Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe

Overview

General Information

Sample name:SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe
Analysis ID:1532531
MD5:6e90c863f1166a43e590204d055ee08a
SHA1:c02e42892470124601b5b1126b2c780bb0f2c502
SHA256:54abe3ef576221e0d1341371378f36e9f63e3f5576069573910fcad5cf43b24f
Tags:exe
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
AI detected suspicious sample
AV process strings found (often used to terminate AV products)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
Detected potential crypto function
Found large amount of non-executed APIs
One or more processes crash
Uses Microsoft's Enhanced Cryptographic Provider

Classification

  • System is w10x64
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeReversingLabs: Detection: 68%
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeVirustotal: Detection: 63%Perma Link
Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.0% probability
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B8599150 CryptStringToBinaryA,?_Random_device@std@@YAIXZ,_Query_perf_frequency,_Query_perf_counter,log,cos,sin,exp,pow,tan,memset,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,memset,CryptStringToBinaryA,_invalid_parameter_noinfo_noreturn,Concurrency::cancel_current_task,malloc,memcpy,getenv,_flushall,CreateProcessA,WaitForSingleObject,GetExitCodeProcess,CloseHandle,CloseHandle,free,0_2_00007FF7B8599150
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\Calc\Builds\922AVUSVRZEXKB\x64\Release\Loader.pdb,, source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe
Source: Binary string: C:\Calc\Builds\922AVUSVRZEXKB\x64\Release\Loader.pdb source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85BA518 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,CloseHandle,CloseHandle,abort,0_2_00007FF7B85BA518
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B8597EC0 InternetOpenA,?_Random_device@std@@YAIXZ,_Query_perf_frequency,_Query_perf_counter,log,cos,sin,exp,pow,tan,memset,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,InternetOpenUrlA,InternetReadFile,memcpy,memset,InternetCloseHandle,InternetCloseHandle,_invalid_parameter_noinfo_noreturn,InternetCloseHandle,_invalid_parameter_noinfo_noreturn,0_2_00007FF7B8597EC0
Source: Amcache.hve.3.drString found in binary or memory: http://upx.sf.net
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85A45800_2_00007FF7B85A4580
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85A06400_2_00007FF7B85A0640
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85A36E00_2_00007FF7B85A36E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85991500_2_00007FF7B8599150
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85B5A000_2_00007FF7B85B5A00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85A59E30_2_00007FF7B85A59E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85B9A200_2_00007FF7B85B9A20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85943E00_2_00007FF7B85943E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85A73E30_2_00007FF7B85A73E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B859D3A00_2_00007FF7B859D3A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85934B00_2_00007FF7B85934B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85BA5180_2_00007FF7B85BA518
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85946400_2_00007FF7B8594640
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B8597EC00_2_00007FF7B8597EC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85B30800_2_00007FF7B85B3080
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 6576 -s 380
Source: classification engineClassification label: mal52.winEXE@2/5@0/0
Source: C:\Windows\System32\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess6576
Source: C:\Windows\System32\WerFault.exeFile created: C:\ProgramData\Microsoft\Windows\WER\Temp\872a0ad2-417c-43c2-b1d6-3f71c6bd732bJump to behavior
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeReversingLabs: Detection: 68%
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeVirustotal: Detection: 63%
Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 6576 -s 380
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeSection loaded: kernel.appcore.dllJump to behavior
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\Calc\Builds\922AVUSVRZEXKB\x64\Release\Loader.pdb,, source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe
Source: Binary string: C:\Calc\Builds\922AVUSVRZEXKB\x64\Release\Loader.pdb source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeAPI coverage: 2.8 %
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85BA518 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,GetFileInformationByHandleEx,GetLastError,CloseHandle,abort,CloseHandle,CloseHandle,abort,0_2_00007FF7B85BA518
Source: Amcache.hve.3.drBinary or memory string: VMware
Source: Amcache.hve.3.drBinary or memory string: VMware Virtual USB Mouse
Source: Amcache.hve.3.drBinary or memory string: vmci.syshbin
Source: Amcache.hve.3.drBinary or memory string: VMware, Inc.
Source: Amcache.hve.3.drBinary or memory string: VMware20,1hbin@
Source: Amcache.hve.3.drBinary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563
Source: Amcache.hve.3.drBinary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
Source: Amcache.hve.3.drBinary or memory string: .Z$c:/windows/system32/drivers/vmci.sys
Source: Amcache.hve.3.drBinary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
Source: Amcache.hve.3.drBinary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev
Source: Amcache.hve.3.drBinary or memory string: c:/windows/system32/drivers/vmci.sys
Source: Amcache.hve.3.drBinary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
Source: Amcache.hve.3.drBinary or memory string: vmci.sys
Source: Amcache.hve.3.drBinary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0
Source: Amcache.hve.3.drBinary or memory string: vmci.syshbin`
Source: Amcache.hve.3.drBinary or memory string: \driver\vmci,\driver\pci
Source: Amcache.hve.3.drBinary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
Source: Amcache.hve.3.drBinary or memory string: VMware20,1
Source: Amcache.hve.3.drBinary or memory string: Microsoft Hyper-V Generation Counter
Source: Amcache.hve.3.drBinary or memory string: NECVMWar VMware SATA CD00
Source: Amcache.hve.3.drBinary or memory string: VMware Virtual disk SCSI Disk Device
Source: Amcache.hve.3.drBinary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
Source: Amcache.hve.3.drBinary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
Source: Amcache.hve.3.drBinary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver
Source: Amcache.hve.3.drBinary or memory string: VMware PCI VMCI Bus Device
Source: Amcache.hve.3.drBinary or memory string: VMware VMCI Bus Device
Source: Amcache.hve.3.drBinary or memory string: VMware Virtual RAM
Source: Amcache.hve.3.drBinary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
Source: Amcache.hve.3.drBinary or memory string: vmci.inf_amd64_68ed49469341f563
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85BB480 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7B85BB480
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85BB2A8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF7B85BB2A8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85BB480 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7B85BB480
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85BB660 SetUnhandledExceptionFilter,0_2_00007FF7B85BB660
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: GetLocaleInfoEx,FormatMessageA,0_2_00007FF7B85BA33C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exeCode function: 0_2_00007FF7B85BB6CC GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF7B85BB6CC
Source: Amcache.hve.3.drBinary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23080.2006-0\msmpeng.exe
Source: Amcache.hve.3.drBinary or memory string: msmpeng.exe
Source: Amcache.hve.3.drBinary or memory string: c:\program files\windows defender\msmpeng.exe
Source: Amcache.hve.3.drBinary or memory string: MsMpEng.exe
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Process Injection
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
DLL Side-Loading
LSASS Memory21
Security Software Discovery
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS12
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe68%ReversingLabsWin64.Trojan.Disco
SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe63%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netAmcache.hve.3.drfalse
  • URL Reputation: safe
unknown
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1532531
Start date and time:2024-10-13 15:26:09 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:8
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe
Detection:MAL
Classification:mal52.winEXE@2/5@0/0
EGA Information:
  • Successful, ratio: 100%
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 5
  • Number of non-executed functions: 53
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 52.168.117.173
  • Excluded domains from analysis (whitelisted): onedsblobprdeus16.eastus.cloudapp.azure.com, ocsp.digicert.com, login.live.com, slscr.update.microsoft.com, otelrules.azureedge.net, blobcollector.events.data.trafficmanager.net, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
TimeTypeDescription
09:27:29API Interceptor1x Sleep call for process: WerFault.exe modified
No context
No context
No context
No context
No context
Process:C:\Windows\System32\WerFault.exe
File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):65536
Entropy (8bit):0.8339947945742358
Encrypted:false
SSDEEP:96:jmF9srPh2sJhqQL7qFf1QXIDcQNc6JcEfcw3L+HbHg/rZHLnxZ1Vz3IdguEROyPV:SXsLh2XLo0TNlkjFdzuiFErZ24lO8X
MD5:04734609A9DBC656A44C0E1D90308D94
SHA1:011EC49124FC0F12DEFC8E37826A071901DF20AD
SHA-256:21882E839C14A7267CE87693C45E538A01E8F9C07EBD6CB2B9B5ECE2F7856FC2
SHA-512:168C6CD07A0FDD6833A7C4FE49F46B73E782FF3EDD3516D60932958AFB2D0B559E4A316EEC9F5836D3CFEC0A52B61602978FE8DD344EC70E7BAA79A7522BC8CF
Malicious:false
Reputation:low
Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.3.7.3.2.9.9.6.3.6.4.9.8.5.4.1.9.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.3.7.3.2.9.9.6.3.7.0.6.1.0.5.8.5.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.f.a.4.3.c.3.5.e.-.9.b.9.c.-.4.5.d.3.-.8.5.9.2.-.9.a.d.6.b.3.5.f.7.2.3.2.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.5.e.f.8.4.0.4.c.-.d.3.d.3.-.4.4.8.b.-.a.b.c.e.-.1.6.b.9.1.1.6.0.5.8.a.e.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....N.s.A.p.p.N.a.m.e.=.S.e.c.u.r.i.t.e.I.n.f.o...c.o.m...W.i.n.6.4...M.a.l.w.a.r.e.X.-.g.e.n...1.4.6.5.6...2.4.7.4.8...e.x.e.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.9.b.0.-.0.0.0.1.-.0.0.1.4.-.8.1.c.c.-.9.7.9.c.7.3.1.d.d.b.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.6.8.6.4.3.a.d.1.2.d.1.1.a.9.0.5.4.8.d.7.2.a.c.c.4.5.5.0.d.3.e.8.a.0.0.0.0.f.f.f.f.!.0.0.0.0.c.0.2.e.4.2.8.9.2.4.7.0.1.2.4.6.0.1.b.5.b.1.1.2.6.b.2.c.7.8.0.b.b.0.f.2.c.5.0.2.!.S.e.c.u.
Process:C:\Windows\System32\WerFault.exe
File Type:Mini DuMP crash report, 15 streams, Sun Oct 13 13:27:16 2024, 0x1205a4 type
Category:dropped
Size (bytes):85116
Entropy (8bit):1.4408355579928152
Encrypted:false
SSDEEP:192:ridk4ZrBuHO/9yyT6IQMjspSa+IA/gC9yzT+wLt57/A239TL83Oqy:t4Zr/9/uIQMjK5pTRt539PSOF
MD5:E7D2362E1FE9EAA0A99D9ADA9F88114C
SHA1:AED17DA830F05AE6BA89D408B80D293457007BF9
SHA-256:3C9E16F2247E65614B6BB0BFB2919617D4CC50B04BF8D70448DF90080BAAD3AF
SHA-512:4E4C482DD7228F6314BBB5DE24F0F12BA4C36900B80230237665EDB104C11595BBB2FD3B58CEEE6B53D902E05CA834C7B81052E4E37CC1A25674724F5880DD18
Malicious:false
Reputation:low
Preview:MDMP..a..... ..........g....................................$...........$...(,..........`.......8...........T...........8...D=......................................................................................................eJ......L.......Lw......................T..............g.............................0..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6.......................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\WerFault.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):8748
Entropy (8bit):3.7038681675732414
Encrypted:false
SSDEEP:192:R6l7wVeJfIPltZ6Y9fcOOgmfcKpDM89bkM2hfWPKqm:R6lXJQPlb6YFLOgmfcOkMQftb
MD5:F47CC0332F28BEAC41C9CCF91D25EB14
SHA1:954EA88D7ADCFF26989EB7770A8E228F02737FD0
SHA-256:60D1273BEBFF4A245379475A2402153FE47A0E0A6072536D7517892BD01BBA25
SHA-512:A74A995808C764D1A8F30FAD0E386F0C1088DDFA9152E91B6EA00111738A66D8F31F582131B59BE20BFFD50689D77718E12F899ACA559E504610C1E4C49AA7D4
Malicious:false
Reputation:low
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.9.0.4.5.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.9.0.4.1...2.0.0.6...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.2.0.0.6.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.2.0.5.7.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.6.5.7.6.<./.P.i.
Process:C:\Windows\System32\WerFault.exe
File Type:XML 1.0 document, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):4896
Entropy (8bit):4.562456261672848
Encrypted:false
SSDEEP:48:cvIwWl8zsEJg771I9/EWpW8VYBYm8M4J5nu8iF6yq85djLTQsd9D9Ad:uIjfCI7cd7VdJ7cPBAd
MD5:95B809442E7B1D55822E833919290129
SHA1:23F3A13093DD88326E703D5E586FBD37ADAC160D
SHA-256:31A9D7FD56EF4204C395FCEDC5316174FF298FCE473FF517B076CE88898F43CE
SHA-512:8B10D12B1235F51E097F6EB4557553C98D5980FCEB183D3C0FB43575F490BFB1F83CDAA9BFBE161C618690D52783FD9208115A65001E20BF7D0EEC3DAFC68694
Malicious:false
Reputation:low
Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="19045" />.. <arg nm="vercsdbld" val="2006" />.. <arg nm="verqfe" val="2006" />.. <arg nm="csdbld" val="2006" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="2057" />.. <arg nm="geoid" val="223" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="541709" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.789.19041.0-11.0.1000" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="409
Process:C:\Windows\System32\WerFault.exe
File Type:MS Windows registry file, NT/2000 or above
Category:dropped
Size (bytes):1835008
Entropy (8bit):4.4658535950339875
Encrypted:false
SSDEEP:6144:WIXfpi67eLPU9skLmb0b4NWSPKaJG8nAgejZMMhA2gX4WABl0uNLdwBCswSb+:bXD94NWlLZMM6YFHF++
MD5:1E9FF353F66966B5DE35E95ECE664488
SHA1:BA3105475861B2AD2B75349A461AED21892A81C6
SHA-256:08D9C780EA97A3F24568E4E74E599A1D4959D04E1A1FD7A6EBC7CE15AFB5CD8F
SHA-512:8675FF62D8AC3F50EE2FDAE74C29890B4CC953137208E618510B7FDB3788031E3EE839FE5DD732366059B2500F7E2EA074034371CE7281BD2471B096B65D4127
Malicious:false
Reputation:low
Preview:regf6...6....\.Z.................... ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e....c...b...#.......c...b...#...........c...b...#......rmtm&Z..s...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
File type:PE32+ executable (GUI) x86-64, for MS Windows
Entropy (8bit):6.342628803287784
TrID:
  • Win64 Executable GUI (202006/5) 92.65%
  • Win64 Executable (generic) (12005/4) 5.51%
  • Generic Win/DOS Executable (2004/3) 0.92%
  • DOS Executable Generic (2002/1) 0.92%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe
File size:233'472 bytes
MD5:6e90c863f1166a43e590204d055ee08a
SHA1:c02e42892470124601b5b1126b2c780bb0f2c502
SHA256:54abe3ef576221e0d1341371378f36e9f63e3f5576069573910fcad5cf43b24f
SHA512:14a38a5b20b4972956349d4718b9a6ed8286c46c3758a28acc382b369b38dbc67f2d9019a95c26430e1d3c77088ad47af0ea96853e56eccb3fdafe36f289665c
SSDEEP:3072:fQCyKBU+DkgSZxPOs82L7a3Mum6kJfADWPlA8lxPMvt6L1Hke0tjwKswX:fQCYtj9FAiNA8l2V6lkeCjwKs
TLSH:DA34494F36650CDCD8ABE139CABB5202F2B3344E473582F7179004261F5BAD69F7AA52
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......&...b...b...b...k.l.p....l..f....l..h....l..C....l..d...)...i...b...y...qk..c...qk..c...qk..c...Richb...................PE..d..
