811 2076->2084 2077->2076 2077->2083 2078->2064 2083->2054 2086 7ff646daf832-7ff646daf835 2083->2086 2084->2083 2085 7ff646daf813-7ff646daf828 2084->2085 2085->2083 2086->2054 2090 7ff646daf837-7ff646daf845 ShowWindow 2086->2090 2090->2054 2091->2070 2093 7ff646daf7b4-7ff646daf7c5 GetExitCodeProcess 2091->2093 2093->2070 2094 7ff646daf7c7-7ff646daf7dc 2093->2094 2094->2070
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ShowWindow$CloseCodeExecuteExitHandleProcessShell_invalid_parameter_noinfo_noreturn
        • String ID: .exe$.inf$Install$p
        • API String ID: 1054546013-3607691742
        • Opcode ID: 67b61dfe47284e38b67ea0c0b1901cc6ac0d6bddf6aab1d537367ec119b3a945
        • Instruction ID: 429f2ca62904286ef83ceeea4bd04983a2f0d2b9dc0758efb418664b97dbd6c9
        • Opcode Fuzzy Hash: 67b61dfe47284e38b67ea0c0b1901cc6ac0d6bddf6aab1d537367ec119b3a945
        • Instruction Fuzzy Hash: D3C1AE62F0CA0295FB58FB66D944279A3B1AF99B84F044271CA4DC77A4DF3EE495C340

        Control-flow Graph

        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Message$Send$DialogDispatchItemPeekShowTranslateWindow
        • String ID:
        • API String ID: 3569833718-0
        • Opcode ID: c58ef51af4c11ae469b78d40ba7290d4e9656f32b0895ce54e4debee0d1a06d9
        • Instruction ID: 5ade036cdc1a2a68aea8c7e66ab75ae96b2f7a3cf2a87fa61903bfc911cd39ff
        • Opcode Fuzzy Hash: c58ef51af4c11ae469b78d40ba7290d4e9656f32b0895ce54e4debee0d1a06d9
        • Instruction Fuzzy Hash: 4441A331B1CA4286F710FF61E810BAAA760EB85B99F441235DD0A87FA5CF7ED4458744
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3668304517-0
        • Opcode ID: 95f682f023754f56a0dcca5eb1f48e82665a17e2aa84d7a71d7c4cda38083178
        • Instruction ID: c5cff5b6c0ff5840bb98494808f0ec1272dbbf77cf95fa1b0a71134472a0ea78
        • Opcode Fuzzy Hash: 95f682f023754f56a0dcca5eb1f48e82665a17e2aa84d7a71d7c4cda38083178
        • Instruction Fuzzy Hash: 7C12C162B0C74185EB10FB65D4482BDA371EB857A8F405336DA6C97AE9DF3ED489C340

        Control-flow Graph

        • Executed
        • Not Executed
        control_flow_graph 3522 7ff646d924c0-7ff646d924fb 3523 7ff646d92506 3522->3523 3524 7ff646d924fd-7ff646d92504 3522->3524 3525 7ff646d92509-7ff646d92578 3523->3525 3524->3523 3524->3525 3526 7ff646d9257a 3525->3526 3527 7ff646d9257d-7ff646d925a8 CreateFileW 3525->3527 3526->3527 3528 7ff646d925ae-7ff646d925de GetLastError call 7ff646d96a0c 3527->3528 3529 7ff646d92688-7ff646d9268d 3527->3529 3535 7ff646d925e0-7ff646d9262a CreateFileW GetLastError 3528->3535 3536 7ff646d9262c 3528->3536 3530 7ff646d92693-7ff646d92697 3529->3530 3532 7ff646d926a5-7ff646d926a9 3530->3532 3533 7ff646d92699-7ff646d9269c 3530->3533 3538 7ff646d926cf-7ff646d926e3 3532->3538 3539 7ff646d926ab-7ff646d926af 3532->3539 3533->3532 3537 7ff646d9269e 3533->3537 3542 7ff646d92632-7ff646d9263a 3535->3542 3536->3542 3537->3532 3540 7ff646d926e5-7ff646d926f0 3538->3540 3541 7ff646d9270c-7ff646d92735 call 7ff646db2320 3538->3541 3539->3538 3543 7ff646d926b1-7ff646d926c9 SetFileTime 3539->3543 3544 7ff646d926f2-7ff646d926fa 3540->3544 3545 7ff646d92708 3540->3545 3546 7ff646d92673-7ff646d92686 3542->3546 3547 7ff646d9263c-7ff646d92653 3542->3547 3543->3538 3549 7ff646d926ff-7ff646d92703 call 7ff646d820b0 3544->3549 3550 7ff646d926fc 3544->3550 3545->3541 3546->3530 3551 7ff646d9266e call 7ff646db220c 3547->3551 3552 7ff646d92655-7ff646d92668 3547->3552 3549->3545 3550->3549 3551->3546 3552->3551 3555 7ff646d92736-7ff646d9273b call 7ff646db7904 3552->3555
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: File$CreateErrorLast$Time_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3536497005-0
        • Opcode ID: dc46ff84bd0c57c9ac2b9914d0228e8f14f7433d989622a2074281460ea8d587
        • Instruction ID: f786f95f9cbfbcea6781034107df7a45d3d9c437e0cd38b9df91d549da24d02b
        • Opcode Fuzzy Hash: dc46ff84bd0c57c9ac2b9914d0228e8f14f7433d989622a2074281460ea8d587
        • Instruction Fuzzy Hash: DD61C266A1C68185E720AF29E41076EA7B1BB847ACF101334DFAE43AD8DF3ED058C744

        Control-flow Graph

        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Global$Resource$Object$AllocBitmapCreateDeleteGdipLoadLock$FindFreeFromSizeofStreamUnlock
        • String ID: ]
        • API String ID: 3561356813-3352871620
        • Opcode ID: 2f79d63664e457f963bfbd157e1c525b341384e02eb8e860e1f42d2dee528bbf
        • Instruction ID: a1442191c59c5dab1074f2a8be2acd2dbabe31b656b9975e4a06281dc22fb48d
        • Opcode Fuzzy Hash: 2f79d63664e457f963bfbd157e1c525b341384e02eb8e860e1f42d2dee528bbf
        • Instruction Fuzzy Hash: 69118621F0D64246FB64BB22E655379E392AF89BC0F080234DD5D87B99EE2EE8058700

        Control-flow Graph

        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Message$DialogDispatchPeekTranslate
        • String ID:
        • API String ID: 1266772231-0
        • Opcode ID: 8f901ab8bb575df3ccfb48a5cb3294f091b017f84468599a2020223c8e70b7dc
        • Instruction ID: b38719a443f9978dc12ed4bcbf63699aba24ab054e79aa4872ff097a252be7d6
        • Opcode Fuzzy Hash: 8f901ab8bb575df3ccfb48a5cb3294f091b017f84468599a2020223c8e70b7dc
        • Instruction Fuzzy Hash: CCF0EC25B3C94282FB50BB60E895A36E361FFD4705F845635E64EC1854DF2ED548CB00

        Control-flow Graph

        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AutoClassCompareCompleteFindNameStringWindow
        • String ID: EDIT
        • API String ID: 4243998846-3080729518
        • Opcode ID: 5198dd27efd6ef2cfe81d4e1a42d30dc263c523227a297f5f4c02164b2b5e029
        • Instruction ID: bb06ac6322e40469370985185bc19ec4d54036f83dc42015bbc3dac0cc999e0c
        • Opcode Fuzzy Hash: 5198dd27efd6ef2cfe81d4e1a42d30dc263c523227a297f5f4c02164b2b5e029
        • Instruction Fuzzy Hash: 10013161B1CA4781FA30BF62F8147F6E390BF99784F881231C94D8B659DE2EE149C640

        Control-flow Graph

        • Executed
        • Not Executed
        control_flow_graph 3888 7ff646d92ce0-7ff646d92d0a 3889 7ff646d92d13-7ff646d92d1b 3888->3889 3890 7ff646d92d0c-7ff646d92d0e 3888->3890 3892 7ff646d92d2b 3889->3892 3893 7ff646d92d1d-7ff646d92d28 GetStdHandle 3889->3893 3891 7ff646d92ea9-7ff646d92ec4 call 7ff646db2320 3890->3891 3895 7ff646d92d31-7ff646d92d3d 3892->3895 3893->3892 3897 7ff646d92d3f-7ff646d92d44 3895->3897 3898 7ff646d92d86-7ff646d92da2 WriteFile 3895->3898 3899 7ff646d92daf-7ff646d92db3 3897->3899 3900 7ff646d92d46-7ff646d92d7a WriteFile 3897->3900 3901 7ff646d92da6-7ff646d92da9 3898->3901 3903 7ff646d92ea2-7ff646d92ea6 3899->3903 3904 7ff646d92db9-7ff646d92dbd 3899->3904 3900->3901 3902 7ff646d92d7c-7ff646d92d82 3900->3902 3901->3899 3901->3903 3902->3900 3905 7ff646d92d84 3902->3905 3903->3891 3904->3903 3906 7ff646d92dc3-7ff646d92dd8 call 7ff646d8b4f8 3904->3906 3905->3901 3909 7ff646d92e1e-7ff646d92e6d call 7ff646db797c call 7ff646d8129c call 7ff646d8bca8 3906->3909 3910 7ff646d92dda-7ff646d92de1 3906->3910 3909->3903 3921 7ff646d92e6f-7ff646d92e86 3909->3921 3910->3895 3911 7ff646d92de7-7ff646d92de9 3910->3911 3911->3895 3913 7ff646d92def-7ff646d92e19 3911->3913 3913->3895 3922 7ff646d92e88-7ff646d92e9b 3921->3922 3923 7ff646d92e9d call 7ff646db220c 3921->3923 3922->3923 3925 7ff646d92ec5-7ff646d92ecb call 7ff646db7904 3922->3925 3923->3903
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: FileWrite$Handle
        • String ID:
        • API String ID: 4209713984-0
        • Opcode ID: 759593f06e971a5af3dff942057e3884964648b854c35b3f90eb8150d1d2c130
        • Instruction ID: 075066ff4636e5df8e4f49e3343a40fb8fdb5cf6dc21888a5166735f9eb3f325
        • Opcode Fuzzy Hash: 759593f06e971a5af3dff942057e3884964648b854c35b3f90eb8150d1d2c130
        • Instruction Fuzzy Hash: 4451E762A2D54682FB50BF25D45477AA350FF84B98F441331EA0E87A94DF3ED589C340

        Control-flow Graph

        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$TextWindow
        • String ID:
        • API String ID: 2912839123-0
        • Opcode ID: 8a0c15bc77fd32c201e399d9c3f52707d58e70f4a32258776395ca5be8329a26
        • Instruction ID: 74e733314b14f7c4b68d187eaf70d1bbc2ac172f2ba9471a4b3868b50d8cd229
        • Opcode Fuzzy Hash: 8a0c15bc77fd32c201e399d9c3f52707d58e70f4a32258776395ca5be8329a26
        • Instruction Fuzzy Hash: 2851A162F28A5285FF00FBA4D8443BDA362AF45BA4F504736DA1D96BE9DF6ED440C304
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_initialize_crt__scrt_release_startup_lock
        • String ID:
        • API String ID: 1452418845-0
        • Opcode ID: f380b52e8f95e6a0f24ce785192d8cb773bc143ddf3d62aee805abe4fb8ed354
        • Instruction ID: be07adfe2ff90d84b06e69bbd06c8335f3a84335bd1f2ec893dc975b153e802a
        • Opcode Fuzzy Hash: f380b52e8f95e6a0f24ce785192d8cb773bc143ddf3d62aee805abe4fb8ed354
        • Instruction Fuzzy Hash: 8F314C62E4C24342FB54BF66D4513BEE291AF45B84F440734E91ECB6DBDE6FA844C250