Icon Hash:90cececece8e8eb0
Entrypoint:0x14002af48
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x140000000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x66F2C558 [Tue Sep 24 13:57:44 2024 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:6
OS Version Minor:0
File Version Major:6
File Version Minor:0
Subsystem Version Major:6
Subsystem Version Minor:0
Import Hash:0e75f62fc1176f33ebe2f7928e1928fc
Instruction
dec eax
sub esp, 28h
call 00007F53212E5360h
dec eax
add esp, 28h
jmp 00007F53212E4A5Fh
int3
int3
dec eax
sub esp, 28h
dec ebp
mov eax, dword ptr [ecx+38h]
dec eax
mov ecx, edx
dec ecx
mov edx, ecx
call 00007F53212E4BF2h
mov eax, 00000001h
dec eax
add esp, 28h
ret
int3
int3
int3
inc eax
push ebx
inc ebp
mov ebx, dword ptr [eax]
dec eax
mov ebx, edx
inc ecx
and ebx, FFFFFFF8h
dec esp
mov ecx, ecx
inc ecx
test byte ptr [eax], 00000004h
dec esp
mov edx, ecx
je 00007F53212E4BF5h
inc ecx
mov eax, dword ptr [eax+08h]
dec ebp
arpl word ptr [eax+04h], dx
neg eax
dec esp
add edx, ecx
dec eax
arpl ax, cx
dec esp
and edx, ecx
dec ecx
arpl bx, ax
dec edx
mov edx, dword ptr [eax+edx]
dec eax
mov eax, dword ptr [ebx+10h]
mov ecx, dword ptr [eax+08h]
dec eax
mov eax, dword ptr [ebx+08h]
test byte ptr [ecx+eax+03h], 0000000Fh
je 00007F53212E4BEDh
movzx eax, byte ptr [ecx+eax+03h]
and eax, FFFFFFF0h
dec esp
add ecx, eax
dec esp
xor ecx, edx
dec ecx
mov ecx, ecx
pop ebx
jmp 00007F53212E454Eh
int3
retn 0000h
int3
dec eax
mov dword ptr [esp+10h], ebx
dec eax
mov dword ptr [esp+18h], esi
push ebp
push edi
inc ecx
push esi
dec eax
mov ebp, esp
dec eax
sub esp, 10h
xor eax, eax
xor ecx, ecx
cpuid
inc esp
mov eax, ecx
inc esp
mov edx, edx
inc ecx
xor edx, 49656E69h
inc ecx
xor eax, 6C65746Eh
inc esp
mov ecx, ebx
inc esp
Programming Language:
  • [IMP] VS2008 SP1 build 30729
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x34fd40x168.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x3e0000x1e0.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x3c0000x1848.pdata
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x3f0000x234.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x2fbc00x70.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x2fa800x140.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x2e0000x720.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x2c66f0x2c800f65ed4f38081c06d231bd9c912bfa599False0.3892314782303371data6.395670348363393IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x2e0000x96200x9800ef7ab754b8ea96fd28239a90c62d59bbFalse0.388671875data5.188144945680934IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x380000x3eb00xc009c7b279cb521d2aa33ec9968b1eb2c1fFalse0.21451822916666666DOS executable (block device driver)4.125390770865239IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.pdata0x3c0000x18480x1a007e269219c0d0f0c6d63d545230a01fa3False0.44771634615384615PEX Binary Archive5.273013078533793IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.rsrc0x3e0000x1e00x2009f1a673dc4e7c166bd12756a73603a62False0.53125data4.7176788329467545IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x3f0000x2340x4000c352fdd52b0f08ef925b47981b4af39False0.4267578125data3.816491633047277IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_MANIFEST0x3e0600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
DLLImport
KERNEL32.dllCreateMutexA, WaitForSingleObject, ReleaseMutex, MultiByteToWideChar, Sleep, GetLastError, OpenMutexA, CloseHandle, GlobalMemoryStatusEx, CreateProcessA, GetExitCodeProcess, FormatMessageA, InitializeSListHead, GetSystemTimeAsFileTime, GetLocaleInfoEx, CreateFileW, FindClose, FindFirstFileW, GetTempPathW, GetFileAttributesExW, AreFileApisANSI, GetModuleHandleW, GetFileInformationByHandleEx, WideCharToMultiByte, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, VirtualAlloc, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, IsDebuggerPresent, GetStartupInfoW, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, LocalFree
SHELL32.dllSHGetFolderPathA
MSVCP140.dll??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z, ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ, ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ, ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ, ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ, ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z, ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z, ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z, ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z, ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z, ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ, ??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z, ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z, ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ, ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ, ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z, ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z, ??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ, ?_Lock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ, ?_Unlock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ, ?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ, ?uflow@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAGXZ, ?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z, ?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z, ?setbuf@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAPEAV12@PEA_W_J@Z, ?sync@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAHXZ, ?imbue@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAXAEBVlocale@2@@Z, ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ, ??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ, ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z, ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z, ??1?$basic_ostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ, ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@H@Z, ?good@ios_base@std@@QEBA_NXZ, ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z, ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z, ?tolower@?$ctype@D@std@@QEBADD@Z, ??1?$codecvt@_WDU_Mbstatet@@@std@@MEAA@XZ, ?_Getcat@?$codecvt@_WDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z, ??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z, ?unshift@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z, ?out@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEB_W1AEAPEB_WPEAD3AEAPEAD@Z, ?in@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEA_W3AEAPEA_W@Z, ?always_noconv@codecvt_base@std@@QEBA_NXZ, ?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z, ??1facet@locale@std@@MEAA@XZ, ??0facet@locale@std@@IEAA@_K@Z, ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ, ?_Incref@facet@locale@std@@UEAAXXZ, ??Bid@locale@std@@QEAA_KXZ, ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ, ??1_Locinfo@std@@QEAA@XZ, ??0_Locinfo@std@@QEAA@PEBD@Z, ?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ, ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ, ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ, ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z, ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z, ?getloc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEBA?AVlocale@2@XZ, ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z, ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ, ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ, ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z, ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z, ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z, ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z, _Query_perf_counter, _Strcoll, ?_Syserror_map@std@@YAPEBDH@Z, ?id@?$collate@D@std@@2V0locale@2@A, ?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A, ?_Xlength_error@std@@YAXPEBD@Z, ?_Random_device@std@@YAIXZ, ?id@?$ctype@D@std@@2V0locale@2@A, ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z, ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z, ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A, ?_Winerror_map@std@@YAHH@Z, ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z, ?_Xbad_alloc@std@@YAXXZ, ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z, ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ, ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z, ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A, ?uncaught_exceptions@std@@YAHXZ, ??0_Lockit@std@@QEAA@H@Z, ??1_Lockit@std@@QEAA@XZ, _Query_perf_frequency, _Strxfrm, ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ
dxgi.dllCreateDXGIFactory
WININET.dllInternetReadFile, InternetCloseHandle, InternetOpenA, InternetOpenUrlA
CRYPT32.dllCryptStringToBinaryA
VCRUNTIME140_1.dll__CxxFrameHandler4
VCRUNTIME140.dllstrchr, __std_terminate, __C_specific_handler, __std_exception_destroy, memcpy, memset, memcmp, _CxxThrowException, memchr, __current_exception, memmove, __std_exception_copy, __current_exception_context
api-ms-win-crt-stdio-l1-1-0.dll_fseeki64, fwrite, fputc, _set_fmode, _get_stream_buffer_pointers, fread, __acrt_iob_func, fflush, fclose, fputwc, ungetwc, fsetpos, fgetc, __stdio_common_vfprintf, fgetwc, ungetc, setvbuf, fgetpos, __p__commode, _flushall
api-ms-win-crt-heap-l1-1-0.dll_callnewh, realloc, _set_new_mode, malloc, free
api-ms-win-crt-utility-l1-1-0.dllsrand, rand
api-ms-win-crt-filesystem-l1-1-0.dll_stat64i32, _unlock_file, _lock_file, _mkdir
api-ms-win-crt-time-l1-1-0.dll_time64
api-ms-win-crt-runtime-l1-1-0.dll_configure_narrow_argv, _initialize_narrow_environment, terminate, abort, _initialize_onexit_table, _register_onexit_function, exit, _crt_atexit, _cexit, _seh_filter_exe, _set_app_type, _get_narrow_winmain_command_line, _initterm, _initterm_e, _exit, _invalid_parameter_noinfo_noreturn, _c_exit, _register_thread_local_exe_atexit_callback
api-ms-win-crt-environment-l1-1-0.dllgetenv
api-ms-win-crt-locale-l1-1-0.dll_configthreadlocale, ___lc_codepage_func
api-ms-win-crt-math-l1-1-0.dllcos, log, exp, pow, sin, __setusermatherr, tan
Language of compilation systemCountry where language is spokenMap
EnglishUnited States
No network behavior found

Click to jump to process

Click to jump to process

Click to dive into process behavior distribution

Click to jump to process

Target ID:0
Start time:09:27:12
Start date:13/10/2024
Path:C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.Win64.MalwareX-gen.14656.24748.exe"
Imagebase:0x7ff7b8590000
File size:233'472 bytes
MD5 hash:6E90C863F1166A43E590204D055EE08A
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

Target ID:3
Start time:09:27:16
Start date:13/10/2024
Path:C:\Windows\System32\WerFault.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\WerFault.exe -u -p 6576 -s 380
Imagebase:0x7ff6971f0000
File size:570'736 bytes
MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Reset < >

    Execution Graph

    Execution Coverage:2.5%
    Dynamic/Decrypted Code Coverage:0.1%
    Signature Coverage:48.2%
    Total number of Nodes:2000
    Total number of Limit Nodes:2