        Control-flow Graph

        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CreateDirectory$ErrorLast_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 2359106489-0
        • Opcode ID: 5cda4ea00785afd89f4b2a0283e369f756aeb3863be6a65230e4b36aaec5c4cf
        • Instruction ID: 816dfb8dec93169656efee05211f0efd89bb89bfa7cbf47af8750f9a08120c37
        • Opcode Fuzzy Hash: 5cda4ea00785afd89f4b2a0283e369f756aeb3863be6a65230e4b36aaec5c4cf
        • Instruction Fuzzy Hash: 7B31A376E0C682C1EB20BB25A464279E361FF89798F510331EE9DC37A5DF3ED4498600
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ErrorLast$FileHandleRead
        • String ID:
        • API String ID: 2244327787-0
        • Opcode ID: 5dece825d5be91adec6864fa12bb564f4e3b5809c08bfde6ef0babe01e3581d0
        • Instruction ID: e6d44b3d138243a568f64228955507ebe5ddd126b3d068dee11ac68363b89871
        • Opcode Fuzzy Hash: 5dece825d5be91adec6864fa12bb564f4e3b5809c08bfde6ef0babe01e3581d0
        • Instruction Fuzzy Hash: 14216221A2C552C1EA60BF31A410239E7A0FB45B9CF144739DA5DC6A84CF7EE8898751
        APIs
          • Part of subcall function 00007FF646D9ECD8: ResetEvent.KERNEL32 ref: 00007FF646D9ECF1
          • Part of subcall function 00007FF646D9ECD8: ReleaseSemaphore.KERNEL32 ref: 00007FF646D9ED07
        • ReleaseSemaphore.KERNEL32 ref: 00007FF646D9E974
        • CloseHandle.KERNELBASE ref: 00007FF646D9E993
        • DeleteCriticalSection.KERNEL32 ref: 00007FF646D9E9AA
        • CloseHandle.KERNEL32 ref: 00007FF646D9E9B7
          • Part of subcall function 00007FF646D9EA5C: WaitForSingleObject.KERNEL32(?,?,?,?,?,?,?,?,00007FF646D9E95F,?,?,?,00007FF646D9463A,?,?,?), ref: 00007FF646D9EA63
          • Part of subcall function 00007FF646D9EA5C: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00007FF646D9E95F,?,?,?,00007FF646D9463A,?,?,?), ref: 00007FF646D9EA6E
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CloseHandleReleaseSemaphore$CriticalDeleteErrorEventLastObjectResetSectionSingleWait
        • String ID:
        • API String ID: 502429940-0
        • Opcode ID: 7c4c69b688bb09167c3d8ec6f4195a818a409db0987586a56ae23aa503e7e0cd
        • Instruction ID: f14dc1b5708e9270bf1e287c58983538aab79b51fb16ecd203d45cb0ebf51a1e
        • Opcode Fuzzy Hash: 7c4c69b688bb09167c3d8ec6f4195a818a409db0987586a56ae23aa503e7e0cd
        • Instruction Fuzzy Hash: BB012D32A19A91E2E758BB21E55466DA770FB84B80F004231DB6E43625CF3AE4B88740
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Thread$CreatePriority
        • String ID: CreateThread failed
        • API String ID: 2610526550-3849766595
        • Opcode ID: cf4f3858e1c5421656891f758a667cd72a6f2059ba57d4f8d940dbc9b5e0f540
        • Instruction ID: c99db7bd832d413f4ad6de042cf9549dbc2644fc143f8f0de377741f0c19de29
        • Opcode Fuzzy Hash: cf4f3858e1c5421656891f758a667cd72a6f2059ba57d4f8d940dbc9b5e0f540
        • Instruction Fuzzy Hash: 7C115B31A0CA42C1E700BF10E8415AAF370FF84788F584331DA5E86669EF3EE596C740
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: DirectoryInitializeMallocSystem
        • String ID: riched20.dll
        • API String ID: 174490985-3360196438
        • Opcode ID: 0d85db053d286d1bd0fa19ead2840fc3f5149c6ee0f027e6ed6c33eb2c824e37
        • Instruction ID: 105ab2f536a624946911a80d138132bb0962757be3b7eb59a386d6b55099ef19
        • Opcode Fuzzy Hash: 0d85db053d286d1bd0fa19ead2840fc3f5149c6ee0f027e6ed6c33eb2c824e37
        • Instruction Fuzzy Hash: 21F04F7161CA4182EB40BF60F41416AF3A0FB88754F440235E98E82B58DF7DD14DCB00
        APIs
          • Part of subcall function 00007FF646DA853C: GlobalMemoryStatusEx.KERNEL32 ref: 00007FF646DA856C
          • Part of subcall function 00007FF646D9AAE0: LoadStringW.USER32 ref: 00007FF646D9AB67
          • Part of subcall function 00007FF646D9AAE0: LoadStringW.USER32 ref: 00007FF646D9AB80
          • Part of subcall function 00007FF646D81FA0: _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646D81FFB
          • Part of subcall function 00007FF646D8129C: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF646D81396
        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646DB01BB
        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646DB01C1
        • SendDlgItemMessageW.USER32 ref: 00007FF646DB01F2
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$LoadString$Concurrency::cancel_current_taskGlobalItemMemoryMessageSendStatus
        • String ID:
        • API String ID: 3106221260-0
        • Opcode ID: ac2348a629674c2f7f7785d079b65ba149da1fb1da7fc5a5014f7405eaf55abc
        • Instruction ID: 8d04adf1b3133de52216ac0d1e46d6068122cfb76c2e8a360508b869b24ca4af
        • Opcode Fuzzy Hash: ac2348a629674c2f7f7785d079b65ba149da1fb1da7fc5a5014f7405eaf55abc
        • Instruction Fuzzy Hash: 3C51BE62F0C64286FB10BBA5D8552FDA322AB99BC8F440336DE1D977DADE2DE504C340
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$FileOperation
        • String ID:
        • API String ID: 2032784890-0
        • Opcode ID: d84b959cb52ac2b45cb228921a01aff5b742bfe85dfebf4c2a95a99d48551309
        • Instruction ID: 9c245b354bfff5b6a8309e442d0fea21decdaaba6ca31611ba92a32a56988478
        • Opcode Fuzzy Hash: d84b959cb52ac2b45cb228921a01aff5b742bfe85dfebf4c2a95a99d48551309
        • Instruction Fuzzy Hash: AF616B62B1CB42D9EB00FF65D8942BC6361EB98788F444736DA1C93BA9DF3AD595C300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CreateFile$_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 2272807158-0
        • Opcode ID: 650906bb36444c59f78769edd7e70a31dc34f49dc41decdeb4024168be9b1e6b
        • Instruction ID: eb55a13a44adc8e7d28bde8afe65a5647156986a0d403c18895a8977eebb1e4c
        • Opcode Fuzzy Hash: 650906bb36444c59f78769edd7e70a31dc34f49dc41decdeb4024168be9b1e6b
        • Instruction Fuzzy Hash: D841C572A2C78582EB20BF15E454669A3A1FB85BB8F105334DFAD43AD5CF3EE4948700
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: TextWindow$Length_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 2176759853-0
        • Opcode ID: 1bf85210b9a87779fb11811f9a7e2f8ba75c636e64e4f9da94f36f1c7ff0fb34
        • Instruction ID: 54019821001010f61c98d545ce2f3fd59c916a9021c8f50c480861f6ad3c68b0
        • Opcode Fuzzy Hash: 1bf85210b9a87779fb11811f9a7e2f8ba75c636e64e4f9da94f36f1c7ff0fb34
        • Instruction Fuzzy Hash: B2217362A1DB8281EA20AF65A84417AA364FB89BD0F145335EB9D43BA9DF3DD150C740
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: std::bad_alloc::bad_alloc
        • String ID:
        • API String ID: 1875163511-0
        • Opcode ID: 0ac8b931c67533783bb99e44ed512301af0920adb1b65b15738df05c1e7b1342
        • Instruction ID: 2765f622f22e671e0b46f6102f21058bf46c5e882b12728a6000b04f64409746
        • Opcode Fuzzy Hash: 0ac8b931c67533783bb99e44ed512301af0920adb1b65b15738df05c1e7b1342
        • Instruction Fuzzy Hash: 9331B522B0C68651FB25BB16E4543BDE3A0FB54B84F584231D28C869E9DF7EE946C301
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AttributesFile$_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 1203560049-0
        • Opcode ID: 30421b436104fcb90b4cd2208b99a3bf3782908f0837f7a91d3eb4cb73bf7196
        • Instruction ID: cef7eee3bb2859323d0bcc363d1feaac55ff10ee4cd0b3db66b731e0be2c989f
        • Opcode Fuzzy Hash: 30421b436104fcb90b4cd2208b99a3bf3782908f0837f7a91d3eb4cb73bf7196
        • Instruction Fuzzy Hash: 7521B832B1C68581FE20BF25E465269A361FFC4B98F105334EA9E827A9EF2DD544C600
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: DeleteFile$_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3118131910-0
        • Opcode ID: 539e2a0488ada646b9a4eb5c90a9f278ffd13936dc8dbc7caf4118334a65d282
        • Instruction ID: 8c034f316355c687e67a038a444a0bb939667ff92f4483972dc0394a9e33a64c
        • Opcode Fuzzy Hash: 539e2a0488ada646b9a4eb5c90a9f278ffd13936dc8dbc7caf4118334a65d282
        • Instruction Fuzzy Hash: 39219832A1C78182FE20BB25F45526EA360FF85B98F501335EA9E87AA9DF3DD544C740
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AttributesFile$_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 1203560049-0
        • Opcode ID: a8bcf6e2598255fa991570dfaf367ef52c8767d47326b3423635884fafe6ecbe
        • Instruction ID: 745bb9ace171cf59a808815ad16d99aaaca8ec9b27260e76315a3c6aac7ecf07
        • Opcode Fuzzy Hash: a8bcf6e2598255fa991570dfaf367ef52c8767d47326b3423635884fafe6ecbe
        • Instruction Fuzzy Hash: C2217432A1C68181EA10BB29E454129A361FB89BA4F500331EA9E83BE9DF3DD544C700
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Process$CurrentExitTerminate
        • String ID:
        • API String ID: 1703294689-0
        • Opcode ID: 44b3a526fe0d15710854bc957cc7a82f9edee4cc7420f0560de4bec5ea2a17a0
        • Instruction ID: 960fa3e39819a8362693dd99e5430a1b4b14cfee2e95cef4defefdc5f7504c0a
        • Opcode Fuzzy Hash: 44b3a526fe0d15710854bc957cc7a82f9edee4cc7420f0560de4bec5ea2a17a0
        • Instruction Fuzzy Hash: 30E0BF28B0C70946FB547B319895779A7526F88B41F105638D94F8739ACE3FE4498741
        APIs
        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646D8F895
        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646D8F89B
          • Part of subcall function 00007FF646D93EC8: FindClose.KERNELBASE(?,?,00000000,00007FF646DA0811), ref: 00007FF646D93EFD
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$CloseFind
        • String ID:
        • API String ID: 3587649625-0
        • Opcode ID: 1c0bb42e79c9fb00636deaf2d0e282c242ffc3b1dd605f464871389e3482b40a
        • Instruction ID: 558365a1d511bdabfb49c6c3635ab3e1cafea0fcba2a82d7644d75869dd66c31
        • Opcode Fuzzy Hash: 1c0bb42e79c9fb00636deaf2d0e282c242ffc3b1dd605f464871389e3482b40a
        • Instruction Fuzzy Hash: 4D91AF73A1CB8190EB10FF25D8482ADA361FB84BD8F905235EA6C87AE9DF79D545C340
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3668304517-0
        • Opcode ID: 08c6e2d20e94fe5d114b94b17f84e93e5249d169b81ce8341d273cd43f7755ea
        • Instruction ID: 43098a31d168ffddf835b936b1882df6d6db265e69f54ecc8a44d9b2317bfb18
        • Opcode Fuzzy Hash: 08c6e2d20e94fe5d114b94b17f84e93e5249d169b81ce8341d273cd43f7755ea
        • Instruction Fuzzy Hash: B641A062F1C65285FF00FBB1D4446BDA321AF44B98F156335DE2DA7AAADE39D4828300
        APIs
        • SetFilePointer.KERNELBASE(00000000,00000002,?,00000F99,?,00007FF646D9274D), ref: 00007FF646D928A9
        • GetLastError.KERNEL32(?,00007FF646D9274D), ref: 00007FF646D928B8
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ErrorFileLastPointer
        • String ID:
        • API String ID: 2976181284-0
        • Opcode ID: 043a82e8aff847b2e282b78885e55c7214a93c585b530bdf19c19deffc600893
        • Instruction ID: 99cf8cc69fdd218bc5c5f97eaf68ff6d64c772fda5510f758a5dadf289848a94
        • Opcode Fuzzy Hash: 043a82e8aff847b2e282b78885e55c7214a93c585b530bdf19c19deffc600893
        • Instruction Fuzzy Hash: E631D622B2DA56C2FB647F2AD9506B9A354AF04BD8F140331DE1D97790DE3ED4498740
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Item_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 1746051919-0
        • Opcode ID: 95739ad7301a08b82252912ada3ab6f57aee1bff7a48893d1edd4817af44debc
        • Instruction ID: e56007980651652d736b1191828ee10172abd50452144b4061ecfd9899505862
        • Opcode Fuzzy Hash: 95739ad7301a08b82252912ada3ab6f57aee1bff7a48893d1edd4817af44debc
        • Instruction Fuzzy Hash: EB31AF22A1C74682EA20BF15E45937AF360EB84B90F445335EAAD87BA9DF3DE544C740
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: File$BuffersFlushTime
        • String ID:
        • API String ID: 1392018926-0
        • Opcode ID: 1f7bfd0f82637a6abdcd08aef8b442a865f6f50d97ba3a1fa7ef62b0e093425a
        • Instruction ID: 4dad6599253485e2b1af0d46406bfee68bb45bf2f7e64ce6861d65483f4dfcce
        • Opcode Fuzzy Hash: 1f7bfd0f82637a6abdcd08aef8b442a865f6f50d97ba3a1fa7ef62b0e093425a
        • Instruction Fuzzy Hash: 1C21B222E1EB46D1EA62BE51E4257BA97E0AF0179CF154231DE4C46299EE3ED58EC200
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ErrorFileLastPointer
        • String ID:
        • API String ID: 2976181284-0
        • Opcode ID: 5eda2cbf1ce6837a88d649c872729f31e823bc49095d59e5e9b193bf7b9166cd
        • Instruction ID: a897901ecd60b9fb2e2a60627a70d00c608e0a3c3b85281cd84aed9ea15f4969
        • Opcode Fuzzy Hash: 5eda2cbf1ce6837a88d649c872729f31e823bc49095d59e5e9b193bf7b9166cd
        • Instruction Fuzzy Hash: 8411AF21A2C642C1FB60BF25E850279A260FB44BB8F540331DA7D922E4CF3ED59AC300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ItemRectTextWindow$Clientswprintf
        • String ID:
        • API String ID: 3322643685-0
        • Opcode ID: ad94589889145b650e3461eb84003e845283bd92425fc2a9221c8100a4e27e71
        • Instruction ID: 4d2c9e38036e2ff44e4c060132e643bc98deaf13b15d147ec5f83081158cddfb
        • Opcode Fuzzy Hash: ad94589889145b650e3461eb84003e845283bd92425fc2a9221c8100a4e27e71
        • Instruction Fuzzy Hash: E4018F20E4D78B81FF597F52E46C279D791AF85744F081275C85D86AEEDE2EE884C340
        APIs
        • GetCurrentProcess.KERNEL32(?,?,?,?,00007FF646D9EBAD,?,?,?,?,00007FF646D95752,?,?,?,00007FF646D956DE), ref: 00007FF646D9EB5C
        • GetProcessAffinityMask.KERNEL32 ref: 00007FF646D9EB6F
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Process$AffinityCurrentMask
        • String ID:
        • API String ID: 1231390398-0
        • Opcode ID: 444071b75e142e51b736d9fa504759652bc9944b894df1f8101a797a07211085
        • Instruction ID: e18e841553faff2b5171b1767e260f0deedc4b6670ec243495078c92e04a9f33
        • Opcode Fuzzy Hash: 444071b75e142e51b736d9fa504759652bc9944b894df1f8101a797a07211085
        • Instruction Fuzzy Hash: CAE06561B1864A86DB59AF5AC4519AAA3A2BF88B44F848135D60BC3614DE2EE5498B00
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Concurrency::cancel_current_task$std::bad_alloc::bad_alloc
        • String ID:
        • API String ID: 1173176844-0
        • Opcode ID: ac554a43d54612151bc7e480101717375080be3004ee5b366f50feb51e7139dd
        • Instruction ID: 0d023a9688cfb65a2a84d31ce42147298f046449025817c0a8392a7cde15ba91
        • Opcode Fuzzy Hash: ac554a43d54612151bc7e480101717375080be3004ee5b366f50feb51e7139dd
        • Instruction Fuzzy Hash: 00E01742E1E10B45FD283A771C661B980404F2DFB0E5C6B30DE3EC86DEAE1FA596C110
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ErrorFreeHeapLast
        • String ID:
        • API String ID: 485612231-0
        • Opcode ID: 7829e02dcbd74b51c5e196648e5aad52518f68633834b7095f7e5950a32ae739
        • Instruction ID: f60214744fc6894da7bb36ed54b249f05c862e25bee5edeeb0a3a2dc4f3001ce
        • Opcode Fuzzy Hash: 7829e02dcbd74b51c5e196648e5aad52518f68633834b7095f7e5950a32ae739
        • Instruction Fuzzy Hash: 5CE0EC60E0E54746FF18BBF298555B8A6D1AF98F51F044235C90FC625AEE3EA4858600
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3668304517-0
        • Opcode ID: 8948bb9802c6c0987d886fae829bf96634841c4c74bd64b8e97cfea881f89bd5
        • Instruction ID: 3979f7d7675b156a8002aa3f1c9926d1c3b98db638dcbb49fd5fab9f42122830
        • Opcode Fuzzy Hash: 8948bb9802c6c0987d886fae829bf96634841c4c74bd64b8e97cfea881f89bd5
        • Instruction Fuzzy Hash: B3D1D872B0C68696EB28BB6595482BDE7A1FB05B84F053235CB2D877B5CF3DE4618700
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CompareString_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 1017591355-0
        • Opcode ID: 60054bf23714923d6cf658706c57d8570bb270d346a0b8b9a17da1f048c8cd6a
        • Instruction ID: 35b8f91de497d8f840e0c3a2b93ed5032026d452960ab1f6d1e5d42e493df590
        • Opcode Fuzzy Hash: 60054bf23714923d6cf658706c57d8570bb270d346a0b8b9a17da1f048c8cd6a
        • Instruction Fuzzy Hash: F8610311E0C647C1FAA4BA25943427EDA91AF49BD8F144331EE4DC6AC5EE7FEC588600
        APIs
          • Part of subcall function 00007FF646D9E948: ReleaseSemaphore.KERNEL32 ref: 00007FF646D9E974
          • Part of subcall function 00007FF646D9E948: CloseHandle.KERNELBASE ref: 00007FF646D9E993
          • Part of subcall function 00007FF646D9E948: DeleteCriticalSection.KERNEL32 ref: 00007FF646D9E9AA
          • Part of subcall function 00007FF646D9E948: CloseHandle.KERNEL32 ref: 00007FF646D9E9B7
        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646DA1ACB
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CloseHandle$CriticalDeleteReleaseSectionSemaphore_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 904680172-0
        • Opcode ID: 706733c944098cb8a605eaf932642e2f84c02d8e7386b9a1576d55af7d044be2
        • Instruction ID: b11050647bde2faaeee74bf5996aa468a3c8e32ffc25b1155767363496b66391
        • Opcode Fuzzy Hash: 706733c944098cb8a605eaf932642e2f84c02d8e7386b9a1576d55af7d044be2
        • Instruction Fuzzy Hash: A261CF62B1DA85A2EE08FB65E5540BCB365FB44F80F544336D72D87AC5CF2AE465C300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3668304517-0
        • Opcode ID: 89b76225f611734f1827ebf27dd46062ec279a58f062f7148514824cdf62f394
        • Instruction ID: cfc66b3ca2d5d844797962a1458cdcaf3375ecb433465028df1935cf79f3992b
        • Opcode Fuzzy Hash: 89b76225f611734f1827ebf27dd46062ec279a58f062f7148514824cdf62f394
        • Instruction Fuzzy Hash: 6651D562A0C68290FA15BF25D4583BDA751FB85BC8F441236EE6D873A6CE3EE485C740
        APIs
          • Part of subcall function 00007FF646D93EC8: FindClose.KERNELBASE(?,?,00000000,00007FF646DA0811), ref: 00007FF646D93EFD
        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646D8E993
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CloseFind_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 1011579015-0
        • Opcode ID: 7ccb79097edba5c9ff264a6ea3acda2e11d4279ec26602cbe1bb149cda34522a
        • Instruction ID: 05717219cfda64d4014522b7057dcb23d39d16b2fab95c75d3074ad758185be5
        • Opcode Fuzzy Hash: 7ccb79097edba5c9ff264a6ea3acda2e11d4279ec26602cbe1bb149cda34522a
        • Instruction Fuzzy Hash: 4E516F22A1C68681FB60BF29D44937DA361FF84B84F441336EA9D876B9DF2ED441C750
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3668304517-0
        • Opcode ID: bebb0f9c194fdd9831c81a75273c0277ea796a53f9961829cd6454e8fab382d6
        • Instruction ID: dfbe3b5b6f4a8aec011e0eb989eded12ded01898ecbe7a7d0a779be66910e9c3
        • Opcode Fuzzy Hash: bebb0f9c194fdd9831c81a75273c0277ea796a53f9961829cd6454e8fab382d6
        • Instruction Fuzzy Hash: F1411962B1CA8192EA18BA17EA1037AE251FB48FC4F448635EE5C87F5ADF3DD4558300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3668304517-0
        • Opcode ID: 79c0921cd87fe934e762e48f5845e8be846b4b6500caa7e1addc831544741880
        • Instruction ID: 06e1572a3ac0c69473ec158a5444ce51a6d108656b6ad644115b62b0dbc3a512
        • Opcode Fuzzy Hash: 79c0921cd87fe934e762e48f5845e8be846b4b6500caa7e1addc831544741880
        • Instruction Fuzzy Hash: B741D172A1CA41C1EF10BF2AE565379A360EB85BDCF051334EA4D876A9DE3EE444C640
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: HandleModule$AddressFreeLibraryProc
        • String ID:
        • API String ID: 3947729631-0
        • Opcode ID: 5b4d6432c9ab27f48bf344f41163fa66ca8822e5b5ed34cf2c0174bd429b5c6d
        • Instruction ID: 07c35ce9a6e3ad340a12a0e4adbafc3687f1d813394576dc3bbcc52b73845c9b
        • Opcode Fuzzy Hash: 5b4d6432c9ab27f48bf344f41163fa66ca8822e5b5ed34cf2c0174bd429b5c6d
        • Instruction Fuzzy Hash: 4841D022E1CA1686FB24BB11D85027CE6A1BF94F40F444676DA0EC76A9CF3FE940C740
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Concurrency::cancel_current_taskstd::bad_alloc::bad_alloc
        • String ID:
        • API String ID: 680105476-0
        • Opcode ID: cf2633b9da943ca9c126a427f9c2b9753697caf8745c5b584b473be633c00b65
        • Instruction ID: 58e9f9c80ac372f38012660ff5577505c3a0f8fc543c113afd8d96d075b172ca
        • Opcode Fuzzy Hash: cf2633b9da943ca9c126a427f9c2b9753697caf8745c5b584b473be633c00b65
        • Instruction Fuzzy Hash: 13219222A0C75285EA14BF52A804279A250FB09FF0F681B30DE7D87BE5DE7EE4558344
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo
        • String ID:
        • API String ID: 3215553584-0
        • Opcode ID: 9dd5a9e84c18447e56e2265fa04046f11d37b96b7f5b774ce3305aa6458b3f00
        • Instruction ID: 389b56214bcac53a9dbcb742e2d559e9d96dc57d46600f7d5a42bb69c3503ea6
        • Opcode Fuzzy Hash: 9dd5a9e84c18447e56e2265fa04046f11d37b96b7f5b774ce3305aa6458b3f00
        • Instruction Fuzzy Hash: 8B113A2691D656C6F720BB50E851539E2A4FB49780F540235E78EDA699DF2EE4008740
        APIs
          • Part of subcall function 00007FF646DAF0A4: GetDlgItem.USER32 ref: 00007FF646DAF0E3
          • Part of subcall function 00007FF646DAF0A4: ShowWindow.USER32 ref: 00007FF646DAF109
          • Part of subcall function 00007FF646DAF0A4: SendMessageW.USER32 ref: 00007FF646DAF11E
          • Part of subcall function 00007FF646DAF0A4: SendMessageW.USER32 ref: 00007FF646DAF136
          • Part of subcall function 00007FF646DAF0A4: SendMessageW.USER32 ref: 00007FF646DAF157
          • Part of subcall function 00007FF646DAF0A4: SendMessageW.USER32 ref: 00007FF646DAF173
          • Part of subcall function 00007FF646DAF0A4: SendMessageW.USER32 ref: 00007FF646DAF1B6
          • Part of subcall function 00007FF646DAF0A4: SendMessageW.USER32 ref: 00007FF646DAF1D4
          • Part of subcall function 00007FF646DAF0A4: SendMessageW.USER32 ref: 00007FF646DAF1E8
          • Part of subcall function 00007FF646DAF0A4: SendMessageW.USER32 ref: 00007FF646DAF212
          • Part of subcall function 00007FF646DAF0A4: SendMessageW.USER32 ref: 00007FF646DAF22A
        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646DAFD03
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: MessageSend$ItemShowWindow_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 1587882848-0
        • Opcode ID: 5bb424aab816160ef4a74488935102a122e6704c0a8f498a4557d78a920d449d
        • Instruction ID: 31f880fffa8c04ac46ab252f872861757aae537eb4cbe136af0576fa893e76a5
        • Opcode Fuzzy Hash: 5bb424aab816160ef4a74488935102a122e6704c0a8f498a4557d78a920d449d
        • Instruction Fuzzy Hash: 2C01DB62A2C68542EE24B725D44637EA311EFC9B94F501335EAAC867DADE2DE1408704
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3668304517-0
        • Opcode ID: 454a1fcff6e1850c8b97cdd7684a735fd34d2cefc8bc4c1965818da2daadb151
        • Instruction ID: 7c089734249346327ee95fe6311b842926b159799e9fee37c813e5c25b2bb22d
        • Opcode Fuzzy Hash: 454a1fcff6e1850c8b97cdd7684a735fd34d2cefc8bc4c1965818da2daadb151
        • Instruction Fuzzy Hash: 340196A2E1CB8541FE11BB68E44526DB361FFD9B94F406335E6AC47BA9DF2EE0408704
        APIs
          • Part of subcall function 00007FF646DB1604: GetModuleHandleW.KERNEL32(?,?,?,00007FF646DB1573,?,?,?,00007FF646DB192A), ref: 00007FF646DB162B
        • DloadProtectSection.DELAYIMP ref: 00007FF646DB15C9
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: DloadHandleModuleProtectSection