    execution_graph 13447 7ff7b85a0640 13448 7ff7b85a066a 13447->13448 13449 7ff7b85a06f8 CreateDXGIFactory ?_Random_device@std@ 13448->13449 13450 7ff7b85a072c 13449->13450 13604 7ff7b8591670 _Query_perf_frequency _Query_perf_counter 13450->13604 13452 7ff7b85a076b 13606 7ff7b85afe80 13452->13606 13454 7ff7b85a07b7 13609 7ff7b85afeb0 13454->13609 13456 7ff7b85a07f5 13612 7ff7b85afee0 13456->13612 13458 7ff7b85a0833 13615 7ff7b85aff10 13458->13615 13460 7ff7b85a0871 13618 7ff7b85aff40 13460->13618 13462 7ff7b85a08af 13621 7ff7b85aff70 13462->13621 13464 7ff7b85a08ed 13465 7ff7b8591670 2 API calls 13464->13465 13493 7ff7b85a092b 13465->13493 13466 7ff7b85a0c7e 13624 7ff7b85ae300 13466->13624 13469 7ff7b85a0c97 ?_Random_device@std@ 13471 7ff7b85a0cab 13469->13471 13470 7ff7b85a363a 13723 7ff7b85ba940 13470->13723 13474 7ff7b8591670 2 API calls 13471->13474 13475 7ff7b85a0ce6 13474->13475 13476 7ff7b85afe80 3 API calls 13475->13476 13478 7ff7b85a0d32 13476->13478 13477 7ff7b85a0a2b pow 13477->13493 13480 7ff7b85afeb0 3 API calls 13478->13480 13479 7ff7b85a0a56 tan 13639 7ff7b85aea80 13479->13639 13483 7ff7b85a0d70 13480->13483 13484 7ff7b85afee0 3 API calls 13483->13484 13486 7ff7b85a0dae 13484->13486 13487 7ff7b85aff10 3 API calls 13486->13487 13488 7ff7b85a0dec 13487->13488 13489 7ff7b85aff40 3 API calls 13488->13489 13490 7ff7b85a0e2a 13489->13490 13491 7ff7b85aff70 3 API calls 13490->13491 13495 7ff7b85a0e68 13491->13495 13493->13466 13493->13477 13493->13479 13497 7ff7b8591670 2 API calls 13493->13497 13643 7ff7b85ae450 13493->13643 13646 7ff7b8592460 13493->13646 13652 7ff7b85ae3f0 13493->13652 13658 7ff7b85aea20 13493->13658 13496 7ff7b8591670 2 API calls 13495->13496 13560 7ff7b85a0ea6 13496->13560 13497->13493 13498 7ff7b85a11ee 13499 7ff7b85ae300 2 API calls 13498->13499 13518 7ff7b85a11fe 13499->13518 13500 7ff7b85a178f ?_Random_device@std@ 13502 7ff7b85a17c0 13500->13502 13502->13502 13504 7ff7b8591670 2 API calls 13502->13504 13505 7ff7b85a1821 13504->13505 13630 7ff7b85ba968 13505->13630 13507 7ff7b85a36d0 13732 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 13507->13732 13508 7ff7b85a1850 13512 7ff7b85a1878 13508->13512 13683 7ff7b85b2150 13508->13683 13511 7ff7b85a36d5 13733 7ff7b8591850 13511->13733 13516 7ff7b85ba968 std::_Facet_Register 3 API calls 13512->13516 13514 7ff7b85ba968 __std_exception_copy malloc _CxxThrowException std::_Facet_Register 13514->13518 13515 7ff7b85a36db 13520 7ff7b85a18fa 13516->13520 13517 7ff7b85a18af _invalid_parameter_noinfo_noreturn 13522 7ff7b85a18b6 _invalid_parameter_noinfo_noreturn 13517->13522 13518->13500 13518->13507 13518->13511 13518->13514 13518->13517 13521 7ff7b85a165b memchr 13518->13521 13518->13522 13525 7ff7b85a1690 memcmp 13518->13525 13529 7ff7b85ba960 free _Receive_impl 13518->13529 13664 7ff7b85ae780 13518->13664 13519 7ff7b85a0f9b pow 13519->13560 13523 7ff7b85b2150 6 API calls 13520->13523 13528 7ff7b85a1922 13520->13528 13521->13518 13522->13508 13523->13528 13524 7ff7b85a0fc6 tan 13526 7ff7b85aea80 7 API calls 13524->13526 13525->13518 13527 7ff7b85a16a8 memchr 13525->13527 13526->13560 13527->13518 13527->13525 13530 7ff7b85ba968 std::_Facet_Register 3 API calls 13528->13530 13529->13518 13531 7ff7b85a1977 13530->13531 13532 7ff7b85b2150 6 API calls 13531->13532 13534 7ff7b85a199f 13531->13534 13532->13534 13533 7ff7b85ae450 4 API calls 13533->13560 13535 7ff7b85ba968 std::_Facet_Register 3 API calls 13534->13535 13536 7ff7b85a19f4 13535->13536 13538 7ff7b85b2150 6 API calls 13536->13538 13539 7ff7b85a1a1c 13536->13539 13537 7ff7b8592460 9 API calls 13537->13560 13538->13539 13540 7ff7b85ba968 std::_Facet_Register 3 API calls 13539->13540 13541 7ff7b85a1a71 13540->13541 13542 7ff7b85b2150 6 API calls 13541->13542 13543 7ff7b85a1a99 13541->13543 13542->13543 13544 7ff7b85ba968 std::_Facet_Register 3 API calls 13543->13544 13545 7ff7b85a1aee 13544->13545 13546 7ff7b85b2150 6 API calls 13545->13546 13591 7ff7b85a1b16 13545->13591 13546->13591 13547 7ff7b85a1b7c _Query_perf_frequency _Query_perf_counter 13547->13591 13548 7ff7b85a2768 GlobalMemoryStatusEx ?_Random_device@std@ 13549 7ff7b85a27a2 13548->13549 13552 7ff7b8591670 2 API calls 13549->13552 13550 7ff7b85a26c4 13550->13548 13551 7ff7b85a274e 13550->13551 13553 7ff7b85a2747 _invalid_parameter_noinfo_noreturn 13550->13553 13720 7ff7b85ba960 13551->13720 13555 7ff7b85a27ce 13552->13555 13553->13551 13557 7ff7b85ba968 std::_Facet_Register 3 API calls 13555->13557 13559 7ff7b85a27fd 13557->13559 13558 7ff7b85ae3f0 2 API calls 13558->13560 13562 7ff7b85b2150 6 API calls 13559->13562 13563 7ff7b85a2822 13559->13563 13560->13498 13560->13519 13560->13524 13560->13533 13560->13537 13560->13558 13561 7ff7b85aea20 collate 2 API calls 13560->13561 13565 7ff7b8591670 2 API calls 13560->13565 13561->13560 13562->13563 13564 7ff7b85ba968 std::_Facet_Register 3 API calls 13563->13564 13566 7ff7b85a2874 13564->13566 13565->13560 13567 7ff7b85b2150 6 API calls 13566->13567 13568 7ff7b85a2899 13566->13568 13567->13568 13569 7ff7b85ba968 std::_Facet_Register 3 API calls 13568->13569 13570 7ff7b85a28eb 13569->13570 13571 7ff7b85b2150 6 API calls 13570->13571 13573 7ff7b85a2910 13570->13573 13571->13573 13572 7ff7b85a1e3f log cos sin exp 13572->13591 13574 7ff7b85ba968 std::_Facet_Register 3 API calls 13573->13574 13575 7ff7b85a2962 13574->13575 13577 7ff7b85b2150 6 API calls 13575->13577 13579 7ff7b85a2987 13575->13579 13576 7ff7b85a1ede pow 13576->13591 13577->13579 13578 7ff7b85a1f4e tan 13699 7ff7b85b11f0 13578->13699 13581 7ff7b85ba968 std::_Facet_Register 3 API calls 13579->13581 13582 7ff7b85a29d9 13581->13582 13584 7ff7b85b2150 6 API calls 13582->13584 13586 7ff7b85a29fc 13582->13586 13583 7ff7b85ba968 std::_Facet_Register 3 API calls 13585 7ff7b85a2043 memset 13583->13585 13584->13586 13585->13591 13589 7ff7b85aff70 3 API calls 13586->13589 13587 7ff7b85a1fa5 13587->13583 13590 7ff7b85a2a40 13589->13590 13592 7ff7b85a2a72 _Query_perf_frequency _Query_perf_counter 13590->13592 13591->13547 13591->13550 13591->13572 13591->13576 13591->13578 13600 7ff7b85a26b6 _invalid_parameter_noinfo_noreturn 13591->13600 13601 7ff7b85ba960 free _Receive_impl 13591->13601 13603 7ff7b85a26bd _invalid_parameter_noinfo_noreturn 13591->13603 13716 7ff7b85b2ac0 13591->13716 13597 7ff7b85a2a8d 13592->13597 13593 7ff7b85a35b2 13593->13470 13594 7ff7b85a3632 13593->13594 13595 7ff7b85a362b _invalid_parameter_noinfo_noreturn 13593->13595 13596 7ff7b85ba960 _Receive_impl free 13594->13596 13595->13594 13596->13470 13597->13593 13598 7ff7b85a2d1f log cos sin exp 13597->13598 13599 7ff7b85a2d90 13598->13599 13602 7ff7b85a2dbe pow 13599->13602 13600->13603 13601->13591 13602->13593 13603->13550 13605 7ff7b8591698 13604->13605 13605->13452 13607 7ff7b85ba968 std::_Facet_Register 3 API calls 13606->13607 13608 7ff7b85afe98 13607->13608 13608->13454 13610 7ff7b85ba968 std::_Facet_Register 3 API calls 13609->13610 13611 7ff7b85afec8 13610->13611 13611->13456 13613 7ff7b85ba968 std::_Facet_Register 3 API calls 13612->13613 13614 7ff7b85afef8 13613->13614 13614->13458 13616 7ff7b85ba968 std::_Facet_Register 3 API calls 13615->13616 13617 7ff7b85aff28 13616->13617 13617->13460 13619 7ff7b85ba968 std::_Facet_Register 3 API calls 13618->13619 13620 7ff7b85aff58 13619->13620 13620->13462 13622 7ff7b85ba968 std::_Facet_Register 3 API calls 13621->13622 13623 7ff7b85aff88 13622->13623 13623->13464 13625 7ff7b85ae315 13624->13625 13626 7ff7b85a0c8e 13624->13626 13627 7ff7b85ae36f 13625->13627 13628 7ff7b85ae38f _invalid_parameter_noinfo_noreturn 13625->13628 13626->13469 13626->13470 13629 7ff7b85ba960 _Receive_impl free 13627->13629 13629->13626 13631 7ff7b85ba982 malloc 13630->13631 13632 7ff7b85ba98c 13631->13632 13634 7ff7b85ba973 13631->13634 13632->13508 13633 7ff7b85ba992 13635 7ff7b85ba99d 13633->13635 13736 7ff7b85bb444 13633->13736 13634->13631 13634->13633 13636 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 13635->13636 13638 7ff7b85ba9a3 13636->13638 13640 7ff7b85aeaa0 13639->13640 13640->13640 13641 7ff7b85b11f0 7 API calls 13640->13641 13642 7ff7b85aeaae 13641->13642 13642->13493 13644 7ff7b85ba968 std::_Facet_Register 3 API calls 13643->13644 13645 7ff7b85ae474 memset 13644->13645 13645->13493 13647 7ff7b85924a6 13646->13647 13648 7ff7b85b2ac0 memcpy 13647->13648 13649 7ff7b85924ea 13648->13649 13650 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 13649->13650 13651 7ff7b85924f7 13650->13651 13651->13493 13653 7ff7b85ae401 13652->13653 13657 7ff7b85ae432 13652->13657 13654 7ff7b85ae445 _invalid_parameter_noinfo_noreturn 13653->13654 13655 7ff7b85ae42a 13653->13655 13656 7ff7b85ba960 _Receive_impl free 13655->13656 13656->13657 13657->13493 13659 7ff7b85aea5f 13658->13659 13660 7ff7b85aea33 13658->13660 13659->13493 13661 7ff7b85aea57 13660->13661 13662 7ff7b85aea78 _invalid_parameter_noinfo_noreturn 13660->13662 13663 7ff7b85ba960 _Receive_impl free 13661->13663 13663->13659 13665 7ff7b85ae7b0 13664->13665 13665->13665 13666 7ff7b85ae8b4 13665->13666 13667 7ff7b85ae7cd 13665->13667 13740 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 13666->13740 13668 7ff7b85ae7f9 13667->13668 13669 7ff7b85ae7d8 memcpy 13667->13669 13672 7ff7b85ae8b9 13668->13672 13673 7ff7b85ae877 13668->13673 13677 7ff7b85ae829 13668->13677 13679 7ff7b85ae836 memcpy 13668->13679 13671 7ff7b85ae8a0 13669->13671 13671->13518 13674 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 13672->13674 13676 7ff7b85ba968 std::_Facet_Register 3 API calls 13673->13676 13678 7ff7b85ae8bf 13674->13678 13676->13679 13680 7ff7b85ba968 std::_Facet_Register 3 API calls 13677->13680 13679->13671 13681 7ff7b85ae831 13680->13681 13681->13679 13682 7ff7b85ae870 _invalid_parameter_noinfo_noreturn 13681->13682 13682->13673 13684 7ff7b85b235f 13683->13684 13688 7ff7b85b218e 13683->13688 13741 7ff7b85b23e0 ?_Xlength_error@std@@YAXPEBD 13684->13741 13685 7ff7b85b2364 13687 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 13685->13687 13689 7ff7b85b236a 13687->13689 13688->13685 13690 7ff7b85b2224 13688->13690 13691 7ff7b85b21fb 13688->13691 13696 7ff7b85b21ed 13688->13696 13692 7ff7b85ba968 std::_Facet_Register 3 API calls 13690->13692 13691->13685 13693 7ff7b85ba968 std::_Facet_Register 3 API calls 13691->13693 13692->13696 13693->13696 13694 7ff7b85b2324 13694->13512 13695 7ff7b85b2358 _invalid_parameter_noinfo_noreturn 13695->13684 13696->13694 13696->13695 13697 7ff7b85b231c 13696->13697 13698 7ff7b85ba960 _Receive_impl free 13697->13698 13698->13694 13700 7ff7b85b12e0 13699->13700 13701 7ff7b85b1216 13699->13701 13742 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 13700->13742 13702 7ff7b85b121c memcpy 13701->13702 13709 7ff7b85b123b 13701->13709 13702->13587 13704 7ff7b85b124c 13706 7ff7b85ba968 std::_Facet_Register 3 API calls 13704->13706 13705 7ff7b85b12e5 13707 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 13705->13707 13712 7ff7b85b1262 13706->13712 13713 7ff7b85b12eb 13707->13713 13709->13704 13709->13705 13710 7ff7b85b12ac 13709->13710 13715 7ff7b85b1267 memcpy 13709->13715 13711 7ff7b85ba968 std::_Facet_Register 3 API calls 13710->13711 13711->13715 13714 7ff7b85b12a5 _invalid_parameter_noinfo_noreturn 13712->13714 13712->13715 13714->13710 13715->13587 13718 7ff7b85b2af0 13716->13718 13717 7ff7b85b2bbc 13717->13591 13718->13717 13719 7ff7b85b2b9d memcpy 13718->13719 13719->13718 13721 7ff7b85bacb4 free 13720->13721 13724 7ff7b85ba949 13723->13724 13725 7ff7b85a3677 13724->13725 13726 7ff7b85bb2dc IsProcessorFeaturePresent 13724->13726 13727 7ff7b85bb2f4 13726->13727 13743 7ff7b85bb3b0 RtlCaptureContext 13727->13743 13734 7ff7b859185e Concurrency::cancel_current_task 13733->13734 13735 7ff7b859186f __std_exception_copy 13734->13735 13735->13515 13739 7ff7b85bb424 13736->13739 13738 7ff7b85bb452 _CxxThrowException 13739->13738 13744 7ff7b85bb3ca RtlLookupFunctionEntry 13743->13744 13745 7ff7b85bb3e0 RtlVirtualUnwind 13744->13745 13746 7ff7b85bb307 13744->13746 13745->13744 13745->13746 13747 7ff7b85bb2a8 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 13746->13747 13748 7ff7b85badd4 13749 7ff7b85bade8 13748->13749 13750 7ff7b85baf20 13749->13750 13751 7ff7b85badf0 __scrt_acquire_startup_lock 13749->13751 14124 7ff7b85bb480 IsProcessorFeaturePresent 13750->14124 13753 7ff7b85baf2a 13751->13753 13759 7ff7b85bae0e __scrt_release_startup_lock 13751->13759 13754 7ff7b85bb480 9 API calls 13753->13754 13755 7ff7b85baf35 13754->13755 13757 7ff7b85baf3d _exit 13755->13757 13756 7ff7b85bae33 13758 7ff7b85baeb9 13770 7ff7b85bb5c8 memset GetStartupInfoW 13758->13770 13759->13756 13759->13758 13762 7ff7b85baeb1 _register_thread_local_exe_atexit_callback 13759->13762 13761 7ff7b85baebe _get_narrow_winmain_command_line 13771 7ff7b85a4580 13761->13771 13762->13758 13767 7ff7b85baee5 13768 7ff7b85baeef 13767->13768 13769 7ff7b85baeea _cexit 13767->13769 13768->13756 13769->13768 13770->13761 13772 7ff7b85a45a4 13771->13772 13773 7ff7b85a4937 VirtualAlloc 13772->13773 13774 7ff7b85a4958 13772->13774 13773->13774 14130 7ff7b85a36e0 13774->14130 13777 7ff7b85a4ade VirtualAlloc 13778 7ff7b85a4b03 13777->13778 13779 7ff7b85a4bee ?