        • String ID:
        • API String ID: 2883838935-0
        • Opcode ID: 902d746097657f35995c40355b3f554eba39218e3fb79a70aefbb70b68ceb6fd
        • Instruction ID: 14b799bbe9d4573d8766a73c17f756f62dc596d0ce66e634427936b5451eec53
        • Opcode Fuzzy Hash: 902d746097657f35995c40355b3f554eba39218e3fb79a70aefbb70b68ceb6fd
        • Instruction Fuzzy Hash: 5811D760E0CA0781FB61BB05EC843B0E3A0AF18B49F140734C90FC62A9EF3FA895C644
        APIs
          • Part of subcall function 00007FF646D940BC: FindFirstFileW.KERNELBASE ref: 00007FF646D9410B
          • Part of subcall function 00007FF646D940BC: FindFirstFileW.KERNELBASE ref: 00007FF646D9415E
          • Part of subcall function 00007FF646D940BC: GetLastError.KERNEL32 ref: 00007FF646D941AF
        • FindClose.KERNELBASE(?,?,00000000,00007FF646DA0811), ref: 00007FF646D93EFD
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Find$FileFirst$CloseErrorLast
        • String ID:
        • API String ID: 1464966427-0
        • Opcode ID: 18fe74ab7ca813274cb64c08179860cc48efc587ad39327f0b25563dc18ddab5
        • Instruction ID: be997a304a81245f91864e043202e87c93ef9e9d45771eb3a9a045e9c36313cd
        • Opcode Fuzzy Hash: 18fe74ab7ca813274cb64c08179860cc48efc587ad39327f0b25563dc18ddab5
        • Instruction Fuzzy Hash: 73F0AF7290C281C5EB10BF75A120279B7609B1ABBCF191339EA3D472D7CE29D4888744
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: FileType
        • String ID:
        • API String ID: 3081899298-0
        • Opcode ID: df9a28314c6b6fddfb177ebf539387614dcb0363737e1ba4f38fe55c4f903e1a
        • Instruction ID: 4c94b7e4ff52e4ad6d10a6dbc4711f47f5eeac36743ded376101588d0411b5d5
        • Opcode Fuzzy Hash: df9a28314c6b6fddfb177ebf539387614dcb0363737e1ba4f38fe55c4f903e1a
        • Instruction Fuzzy Hash: B3D01212D1E451C2EE10BB369C6103C6350AFA6739FA40730D63EC16E1CE1E949AAB11
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CurrentDirectory
        • String ID:
        • API String ID: 1611563598-0
        • Opcode ID: 176ab68ebee512dad0278907058cd855c5c44f8615b79807412a7d406b36e525
        • Instruction ID: 020e4544a1179d2fc6c1d02a13291f31f24de3a59f9893b178cf17f744e4a158
        • Opcode Fuzzy Hash: 176ab68ebee512dad0278907058cd855c5c44f8615b79807412a7d406b36e525
        • Instruction Fuzzy Hash: 38C08C20F0A502C1EF087B26C8C901813A4BB40B08F604234D10DC1120CE2EC4EEA345
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AllocHeap
        • String ID:
        • API String ID: 4292702814-0
        • Opcode ID: c4d23aaef5024e3722ccbb242168b3e22d65bf63548bcaacbbf61b8d0a3ba7a1
        • Instruction ID: 583e80f921a6045215bd535a3443a0f7a7ae144660506b372e476154cbbe5030
        • Opcode Fuzzy Hash: c4d23aaef5024e3722ccbb242168b3e22d65bf63548bcaacbbf61b8d0a3ba7a1
        • Instruction Fuzzy Hash: 85F09054F0E30749FE5C7B629911BB8D2805F49F80F0C5630C90ECA3C9ED2EE6818610
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CloseHandle
        • String ID:
        • API String ID: 2962429428-0
        • Opcode ID: ccbd9008d2c4ce7168f8d058ff2f34620ae6bf54bfe45a0cbca9d6a6f1a7c065
        • Instruction ID: c17abc1a3fc947d871a2535dda5e7a2cb5dfe90763ce1f5cfaf20bbf7a142139
        • Opcode Fuzzy Hash: ccbd9008d2c4ce7168f8d058ff2f34620ae6bf54bfe45a0cbca9d6a6f1a7c065
        • Instruction Fuzzy Hash: 21F0AF22A1C68285FB24BF20E451379A660EB15B7CF485334D73D811D4CF2AD8A9C300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AllocHeap
        • String ID:
        • API String ID: 4292702814-0
        • Opcode ID: 5fa632deebd8181b9f3ea37834cf4eccbda839d7d0d6f948310c23224b4a93e7
        • Instruction ID: fa1e939bc4c7539475cced27dac14e8d3da6b01aad4282a55baed86d8915154d
        • Opcode Fuzzy Hash: 5fa632deebd8181b9f3ea37834cf4eccbda839d7d0d6f948310c23224b4a93e7
        • Instruction Fuzzy Hash: F0F03051F0D24745FF547BB158617B5D6905F88FA0F485731DD6FC62C9DE2EE4808211
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$CloseErrorFileHandleLastwcscpy$ControlCreateCurrentDeleteDeviceDirectoryProcessRemove
        • String ID: SeCreateSymbolicLinkPrivilege$SeRestorePrivilege$UNC\$\??\
        • API String ID: 2659423929-3508440684
        • Opcode ID: f1e6eec8ecbe5e09d381db8a89365ebfa2c377f5d47fbbeb23eb751c6f3faf25
        • Instruction ID: 237788fd9754ea33b5f8a83e64bf884772f41ba226e1abf0d86cf4ce9fd32655
        • Opcode Fuzzy Hash: f1e6eec8ecbe5e09d381db8a89365ebfa2c377f5d47fbbeb23eb751c6f3faf25
        • Instruction Fuzzy Hash: 0F62A1A2F1C64285FB00BB74D4493BDA361AB857A8F505331DA6D97AE9DF3DE189C300
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$ErrorLastLoadString$Concurrency::cancel_current_taskInit_thread_footer
        • String ID: %ls$%s: %s
        • API String ID: 2539828978-2259941744
        • Opcode ID: 9a779180c2f6beaa19fabe2452816d46f3d0bc12dac556602175926542dd33a8
        • Instruction ID: 23fa9689146ec25a5d2e4db1ab13d71b531fbfb7134cf84b9f8b0c645f57bd22
        • Opcode Fuzzy Hash: 9a779180c2f6beaa19fabe2452816d46f3d0bc12dac556602175926542dd33a8
        • Instruction Fuzzy Hash: 6EB2A863A1C68282EA14BB25D4552BEE311FFDA794F104336E69D83BEAEF6DD544C300
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfomemcpy_s
        • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
        • API String ID: 1759834784-2761157908
        • Opcode ID: c1568b5568d689d261f1f0b975b9c1104ab10acfc5286cd5346a40821ab4f9bc
        • Instruction ID: cdf5675173772ee4f436842bc8a7232a311835019b36a77c4674ab418948b5ac
        • Opcode Fuzzy Hash: c1568b5568d689d261f1f0b975b9c1104ab10acfc5286cd5346a40821ab4f9bc
        • Instruction Fuzzy Hash: BBB2D672E0C2868BE735BE69D4407F9B7A1FB44788F515235DA0B97B88DF3AE5048B40
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: NamePath$File_invalid_parameter_noinfo_noreturn$LongMoveShort$CompareCreateString
        • String ID: rtmp
        • API String ID: 3587137053-870060881
        • Opcode ID: 6844fc52beb637c2b27de38a8f1773b81546f1263b6adb3febe2d016913ca72a
        • Instruction ID: bd2f2cc962e09be6ed4f916f375ae8638f8513023160b206c3845fa8164c65c1
        • Opcode Fuzzy Hash: 6844fc52beb637c2b27de38a8f1773b81546f1263b6adb3febe2d016913ca72a
        • Instruction Fuzzy Hash: F1F1B122B1CA4281EB10FF65D8941BDA761FB897C8F501236EA4DC3AA9DF3DD588C740
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: FullNamePath_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 1693479884-0
        • Opcode ID: b93ad2ce8aad967ae532d61f25a7d43417873e191935b00f4afba2dee12255a3
        • Instruction ID: 89f48c24daa76f57560ed5e4e594a492d810ffd9875a9b2f41c24d0967ab5f12
        • Opcode Fuzzy Hash: b93ad2ce8aad967ae532d61f25a7d43417873e191935b00f4afba2dee12255a3
        • Instruction Fuzzy Hash: 7CA1C362F18A5284FF00BB7988541BDA761AB45BE8F145335DE2D97BD8DE3EE8458300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
        • String ID:
        • API String ID: 3140674995-0
        • Opcode ID: eb4060bcbbf6947450414bc0ac192b8da1feec02df413969c5a674799d26ef14
        • Instruction ID: 690d9e77e3b4410b4e3cea2a6559a8ab7020765779cc88ddf77f6e24f1805563
        • Opcode Fuzzy Hash: eb4060bcbbf6947450414bc0ac192b8da1feec02df413969c5a674799d26ef14
        • Instruction Fuzzy Hash: 99316172609B818AFB60AF60E8507EDB364FB84B44F44453ADA4E87B98DF3DD548C710
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
        • String ID:
        • API String ID: 1239891234-0
        • Opcode ID: 5940ef1d6d2c32beaf7af9e8e0892e721e3d30544378453b8f42f9f5775f8da8
        • Instruction ID: 5f10aecb65bd6f9050c0ed2bbeb6c57a59219b394efa1a4c84906f290e1b8870
        • Opcode Fuzzy Hash: 5940ef1d6d2c32beaf7af9e8e0892e721e3d30544378453b8f42f9f5775f8da8
        • Instruction Fuzzy Hash: 0E31743660CB8186E760EF25E8406AEB7A4FB84B54F540236EE8D83B99DF3DD555CB00
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3668304517-0
        • Opcode ID: de7e979c67e4817373834f9f72e386e265cdabefc4602517d7b45e75046ae0e2
        • Instruction ID: 12782a4e4160361e58ad5d1598007a62c39992ec3299bb4e95500b022259dca0
        • Opcode Fuzzy Hash: de7e979c67e4817373834f9f72e386e265cdabefc4602517d7b45e75046ae0e2
        • Instruction Fuzzy Hash: EEB1D762B1868655EB10BB65DC482EDA361FF89784F402331DA6C87BE9DF3DD548C300
        APIs
        • _invalid_parameter_noinfo.LIBCMT ref: 00007FF646DBFAC4
          • Part of subcall function 00007FF646DB7934: GetCurrentProcess.KERNEL32(00007FF646DC0CCD), ref: 00007FF646DB7961
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CurrentProcess_invalid_parameter_noinfo
        • String ID: *?$.
        • API String ID: 2518042432-3972193922
        • Opcode ID: f96344909874f118cd7fc652812aee2de17a0b901a5c412331694f6fbd6e8fc4
        • Instruction ID: ccf5deacf73d981d1d8110bf6160b2e8ed40389234723c865e2c1285888dd8de
        • Opcode Fuzzy Hash: f96344909874f118cd7fc652812aee2de17a0b901a5c412331694f6fbd6e8fc4
        • Instruction Fuzzy Hash: E951F266B18B9581EF14FFA298504B8A3A4FB48FD8B444632DE5D97B89DE3DD0428300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: memcpy_s
        • String ID:
        • API String ID: 1502251526-0
        • Opcode ID: b531b63a04a12e36dec63d06dc2411054f876835da8b044adf2bb9f605172619
        • Instruction ID: 59b700944e5499a29a168783f55825faf2bddb4bf75cd13dcd91b89f686a9ae3
        • Opcode Fuzzy Hash: b531b63a04a12e36dec63d06dc2411054f876835da8b044adf2bb9f605172619
        • Instruction Fuzzy Hash: 40D18332B1C68A87DB74EF15A18466AF7A1F798784F148234DB4E97B44DE3EE941CB00
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ErrorFormatFreeLastLocalMessage
        • String ID:
        • API String ID: 1365068426-0
        • Opcode ID: c27e05edbcf0c556cf9f4b9f4aa6354f64d9dc72ff0f252d3a2ededa039666af
        • Instruction ID: 82a9f3fb0bc66add403f59a12e3ac601bbaf71dc5ebbbec7f220e62064e9028b
        • Opcode Fuzzy Hash: c27e05edbcf0c556cf9f4b9f4aa6354f64d9dc72ff0f252d3a2ededa039666af
        • Instruction Fuzzy Hash: 62016271A0C78682E710BF23B85457AE791FB89BC0F085134EA9E87B59CF3DD5049700
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID: .
        • API String ID: 0-248832578
        • Opcode ID: 7c9d8364e7b62915daf92aecf888b4814fe01b6aae5fc02ec6e7aa2f3019df5b
        • Instruction ID: d6ce0b540563b4b5b1cd4ed29586a3aba98117c8d2087b368aa9450b3d00a0f2
        • Opcode Fuzzy Hash: 7c9d8364e7b62915daf92aecf888b4814fe01b6aae5fc02ec6e7aa2f3019df5b
        • Instruction Fuzzy Hash: 9631FB22B0C69545FB64BB36A8057B9EA91EB94FE4F148335EE5C87BC9CE3DD5018300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ExceptionRaise_clrfp
        • String ID:
        • API String ID: 15204871-0
        • Opcode ID: 131550a8e914c8a4384a7255cc8ec53066b4dff0b7ecc1394be8dfb6b4310eca
        • Instruction ID: eb8b735d35664509a1c6ccbb5f0f7033cc8a009c82c7ea8113d96e9172da1120
        • Opcode Fuzzy Hash: 131550a8e914c8a4384a7255cc8ec53066b4dff0b7ecc1394be8dfb6b4310eca
        • Instruction Fuzzy Hash: F5B13F73614B898BEB15EF29C84536C7BA0F784B58F158A31DA5E877A4CF3AD861C700
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ObjectRelease$CapsDevice
        • String ID:
        • API String ID: 1061551593-0
        • Opcode ID: 68dbe16693602acb82a0a9c061fd0d735b77194d41f4ab9e90264308bb487059
        • Instruction ID: 58ce2480b447a75a7f197c75b1193f0097e158503def6223be738321f1ae5b1c
        • Opcode Fuzzy Hash: 68dbe16693602acb82a0a9c061fd0d735b77194d41f4ab9e90264308bb487059
        • Instruction Fuzzy Hash: 0F811C76B1CA1586EB20EF6AD4406ADB771FB88B88F004232DE0E97768DF7AD545C740
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: FormatInfoLocaleNumber
        • String ID:
        • API String ID: 2169056816-0
        • Opcode ID: a0c8fcaef59427837b2a7c7753e3d717a8442860a15e47712294eddcbb527c28
        • Instruction ID: a21ee3001a8bd3c2482c60a2c73277ae14023dfae6f1f48135c219c285961544
        • Opcode Fuzzy Hash: a0c8fcaef59427837b2a7c7753e3d717a8442860a15e47712294eddcbb527c28
        • Instruction Fuzzy Hash: F3116D32A0CB8595E7A1BF11E8107E9B360FF88B48F844235DA4D83668DF3DE145CB44
        APIs
          • Part of subcall function 00007FF646D924C0: CreateFileW.KERNELBASE ref: 00007FF646D9259B
          • Part of subcall function 00007FF646D924C0: GetLastError.KERNEL32 ref: 00007FF646D925AE
          • Part of subcall function 00007FF646D924C0: CreateFileW.KERNEL32 ref: 00007FF646D9260E
          • Part of subcall function 00007FF646D924C0: GetLastError.KERNEL32 ref: 00007FF646D92617
        • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 00007FF646D915D0
          • Part of subcall function 00007FF646D93980: MoveFileW.KERNEL32 ref: 00007FF646D939BD
          • Part of subcall function 00007FF646D93980: MoveFileW.KERNEL32 ref: 00007FF646D93A34
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: File$CreateErrorLastMove$_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 34527147-0
        • Opcode ID: b6c9c40237190830a1427cc90f699f3ed679a8c4b0b9819d305839f030af1316
        • Instruction ID: abeba160e729f1188fd23370bc81bffef6a9fabb2fafac3cc9601a68df6773fc
        • Opcode Fuzzy Hash: b6c9c40237190830a1427cc90f699f3ed679a8c4b0b9819d305839f030af1316
        • Instruction Fuzzy Hash: 2291B122B2C64682EB50FF62D8542BDA361FB58BC8F405232EE0D87B95DE3ED549C740
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Version
        • String ID:
        • API String ID: 1889659487-0
        • Opcode ID: 6220f8f0736b52f52a4f9f0684f7fcd1da0b773ba531a70ae5974f71c0de4052
        • Instruction ID: 0fecdaa7274cdd82a852227bf0a738457e5a04344d66a586cd09fdf9dddbd43d
        • Opcode Fuzzy Hash: 6220f8f0736b52f52a4f9f0684f7fcd1da0b773ba531a70ae5974f71c0de4052
        • Instruction Fuzzy Hash: E50113B1A0CA428AF664BB10E85077AB6A1FB98318F500334D65D82B94DF3EE8048E00
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo
        • String ID: 0
        • API String ID: 3215553584-4108050209
        • Opcode ID: 0fbd957179d89af9e1d3453d65279f22830f04fe064c784c04e338e6c7bf3646
        • Instruction ID: bc1c34fde526836a70aa72b195ebb0f63729521d7afd9dce558f114ead788d0c
        • Opcode Fuzzy Hash: 0fbd957179d89af9e1d3453d65279f22830f04fe064c784c04e338e6c7bf3646
        • Instruction Fuzzy Hash: 8781D621A1C2428AEBA8BA15A48067DA390EF91F44F541737DD09DB69DCF3FE845C741
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo
        • String ID: 0
        • API String ID: 3215553584-4108050209
        • Opcode ID: a261a21fa45f21d734edfefcd2ffe271b1157111beaf653bc061adca1a26389c
        • Instruction ID: a67afc4facc5ba057791de2247d0ce86079b8305fb53327b9d9469c1c008208b
        • Opcode Fuzzy Hash: a261a21fa45f21d734edfefcd2ffe271b1157111beaf653bc061adca1a26389c
        • Instruction Fuzzy Hash: 07710721A0C28346FBA8BA2990406BDE7909F42F44F181735DD0DDB7DECE2FE8468B45
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID: gj
        • API String ID: 0-4203073231
        • Opcode ID: 226aa63bfce789330e15763d8953fb7d553c3450d9c1aa6f260de1088bdface5
        • Instruction ID: c030e150d7e9b98ba88349c756ca80fa9cb43b1afd2e23d02888cd8363fab0cb
        • Opcode Fuzzy Hash: 226aa63bfce789330e15763d8953fb7d553c3450d9c1aa6f260de1088bdface5
        • Instruction Fuzzy Hash: C55191777286908BD764CF25E410A9EB3A5F388758F445226EF4A93B09CB39E945CF40
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID: @
        • API String ID: 0-2766056989
        • Opcode ID: 49e7fa989fc271adaa8e130b28d1cae0d9f82f392019a5f874cdac11a507a941
        • Instruction ID: 1ada4361b2a4dea218821560fd16989f5aca6720872ac6acff80394ff7376c1b
        • Opcode Fuzzy Hash: 49e7fa989fc271adaa8e130b28d1cae0d9f82f392019a5f874cdac11a507a941
        • Instruction Fuzzy Hash: 2841CEA2718A4586EF44EF2AE5142A9B3A1FB58FD4B499236DE1DC7758DE3DD042C300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: HeapProcess
        • String ID:
        • API String ID: 54951025-0
        • Opcode ID: 4ce929ddb23f73c0a8458b43b9ad49d4d7e2a2f746430c3d48bba7e89996d797
        • Instruction ID: ea2eb3469b467e2475e2d10b1388c389a68b8f62938d8bb92ee6dacd21ebedc6
        • Opcode Fuzzy Hash: 4ce929ddb23f73c0a8458b43b9ad49d4d7e2a2f746430c3d48bba7e89996d797
        • Instruction Fuzzy Hash: 30B09220E1BE06C2EA083B11AC82294A2A4BF48700F949138C10DC1320DE3E20AA4700
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 1df1e6e81a57214c8643d36be1bb9cde3812740f73d4ab830297bee2ffae98a2
        • Instruction ID: 33dbc584e7a70f8062f1010b40e2ad1ac36795867c1c7f91c89e926391f9922b
        • Opcode Fuzzy Hash: 1df1e6e81a57214c8643d36be1bb9cde3812740f73d4ab830297bee2ffae98a2
        • Instruction Fuzzy Hash: 8782F473A0D7C186DB15EF28D4046BCBBA2E755B88F19823ACA4E87785DE3ED945C310
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: fb6bb4a62616f0bcd3e2e2126cd32946fe2ad160a7c0dbd4e5bd03ed1428d6a6
        • Instruction ID: 5e2a982efcfffa15b96106223a562cb4d3c607105c820a05a3c43a3d41d88381
        • Opcode Fuzzy Hash: fb6bb4a62616f0bcd3e2e2126cd32946fe2ad160a7c0dbd4e5bd03ed1428d6a6
        • Instruction Fuzzy Hash: AC627D9AD3AF9A1EE303A53954131D2E35C0EF74C9551E31BFCE431E66EB92A6832314
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 83a45c88a368d7276059de07aefbbc35b61cea5d64746511b72f3674958eea04
        • Instruction ID: d5e13f5cc816695c6ed80f542c89cba64396c5b34b4d717ad87b8ce6f78a3e4d
        • Opcode Fuzzy Hash: 83a45c88a368d7276059de07aefbbc35b61cea5d64746511b72f3674958eea04
        • Instruction Fuzzy Hash: 2B82E0B3A0D6C18ADB15EE28D4446FCBBA1E755B48F098236CA4D87789DE3ED885C710
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: ffdf8f5a64276e3eb417e3b9ae5b43350349d41efb04db03fca9f8ba9e24336f
        • Instruction ID: 3dcd8908a6d7b37ddc94f3e077d0964f25874c17ca224a5d373488a40069126e
        • Opcode Fuzzy Hash: ffdf8f5a64276e3eb417e3b9ae5b43350349d41efb04db03fca9f8ba9e24336f
        • Instruction Fuzzy Hash: 2D22E573B246508BD728CF25C89AE5E3766F798744B4B8228DF0ACB789DB39D505CB40
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 21143e83615dcc23e36b64f0d60848ac948cba63854c17a605a1a3ec217f9251
        • Instruction ID: f24b8644580a42171fba6de4be0210a02b602884a85c1b39164bdded35142500
        • Opcode Fuzzy Hash: 21143e83615dcc23e36b64f0d60848ac948cba63854c17a605a1a3ec217f9251
        • Instruction Fuzzy Hash: 9B32B173A0C6918BE718EF24D550ABC77A1F794B48F058239DA4A87B88DF3DE865C740
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 063370d9e2e9571dc593e8358d008e0ec5385ad0435e9f2f5019d46da215c13b
        • Instruction ID: b84bafced2c0499eae56aa8f662cc7f3dc99707cf6fcdfe06149bba7d2240731
        • Opcode Fuzzy Hash: 063370d9e2e9571dc593e8358d008e0ec5385ad0435e9f2f5019d46da215c13b
        • Instruction Fuzzy Hash: 5AC1ADB7B281908FE350CF7AE400A9D7BB1F39878CB51A125DF59A3B09D639E645CB40
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 602477e063b5c1ca901f2159ae3c7fc010244aaa433e93e1960e83d539d05e76
        • Instruction ID: 6fb8f3d6340716ea82d2e50b4887920e50c836f10e156259a2def924a8c4dc0d
        • Opcode Fuzzy Hash: 602477e063b5c1ca901f2159ae3c7fc010244aaa433e93e1960e83d539d05e76
        • Instruction Fuzzy Hash: 7EA10473B0C18287EB25FE36D4447B9A692EB90748F594735DA4AC7786CE3EE981C340
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: e3f156a61251d3696a660eff3e2c5499dd818c979554cbf7ea7c30eccab92618
        • Instruction ID: 88bf67e04a677973dc4af75edeb60e1e61efd65ef0e0931667aca4aaecbb90bb
        • Opcode Fuzzy Hash: e3f156a61251d3696a660eff3e2c5499dd818c979554cbf7ea7c30eccab92618
        • Instruction Fuzzy Hash: 40C10673A291E08DE302CBB5A4348FD3FF1E71E34DB4A4251EF9666B4AC6295205DF60
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AddressProc
        • String ID:
        • API String ID: 190572456-0
        • Opcode ID: ba0d91b71a6ba36ace61fab0c0f7d4922daa1e3f8d028e3e8b3457ff5b2a4fa0
        • Instruction ID: 2f8f876ad0420b0e0a5bd1bf9df00e38a2b8cada35cfe3083ffe72bc9f6b7e25
        • Opcode Fuzzy Hash: ba0d91b71a6ba36ace61fab0c0f7d4922daa1e3f8d028e3e8b3457ff5b2a4fa0
        • Instruction Fuzzy Hash: 98912162B1C58196EB11FF29D4502FDA721FF95B88F441231EF4E87659EE3AE64AC300
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: cfd80b8924012b3a81ce264cde7180753b201b1e387c519ebd9873ce58afa85e
        • Instruction ID: 5f3790f0565d96ae59c7e2953d669d441ca1597bd7c22a35de7b4a91a0c17635
        • Opcode Fuzzy Hash: cfd80b8924012b3a81ce264cde7180753b201b1e387c519ebd9873ce58afa85e
        • Instruction Fuzzy Hash: 95611763F1C1D189EB01EF7585104FEBFB1AB49788B464232CE9997646CE3EE509CB50
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 8137a9b05b05aada6fbcd6bbdda66db02b1ef4637fe403d2df7c72722ebbdea5
        • Instruction ID: f10eb0593905aaf4824605c977895beecc264a1bf75366c1aa1b618946f14045
        • Opcode Fuzzy Hash: 8137a9b05b05aada6fbcd6bbdda66db02b1ef4637fe403d2df7c72722ebbdea5
        • Instruction Fuzzy Hash: 25513673B2C1614BE728AF2AD0047BDB761FB90B48F494234DB4987688DE3EE545CB00
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 525267a7f117e2089c634eae81b531c40420bccc1aa688f1dd99d62513960580
        • Instruction ID: 82e1d961f2c1db69b11900c37e3f1b5a25867017ddc00a09e34830570a9c7527
        • Opcode Fuzzy Hash: 525267a7f117e2089c634eae81b531c40420bccc1aa688f1dd99d62513960580
        • Instruction Fuzzy Hash: DE31B2B2A1C6818BD718FE2696A02BEB791B744344F048239DF4AC7B42DE3DE445C700
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: 20052d42666034676028b01d15d2cffdefdd266dec7e2dd0f98b8d8f07818195
        • Instruction ID: cd575b04b22dac7bdda592ac1c477537b4a95a9639459da39937af27922c36b9
        • Opcode Fuzzy Hash: 20052d42666034676028b01d15d2cffdefdd266dec7e2dd0f98b8d8f07818195
        • Instruction Fuzzy Hash: CEF068B1B1D6558BDBA5FF29E442629B7D0F708380F548139D58DC7B08DA3D94608F04
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID:
        • API String ID:
        • Opcode ID: e57e15d0ab639cfe726454a8769b7378f2b682ff734fe90589bfb13db1bf513a
        • Instruction ID: be0f0106aaf3c7182add355d65803dd277ec44b9e9718d7f5251cda70d65c36a
        • Opcode Fuzzy Hash: e57e15d0ab639cfe726454a8769b7378f2b682ff734fe90589bfb13db1bf513a
        • Instruction Fuzzy Hash: A4A0027190CC46D0F744BB10E860871A730FB50700B511231F00EC21A8DF3EA401D304
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID: :$EFS:$LOGGED_UTILITY_STREAM$:$I30:$INDEX_ALLOCATION$:$TXF_DATA:$LOGGED_UTILITY_STREAM$::$ATTRIBUTE_LIST$::$BITMAP$::$DATA$::$EA$::$EA_INFORMATION$::$FILE_NAME$::$INDEX_ALLOCATION$::$INDEX_ROOT$::$LOGGED_UTILITY_STREAM$::$OBJECT_ID$::$REPARSE_POINT
        • API String ID: 3668304517-727060406
        • Opcode ID: 74d68d42448b2834d40d390ad32eed462d68e051ec4e29c63c0154d737a3ceed
        • Instruction ID: 88eab69392e56f5e1b09e25f7cb382c984ec3e0663f1b475b48f349121f4bd3f
        • Opcode Fuzzy Hash: 74d68d42448b2834d40d390ad32eed462d68e051ec4e29c63c0154d737a3ceed
        • Instruction Fuzzy Hash: 4041E636B09B0599FB00BF60E4843E973B9EB48798F401236DA5D83BA8EF3AD155C340