_Random_device@std@ 13778->13779 13782 7ff7b85a5ced 13778->13782 13780 7ff7b85a4c20 13779->13780 13780->13780 13781 7ff7b8591670 2 API calls 13780->13781 13783 7ff7b85a4c89 13781->13783 13786 7ff7b85ab854 13782->13786 13787 7ff7b85a5f47 13782->13787 13784 7ff7b85ba968 std::_Facet_Register 3 API calls 13783->13784 13785 7ff7b85a4cbe 13784->13785 13791 7ff7b85b2150 6 API calls 13785->13791 13794 7ff7b85a4cea 13785->13794 14712 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 13786->14712 14179 7ff7b85b1b10 13787->14179 13790 7ff7b85a5f82 CreateMutexA 13793 7ff7b85a5fbf 13790->13793 13799 7ff7b85a5ff4 13790->13799 13791->13794 13796 7ff7b85a76f4 _invalid_parameter_noinfo_noreturn 13793->13796 13797 7ff7b85ba960 _Receive_impl free 13793->13797 13795 7ff7b85ba968 std::_Facet_Register 3 API calls 13794->13795 13798 7ff7b85a4d51 13795->13798 13802 7ff7b85a76fb 13796->13802 13797->13799 13801 7ff7b85b2150 6 API calls 13798->13801 13804 7ff7b85a4d7d 13798->13804 13800 7ff7b85a62cd VirtualAlloc 13799->13800 13809 7ff7b85a62f2 13799->13809 13800->13809 13801->13804 14192 7ff7b85b0680 13802->14192 13806 7ff7b85ba968 std::_Facet_Register 3 API calls 13804->13806 13805 7ff7b85a793e 13810 7ff7b85a7946 OpenMutexA 13805->13810 13807 7ff7b85a4de4 13806->13807 13812 7ff7b85b2150 6 API calls 13807->13812 13814 7ff7b85a4e10 13807->13814 13808 7ff7b85a644d VirtualAlloc 13811 7ff7b85a6472 13808->13811 13809->13808 13809->13811 13813 7ff7b85aea20 collate 2 API calls 13810->13813 13811->13802 13815 7ff7b85a6561 ?_Random_device@std@ 13811->13815 13812->13814 13826 7ff7b85a7966 13813->13826 13816 7ff7b85ba968 std::_Facet_Register 3 API calls 13814->13816 13817 7ff7b85a6590 13815->13817 13818 7ff7b85a4e77 13816->13818 13817->13817 13819 7ff7b85a65b2 _Query_perf_frequency _Query_perf_counter 13817->13819 13820 7ff7b85b2150 6 API calls 13818->13820 13822 7ff7b85a4ea3 13818->13822 13821 7ff7b85a6607 13819->13821 13820->13822 13825 7ff7b85ba968 std::_Facet_Register 3 API calls 13821->13825 13824 7ff7b85ba968 std::_Facet_Register 3 API calls 13822->13824 13823 7ff7b85a7c0c VirtualAlloc 13831 7ff7b85a7c2d 13823->13831 13827 7ff7b85a4f0a 13824->13827 13828 7ff7b85a66bd 13825->13828 13826->13823 13829 7ff7b85a7bf7 13826->13829 13830 7ff7b85a7cef 13826->13830 13833 7ff7b85b2150 6 API calls 13827->13833 13835 7ff7b85a4f36 13827->13835 13832 7ff7b85b2150 6 API calls 13828->13832 13836 7ff7b85a66e9 13828->13836 13829->13823 13834 7ff7b85a7d2e CloseHandle ?_Random_device@std@ 13830->13834 13851 7ff7b85a8361 13830->13851 13831->13830 13832->13836 13833->13835 13837 7ff7b85a7d4c 13834->13837 13838 7ff7b85ba968 std::_Facet_Register 3 API calls 13835->13838 13839 7ff7b85ba968 std::_Facet_Register 3 API calls 13836->13839 13842 7ff7b8591670 2 API calls 13837->13842 13840 7ff7b85a4f9d 13838->13840 13841 7ff7b85a6750 13839->13841 13844 7ff7b85b2150 6 API calls 13840->13844 13944 7ff7b85a4fc9 13840->13944 13843 7ff7b85b2150 6 API calls 13841->13843 13845 7ff7b85a677c 13841->13845 13848 7ff7b85a7d90 13842->13848 13843->13845 13844->13944 13847 7ff7b85ba968 std::_Facet_Register 3 API calls 13845->13847 13846 7ff7b85a504a _Query_perf_frequency _Query_perf_counter 13846->13944 13850 7ff7b85a67e3 13847->13850 13852 7ff7b85afe80 3 API calls 13848->13852 13849 7ff7b85a85ec VirtualAlloc 13854 7ff7b85a860d 13849->13854 13855 7ff7b85b2150 6 API calls 13850->13855 13857 7ff7b85a680f 13850->13857 13851->13849 13853 7ff7b85a85d7 13851->13853 13862 7ff7b85a86cf 13851->13862 13866 7ff7b85a7de7 13852->13866 13853->13849 13854->13862 13855->13857 13856 7ff7b85a5ce8 13858 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 13856->13858 13860 7ff7b85ba968 std::_Facet_Register 3 API calls 13857->13860 13861 7ff7b85ab7fa 13858->13861 13859 7ff7b85a5ce0 13863 7ff7b85ba960 _Receive_impl free 13859->13863 13864 7ff7b85a6876 13860->13864 14122 7ff7b85bb60c GetModuleHandleW 13861->14122 13862->13862 14200 7ff7b85b0720 13862->14200 13863->13856 13868 7ff7b85b2150 6 API calls 13864->13868 13871 7ff7b85a68a2 13864->13871 13865 7ff7b85a5c59 13865->13796 13865->13856 13865->13859 13869 7ff7b85afeb0 3 API calls 13866->13869 13868->13871 13881 7ff7b85a7e34 13869->13881 13873 7ff7b85ba968 std::_Facet_Register 3 API calls 13871->13873 13875 7ff7b85a6909 13873->13875 13874 7ff7b85a8995 14216 7ff7b8592710 13874->14216 13877 7ff7b85b2150 6 API calls 13875->13877 13880 7ff7b85a6935 13875->13880 13877->13880 13878 7ff7b85a8c43 14383 7ff7b85ac650 ?_Init@locale@std@@CAPEAV_Locimp@12@_N 13878->14383 13879 7ff7b85a89a5 13879->13878 13879->13879 13884 7ff7b85a8c12 13879->13884 13883 7ff7b85ba968 std::_Facet_Register 3 API calls 13880->13883 13885 7ff7b85afee0 3 API calls 13881->13885 13887 7ff7b85a699c 13883->13887 13888 7ff7b85aea80 7 API calls 13884->13888 13898 7ff7b85a7e81 13885->13898 13890 7ff7b85b2150 6 API calls 13887->13890 13959 7ff7b85a69c8 13887->13959 13889 7ff7b85a8c27 13888->13889 14222 7ff7b859d3a0 13889->14222 13890->13959 13894 7ff7b85aea80 7 API calls 13897 7ff7b85a9047 13894->13897 13895 7ff7b85aea20 collate 2 API calls 13895->13878 13896 7ff7b85a6a50 _Query_perf_frequency _Query_perf_counter 13896->13959 14400 7ff7b8597ec0 13897->14400 13900 7ff7b85aff10 3 API calls 13898->13900 13911 7ff7b85a7ece 13900->13911 13901 7ff7b85a5330 log cos sin exp 13901->13944 13905 7ff7b85aea20 collate 2 API calls 13907 7ff7b85a907e 13905->13907 13906 7ff7b85a53cf pow 13906->13944 13909 7ff7b85a908c ?_Random_device@std@ 13907->13909 13908 7ff7b85a7663 13908->13796 13908->13856 13908->13859 13910 7ff7b85a90a1 13909->13910 13915 7ff7b8591670 2 API calls 13910->13915 13913 7ff7b85aff40 3 API calls 13911->13913 13912 7ff7b85a5432 tan 13914 7ff7b85b11f0 7 API calls 13912->13914 13919 7ff7b85a7f1b 13913->13919 13922 7ff7b85a548d 13914->13922 13918 7ff7b85a90e1 13915->13918 13916 7ff7b85ba968 std::_Facet_Register 3 API calls 13917 7ff7b85a5536 memset 13916->13917 13917->13944 13920 7ff7b85afe80 3 API calls 13918->13920 13921 7ff7b85aff70 3 API calls 13919->13921 13924 7ff7b85a9138 13920->13924 13926 7ff7b85a7f68 13921->13926 13922->13916 13923 7ff7b85b2ac0 memcpy 13923->13944 13925 7ff7b85afeb0 3 API calls 13924->13925 13932 7ff7b85a9185 13925->13932 13928 7ff7b8591670 2 API calls 13926->13928 13927 7ff7b85a6d30 log cos sin exp 13927->13959 13974 7ff7b85a7fb5 13928->13974 13929 7ff7b85a6dcf pow 13929->13959 13930 7ff7b85a834b 13931 7ff7b85ae300 2 API calls 13930->13931 13933 7ff7b85a835c ReleaseMutex 13931->13933 13934 7ff7b85afee0 3 API calls 13932->13934 13933->13856 13940 7ff7b85a91d2 13934->13940 13936 7ff7b85a6e32 tan 13937 7ff7b85b11f0 7 API calls 13936->13937 13942 7ff7b85a6e8d 13937->13942 13938 7ff7b85ba968 std::_Facet_Register 3 API calls 13939 7ff7b85a6f36 memset 13938->13939 13939->13959 13941 7ff7b85aff10 3 API calls 13940->13941 13946 7ff7b85a921f 13941->13946 13942->13938 13943 7ff7b85b2ac0 memcpy 13943->13959 13944->13846 13944->13865 13944->13901 13944->13906 13944->13912 13944->13923 13950 7ff7b85a5c4b _invalid_parameter_noinfo_noreturn 13944->13950 13951 7ff7b85ba960 free _Receive_impl 13944->13951 13953 7ff7b85a5c52 _invalid_parameter_noinfo_noreturn 13944->13953 13945 7ff7b85a80ca pow 13945->13974 13947 7ff7b85aff40 3 API calls 13946->13947 13952 7ff7b85a926c 13947->13952 13948 7ff7b85a80f7 tan 13949 7ff7b85aea80 7 API calls 13948->13949 13949->13974 13950->13953 13951->13944 13954 7ff7b85aff70 3 API calls 13952->13954 13953->13865 13957 7ff7b85a92b9 13954->13957 13955 7ff7b85ae450 4 API calls 13955->13974 13956 7ff7b8592460 9 API calls 13956->13974 13958 7ff7b8591670 2 API calls 13957->13958 14000 7ff7b85a9306 13958->14000 13959->13896 13959->13908 13959->13927 13959->13929 13959->13936 13959->13943 13962 7ff7b85ba960 free _Receive_impl 13959->13962 13964 7ff7b85a7655 _invalid_parameter_noinfo_noreturn 13959->13964 13966 7ff7b85a765c _invalid_parameter_noinfo_noreturn 13959->13966 13960 7ff7b85a969b 13961 7ff7b85ae300 2 API calls 13960->13961 13965 7ff7b85a96b3 13961->13965 13962->13959 13963 7ff7b85a994c VirtualAlloc 13967 7ff7b85a996d 13963->13967 13964->13966 13965->13963 13965->13967 13966->13908 14476 7ff7b85afc80 13967->14476 13971 7ff7b85a941a pow 13971->14000 13972 7ff7b85ae3f0 2 API calls 13972->13974 13974->13930 13974->13945 13974->13948 13974->13955 13974->13956 13974->13972 13977 7ff7b85aea20 collate 2 API calls 13974->13977 13982 7ff7b8591670 2 API calls 13974->13982 13976 7ff7b85a9448 tan 13979 7ff7b85aea80 7 API calls 13976->13979 13977->13974 13979->14000 13980 7ff7b85afd60 11 API calls 13981 7ff7b85a9aea 13980->13981 13983 7ff7b85aea20 collate 2 API calls 13981->13983 13982->13974 13984 7ff7b85a9af8 13983->13984 13985 7ff7b85aea20 collate 2 API calls 13984->13985 13986 7ff7b85a9b06 13985->13986 13988 7ff7b85aea20 collate 2 API calls 13986->13988 13987 7ff7b85ae450 4 API calls 13987->14000 13989 7ff7b85a9b14 ?_Random_device@std@ 13988->13989 13990 7ff7b85a9b29 13989->13990 13992 7ff7b8591670 2 API calls 13990->13992 13991 7ff7b8592460 9 API calls 13991->14000 13993 7ff7b85a9b66 13992->13993 13994 7ff7b85afe80 3 API calls 13993->13994 13995 7ff7b85a9bbd 13994->13995 13996 7ff7b85afeb0 3 API calls 13995->13996 13997 7ff7b85a9c0a 13996->13997 13998 7ff7b85afee0 3 API calls 13997->13998 14002 7ff7b85a9c57 13998->14002 13999 7ff7b85ae3f0 2 API calls 13999->14000 14000->13960 14000->13971 14000->13976 14000->13987 14000->13991 14000->13999 14001 7ff7b85aea20 collate 2 API calls 14000->14001 14004 7ff7b8591670 2 API calls 14000->14004 14001->14000 14003 7ff7b85aff10 3 API calls 14002->14003 14005 7ff7b85a9ca4 14003->14005 14004->14000 14006 7ff7b85aff40 3 API calls 14005->14006 14007 7ff7b85a9cf1 14006->14007 14008 7ff7b85aff70 3 API calls 14007->14008 14045 7ff7b85a9d3e 14008->14045 14009 7ff7b8591670 2 API calls 14009->14045 14010 7ff7b85aa0fa 14011 7ff7b85ae300 2 API calls 14010->14011 14012 7ff7b85aa10b 14011->14012 14013 7ff7b85b0680 7 API calls 14012->14013 14014 7ff7b85aa3cf 14013->14014 14015 7ff7b85afd00 11 API calls 14014->14015 14016 7ff7b85aa3e8 14015->14016 14017 7ff7b8597ec0 49 API calls 14016->14017 14018 7ff7b85aa3f8 14017->14018 14490 7ff7b8599150 14018->14490 14020 7ff7b85aa409 14564 7ff7b85ae1f0 14020->14564 14025 7ff7b85aea20 collate 2 API calls 14027 7ff7b85aa42c 14025->14027 14026 7ff7b85a9e96 pow 14026->14045 14028 7ff7b85aea20 collate 2 API calls 14027->14028 14030 7ff7b85aa43a ?_Random_device@std@ 14028->14030 14029 7ff7b85a9ec4 tan 14031 7ff7b85aea80 7 API calls 14029->14031 14032 7ff7b85aa44f 14030->14032 14031->14045 14033 7ff7b8591670 2 API calls 14032->14033 14035 7ff7b85aa48c 14033->14035 14034 7ff7b85ae450 4 API calls 14034->14045 14036 7ff7b85afe80 3 API calls 14035->14036 14038 7ff7b85aa4e3 14036->14038 14037 7ff7b8592460 9 API calls 14037->14045 14039 7ff7b85afeb0 3 API calls 14038->14039 14040 7ff7b85aa530 14039->14040 14041 7ff7b85afee0 3 API calls 14040->14041 14042 7ff7b85aa57d 14041->14042 14043 7ff7b85aff10 3 API calls 14042->14043 14047 7ff7b85aa5ca 14043->14047 14044 7ff7b85ae3f0 2 API calls 14044->14045 14045->14009 14045->14010 14045->14026 14045->14029 14045->14034 14045->14037 14045->14044 14046 7ff7b85aea20 collate 2 API calls 14045->14046 14046->14045 14048 7ff7b85aff40 3 API calls 14047->14048 14049 7ff7b85aa617 14048->14049 14050 7ff7b85aff70 3 API calls 14049->14050 14072 7ff7b85aa664 14050->14072 14051 7ff7b8591670 2 API calls 14051->14072 14052 7ff7b85aaa2a 14053 7ff7b85ae300 2 API calls 14052->14053 14054 7ff7b85aaa3b 14053->14054 14576 7ff7b8594640 14054->14576 14057 7ff7b85afd00 11 API calls 14058 7ff7b85aaa9f 14057->14058 14059 7ff7b85afd60 11 API calls 14058->14059 14060 7ff7b85aaab7 14059->14060 14061 7ff7b85afd00 11 API calls 14060->14061 14062 7ff7b85aaacd 14061->14062 14063 7ff7b85aea20 collate 2 API calls 14062->14063 14070 7ff7b85aa7c6 pow 14070->14072 14072->14051 14072->14052 14072->14070 14074 7ff7b85aa7f4 tan 14072->14074 14081 7ff7b85ae450 4 API calls 14072->14081 14088 7ff7b8592460 9 API calls 14072->14088 14107 7ff7b85ae3f0 2 API calls 14072->14107 14109 7ff7b85aea20 collate 2 API calls 14072->14109 14076 7ff7b85aea80 7 API calls 14074->14076 14076->14072 14081->14072 14088->14072 14107->14072 14109->14072 14123 7ff7b85baee1 14122->14123 14123->13755 14123->13767 14125 7ff7b85bb4a6 14124->14125 14126 7ff7b85bb4b4 memset RtlCaptureContext RtlLookupFunctionEntry 14125->14126 14127 7ff7b85bb52a memset IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 14126->14127 14128 7ff7b85bb4ee RtlVirtualUnwind 14126->14128 14129 7ff7b85bb5aa 14127->14129 14128->14127 14129->13753 14713 7ff7b85bb9a0 14130->14713 14133 7ff7b85a37a0 14133->14133 14134 7ff7b8591670 2 API calls 14133->14134 14135 7ff7b85a37ee 14134->14135 14136 7ff7b85ba968 std::_Facet_Register 3 API calls 14135->14136 14137 7ff7b85a3816 14136->14137 14138 7ff7b85b2150 6 API calls 14137->14138 14140 7ff7b85a3836 14137->14140 14138->14140 14139 7ff7b85ba968 std::_Facet_Register 3 API calls 14141 7ff7b85a3875 14139->14141 14140->14139 14142 7ff7b85b2150 6 API calls 14141->14142 14144 7ff7b85a3895 14141->14144 14142->14144 14143 7ff7b85ba968 std::_Facet_Register 3 API calls 14145 7ff7b85a38d4 14143->14145 14144->14143 14146 7ff7b85b2150 6 API calls 14145->14146 14148 7ff7b85a38f4 14145->14148 14146->14148 14147 7ff7b85ba968 std::_Facet_Register 3 API calls 14149 7ff7b85a3933 14147->14149 14148->14147 14150 7ff7b85b2150 6 API calls 14149->14150 14152 7ff7b85a3953 14149->14152 14150->14152 14151 7ff7b85ba968 std::_Facet_Register 3 API calls 14153 7ff7b85a3992 14151->14153 14152->14151 14154 7ff7b85b2150 6 API calls 14153->14154 14156 7ff7b85a39b2 14153->14156 14154->14156 14155 7ff7b85ba968 std::_Facet_Register 3 API calls 14157 7ff7b85a39f1 14155->14157 14156->14155 14158 7ff7b85b2150 6 API calls 14157->14158 14169 7ff7b85a3a11 14157->14169 14158->14169 14159 7ff7b85a3a73 _Query_perf_frequency _Query_perf_counter 14159->14169 14160 7ff7b85a4502 SleepEx 14161 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14160->14161 14164 7ff7b85a451a 14161->14164 14162 7ff7b85a44fa 14166 7ff7b85ba960 _Receive_impl free 14162->14166 14163 7ff7b85a448a 14163->14160 14163->14162 14165 7ff7b85a44f3 _invalid_parameter_noinfo_noreturn 14163->14165 14164->13777 14164->13778 14165->14162 14166->14160 14167 7ff7b85a3d2c log cos sin exp 14167->14169 14168 7ff7b85a3dc1 pow 14168->14169 14169->14159 14169->14163 14169->14167 14169->14168 14170 7ff7b85a3e20 tan 14169->14170 14175 7ff7b85b2ac0 memcpy 14169->14175 14176 7ff7b85a447c _invalid_parameter_noinfo_noreturn 14169->14176 14177 7ff7b85a4483 _invalid_parameter_noinfo_noreturn 14169->14177 14178 7ff7b85ba960 free _Receive_impl 14169->14178 14171 7ff7b85b11f0 7 API calls 14170->14171 14174 7ff7b85a3e6b 14171->14174 14172 7ff7b85ba968 std::_Facet_Register 3 API calls 14173 7ff7b85a3edf memset 14172->14173 14173->14169 14174->14172 14175->14169 14176->14177 14177->14163 14178->14169 14180 7ff7b85b1be8 memcpy memcpy 14179->14180 14185 7ff7b85b1b67 14179->14185 14180->13790 14181 7ff7b85b1b7c 14183 7ff7b85ba968 std::_Facet_Register 3 API calls 14181->14183 14182 7ff7b85b1b97 14182->14180 14188 7ff7b85b1b92 14183->14188 14184 7ff7b85b1bdd 14187 7ff7b85ba968 std::_Facet_Register 3 API calls 14184->14187 14185->14181 14185->14182 14185->14184 14186 7ff7b85b1c29 14185->14186 14189 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 14186->14189 14187->14182 14188->14182 14190 7ff7b85b1bd6 _invalid_parameter_noinfo_noreturn 14188->14190 14191 7ff7b85b1c2e 14189->14191 14190->14184 14193 7ff7b85b0690 14192->14193 14193->14193 14194 7ff7b85b06dd 14193->14194 14195 7ff7b85b06b0 14193->14195 14715 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 14194->14715 14197 7ff7b85b1b10 6 API calls 14195->14197 14199 7ff7b85b06d4 14197->14199 14199->13805 14201 7ff7b85b0740 14200->14201 14201->14201 14716 7ff7b85ba3dc ___lc_codepage_func 14201->14716 14206 7ff7b85930c0 14207 7ff7b85930df 14206->14207 14775 7ff7b85ba518 14207->14775 14210 7ff7b8593191 14211 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14210->14211 14212 7ff7b85931a4 14211->14212 14212->13874 14213 7ff7b85931e2 14213->13874 14214 7ff7b85931b1 14214->14213 14215 7ff7b85ba960 _Receive_impl free 14214->14215 14215->14213 14217 7ff7b8592754 14216->14217 14218 7ff7b8592723 14216->14218 14217->13879 14219 7ff7b859276b _invalid_parameter_noinfo_noreturn 14218->14219 14220 7ff7b859274c 14218->14220 14221 7ff7b85ba960 _Receive_impl free 14220->14221 14221->14217 14223 7ff7b859d3ca 14222->14223 14224 7ff7b859d4a8 MultiByteToWideChar 14223->14224 14225 7ff7b859d4de 14224->14225 14226 7ff7b859d4eb MultiByteToWideChar 14225->14226 14227 7ff7b85ae780 7 API calls 14226->14227 14228 7ff7b859d515 14227->14228 14229 7ff7b85ba960 _Receive_impl free 14228->14229 14230 7ff7b859d51d 14229->14230 14814 7ff7b85934b0 14230->14814 14233 7ff7b8592710 2 API calls 14234 7ff7b859d552 14233->14234 14235 7ff7b8592710 2 API calls 14234->14235 14237 7ff7b859d55f 14235->14237 14236 7ff7b859d89a VirtualAlloc 14238 7ff7b859d8bb ?_Random_device@std@ 14236->14238 14237->14236 14237->14238 14240 7ff7b859d9c2 14238->14240 14241 7ff7b8591670 2 API calls 14240->14241 14242 7ff7b859d9ff 14241->14242 14243 7ff7b85afe80 3 API calls 14242->14243 14244 7ff7b859da44 14243->14244 14245 7ff7b85afeb0 3 API calls 14244->14245 14246 7ff7b859da81 14245->14246 14247 7ff7b85afee0 3 API calls 14246->14247 14248 7ff7b859dabe 14247->14248 14249 7ff7b85aff10 3 API calls 14248->14249 14250 7ff7b859dafb 14249->14250 14251 7ff7b85aff40 3 API calls 14250->14251 14252 7ff7b859db38 14251->14252 14253 7ff7b85aff70 3 API calls 14252->14253 14254 7ff7b859db75 14253->14254 14255 7ff7b8591670 2 API calls 14254->14255 14283 7ff7b859dbb2 14255->14283 14256 7ff7b859df0c 14257 7ff7b85ae300 2 API calls 14256->14257 14259 7ff7b859df23 14257->14259 14258 7ff7b859df8a VirtualAlloc 14260 7ff7b859dfab 14258->14260 14259->14258 14259->14260 14261 7ff7b85b0680 7 API calls 14260->14261 14263 7ff7b859e5b9 14261->14263 14262 7ff7b859dcbb pow 14262->14283 14264 7ff7b85afd00 11 API calls 14263->14264 14268 7ff7b859e5cd 14264->14268 14265 7ff7b859dce6 tan 14266 7ff7b85aea80 7 API calls 14265->14266 14266->14283 14267 7ff7b85ae450 4 API calls 14267->14283 14269 7ff7b859e63a VirtualAlloc 14268->14269 14270 7ff7b859e65b 14268->14270 14269->14270 14272 7ff7b85aea20 collate 2 API calls 14270->14272 14271 7ff7b8592460 9 API calls 14271->14283 14273 7ff7b859e75a 14272->14273 14274 7ff7b85aea20 collate 2 API calls 14273->14274 14275 7ff7b859e767 ?_Random_device@std@ 14274->14275 14276 7ff7b859e77b 14275->14276 14277 7ff7b8591670 2 API calls 14276->14277 14278 7ff7b859e7b4 14277->14278 14279 7ff7b85afe80 3 API calls 14278->14279 14280 7ff7b859e7f9 14279->14280 14281 7ff7b85afeb0 3 API calls 14280->14281 14285 7ff7b859e836 14281->14285 14282 7ff7b85ae3f0 2 API calls 14282->14283 14283->14256 14283->14262 14283->14265 14283->14267 14283->14271 14283->14282 14284 7ff7b85aea20 collate 2 API calls 14283->14284 14287 7ff7b8591670 2 API calls 14283->14287 14284->14283 14286 7ff7b85afee0 3 API calls 14285->14286 14288 7ff7b859e873 14286->14288 14287->14283 14289 7ff7b85aff10 3 API calls 14288->14289 14290 7ff7b859e8b0 14289->14290 14291 7ff7b85aff40 3 API calls 14290->14291 14292 7ff7b859e8ed 14291->14292 14293 7ff7b85aff70 3 API calls 14292->14293 14294 7ff7b859e92a 14293->14294 14295 7ff7b8591670 2 API calls 14294->14295 14320 7ff7b859e967 14295->14320 14296 7ff7b859ecac 14297 7ff7b85ae300 2 API calls 14296->14297 14299 7ff7b859ecc3 14297->14299 14298 7ff7b859ed29 VirtualAlloc 14301 7ff7b859ed4a 14298->14301 14299->14298 14299->14301 14300 7ff7b859ea5b pow 14300->14320 14302 7ff7b859f0fd VirtualAlloc 14301->14302 14305 7ff7b859f11e ?_Random_device@std@ 14301->14305 14302->14305 14303 7ff7b859ea86 tan 14304 7ff7b85aea80 7 API calls 14303->14304 14304->14320 14307 7ff7b859f222 14305->14307 14308 7ff7b8591670 2 API calls 14307->14308 14310 7ff7b859f25b 14308->14310 14309 7ff7b85ae450 4 API calls 14309->14320 14312 7ff7b85afe80 3 API calls 14310->14312 14311 7ff7b8592460 9 API calls 14311->14320 14313 7ff7b859f2a0 14312->14313 14314 7ff7b85afeb0 3 API calls 14313->14314 14315 7ff7b859f2dd 14314->14315 14316 7ff7b85afee0 3 API calls 14315->14316 14317 7ff7b859f31a 14316->14317 14318 7ff7b85aff10 3 API calls 14317->14318 14323 7ff7b859f357 14318->14323 14319 7ff7b85ae3f0 2 API calls 14319->14320 14320->14296 14320->14300 14320->14303 14320->14309 14320->14311 14320->14319 14321 7ff7b85aea20 collate 2 API calls 14320->14321 14322 7ff7b8591670 2 API calls 14320->14322 14321->14320 14322->14320 14324 7ff7b85aff40 3 API calls 14323->14324 14325 7ff7b859f394 14324->14325 14326 7ff7b85aff70 3 API calls 14325->14326 14327 7ff7b859f3d1 14326->14327 14328 7ff7b8591670 2 API calls 14327->14328 14354 7ff7b859f40e 14328->14354 14329 7ff7b859f74c 14330 7ff7b85ae300 2 API calls 14329->14330 14332 7ff7b859f763 14330->14332 14331 7ff7b859f7c9 VirtualAlloc 14333 7ff7b859f7ea 14331->14333 14332->14331 14332->14333 14334 7ff7b85b0680 7 API calls 14333->14334 14339 7ff7b859faea 14334->14339 14335 7ff7b859f4fb pow 14335->14354 14336 7ff7b859f526 tan 14337 7ff7b85aea80 7 API calls 14336->14337 14337->14354 14338 7ff7b859fb59 VirtualAlloc 14340 7ff7b859fb7a 14338->14340 14339->14338 14339->14340 14342 7ff7b85aea20 collate 2 API calls 14340->14342 14341 7ff7b85ae450 4 API calls 14341->14354 14343 7ff7b859fc7a ?_Random_device@std@ 14342->14343 14345 7ff7b859fc8e 14343->14345 14344 7ff7b8592460 9 API calls 14344->14354 14346 7ff7b8591670 2 API calls 14345->14346 14347 7ff7b859fcc7 14346->14347 14348 7ff7b85afe80 3 API calls 14347->14348 14349 7ff7b859fd0c 14348->14349 14350 7ff7b85afeb0 3 API calls 14349->14350 14351 7ff7b859fd49 14350->14351 14352 7ff7b85afee0 3 API calls 14351->14352 14357 7ff7b859fd86 14352->14357 14353 7ff7b85ae3f0 2 API calls 14353->14354 14354->14329 14354->14335 14354->14336 14354->14341 14354->14344 14354->14353 14355 7ff7b85aea20 collate 2 API calls 14354->14355 14356 7ff7b8591670 2 API calls 14354->14356 14355->14354 14356->14354 14358 7ff7b85aff10 3 API calls 14357->14358 14359 7ff7b859fdc3 14358->14359 14360 7ff7b85aff40 3 API calls 14359->14360 14361 7ff7b859fe00 14360->14361 14362 7ff7b85aff70 3 API calls 14361->14362 14363 7ff7b859fe3d 14362->14363 14364 7ff7b8591670 2 API calls 14363->14364 14380 7ff7b859fe7a 14364->14380 14365 7ff7b85a01bc 14366 7ff7b85ae300 2 API calls 14365->14366 14368 7ff7b85a01d3 14366->14368 14367 7ff7b85a049a VirtualAlloc 14369 7ff7b85a04bb 14367->14369 14368->14367 14368->14369 14370 7ff7b85aea20 collate 2 API calls 14369->14370 14371 7ff7b85a05b3 14370->14371 14372 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14371->14372 14374 7ff7b85a05e1 14372->14374 14373 7ff7b859ff6b pow 14373->14380 14374->13895 14375 7ff7b859ff96 tan 14376 7ff7b85aea80 7 API calls 14375->14376 14376->14380 14377 7ff7b85ae450 4 API calls 14377->14380 14378 7ff7b8592460 9 API calls 14378->14380 14379 7ff7b85ae3f0 2 API calls 14379->14380 14380->14365 14380->14373 14380->14375 14380->14377 14380->14378 14380->14379 14381 7ff7b85aea20 collate 2 API calls 14380->14381 14382 7ff7b8591670 2 API calls 14380->14382 14381->14380 14382->14380 15021 7ff7b85b1840 ??0_Lockit@std@@QEAA@H ??Bid@locale@std@ 14383->15021 14388 7ff7b85ba968 std::_Facet_Register 3 API calls 14389 7ff7b85ac721 14388->14389 15054 7ff7b85b2430 14389->15054 14393 7ff7b85ac79b 14394 7ff7b85ac7fb 14393->14394 14396 7ff7b85ac7f6 14393->14396 14399 7ff7b85ac7ef _invalid_parameter_noinfo_noreturn 14393->14399 14395 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14394->14395 14398 7ff7b85a8d97 14395->14398 14397 7ff7b85ba960 _Receive_impl free 14396->14397 14397->14394 14398->13894 14399->14396 14401 7ff7b8597ee2 14400->14401 14401->14401 14402 7ff7b85981b2 InternetOpenA ?