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Handle$AddressCriticalModuleProcSection$CloseCountCreateDeleteEventInitializeSpin
        • String ID: SleepConditionVariableCS$WakeAllConditionVariable$api-ms-win-core-synch-l1-2-0.dll$kernel32.dll
        • API String ID: 2565136772-3242537097
        • Opcode ID: 6e1e709f092c3aabc6fb1c9db3d7c09c3ef1a4a7bf2af41e7ac9402dec2f511f
        • Instruction ID: d76768163ce39ef6343f438d4f2f160512bf081b7c1c597c592081748c2480db
        • Opcode Fuzzy Hash: 6e1e709f092c3aabc6fb1c9db3d7c09c3ef1a4a7bf2af41e7ac9402dec2f511f
        • Instruction Fuzzy Hash: 37210C65E1DA0781FF55BF55E855974E3A0AF48B81F840735C91FC26A8DE3EE445C700
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$Xinvalid_argumentstd::_
        • String ID: DXGIDebug.dll$UNC$\\?\
        • API String ID: 4097890229-4048004291
        • Opcode ID: 4f1437804bcdce90e20cec30e65ff0fa4fbfed6c2bf85bcea305f217ae80ce6c
        • Instruction ID: 4ceeb4c646e9b4740b3d1cde0e88cea3a79ce04481f821ce8f1ae1c79e8c0154
        • Opcode Fuzzy Hash: 4f1437804bcdce90e20cec30e65ff0fa4fbfed6c2bf85bcea305f217ae80ce6c
        • Instruction Fuzzy Hash: 6E12AC22B0CA8280EF10FB65D8641ADA371EB85B98F505335DA6D87BE9DF3ED549C340
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_taskDialog
        • String ID: GETPASSWORD1$Software\WinRAR SFX
        • API String ID: 431506467-1315819833
        • Opcode ID: d8322a208530c57668d9ab0bd9eeb9a998ed53718cd7cec1bf797515a4396991
        • Instruction ID: f1a7f36a4a3572d774fd7308a363c2635fba9973c20c2499639787ca7f0eb272
        • Opcode Fuzzy Hash: d8322a208530c57668d9ab0bd9eeb9a998ed53718cd7cec1bf797515a4396991
        • Instruction Fuzzy Hash: 9DB1BD62F1DB8285FB00BBA4D4442BDA372AB85798F444336DA1DA6BD9DF3EE445C340
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$Global$AllocCreateStream
        • String ID: </html>$<html>$<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head>$<style>body{font-family:"Arial";font-size:12;}</style>
        • API String ID: 2868844859-1533471033
        • Opcode ID: 99020ba5446ec8b5071b5be278ebc62a02c6a64c5a04705e5c2bdc59161e89ed
        • Instruction ID: deacda46990671da16d99c8a8a75e7021a22548b127e9d2956eaf026ee383c39
        • Opcode Fuzzy Hash: 99020ba5446ec8b5071b5be278ebc62a02c6a64c5a04705e5c2bdc59161e89ed
        • Instruction Fuzzy Hash: C9819F62F1CA4685FB00FBA5D8502FDA371AF49B88F401235DE1D9769AEE3AD50AC344
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo
        • String ID: INF$NAN$NAN(IND)$NAN(SNAN)$inf$nan$nan(ind)$nan(snan)
        • API String ID: 3215553584-2617248754
        • Opcode ID: ca8329083cbd7a022b2adefca7a3bb58d0ae1dff90efa4c28dbe4d3f14657870
        • Instruction ID: 4f9e6da3d3bea7ca4d2f52a8e0fa97c9095ac30d6f457ead2aa0c70b130a6292
        • Opcode Fuzzy Hash: ca8329083cbd7a022b2adefca7a3bb58d0ae1dff90efa4c28dbe4d3f14657870
        • Instruction Fuzzy Hash: EB41AF72A09B4589EB04EF25E8417ED73A4EB18798F014636EF5D87B58DE3ED025C344
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ItemTextWindow
        • String ID: LICENSEDLG
        • API String ID: 2478532303-2177901306
        • Opcode ID: e29db3841e3cac596c2aa5df9f59b5580221106af80a371471668d29e16b4ce4
        • Instruction ID: 9be95f254907f2aa1dc80d3a652935b62756fc9e1e9d773b9558843365730ea9
        • Opcode Fuzzy Hash: e29db3841e3cac596c2aa5df9f59b5580221106af80a371471668d29e16b4ce4
        • Instruction Fuzzy Hash: 2C417C65B0CA5282FB54BB52E854779E3A1EF85B85F084335D90E83BA4CF3EE546C704
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Window$MessageObjectSend$ClassDeleteLongName
        • String ID: STATIC
        • API String ID: 2845197485-1882779555
        • Opcode ID: 028936735c5caa7e1c5955390d3996a5d13f8d6e72d7f98742e6e6c768b0ab82
        • Instruction ID: adc7f322a75b824fb4c07d821ad041e1f94c94341a04debb97a861282515ca26
        • Opcode Fuzzy Hash: 028936735c5caa7e1c5955390d3996a5d13f8d6e72d7f98742e6e6c768b0ab82
        • Instruction Fuzzy Hash: D6318F26B0CA4286FA64BB12E5547B9E3A1FF89BC0F040630DD4D87B5ADE3EE4068740
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AddressProc$CurrentDirectoryProcessSystem
        • String ID: Crypt32.dll$CryptProtectMemory$CryptProtectMemory failed$CryptUnprotectMemory$CryptUnprotectMemory failed
        • API String ID: 2915667086-2207617598
        • Opcode ID: d2e93635ec338890dfe438c4789fcaf7e26687fbfe6c7ce53d5981307f2d6baa
        • Instruction ID: 4b3e02f83fb4681ee58641c1cad9c5fef19692de697c2f71e140eaf133577941
        • Opcode Fuzzy Hash: d2e93635ec338890dfe438c4789fcaf7e26687fbfe6c7ce53d5981307f2d6baa
        • Instruction Fuzzy Hash: 34316B20E0DB06C0FB55BB16E86497AE7A0AF54B94F051335C81E873A4DEBEE549C300
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID: $
        • API String ID: 3668304517-227171996
        • Opcode ID: c3d23b65519d6b0e16bf2cf387636935753ce78294b0e94f23a44a4be1d6057b
        • Instruction ID: 69af2e50130a4e5b0b3902c680e5a611bdc40a1ea9fbd4e54e9ccacf4744ed9e
        • Opcode Fuzzy Hash: c3d23b65519d6b0e16bf2cf387636935753ce78294b0e94f23a44a4be1d6057b
        • Instruction Fuzzy Hash: 89F1AE62F1D64684EF10BB65D4482BDA362AB84B98F405731CE6D97BD9DF7EE180C340
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Is_bad_exception_allowedabortstd::bad_alloc::bad_alloc
        • String ID: csm$csm$csm
        • API String ID: 2940173790-393685449
        • Opcode ID: 65edb01f61f21fff02eaccc9a46b43a233fa456fccf40e480b66f774ee54b1a7
        • Instruction ID: ddb5ec5882a9bf0986daea5077c3098d7c1ab9565ffbceff74af6d0a0bb5d938
        • Opcode Fuzzy Hash: 65edb01f61f21fff02eaccc9a46b43a233fa456fccf40e480b66f774ee54b1a7
        • Instruction Fuzzy Hash: DDE19072A1C7828AE721FF25D4813ADB7A0FB45B58F144235DA8D9779ACF39E885C700
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AllocClearStringVariant
        • String ID: Name$ROOT\CIMV2$SELECT * FROM Win32_OperatingSystem$WQL$Windows 10
        • API String ID: 1959693985-3505469590
        • Opcode ID: a8b35b7bcd37d82ee4aaa20c3b876beaab518b1de9e1ce59ea14af8b32f1fe8d
        • Instruction ID: 490086f6449ee6b412b2c037ecc91d5651eeca9363bbc2e8a7d0a01f152d6964
        • Opcode Fuzzy Hash: a8b35b7bcd37d82ee4aaa20c3b876beaab518b1de9e1ce59ea14af8b32f1fe8d
        • Instruction Fuzzy Hash: 0C712F36A18B15C5EB20EF25D8905ADBBB4FB84B98F445232DA4E87B64CF3ED544C300
        APIs
        • LoadLibraryExW.KERNEL32(?,?,00000000,00007FF646DB74F3,?,?,?,00007FF646DB525E,?,?,?,00007FF646DB5219), ref: 00007FF646DB7371
        • GetLastError.KERNEL32(?,?,00000000,00007FF646DB74F3,?,?,?,00007FF646DB525E,?,?,?,00007FF646DB5219), ref: 00007FF646DB737F
        • LoadLibraryExW.KERNEL32(?,?,00000000,00007FF646DB74F3,?,?,?,00007FF646DB525E,?,?,?,00007FF646DB5219), ref: 00007FF646DB73A9
        • FreeLibrary.KERNEL32(?,?,00000000,00007FF646DB74F3,?,?,?,00007FF646DB525E,?,?,?,00007FF646DB5219), ref: 00007FF646DB73EF
        • GetProcAddress.KERNEL32(?,?,00000000,00007FF646DB74F3,?,?,?,00007FF646DB525E,?,?,?,00007FF646DB5219), ref: 00007FF646DB73FB
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Library$Load$AddressErrorFreeLastProc
        • String ID: api-ms-
        • API String ID: 2559590344-2084034818
        • Opcode ID: eedfc97f7024c66fbeb39a7219499b253e22696fd1fdab2c5f769bf1fd383016
        • Instruction ID: 6c6cffa771b1434d78d6a5b5de7dc910eb879faf68ae786800b856a334cfd839
        • Opcode Fuzzy Hash: eedfc97f7024c66fbeb39a7219499b253e22696fd1fdab2c5f769bf1fd383016
        • Instruction Fuzzy Hash: 6631C421B1EA4292FF11BB16A800979A794FF48FA0F594735DD2D8B798DF3EE4418710
        APIs
        • GetModuleHandleW.KERNEL32(?,?,?,00007FF646DB1573,?,?,?,00007FF646DB192A), ref: 00007FF646DB162B
        • GetProcAddress.KERNEL32(?,?,?,00007FF646DB1573,?,?,?,00007FF646DB192A), ref: 00007FF646DB1648
        • GetProcAddress.KERNEL32(?,?,?,00007FF646DB1573,?,?,?,00007FF646DB192A), ref: 00007FF646DB1664
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AddressProc$HandleModule
        • String ID: AcquireSRWLockExclusive$KERNEL32.DLL$ReleaseSRWLockExclusive
        • API String ID: 667068680-1718035505
        • Opcode ID: 4fe35f58cd4175722fa2f4edd42b7d77b08fa8d78ae8e9bf73ccac7c2071e7f8
        • Instruction ID: 3396c882a6fcc544ad91896d054a65523850272455a52f55e0857bb91202ca66
        • Opcode Fuzzy Hash: 4fe35f58cd4175722fa2f4edd42b7d77b08fa8d78ae8e9bf73ccac7c2071e7f8
        • Instruction Fuzzy Hash: 23111B30A1EB0681FE65BB05FE40274D2A5AF0DB94F5C5735C81E8639CEE3EE4848640
        APIs
          • Part of subcall function 00007FF646D951A4: GetVersionExW.KERNEL32 ref: 00007FF646D951D5
        • FileTimeToLocalFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF646D85AB4), ref: 00007FF646D9ED8C
        • FileTimeToSystemTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF646D85AB4), ref: 00007FF646D9ED98
        • SystemTimeToTzSpecificLocalTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF646D85AB4), ref: 00007FF646D9EDA8
        • SystemTimeToFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF646D85AB4), ref: 00007FF646D9EDB6
        • SystemTimeToFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF646D85AB4), ref: 00007FF646D9EDC4
        • FileTimeToSystemTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000001,00007FF646D85AB4), ref: 00007FF646D9EE05
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Time$File$System$Local$SpecificVersion
        • String ID:
        • API String ID: 2092733347-0
        • Opcode ID: 197518eb8103cda2bd6b54f1f5e99fa721289ee203340eaf45d2c62117a67569
        • Instruction ID: 8ad3dc2834196ad47250bef00aee0f6b889d0412bfea53eb059da5b7fa0bb8ee
        • Opcode Fuzzy Hash: 197518eb8103cda2bd6b54f1f5e99fa721289ee203340eaf45d2c62117a67569
        • Instruction Fuzzy Hash: EA519CB2B04651CAEB14EFA8D4545ACB7B1FB48B88B60413ADE0E97B58DF39E545C700
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Time$File$System$Local$SpecificVersion
        • String ID:
        • API String ID: 2092733347-0
        • Opcode ID: 93bf5fe4be91675a5f4cba4a2df0f2c5ed0bd126a165fd4d88c3e7d5e64543a6
        • Instruction ID: be77b9ac2c0746b6629543f5842bfad7ddfe105eb81e82c2243efb7eeef0b499
        • Opcode Fuzzy Hash: 93bf5fe4be91675a5f4cba4a2df0f2c5ed0bd126a165fd4d88c3e7d5e64543a6
        • Instruction Fuzzy Hash: D6313A62B14A51CEFB14EFB5D8901ACB770FB08758B54513AEE0EA7A58EF38D895C700
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID: .rar$exe$rar$sfx
        • API String ID: 3668304517-630704357
        • Opcode ID: ded382a5f33e5d00d019a19aa0952dad5d31072c5da8fffb523e0446b7f74fbf
        • Instruction ID: 863c196cf2298f5efe627192a1cce0c5177b0d8ee21e3cd8d31070bb9d2f1788
        • Opcode Fuzzy Hash: ded382a5f33e5d00d019a19aa0952dad5d31072c5da8fffb523e0446b7f74fbf
        • Instruction Fuzzy Hash: EFA1AF22A1CA0680EB04BF25D8656BCA361BF45B9CF541335DE1E876E9DF3EE589C340
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: abort$CallEncodePointerTranslator
        • String ID: MOC$RCC
        • API String ID: 2889003569-2084237596
        • Opcode ID: 0f4c2d06ef2d655583c55900dbb020dcf620b12558a4295111afe460be181df6
        • Instruction ID: d6858c9afc0feba2e7a50b68852582ad998be8763f40dff09f5817a7e3f93616
        • Opcode Fuzzy Hash: 0f4c2d06ef2d655583c55900dbb020dcf620b12558a4295111afe460be181df6
        • Instruction Fuzzy Hash: DF91A173A08B818AE711EF65E8802ADBBA0F744B88F144239EF4D97759DF39D595C700
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
        • String ID: csm$f
        • API String ID: 2395640692-629598281
        • Opcode ID: a7c39da158025e753bf36dfb1e051fd0b17def11f5f8def40396cbfe1c046983
        • Instruction ID: 93eb0c476904d3a7393e154d9206efeb23d7cfa1c69c93e127931ed37e394fdc
        • Opcode Fuzzy Hash: a7c39da158025e753bf36dfb1e051fd0b17def11f5f8def40396cbfe1c046983
        • Instruction Fuzzy Hash: 8F51BE32A1D6028AEB54FF16E844A29B795FB40FC8F548230DA5E8778CDF7AEC418740
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ErrorLast_invalid_parameter_noinfo_noreturn$CloseCurrentHandleProcess
        • String ID: SeRestorePrivilege$SeSecurityPrivilege
        • API String ID: 2102711378-639343689
        • Opcode ID: cc2cdb65981a4fcc868e5d913d4f06653a23f25da57a99a038b17aaaeb8469e6
        • Instruction ID: 6560c872d8eb9abbce2b6501605269fe84aa01876f6cca0a611e5b77025ed237
        • Opcode Fuzzy Hash: cc2cdb65981a4fcc868e5d913d4f06653a23f25da57a99a038b17aaaeb8469e6
        • Instruction Fuzzy Hash: 2251D362F1C74285FB10FB65D8456BDA360AF947A4F041335DE6E936E6DE3EA485C300
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Window$Show$Rect
        • String ID: RarHtmlClassName
        • API String ID: 2396740005-1658105358
        • Opcode ID: 2556132b3669e06fd82c4edcfb73ee53acbff31ec70f5bbfd324b20a510b6699
        • Instruction ID: 8cafc0e5f4c0deab5dfff9015de5f036b51e0624467f34896c9955bde149ba97
        • Opcode Fuzzy Hash: 2556132b3669e06fd82c4edcfb73ee53acbff31ec70f5bbfd324b20a510b6699
        • Instruction Fuzzy Hash: 2C517326A0DB4286EB24BF26E45437AE3A1FF85B80F044635DE4E87B55DF3EE4458B00
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: EnvironmentVariable$_invalid_parameter_noinfo_noreturn
        • String ID: sfxcmd$sfxpar
        • API String ID: 3540648995-3493335439
        • Opcode ID: 42a5c16ff962b42e9c466757ddc2add4312beed441a9accfeec164922430c806
        • Instruction ID: f4b4add9e0f6aba9a27ab286226a7c11b75878f9ef97e5c96148b5e840f9ec24
        • Opcode Fuzzy Hash: 42a5c16ff962b42e9c466757ddc2add4312beed441a9accfeec164922430c806
        • Instruction Fuzzy Hash: FB316D72A1CA0684FF04BB65E8841ACA371FB88B98F140636DE5E977A9DF39D046C344
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID:
        • String ID: RENAMEDLG$REPLACEFILEDLG
        • API String ID: 0-56093855
        • Opcode ID: 98f895654b64cd1d2f90e97d30244ed9b67d31cc2014a88c355cd353264df31a
        • Instruction ID: 3cf293724bd241a863f02e00eeaec4799aae65816bc785f6d8990eaeab02d7b3
        • Opcode Fuzzy Hash: 98f895654b64cd1d2f90e97d30244ed9b67d31cc2014a88c355cd353264df31a
        • Instruction Fuzzy Hash: A521F82590DF4B80FB54BB15F844174E3A0EB89B88F180676DA8DC7764DE3EE599C340
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AddressFreeHandleLibraryModuleProc
        • String ID: CorExitProcess$mscoree.dll
        • API String ID: 4061214504-1276376045
        • Opcode ID: 42a4ca90c7c49dddb16080121233970ff8583544d2054868cb5f0899d871e2db
        • Instruction ID: 0761f0c4dc5e8117e0de6ce77dc50ff23848b99fecc15ba053ffab20799c7d4d
        • Opcode Fuzzy Hash: 42a4ca90c7c49dddb16080121233970ff8583544d2054868cb5f0899d871e2db
        • Instruction Fuzzy Hash: C2F062A1A1DA4681FF44BB11F450679A7A0FF88B90F441139E95F86668DF3EE485C700
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo
        • String ID:
        • API String ID: 3215553584-0
        • Opcode ID: cf462e6f26ae3af6f96c078c51b53c82231ed120809331cf2f591469c69a5a17
        • Instruction ID: 67f62baf7f24e7fdf0f8ba17abf79817f48aafcaf23d2bdc9150ec620eb6ec6f
        • Opcode Fuzzy Hash: cf462e6f26ae3af6f96c078c51b53c82231ed120809331cf2f591469c69a5a17
        • Instruction Fuzzy Hash: BA81BE22E1CB5A89F720BB6598406BDA6A0BF45B98F404336DD0F93AD9DF3EA445C740
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: File$Create$CloseHandleTime_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 2398171386-0
        • Opcode ID: 94d33130e0d3e07453908689b86af48371af1e3e167329ed22bda644dbf2c176
        • Instruction ID: e582d403d5f78572693e6d62276ec4614b0b03424b9ed22b795442f1a04e6cc1
        • Opcode Fuzzy Hash: 94d33130e0d3e07453908689b86af48371af1e3e167329ed22bda644dbf2c176
        • Instruction Fuzzy Hash: 5A51A272B1CA4299FB50FF65E4603BDA371AB847ACF014735DE1D867E8DE3994598300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: FileWrite$ByteCharConsoleErrorLastMultiWide
        • String ID:
        • API String ID: 3659116390-0
        • Opcode ID: 8f90b3f8899b92826fb288bc35eb601c263b89b4fb676f823db5d062d6f6b41f
        • Instruction ID: 379a27dcfc7deae5c6f9d90c4870dc7409466e7564b97801cec86189ae0f626d
        • Opcode Fuzzy Hash: 8f90b3f8899b92826fb288bc35eb601c263b89b4fb676f823db5d062d6f6b41f
        • Instruction Fuzzy Hash: 3751E132A18A5589F710EF25D4403ACBBB1FB54B98F048235DE4E97B98DF3AD156C700
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ByteCharMultiWide$AllocString
        • String ID:
        • API String ID: 262959230-0
        • Opcode ID: 8c2dc27bb1e4af113538b7172bb6dd323e96cb8c94470b0dbd49c9d6f404eed7
        • Instruction ID: 2822b8e8c7f8aacb496961a78f8db011cc6f33e9e1b56d0de0db77807e337bbd
        • Opcode Fuzzy Hash: 8c2dc27bb1e4af113538b7172bb6dd323e96cb8c94470b0dbd49c9d6f404eed7
        • Instruction Fuzzy Hash: DF419222A0D64689EB14BF269850279A291EF4CFA4F144734EA6EC7BDDDF3EE1418300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: AddressProc
        • String ID:
        • API String ID: 190572456-0
        • Opcode ID: d8da239e760e4119be076ce5ae60c5d71a4e7276355522d8061e2664917ecd9d
        • Instruction ID: 1b263b246b489d75a23119920cad7b00cb414de9a70e562ac51389eac6a1731d
        • Opcode Fuzzy Hash: d8da239e760e4119be076ce5ae60c5d71a4e7276355522d8061e2664917ecd9d
        • Instruction Fuzzy Hash: 8441C262B0DA4281FA19BF16A904675E2D5BF58FE0F198735DD1ECB798EE3EE4408304
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _set_statfp
        • String ID:
        • API String ID: 1156100317-0
        • Opcode ID: f3bd3298a46f29c998dca386ec4adc9bd6d7efdfabb851da102e47160911a3a1
        • Instruction ID: 85e8720f6cb827ff384e98827a5430ab6b8f10733a1cd38b5da641d8c93b4804
        • Opcode Fuzzy Hash: f3bd3298a46f29c998dca386ec4adc9bd6d7efdfabb851da102e47160911a3a1
        • Instruction Fuzzy Hash: 16110676E1CB0F81FA543168E5463798141AF543B0F48C330EA7FCA6D6CE6EACE06205
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Message$DispatchObjectPeekSingleTranslateWait
        • String ID:
        • API String ID: 3621893840-0
        • Opcode ID: eb57a341668d454e4e6cd52f39bb1811463ddcab187ea95c48cb89abc8d18535
        • Instruction ID: a4b00ba97e64a0edc2b4133b991023ef3a072dff7487f7e026b0355c20d472c1
        • Opcode Fuzzy Hash: eb57a341668d454e4e6cd52f39bb1811463ddcab187ea95c48cb89abc8d18535
        • Instruction Fuzzy Hash: 47F01221F3C94682F754B760E455B7AA251FFE4B05F441530E54FC2994DF2DD689CB00
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: __except_validate_context_recordabort
        • String ID: csm$csm
        • API String ID: 746414643-3733052814
        • Opcode ID: 91fc108a1c492767e4bb41002f60c2920875b1ec76e01922ab372504797a4c8e
        • Instruction ID: 2bafe0c86d822baa8669e9255e7eba238b486b945e009e8d76ac24dbea7e7aac
        • Opcode Fuzzy Hash: 91fc108a1c492767e4bb41002f60c2920875b1ec76e01922ab372504797a4c8e
        • Instruction Fuzzy Hash: B8718D62A0DAD18ADB60BF25985077DBBA0EB05F89F148236DA4C87B89CF2DD495C740
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo
        • String ID: $*
        • API String ID: 3215553584-3982473090
        • Opcode ID: 42643a1ee39b50d27a50b926b179a62c0cdc4d381fe14b17104e750277292b9f
        • Instruction ID: 27f2cab18d0a4518b14ed4bce6b0504b6922405ced3fd9f88eabf732d3fff3f5
        • Opcode Fuzzy Hash: 42643a1ee39b50d27a50b926b179a62c0cdc4d381fe14b17104e750277292b9f
        • Instruction Fuzzy Hash: 8B513372D1DA428AE775BE28844537CBBA1FB06F59F181336C64A8529DCF3EE481C705
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ByteCharMultiWide$StringType
        • String ID: $%s
        • API String ID: 3586891840-3791308623
        • Opcode ID: 8174e861c2faa6f2f7f5292a0ee7474812abc1109b8acb2517e9a7bc716d8d39
        • Instruction ID: 2efe64d6dafd889b53a490ead4733908ad56ad47f26daec4a77b074678343e53
        • Opcode Fuzzy Hash: 8174e861c2faa6f2f7f5292a0ee7474812abc1109b8acb2517e9a7bc716d8d39
        • Instruction Fuzzy Hash: 7541A122B1CB959AEB61BF65D8006A9A391FF48BA8F480335DE1E877C4DF3DE4458340
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CreateFrameInfo__except_validate_context_recordabort
        • String ID: csm
        • API String ID: 2466640111-1018135373
        • Opcode ID: ef48871438151390fa300b301edbe87f2aaf35895cd4fd9de5e2d21b12dcaab2
        • Instruction ID: 34ab705930ee32a3388b211f5dba253cc5c77e852560da0a0f75dcdf755be577
        • Opcode Fuzzy Hash: ef48871438151390fa300b301edbe87f2aaf35895cd4fd9de5e2d21b12dcaab2
        • Instruction Fuzzy Hash: 2F514B76A1D78187D620BF16E44126EB7A4FB89F90F140634EB8D87B99CF39E450CB40
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ByteCharErrorFileLastMultiWideWrite
        • String ID: U
        • API String ID: 2456169464-4171548499
        • Opcode ID: a3c4996b5397ae7c68c43f4944c85cd830f0b958292ccb38960a62bfe152ddee
        • Instruction ID: 2f739ea85dcfce01967785931ded287cf823e21fda5154b310edb26e0ce18eee
        • Opcode Fuzzy Hash: a3c4996b5397ae7c68c43f4944c85cd830f0b958292ccb38960a62bfe152ddee
        • Instruction Fuzzy Hash: 3141B42261DB8582EB20AF25E4447B9B760FB98794F544231EE4EC7788DF7DD441C700
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ObjectRelease
        • String ID:
        • API String ID: 1429681911-3916222277
        • Opcode ID: 0b5772d91688d342ea342be5c9c3c9ea07a5ad9e93d570546deb1a9808731c40
        • Instruction ID: b60c1351231857d49382e678897b2c21def9c2d9b710a290845ac79330919a80
        • Opcode Fuzzy Hash: 0b5772d91688d342ea342be5c9c3c9ea07a5ad9e93d570546deb1a9808731c40
        • Instruction Fuzzy Hash: FD311836618B4286EA14EF13F81862AF7A1FB89FD1F504535ED4A83B58CE3DE449CB00
        APIs
        • InitializeCriticalSection.KERNEL32(?,?,?,00007FF646DA317F,?,?,00001000,00007FF646D8E51D), ref: 00007FF646D9E8BB
        • CreateSemaphoreW.KERNEL32(?,?,?,00007FF646DA317F,?,?,00001000,00007FF646D8E51D), ref: 00007FF646D9E8CB
        • CreateEventW.KERNEL32(?,?,?,00007FF646DA317F,?,?,00001000,00007FF646D8E51D), ref: 00007FF646D9E8E4
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: Create$CriticalEventInitializeSectionSemaphore
        • String ID: Thread pool initialization failed.
        • API String ID: 3340455307-2182114853
        • Opcode ID: 6610cce2f1ff4f40d78c24fcbab0d777ace7136147ab701da82aad1b7a389e44
        • Instruction ID: bcaa5684165a714876ddf8d002c845a57d91331fff738375442aa9d8a705e5ec
        • Opcode Fuzzy Hash: 6610cce2f1ff4f40d78c24fcbab0d777ace7136147ab701da82aad1b7a389e44
        • Instruction Fuzzy Hash: D221D232E1D60286F710BF24D4547AE76E2EF88B0CF188234CA0D8A295CF7F9459C780
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CapsDeviceRelease
        • String ID:
        • API String ID: 127614599-3916222277
        • Opcode ID: a42f7bf34e2550c06df92b4c4441a28b155cc5d7cfc3f2a0da00e80f490195b4
        • Instruction ID: 322372b3aa4420c3e8245df0f5dc7c9d39f515093ee2604a3e2c75539864e8bd
        • Opcode Fuzzy Hash: a42f7bf34e2550c06df92b4c4441a28b155cc5d7cfc3f2a0da00e80f490195b4