_Random_device@std@ 14401->14402 14403 7ff7b85981f0 14402->14403 14403->14403 14404 7ff7b8591670 2 API calls 14403->14404 14405 7ff7b859823d 14404->14405 14406 7ff7b85ba968 std::_Facet_Register 3 API calls 14405->14406 14407 7ff7b8598263 14406->14407 14408 7ff7b85b2150 6 API calls 14407->14408 14410 7ff7b8598281 14407->14410 14408->14410 14409 7ff7b85ba968 std::_Facet_Register 3 API calls 14411 7ff7b85982bd 14409->14411 14410->14409 14412 7ff7b85b2150 6 API calls 14411->14412 14414 7ff7b85982db 14411->14414 14412->14414 14413 7ff7b85ba968 std::_Facet_Register 3 API calls 14415 7ff7b8598317 14413->14415 14414->14413 14416 7ff7b85b2150 6 API calls 14415->14416 14418 7ff7b8598335 14415->14418 14416->14418 14417 7ff7b85ba968 std::_Facet_Register 3 API calls 14419 7ff7b8598371 14417->14419 14418->14417 14420 7ff7b85b2150 6 API calls 14419->14420 14422 7ff7b859838f 14419->14422 14420->14422 14421 7ff7b85ba968 std::_Facet_Register 3 API calls 14423 7ff7b85983cb 14421->14423 14422->14421 14424 7ff7b85b2150 6 API calls 14423->14424 14426 7ff7b85983e9 14423->14426 14424->14426 14425 7ff7b85ba968 std::_Facet_Register 3 API calls 14427 7ff7b8598425 14425->14427 14426->14425 14428 7ff7b85b2150 6 API calls 14427->14428 14460 7ff7b859844b 14427->14460 14428->14460 14429 7ff7b85984aa _Query_perf_frequency _Query_perf_counter 14429->14460 14430 7ff7b8598f22 14431 7ff7b859907c InternetCloseHandle 14430->14431 14435 7ff7b8598f61 InternetOpenUrlA 14430->14435 14433 7ff7b859909f 14431->14433 14434 7ff7b85990cb 14431->14434 14432 7ff7b8598f1a 14437 7ff7b85ba960 _Receive_impl free 14432->14437 14438 7ff7b85990c3 14433->14438 14441 7ff7b8599140 _invalid_parameter_noinfo_noreturn 14433->14441 14439 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14434->14439 14435->14431 14447 7ff7b8598f86 14435->14447 14436 7ff7b8598f13 _invalid_parameter_noinfo_noreturn 14436->14432 14437->14430 14442 7ff7b85ba960 _Receive_impl free 14438->14442 14444 7ff7b85990ed 14439->14444 14440 7ff7b8598ea8 14440->14430 14440->14432 14440->14436 14442->14434 14443 7ff7b8598f90 InternetReadFile 14443->14447 14464 7ff7b85b0780 14444->14464 14445 7ff7b85b1060 10 API calls 14448 7ff7b8598ffe memset 14445->14448 14446 7ff7b8598fd1 memcpy 14446->14448 14447->14443 14447->14445 14447->14446 14448->14443 14449 7ff7b8599019 InternetCloseHandle InternetCloseHandle 14448->14449 14449->14434 14450 7ff7b8599051 14449->14450 14450->14438 14451 7ff7b8599075 _invalid_parameter_noinfo_noreturn 14450->14451 14451->14431 14452 7ff7b859874c log cos sin exp 14452->14460 14453 7ff7b85987e1 pow 14453->14460 14454 7ff7b8598840 tan 14455 7ff7b85b11f0 7 API calls 14454->14455 14458 7ff7b859888b 14455->14458 14456 7ff7b85ba968 std::_Facet_Register 3 API calls 14457 7ff7b85988fe memset 14456->14457 14457->14460 14458->14456 14459 7ff7b85b2ac0 memcpy 14459->14460 14460->14429 14460->14440 14460->14452 14460->14453 14460->14454 14460->14459 14461 7ff7b8598e9a _invalid_parameter_noinfo_noreturn 14460->14461 14462 7ff7b85ba960 free _Receive_impl 14460->14462 14463 7ff7b8598ea1 _invalid_parameter_noinfo_noreturn 14460->14463 14461->14463 14462->14460 14463->14440 14465 7ff7b85b07e0 14464->14465 14465->14465 14466 7ff7b85b11f0 7 API calls 14465->14466 14467 7ff7b85b07f7 14466->14467 15637 7ff7b85b2d90 14467->15637 14470 7ff7b85b0872 14472 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14470->14472 14471 7ff7b85b086d 14474 7ff7b85ba960 _Receive_impl free 14471->14474 14475 7ff7b85a9070 14472->14475 14473 7ff7b85b0866 _invalid_parameter_noinfo_noreturn 14473->14471 14474->14470 14475->13905 14477 7ff7b85afca0 14476->14477 14477->14477 14478 7ff7b85afcf3 14477->14478 14479 7ff7b85afcbc 14477->14479 15780 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 14478->15780 14480 7ff7b85b1b10 6 API calls 14479->14480 14482 7ff7b85a9aa3 14480->14482 14484 7ff7b85afd60 14482->14484 15781 7ff7b85ae980 14484->15781 14486 7ff7b85a9abb 14487 7ff7b85afd00 14486->14487 15788 7ff7b85ae8f0 14487->15788 14489 7ff7b85a9ad1 14489->13980 14491 7ff7b8599172 14490->14491 14492 7ff7b859922c CryptStringToBinaryA 14491->14492 14493 7ff7b8599271 ?_Random_device@std@ 14492->14493 14544 7ff7b8599258 14492->14544 14494 7ff7b8599290 14493->14494 14494->14494 14496 7ff7b8591670 2 API calls 14494->14496 14495 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14497 7ff7b859a11c 14495->14497 14498 7ff7b85992dd 14496->14498 14497->14020 14499 7ff7b85ba968 std::_Facet_Register 3 API calls 14498->14499 14500 7ff7b8599303 14499->14500 14501 7ff7b85b2150 6 API calls 14500->14501 14503 7ff7b8599321 14500->14503 14501->14503 14502 7ff7b85ba968 std::_Facet_Register 3 API calls 14504 7ff7b859935e 14502->14504 14503->14502 14505 7ff7b85b2150 6 API calls 14504->14505 14507 7ff7b859937c 14504->14507 14505->14507 14506 7ff7b85ba968 std::_Facet_Register 3 API calls 14508 7ff7b85993b9 14506->14508 14507->14506 14509 7ff7b85b2150 6 API calls 14508->14509 14511 7ff7b85993d7 14508->14511 14509->14511 14510 7ff7b85ba968 std::_Facet_Register 3 API calls 14512 7ff7b8599414 14510->14512 14511->14510 14513 7ff7b85b2150 6 API calls 14512->14513 14515 7ff7b8599432 14512->14515 14513->14515 14514 7ff7b85ba968 std::_Facet_Register 3 API calls 14516 7ff7b859946f 14514->14516 14515->14514 14517 7ff7b85b2150 6 API calls 14516->14517 14520 7ff7b859948d 14516->14520 14517->14520 14518 7ff7b85ba968 std::_Facet_Register 3 API calls 14519 7ff7b85994ca 14518->14519 14521 7ff7b85b2150 6 API calls 14519->14521 14560 7ff7b85994e8 14519->14560 14520->14518 14521->14560 14522 7ff7b8599548 _Query_perf_frequency _Query_perf_counter 14522->14560 14523 7ff7b8599fd6 14524 7ff7b859a044 CryptStringToBinaryA 14523->14524 14525 7ff7b859a01f 14523->14525 14526 7ff7b8599ff3 14523->14526 14534 7ff7b859a07d 14524->14534 14524->14544 14533 7ff7b85ba968 std::_Facet_Register 3 API calls 14525->14533 14531 7ff7b859a000 14526->14531 14532 7ff7b859a16f 14526->14532 14527 7ff7b8599f5a 14527->14523 14529 7ff7b8599fce 14527->14529 14535 7ff7b8599fc7 _invalid_parameter_noinfo_noreturn 14527->14535 14530 7ff7b85ba960 _Receive_impl free 14529->14530 14530->14523 14536 7ff7b85ba968 std::_Facet_Register 3 API calls 14531->14536 14538 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 14532->14538 14537 7ff7b859a027 memset 14533->14537 14539 7ff7b859a0c5 14534->14539 14542 7ff7b859a0be _invalid_parameter_noinfo_noreturn 14534->14542 14534->14544 14535->14529 14540 7ff7b859a005 14536->14540 14537->14524 14541 7ff7b859a174 malloc memcpy 14538->14541 14543 7ff7b85ba960 _Receive_impl free 14539->14543 14540->14537 14540->14542 14546 7ff7b859a255 14541->14546 14547 7ff7b859a46c getenv _flushall CreateProcessA 14541->14547 14542->14539 14543->14544 14544->14495 14546->14547 14548 7ff7b859a4d0 WaitForSingleObject GetExitCodeProcess CloseHandle CloseHandle 14547->14548 14549 7ff7b859a506 free 14547->14549 14548->14549 14550 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14549->14550 14551 7ff7b859a523 14550->14551 14551->14020 14552 7ff7b85997fc log cos sin exp 14552->14560 14553 7ff7b8599891 pow 14553->14560 14554 7ff7b85998f0 tan 14555 7ff7b85b11f0 7 API calls 14554->14555 14558 7ff7b859993b 14555->14558 14556 7ff7b85ba968 std::_Facet_Register 3 API calls 14557 7ff7b85999ae memset 14556->14557 14557->14560 14558->14556 14559 7ff7b85b2ac0 memcpy 14559->14560 14560->14522 14560->14527 14560->14552 14560->14553 14560->14554 14560->14559 14561 7ff7b8599f4c _invalid_parameter_noinfo_noreturn 14560->14561 14562 7ff7b8599f53 _invalid_parameter_noinfo_noreturn 14560->14562 14563 7ff7b85ba960 free _Receive_impl 14560->14563 14561->14562 14562->14527 14563->14560 14565 7ff7b85ae20d 14564->14565 14569 7ff7b85aa411 14564->14569 14566 7ff7b85ae2a0 _invalid_parameter_noinfo_noreturn 14565->14566 14567 7ff7b85ae248 14565->14567 14565->14569 14568 7ff7b85ba960 _Receive_impl free 14567->14568 14568->14569 14570 7ff7b85ae190 14569->14570 14571 7ff7b85aa41e 14570->14571 14572 7ff7b85ae1a1 14570->14572 14571->14025 14573 7ff7b85ae1c6 14572->14573 14574 7ff7b85ae1e1 _invalid_parameter_noinfo_noreturn 14572->14574 14575 7ff7b85ba960 _Receive_impl free 14573->14575 14575->14571 14577 7ff7b859466a 14576->14577 14577->14577 14578 7ff7b85b11f0 7 API calls 14577->14578 14579 7ff7b85949ee 14578->14579 14580 7ff7b85b11f0 7 API calls 14579->14580 14581 7ff7b8594c7a 14580->14581 14582 7ff7b85b11f0 7 API calls 14581->14582 14583 7ff7b8594efa 14582->14583 14584 7ff7b85b11f0 7 API calls 14583->14584 14585 7ff7b859516a 14584->14585 14586 7ff7b85b11f0 7 API calls 14585->14586 14587 7ff7b85953da 14586->14587 14588 7ff7b85b11f0 7 API calls 14587->14588 14589 7ff7b859565a 14588->14589 14590 7ff7b85b11f0 7 API calls 14589->14590 14591 7ff7b85958da 14590->14591 14592 7ff7b85b11f0 7 API calls 14591->14592 14593 7ff7b8595b5a 14592->14593 14594 7ff7b85b11f0 7 API calls 14593->14594 14595 7ff7b8595ddb 14594->14595 14596 7ff7b85b11f0 7 API calls 14595->14596 14597 7ff7b8596071 14596->14597 14598 7ff7b85b11f0 7 API calls 14597->14598 14599 7ff7b85962f1 14598->14599 14600 7ff7b85b11f0 7 API calls 14599->14600 14601 7ff7b8596571 14600->14601 14602 7ff7b85b11f0 7 API calls 14601->14602 14603 7ff7b8596811 14602->14603 14604 7ff7b85b11f0 7 API calls 14603->14604 14605 7ff7b8596aa1 14604->14605 14606 7ff7b85b11f0 7 API calls 14605->14606 14607 7ff7b8596d20 14606->14607 14608 7ff7b85ba968 std::_Facet_Register 3 API calls 14607->14608 14609 7ff7b8596d3d 14608->14609 14610 7ff7b85aeac0 20 API calls 14609->14610 14611 7ff7b8596dba 14609->14611 14610->14609 15795 7ff7b85b12f0 14611->15795 14613 7ff7b8596dcc 14614 7ff7b8596df6 ?