        • Instruction Fuzzy Hash: EBE08C20B0CA4282EB187BB6F58912AA261EB4CBD0F158135DA1A87798CE3DC4844300
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$FileTime
        • String ID:
        • API String ID: 1137671866-0
        • Opcode ID: 3e0de6b87fc756f79ac571a371d77b74ab10159eff9a06e36aa9ff194842a8ae
        • Instruction ID: 3e89611423ee3ed8391701934838957e88ae8e8ed5065dd08e88abfddcb24de1
        • Opcode Fuzzy Hash: 3e0de6b87fc756f79ac571a371d77b74ab10159eff9a06e36aa9ff194842a8ae
        • Instruction Fuzzy Hash: 47A1A462A1CB8681EA10FF65D8542BDA361FF85794F406332EA5D83AE9DF3EE544C700
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ErrorLast
        • String ID:
        • API String ID: 1452528299-0
        • Opcode ID: 5ccedb2c5f7bd69c3059bffbe8bdf76c6f23c3f2fe52f83280dfbc353a50fdd3
        • Instruction ID: f4450a8ed20090fc28131da84bbb8cbb91c8a31898475466b7ba2189133d814b
        • Opcode Fuzzy Hash: 5ccedb2c5f7bd69c3059bffbe8bdf76c6f23c3f2fe52f83280dfbc353a50fdd3
        • Instruction Fuzzy Hash: 7951AF62F1CA4695FB00BF65D4452BCA321EB88B9CF404336DA1D97BEADE29D145C340
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CreateCurrentDirectoryErrorFreeLastLocalProcess
        • String ID:
        • API String ID: 1077098981-0
        • Opcode ID: 5a43cb7f5a8bc2b697eb0b834037522765625dc86c8d5e2913923eaf6a834e49
        • Instruction ID: 70de756aa4969f1698505267d02d29b34722dbca00a42bd2ff6fef429a56da34
        • Opcode Fuzzy Hash: 5a43cb7f5a8bc2b697eb0b834037522765625dc86c8d5e2913923eaf6a834e49
        • Instruction Fuzzy Hash: 6251543262CB4286EB50AF62E84476DB774FB84B84F501235EA4E97A58DF3DD544CB40
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo$ByteCharErrorLastMultiWide
        • String ID:
        • API String ID: 4141327611-0
        • Opcode ID: fdb879c7c344a6dcddabd48f24568e2f5e84c2dc3f6ceef9c32cec135b3ccbbf
        • Instruction ID: af563219d16a0331457f972cc6d1754db4c098d0dc51cea05db0127f18722c7e
        • Opcode Fuzzy Hash: fdb879c7c344a6dcddabd48f24568e2f5e84c2dc3f6ceef9c32cec135b3ccbbf
        • Instruction Fuzzy Hash: 50418032A0C68246FB65BF11D140379E6A0EF98F90F158236DA5E87ADDDF7EE8418700
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: FileMove_invalid_parameter_noinfo_noreturn
        • String ID:
        • API String ID: 3823481717-0
        • Opcode ID: 2b6e6cda77fd8470acf22c2ab4e7c3ce966b7b843ddf4af9049b565a023b9c35
        • Instruction ID: c4ac0e7f463cd78363a0df85e683ee3a1344b8aa18807c7b6824a091a6979670
        • Opcode Fuzzy Hash: 2b6e6cda77fd8470acf22c2ab4e7c3ce966b7b843ddf4af9049b565a023b9c35
        • Instruction Fuzzy Hash: 87419D62F18B5184FF00FF69D8555AC6371BB44BA8B005335DE5EA7AA9DF39D445C300
        APIs
        • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF646DBC45B), ref: 00007FF646DC0B91
        • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,00007FF646DBC45B), ref: 00007FF646DC0BF3
        • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,00007FF646DBC45B), ref: 00007FF646DC0C2D
        • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,?,?,00007FF646DBC45B), ref: 00007FF646DC0C57
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ByteCharEnvironmentMultiStringsWide$Free
        • String ID:
        • API String ID: 1557788787-0
        • Opcode ID: 23704c5f87cc5d65a6a85ab0da0438508b9fc27f2b888927c3d6011bf25654c1
        • Instruction ID: cf6634fed971d93d925148fa76d7d90e4eeb8404de1a412d5a880947bf129b95
        • Opcode Fuzzy Hash: 23704c5f87cc5d65a6a85ab0da0438508b9fc27f2b888927c3d6011bf25654c1
        • Instruction Fuzzy Hash: 95216131B1CB5581EA24BF126540029F6A5FB94FD0B484235DE9FA3BA4DF3EE4528704
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ErrorLast$abort
        • String ID:
        • API String ID: 1447195878-0
        • Opcode ID: df247b5a3948333368795c339682862bf84e23f7c025c70b8dad3e7beb060077
        • Instruction ID: 52907dd69b03d9ba9cb1a0e7f356094d6a509063eb24883e5e4801c51055724e
        • Opcode Fuzzy Hash: df247b5a3948333368795c339682862bf84e23f7c025c70b8dad3e7beb060077
        • Instruction Fuzzy Hash: 05014824B0D64642FA58BB22A65657C91A19F48F90F14473AD92FC27DEED2FF8048600
        APIs
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: CapsDevice$Release
        • String ID:
        • API String ID: 1035833867-0
        • Opcode ID: de15d0a72ac65e47349a1b4cc9ca260558533dfe27db70e7b1e031f833f09c6c
        • Instruction ID: c207bd4ade2d758b97a40d85be6128d2d07585cd481708018164e22126e36b3b
        • Opcode Fuzzy Hash: de15d0a72ac65e47349a1b4cc9ca260558533dfe27db70e7b1e031f833f09c6c
        • Instruction Fuzzy Hash: 76E0ED60F0DA0282FF58BBB2E85913AE190EF58B41F484639CC1FC6360DD3EA085C610
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn
        • String ID: DXGIDebug.dll
        • API String ID: 3668304517-540382549
        • Opcode ID: 959b456e8a22be6a5b0903782329af9a84473569178788a0c59be25aa0c6c2c3
        • Instruction ID: 49ad1adbb83ec69c89fd77178f9bb30261047d87660fa1cae36898a1d15c5274
        • Opcode Fuzzy Hash: 959b456e8a22be6a5b0903782329af9a84473569178788a0c59be25aa0c6c2c3
        • Instruction Fuzzy Hash: 9D71AE72A18B8186EB14EF25E8443ADB3A4FB58BD8F444235DBAD47BA9DF79D051C300
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo
        • String ID: e+000$gfff
        • API String ID: 3215553584-3030954782
        • Opcode ID: ffbcb58cc87a1110f60409a8afde5d08377aab6ce8cf060c3284a5669936e3c2
        • Instruction ID: 1a585ebd62c3aaeb8077fcdbba1adebbba0222cfeea398f1b2d9fe9be172dfdd
        • Opcode Fuzzy Hash: ffbcb58cc87a1110f60409a8afde5d08377aab6ce8cf060c3284a5669936e3c2
        • Instruction Fuzzy Hash: E751E762B1C7C246E725AB359941769AB91AB81FD0F089331C69DCBBD9CE2ED444C700
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: _invalid_parameter_noinfo_noreturn$swprintf
        • String ID: SIZE
        • API String ID: 449872665-3243624926
        • Opcode ID: 049592b23eccf18b91a3e94430bb7a89aa9f7458b84fc95e0ae4febadba54acb
        • Instruction ID: 3a1aa18861b4fd7b31b9383954db78c9116d5b452feb58624de36bc381888959
        • Opcode Fuzzy Hash: 049592b23eccf18b91a3e94430bb7a89aa9f7458b84fc95e0ae4febadba54acb
        • Instruction Fuzzy Hash: BB41D262A2C68286EE50FF24E4513BEA360EF85795F444331EA9D866DAEE3ED544C700
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: FileModuleName_invalid_parameter_noinfo
        • String ID: C:\Users\user\Desktop\Bzw4UJiXNj.exe
        • API String ID: 3307058713-3134782488
        • Opcode ID: 2b307fc7043d57580c2760bc14d10e66149d3294dbd6a1f00798eb6953a6f573
        • Instruction ID: 69dccee6c17b6bf493a75751437b14a35a0f26b3198057343ff4a8e529a868cc
        • Opcode Fuzzy Hash: 2b307fc7043d57580c2760bc14d10e66149d3294dbd6a1f00798eb6953a6f573
        • Instruction Fuzzy Hash: 6A417EB6A0CA568AEB15BF25E4401BCF794FF44B94B444236EA5E87B49DE3EE441C340
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ItemText$DialogWindow
        • String ID: ASKNEXTVOL
        • API String ID: 445417207-3402441367
        • Opcode ID: f0dceadf3d752cefa43c456a4aa636b7842370cfa9b7c94ead96106e5a66dd1b
        • Instruction ID: 486e842a63e4dc40996209aba8a95c9c5efc1acfd052862e003d7353c268ad4e
        • Opcode Fuzzy Hash: f0dceadf3d752cefa43c456a4aa636b7842370cfa9b7c94ead96106e5a66dd1b
        • Instruction Fuzzy Hash: 2441C622E1CA4281FB50BB52E8542B9E3A1EF95BC4F144235DE4D8B7A9CE3EE455C340
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ByteCharMultiWide_snwprintf
        • String ID: $%s$@%s
        • API String ID: 2650857296-834177443
        • Opcode ID: 68d6d98aec82f67e7f26d78b4367655257a27e60e60eb814561ac576190adeba
        • Instruction ID: 83c0cbaf7c6b32c677ba9b29a56c261177438b0653a5019ba553adedf21a9f16
        • Opcode Fuzzy Hash: 68d6d98aec82f67e7f26d78b4367655257a27e60e60eb814561ac576190adeba
        • Instruction Fuzzy Hash: 0431E672B1CA46D5EA10FF66E4506E9A3A0FB44B88F441232DE0D5B799EE3EE509C740
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: FileHandleType
        • String ID: @
        • API String ID: 3000768030-2766056989
        • Opcode ID: 01c4e23626c5bd34e0d32a71787dfe5976e9b76bf070a7e2fa99837352baeece
        • Instruction ID: a715ed6ee414abb0c8c1691515d5972a190e442555817d2dc9cb4f10a48e1bcf
        • Opcode Fuzzy Hash: 01c4e23626c5bd34e0d32a71787dfe5976e9b76bf070a7e2fa99837352baeece
        • Instruction Fuzzy Hash: EA219622E0CB9241EB64BB25D490139A651EB45FB4F281335D66F8B7ECCE3ED881D345
        APIs
        • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF646DB1D3E), ref: 00007FF646DB40BC
        • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF646DB1D3E), ref: 00007FF646DB4102
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ExceptionFileHeaderRaise
        • String ID: csm
        • API String ID: 2573137834-1018135373
        • Opcode ID: 995ce70781ed1107fbe35a2df86b6ab92d82f2488d4e31342cdb9a65d606da21
        • Instruction ID: f0583bca3097946038d0744568c5e0e851395f1f1164d25094ca06ba3cc7cfc2
        • Opcode Fuzzy Hash: 995ce70781ed1107fbe35a2df86b6ab92d82f2488d4e31342cdb9a65d606da21
        • Instruction Fuzzy Hash: A3113D3261CB8582EB20AB16E440269B7E5FB98B94F184231EF8D47758DF3DD555C700
        APIs
        • WaitForSingleObject.KERNEL32(?,?,?,?,?,?,?,?,00007FF646D9E95F,?,?,?,00007FF646D9463A,?,?,?), ref: 00007FF646D9EA63
        • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00007FF646D9E95F,?,?,?,00007FF646D9463A,?,?,?), ref: 00007FF646D9EA6E
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: ErrorLastObjectSingleWait
        • String ID: WaitForMultipleObjects error %d, GetLastError %d
        • API String ID: 1211598281-2248577382
        • Opcode ID: 98ce5a6e9b01a49333d4d7b683bb298ff4a8e953ba0927a3bf2f7aa8eb90df55
        • Instruction ID: 4e0ef05d589eaf86c317ee1f0fae80f5f9cad0143556b4ef9fd50526df8a60c0
        • Opcode Fuzzy Hash: 98ce5a6e9b01a49333d4d7b683bb298ff4a8e953ba0927a3bf2f7aa8eb90df55
        • Instruction Fuzzy Hash: E0E04F21E1DC4281F600BB35DC46878A6507FA1770F941330D13EC55F19F2EAA4AC300
        APIs
        Strings
        Memory Dump Source
        • Source File: 00000000.00000002.2163008136.00007FF646D81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF646D80000, based on PE: true
        • Associated: 00000000.00000002.2162996148.00007FF646D80000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163036733.00007FF646DC8000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DDB000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163053987.00007FF646DE4000.00000004.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEA000.00000002.00000001.01000000.00000003.sdmpDownload File
        • Associated: 00000000.00000002.2163078941.00007FF646DEE000.00000002.00000001.01000000.00000003.sdmpDownload File
        Joe Sandbox IDA Plugin
        • Snapshot File: hcaresult_0_2_7ff646d80000_Bzw4UJiXNj.jbxd
        Similarity
        • API ID: FindHandleModuleResource
        • String ID: RTL
        • API String ID: 3537982541-834975271
        • Opcode ID: e39cf6139d6c3c808756c827088780cb49cd2dd94430b396554b51375d39015a
        • Instruction ID: 8e5222f6e841c558af9e74f95ff20aef6ab967ad4b61b207e50c7644c757fae2
        • Opcode Fuzzy Hash: e39cf6139d6c3c808756c827088780cb49cd2dd94430b396554b51375d39015a
        • Instruction Fuzzy Hash: 6DD05E91F0D60A82FF197B76A449774A6905F1CB82F484138C85F8A394EE2ED088C750