_Random_device@std@ 14613->14614 14615 7ff7b8596e20 14614->14615 14615->14615 14616 7ff7b8591670 2 API calls 14615->14616 14617 7ff7b8596e7c 14616->14617 14618 7ff7b85ba968 std::_Facet_Register 3 API calls 14617->14618 14619 7ff7b8596eab 14618->14619 14620 7ff7b85b2150 6 API calls 14619->14620 14623 7ff7b8596ecf 14619->14623 14620->14623 14621 7ff7b85ba968 std::_Facet_Register 3 API calls 14622 7ff7b8596f11 14621->14622 14624 7ff7b85b2150 6 API calls 14622->14624 14626 7ff7b8596f35 14622->14626 14623->14621 14624->14626 14625 7ff7b85ba968 std::_Facet_Register 3 API calls 14627 7ff7b8596f77 14625->14627 14626->14625 14628 7ff7b85b2150 6 API calls 14627->14628 14630 7ff7b8596f9b 14627->14630 14628->14630 14629 7ff7b85ba968 std::_Facet_Register 3 API calls 14631 7ff7b8596fdd 14629->14631 14630->14629 14632 7ff7b85b2150 6 API calls 14631->14632 14635 7ff7b8597001 14631->14635 14632->14635 14633 7ff7b85ba968 std::_Facet_Register 3 API calls 14634 7ff7b8597043 14633->14634 14636 7ff7b85b2150 6 API calls 14634->14636 14638 7ff7b8597067 14634->14638 14635->14633 14636->14638 14637 7ff7b85ba968 std::_Facet_Register 3 API calls 14639 7ff7b85970a9 14637->14639 14638->14637 14640 7ff7b85b2150 6 API calls 14639->14640 14675 7ff7b85970cd 14639->14675 14640->14675 14641 7ff7b8597132 _Query_perf_frequency _Query_perf_counter 14641->14675 14642 7ff7b8597cb5 _time64 srand rand 15800 7ff7b85943e0 SHGetFolderPathA 14642->15800 14645 7ff7b8597c29 14645->14642 14646 7ff7b8597cad 14645->14646 14648 7ff7b8597ca6 _invalid_parameter_noinfo_noreturn 14645->14648 14649 7ff7b85ba960 _Receive_impl free 14646->14649 14647 7ff7b85ae980 11 API calls 14650 7ff7b8597d0a 14647->14650 14648->14646 14649->14642 14651 7ff7b8597d7e _stat64i32 14650->14651 14652 7ff7b8597d79 14650->14652 14654 7ff7b8597d72 _invalid_parameter_noinfo_noreturn 14650->14654 14656 7ff7b8597db0 14651->14656 14655 7ff7b85ba960 _Receive_impl free 14652->14655 14654->14652 14655->14651 14657 7ff7b8597dd4 14656->14657 14658 7ff7b8597dce _mkdir 14656->14658 14659 7ff7b8597e31 14657->14659 14660 7ff7b85b12f0 2 API calls 14657->14660 14658->14657 14661 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14659->14661 14662 7ff7b8597def 14660->14662 14663 7ff7b8597e5c 14661->14663 14664 7ff7b8597e2c 14662->14664 14665 7ff7b8597e25 _invalid_parameter_noinfo_noreturn 14662->14665 14663->14057 14666 7ff7b85ba960 _Receive_impl free 14664->14666 14665->14664 14666->14659 14667 7ff7b85973ff log cos sin exp 14667->14675 14668 7ff7b859749e pow 14668->14675 14669 7ff7b8597500 tan 14670 7ff7b85b11f0 7 API calls 14669->14670 14674 7ff7b8597557 14670->14674 14671 7ff7b85ba968 std::_Facet_Register 3 API calls 14672 7ff7b85975f3 memset 14671->14672 14672->14675 14673 7ff7b85b2ac0 memcpy 14673->14675 14674->14671 14675->14641 14675->14645 14675->14667 14675->14668 14675->14669 14675->14673 14676 7ff7b8597c1b _invalid_parameter_noinfo_noreturn 14675->14676 14677 7ff7b8597c22 _invalid_parameter_noinfo_noreturn 14675->14677 14678 7ff7b85ba960 free _Receive_impl 14675->14678 14676->14677 14677->14645 14678->14675 14714 7ff7b85a370a ?_Random_device@std@ 14713->14714 14714->14133 14717 7ff7b85ba3ef AreFileApisANSI 14716->14717 14718 7ff7b85b0754 14716->14718 14717->14718 14719 7ff7b85925c0 14718->14719 14720 7ff7b8592612 14719->14720 14721 7ff7b85926da 14719->14721 14722 7ff7b85926fb 14720->14722 14734 7ff7b85ba404 MultiByteToWideChar 14720->14734 14721->14206 14761 7ff7b8591d70 14722->14761 14725 7ff7b8592701 14726 7ff7b8592050 12 API calls 14725->14726 14728 7ff7b859270d 14726->14728 14729 7ff7b859264d 14731 7ff7b85ba404 __std_fs_convert_narrow_to_wide 2 API calls 14729->14731 14732 7ff7b85926cf 14731->14732 14732->14721 14757 7ff7b8592050 14732->14757 14735 7ff7b8592632 14734->14735 14736 7ff7b85ba42e GetLastError 14734->14736 14735->14725 14735->14729 14737 7ff7b85b1380 14735->14737 14736->14735 14738 7ff7b85b1526 14737->14738 14740 7ff7b85b13af 14737->14740 14765 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 14738->14765 14741 7ff7b85b152b 14740->14741 14742 7ff7b85b1431 14740->14742 14743 7ff7b85b145d 14740->14743 14751 7ff7b85b1415 14740->14751 14745 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 14741->14745 14742->14741 14746 7ff7b85b143e 14742->14746 14744 7ff7b85ba968 std::_Facet_Register 3 API calls 14743->14744 14744->14751 14747 7ff7b85b1531 14745->14747 14748 7ff7b85ba968 std::_Facet_Register 3 API calls 14746->14748 14748->14751 14749 7ff7b85b14dd memcpy 14753 7ff7b85b14d4 14749->14753 14750 7ff7b85b147d memcpy 14752 7ff7b85b1490 14750->14752 14751->14749 14751->14750 14754 7ff7b85b14d6 _invalid_parameter_noinfo_noreturn 14751->14754 14752->14754 14755 7ff7b85b14c9 14752->14755 14753->14729 14754->14749 14756 7ff7b85ba960 _Receive_impl free 14755->14756 14756->14753 14758 7ff7b8592060 14757->14758 14766 7ff7b8591c80 14758->14766 14762 7ff7b8591d7e 14761->14762 14763 7ff7b8591c80 11 API calls 14762->14763 14764 7ff7b8591d95 _CxxThrowException __std_exception_copy 14763->14764 14764->14725 14767 7ff7b8591cb6 __std_exception_copy 14766->14767 14768 7ff7b8591d05 14767->14768 14769 7ff7b8591d3a 14767->14769 14770 7ff7b8591d35 14768->14770 14772 7ff7b8591d2e _invalid_parameter_noinfo_noreturn 14768->14772 14771 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14769->14771 14773 7ff7b85ba960 _Receive_impl free 14770->14773 14774 7ff7b8591d5b _CxxThrowException 14771->14774 14772->14770 14773->14769 14776 7ff7b85ba55a 14775->14776 14777 7ff7b85ba620 14776->14777 14779 7ff7b85ba5bb GetFileAttributesExW 14776->14779 14788 7ff7b85ba563 14776->14788 14777->14788 14811 7ff7b85ba840 CreateFileW 14777->14811 14778 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14781 7ff7b85930f8 14778->14781 14779->14777 14783 7ff7b85ba5cf GetLastError 14779->14783 14781->14210 14781->14214 14786 7ff7b85ba5de FindFirstFileW 14783->14786 14783->14788 14784 7ff7b85ba6be 14789 7ff7b85ba76f 14784->14789 14790 7ff7b85ba6cd GetFileInformationByHandleEx 14784->14790 14785 7ff7b85ba69e 14787 7ff7b85ba6a9 CloseHandle 14785->14787 14785->14788 14791 7ff7b85ba5f2 GetLastError 14786->14791 14792 7ff7b85ba5fd FindClose 14786->14792 14787->14788 14793 7ff7b85ba830 abort 14787->14793 14788->14778 14794 7ff7b85ba78a GetFileInformationByHandleEx 14789->14794 14795 7ff7b85ba7ca 14789->14795 14796 7ff7b85ba710 14790->14796 14797 7ff7b85ba6e7 GetLastError 14790->14797 14791->14788 14792->14777 14793->14788 14794->14795 14798 7ff7b85ba7a0 GetLastError 14794->14798 14800 7ff7b85ba7e1 14795->14800 14801 7ff7b85ba81d 14795->14801 14796->14789 14806 7ff7b85ba731 GetFileInformationByHandleEx 14796->14806 14797->14788 14799 7ff7b85ba6f5 CloseHandle 14797->14799 14798->14788 14803 7ff7b85ba7b2 CloseHandle 14798->14803 14799->14788 14804 7ff7b85ba702 abort 14799->14804 14800->14788 14805 7ff7b85ba7e7 CloseHandle 14800->14805 14801->14788 14802 7ff7b85ba823 CloseHandle 14801->14802 14802->14788 14802->14793 14803->14788 14807 7ff7b85ba7c3 abort 14803->14807 14804->14788 14805->14788 14805->14793 14806->14789 14808 7ff7b85ba74d GetLastError 14806->14808 14807->14795 14808->14788 14809 7ff7b85ba75b CloseHandle 14808->14809 14809->14788 14810 7ff7b85ba768 abort 14809->14810 14810->14789 14812 7ff7b85ba882 GetLastError 14811->14812 14813 7ff7b85ba698 14811->14813 14812->14813 14813->14784 14813->14785 14815 7ff7b85934d2 14814->14815 14868 7ff7b85ae060 ?_Init@locale@std@@CAPEAV_Locimp@12@_N 14815->14868 14818 7ff7b85935d0 14818->14818 14819 7ff7b8591670 2 API calls 14818->14819 14820 7ff7b859361c 14819->14820 14821 7ff7b85ba968 std::_Facet_Register 3 API calls 14820->14821 14822 7ff7b8593644 14821->14822 14823 7ff7b85b2150 6 API calls 14822->14823 14825 7ff7b8593664 14822->14825 14823->14825 14824 7ff7b85ba968 std::_Facet_Register 3 API calls 14826 7ff7b85936a3 14824->14826 14825->14824 14827 7ff7b85b2150 6 API calls 14826->14827 14829 7ff7b85936c3 14826->14829 14827->14829 14828 7ff7b85ba968 std::_Facet_Register 3 API calls 14830 7ff7b8593702 14828->14830 14829->14828 14831 7ff7b85b2150 6 API calls 14830->14831 14833 7ff7b8593722 14830->14833 14831->14833 14832 7ff7b85ba968 std::_Facet_Register 3 API calls 14834 7ff7b8593761 14832->14834 14833->14832 14835 7ff7b85b2150 6 API calls 14834->14835 14837 7ff7b8593781 14834->14837 14835->14837 14836 7ff7b85ba968 std::_Facet_Register 3 API calls 14838 7ff7b85937c0 14836->14838 14837->14836 14839 7ff7b85b2150 6 API calls 14838->14839 14841 7ff7b85937e0 14838->14841 14839->14841 14840 7ff7b85ba968 std::_Facet_Register 3 API calls 14842 7ff7b859381f 14840->14842 14841->14840 14843 7ff7b85b2150 6 API calls 14842->14843 14856 7ff7b859383f 14842->14856 14843->14856 14844 7ff7b85938a1 _Query_perf_frequency _Query_perf_counter 14844->14856 14845 7ff7b8594328 14872 7ff7b85af760 14845->14872 14846 7ff7b85942a8 14846->14845 14847 7ff7b8594320 14846->14847 14850 7ff7b8594319 _invalid_parameter_noinfo_noreturn 14846->14850 14851 7ff7b85ba960 _Receive_impl free 14847->14851 14849 7ff7b8594350 14904 7ff7b85adf70 14849->14904 14850->14847 14851->14845 14854 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14855 7ff7b859437e 14854->14855 14855->14233 14856->14844 14856->14846 14857 7ff7b8593b5c log cos sin exp 14856->14857 14858 7ff7b8593bf1 pow 14856->14858 14859 7ff7b8593c50 tan 14856->14859 14864 7ff7b85b2ac0 memcpy 14856->14864 14865 7ff7b859429a _invalid_parameter_noinfo_noreturn 14856->14865 14866 7ff7b85942a1 _invalid_parameter_noinfo_noreturn 14856->14866 14867 7ff7b85ba960 free _Receive_impl 14856->14867 14857->14856 14858->14856 14860 7ff7b85b11f0 7 API calls 14859->14860 14863 7ff7b8593c9b 14860->14863 14861 7ff7b85ba968 std::_Facet_Register 3 API calls 14862 7ff7b8593d0e memset 14861->14862 14862->14856 14863->14861 14864->14856 14865->14866 14866->14846 14867->14856 14869 7ff7b85ba968 std::_Facet_Register 3 API calls 14868->14869 14870 7ff7b85ae0c9 ??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@ ??Bid@locale@std@ ?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD 14869->14870 14871 7ff7b85935a7 ?_Random_device@std@ 14870->14871 14871->14818 14891 7ff7b85af7ce 14872->14891 14873 7ff7b85afadb 14874 7ff7b85afa1f 14873->14874 14877 7ff7b85afa1a 14873->14877 14879 7ff7b85afb24 _invalid_parameter_noinfo_noreturn 14873->14879 14876 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 14874->14876 14875 7ff7b85af800 ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD 14875->14891 14878 7ff7b85afa2e 14876->14878 14880 7ff7b85ba960 _Receive_impl free 14877->14880 14878->14849 14881 7ff7b85afb2b 14879->14881 14880->14874 14993 7ff7b8591980 14881->14993 14882 7ff7b85af8cc memcpy 14882->14891 14883 7ff7b85afa42 14883->14881 14889 7ff7b85aeac0 20 API calls 14883->14889 14884 7ff7b85af993 14885 7ff7b85afb30 14884->14885 14971 7ff7b85aeac0 14884->14971 14890 7ff7b8591980 Concurrency::cancel_current_task 11 API calls 14885->14890 14895 7ff7b85afa59 14889->14895 14896 7ff7b85afb36 14890->14896 14891->14873 14891->14875 14891->14882 14891->14883 14891->14884 14912 7ff7b85b1540 14891->14912 14932 7ff7b85b1060 14891->14932 14952 7ff7b85b16b0 14891->14952 14894 7ff7b85af9aa 14897 7ff7b85af9de 14894->14897 14899 7ff7b85af9e3 14894->14899 14900 7ff7b85afa89 _invalid_parameter_noinfo_noreturn 14894->14900 14898 7ff7b85afa90 14895->14898 14895->14899 14895->14900 14896->14849 14901 7ff7b85ba960 _Receive_impl free 14897->14901 14902 7ff7b85ba960 _Receive_impl free 14898->14902 14899->14874 14899->14877 14903 7ff7b85afad4 _invalid_parameter_noinfo_noreturn 14899->14903 14900->14898 14901->14899 14902->14899 14903->14873 14905 7ff7b85adf91 14904->14905 14906 7ff7b85adfc7 14904->14906 14908 7ff7b85ba960 _Receive_impl free 14905->14908 14910 7ff7b85ae04d _invalid_parameter_noinfo_noreturn 14905->14910 14907 7ff7b859435a 14906->14907 14909 7ff7b85ae008 14906->14909 14906->14910 14907->14854 14908->14906 14911 7ff7b85ba960 _Receive_impl free 14909->14911 14911->14907 14913 7ff7b85b1699 14912->14913 14918 7ff7b85b1570 14912->14918 14996 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 14913->14996 14915 7ff7b85b15d5 14917 7ff7b85ba968 std::_Facet_Register 3 API calls 14915->14917 14916 7ff7b85b169e 14922 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 14916->14922 14921 7ff7b85b15bb 14917->14921 14918->14915 14919 7ff7b85b1600 14918->14919 14920 7ff7b85b15c8 14918->14920 14918->14921 14924 7ff7b85ba968 std::_Facet_Register 3 API calls 14919->14924 14920->14915 14920->14916 14923 7ff7b85b1660 _invalid_parameter_noinfo_noreturn 14921->14923 14926 7ff7b85b1667 memcpy 14921->14926 14927 7ff7b85b161c memcpy 14921->14927 14925 7ff7b85b16a4 14922->14925 14923->14926 14924->14921 14928 7ff7b85b165e 14926->14928 14929 7ff7b85b1653 14927->14929 14930 7ff7b85b163e 14927->14930 14928->14891 14931 7ff7b85ba960 _Receive_impl free 14929->14931 14930->14923 14930->14929 14931->14928 14933 7ff7b85b11d9 14932->14933 14936 7ff7b85b1098 14932->14936 14997 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 14933->14997 14935 7ff7b85b10fd 14938 7ff7b85ba968 std::_Facet_Register 3 API calls 14935->14938 14936->14935 14939 7ff7b85b10f0 14936->14939 14940 7ff7b85b1128 14936->14940 14941 7ff7b85b10e3 14936->14941 14937 7ff7b85b11de 14942 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 14937->14942 14938->14941 14939->14935 14939->14937 14944 7ff7b85ba968 std::_Facet_Register 3 API calls 14940->14944 14943 7ff7b85b1195 _invalid_parameter_noinfo_noreturn 14941->14943 14946 7ff7b85b1148 memcpy memcpy 14941->14946 14947 7ff7b85b119c memcpy memcpy 14941->14947 14945 7ff7b85b11e4 14942->14945 14943->14947 14944->14941 14949 7ff7b85b1173 14946->14949 14950 7ff7b85b1188 14946->14950 14948 7ff7b85b1193 14947->14948 14948->14891 14949->14943 14949->14950 14951 7ff7b85ba960 _Receive_impl free 14950->14951 14951->14948 14953 7ff7b85b1827 14952->14953 14958 7ff7b85b16dd 14952->14958 14998 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 14953->14998 14955 7ff7b85b1747 14957 7ff7b85ba968 std::_Facet_Register 3 API calls 14955->14957 14956 7ff7b85b182c 14960 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 14956->14960 14959 7ff7b85b172d 14957->14959 14958->14955 14958->14959 14961 7ff7b85b1772 14958->14961 14962 7ff7b85b173a 14958->14962 14963 7ff7b85b17e2 _invalid_parameter_noinfo_noreturn 14959->14963 14965 7ff7b85b1796 memcpy memset 14959->14965 14970 7ff7b85b17e0 14959->14970 14966 7ff7b85b1832 14960->14966 14964 7ff7b85ba968 std::_Facet_Register 3 API calls 14961->14964 14962->14955 14962->14956 14963->14970 14964->14959 14967 7ff7b85b17c0 14965->14967 14968 7ff7b85b17d5 14965->14968 14967->14963 14967->14968 14969 7ff7b85ba960 _Receive_impl free 14968->14969 14969->14970 14970->14891 14972 7ff7b85aeaee 14971->14972 14973 7ff7b85aeb04 14972->14973 14974 7ff7b85aebc9 14972->14974 14975 7ff7b85aeb0a 14973->14975 14977 7ff7b85aebce 14973->14977 14978 7ff7b85aeb3a 14973->14978 14979 7ff7b85aeb9e memcpy 14973->14979 14980 7ff7b85aeb99 14973->14980 14999 7ff7b85918f0 ?_Xlength_error@std@@YAXPEBD 14974->14999 14975->14894 14981 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 14977->14981 14982 7ff7b85ba968 std::_Facet_Register 3 API calls 14978->14982 14979->14894 14983 7ff7b85ba968 std::_Facet_Register 3 API calls 14980->14983 14984 7ff7b85aebd4 14981->14984 14985 7ff7b85aeb50 14982->14985 14983->14979 14988 7ff7b85aec3e ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA 14984->14988 15000 7ff7b85af0e0 14984->15000 14986 7ff7b85aeb92 _invalid_parameter_noinfo_noreturn 14985->14986 14987 7ff7b85aeb58 14985->14987 14986->14980 14987->14979 14990 7ff7b85aec4e 14988->14990 14991 7ff7b85aec5b 14988->14991 14992 7ff7b85ba960 _Receive_impl free 14990->14992 14991->14894 14992->14991 15018 7ff7b8591910 __std_exception_copy 14993->15018 15001 7ff7b85af155 15000->15001 15002 7ff7b85af0f7 15000->15002 15003 7ff7b85af157 ?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@ 15001->15003 15006 7ff7b85aeff0 15002->15006 15003->14988 15005 7ff7b85af131 fclose 15005->15003 15007 7ff7b85af0c3 15006->15007 15008 7ff7b85af013 15006->15008 15009 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15007->15009 15008->15007 15010 7ff7b85af01d 15008->15010 15011 7ff7b85af0d2 15009->15011 15012 7ff7b85af061 15010->15012 15013 7ff7b85af036 ?unshift@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD 15010->15013 15011->15005 15015 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15012->15015 15014 7ff7b85af05c 15013->15014 15014->15012 15017 7ff7b85af097 fwrite 15014->15017 15016 7ff7b85af07e 15015->15016 15016->15005 15017->15012 15019 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15018->15019 15020 7ff7b8591972 _CxxThrowException __std_exception_copy 15019->15020 15020->14885 15022 7ff7b85b18aa 15021->15022 15023 7ff7b85b18c1 ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12 15022->15023 15024 7ff7b85b18cd 15022->15024 15025 7ff7b85b19d0 ??1_Lockit@std@@QEAA 15022->15025 15023->15024 15024->15025 15027 7ff7b85b18e3 15024->15027 15029 7ff7b85ba968 std::_Facet_Register 3 API calls 15024->15029 15026 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15025->15026 15028 7ff7b85ac6ab 15026->15028 15027->15025 15040 7ff7b85afb70 ??0_Lockit@std@@QEAA@H ??Bid@locale@std@ 15028->15040 15030 7ff7b85b18f5 15029->15030 15070 7ff7b8592150 15030->15070 15034 7ff7b85b19b0 15080 7ff7b85ba8a0 15034->15080 15035 7ff7b85b197b 15037 7ff7b85b19ab 15035->15037 15039 7ff7b85b19a4 _invalid_parameter_noinfo_noreturn 15035->15039 15038 7ff7b85ba960 _Receive_impl free 15037->15038 15038->15034 15039->15037 15041 7ff7b85afbd2 15040->15041 15042 7ff7b85afc47 ??1_Lockit@std@@QEAA 15041->15042 15043 7ff7b85afbe9 ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12 15041->15043 15044 7ff7b85afbf5 15041->15044 15045 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15042->15045 15043->15044 15044->15042 15047 7ff7b85afc0c ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@ 15044->15047 15046 7ff7b85ac6b7 15045->15046 15046->14388 15048 7ff7b85afc20 15047->15048 15049 7ff7b85afc77 15047->15049 15051 7ff7b85ba8a0 std::_Facet_Register 3 API calls 15048->15051 15083 7ff7b85920c0 15049->15083 15053 7ff7b85afc32 15051->15053 15052 7ff7b85afc7c 15053->15042 15055 7ff7b85b245b strchr 15054->15055 15056 7ff7b85ac791 15054->15056 15055->15056 15057 7ff7b85b1fc0 15056->15057 15087 7ff7b85b2a30 15057->15087 15062 7ff7b85b2139 15111 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15062->15111 15063 7ff7b85b1ffd 15107 7ff7b85b2970 15063->15107 15068 7ff7b85ba968 std::_Facet_Register 3 API calls 15069 7ff7b85b2012 15068->15069 15069->14393 15071 7ff7b85921b3 15070->15071 15073 7ff7b8592175 15070->15073 15074 7ff7b859224a 15071->15074 15076 7ff7b8592282 _invalid_parameter_noinfo_noreturn 15071->15076 15077 7ff7b85ba960 _Receive_impl free 15071->15077 15072 7ff7b859228e ??0_Locinfo@std@@QEAA@PEBD ??0facet@locale@std@@IEAA@_K ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@ ??1_Locinfo@std@@QEAA 15072->15034 15072->15035 15075 7ff7b85b11f0 7 API calls 15073->15075 15074->15072 15074->15076 15078 7ff7b8592289 15074->15078 15075->15071 15076->15078 15077->15074 15079 7ff7b85ba960 _Receive_impl free 15078->15079 15079->15072 15081 7ff7b85ba968 std::_Facet_Register 3 API calls 15080->15081 15082 7ff7b85ba8b3 15081->15082 15082->15027 15086 7ff7b8592090 15083->15086 15085 7ff7b85920ce _CxxThrowException __std_exception_copy 15085->15052 15086->15085 15088 7ff7b85ba968 std::_Facet_Register 3 API calls 15087->15088 15089 7ff7b85b1fe5 15088->15089 15090 7ff7b85b2700 15089->15090 15112 7ff7b85b3210 15090->15112 15093 7ff7b85b2741 15095 7ff7b85ba968 std::_Facet_Register 3 API calls 15093->15095 15094 7ff7b85b1ff0 15094->15062 15094->15063 15097 7ff7b85b275b 15095->15097 15100 7ff7b85ba968 std::_Facet_Register 3 API calls 15097->15100 15099 7ff7b85b2970 3 API calls 15099->15093 15105 7ff7b85b27c5 15100->15105 15101 7ff7b85b2430 strchr 15101->15105 15102 7ff7b85b3210 51 API calls 15102->15105 15103 7ff7b85b3880 3 API calls 15103->15105 15104 7ff7b85ba968 std::_Facet_Register 3 API calls 15104->15105 15105->15094 15105->15101 15105->15102 15105->15103 15105->15104 15106 7ff7b85b2970 3 API calls 15105->15106 15106->15105 15108 7ff7b85b298d 15107->15108 15109 7ff7b85ba968 std::_Facet_Register 3 API calls 15108->15109 15110 7ff7b85b2008 15109->15110 15110->15068 15113 7ff7b85b2717 15112->15113 15134 7ff7b85b3230 15112->15134 15113->15093 15113->15094 15135 7ff7b85b3880 15113->15135 15114 7ff7b85b3880 __std_exception_copy malloc _CxxThrowException 15114->15134 15117 7ff7b85b3853 15273 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15117->15273 15121 7ff7b85b385e 15274 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15121->15274 15125 7ff7b85b3869 15275 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15125->15275 15126 7ff7b85b2430 strchr 15126->15134 15128 7ff7b85b3874 15276 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15128->15276 15130 7ff7b85b383e 15271 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15130->15271 15133 7ff7b85b3848 15272 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15133->15272 15134->15113 15134->15114 15134->15117 15134->15121 15134->15125 15134->15126 15134->15128 15134->15130 15134->15133 15138 7ff7b85b41f0 15134->15138 15162 7ff7b85b4060 15134->15162 15197 7ff7b85b4380 15134->15197 15235 7ff7b85b47e0 15134->15235 15246 7ff7b85b4580 15134->15246 15136 7ff7b85ba968 std::_Facet_Register 3 API calls 15135->15136 15137 7ff7b85b2736 15136->15137 15137->15099 15139 7ff7b85b4316 15138->15139 15140 7ff7b85b4209 15138->15140 15284 7ff7b85b6380 15139->15284 15277 7ff7b85b5ed0 15140->15277 15145 7ff7b85b421b 15146 7ff7b85b424f 15145->15146 15147 7ff7b85b422d 15145->15147 15154 7ff7b85b434a 15146->15154 15158 7ff7b85b429b 15146->15158 15148 7ff7b85b4368 15147->15148 15149 7ff7b85b4237 15147->15149 15331 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15148->15331 15153 7ff7b85b47e0 16 API calls 15149->15153 15156 7ff7b85b4244 15153->15156 15159 7ff7b85b435d 15154->15159 15329 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15154->15329 15156->15134 15160 7ff7b85ba968 std::_Facet_Register 3 API calls 15158->15160 15330 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15159->15330 15161 7ff7b85b42a5 15160->15161 15161->15134 15163 7ff7b85b6a70 3 API calls 15162->15163 15171 7ff7b85b407e 15163->15171 15164 7ff7b85b40f1 15165 7ff7b85b41ca 15164->15165 15167 7ff7b85b4116 ?tolower@?$ctype@D@std@@QEBADD 15164->15167 15168 7ff7b85b412b 15164->15168 15392 7ff7b85b7b60 15165->15392 15166 7ff7b85b2430 strchr 15166->15164 15167->15168 15170 7ff7b85ba968 std::_Facet_Register 3 API calls 15168->15170 15173 7ff7b85b4142 15168->15173 15170->15173 15171->15164 15171->15166 15172 7ff7b85b2430 strchr 15172->15165 15173->15172 15174 7ff7b85b7b60 26 API calls 15193 7ff7b85b60ce 15174->15193 15175 7ff7b85b635a 15443 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15175->15443 15176 7ff7b85b6255 15176->15134 15178 7ff7b85b61ea ?tolower@?$ctype@D@std@@QEBADD 15178->15193 15179 7ff7b85b6365 15444 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15179->15444 15180 7ff7b85b2430 strchr 15180->15193 15181 7ff7b85ba968 std::_Facet_Register 3 API calls 15181->15193 15184 7ff7b85b6265 15186 7ff7b85b628f 15184->15186 15187 7ff7b85b627b ?tolower@?$ctype@D@std@@QEBADD 15184->15187 15185 7ff7b85b6350 15442 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15185->15442 15189 7ff7b85b62a6 15186->15189 15190 7ff7b85ba968 std::_Facet_Register 3 API calls 15186->15190 15187->15186 15191 7ff7b85b62e6 ?tolower@?$ctype@D@std@@QEBADD 15189->15191 15192 7ff7b85b62fa 15189->15192 15190->15189 15191->15192 15192->15176 15196 7ff7b85ba968 std::_Facet_Register 3 API calls 15192->15196 15193->15174 15193->15175 15193->15176 15193->15178 15193->15179 15193->15180 15193->15181 15193->15184 15193->15185 15195 7ff7b85b5840 10 API calls 15193->15195 15425 7ff7b85b7f00 15193->15425 15195->15193 15196->15176 15198 7ff7b85b4398 15197->15198 15199 7ff7b85b44a1 15198->15199 15202 7ff7b85b43bf 15198->15202 15233 7ff7b85b4566 15198->15233 15200 7ff7b85b44d1 15199->15200 15201 7ff7b85b44aa 15199->15201 15205 7ff7b85b44e1 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15200->15205 15206 7ff7b85b44ed 15200->15206 15204 7ff7b85b3880 3 API calls 15201->15204 15209 7ff7b85b2430 strchr 15202->15209 15208 7ff7b85b44b8 15204->15208 15205->15206 15210 7ff7b85b2a30 3 API calls 15206->15210 15211 7ff7b85b2700 50 API calls 15208->15211 15220 7ff7b85b4403 15209->15220 15212 7ff7b85b44f6 15210->15212 15213 7ff7b85b44c3 15211->15213 15214 7ff7b85b2700 50 API calls 15212->15214 15215 7ff7b85b2970 3 API calls 15213->15215 15217 7ff7b85b4501 15214->15217 15218 7ff7b85b44cf 15215->15218 15216 7ff7b85b2430 strchr 15219 7ff7b85b4450 15216->15219 15221 7ff7b85b2970 3 API calls 15217->15221 15218->15134 15219->15201 15222 7ff7b85b4455 15219->15222 15220->15216 15223 7ff7b85b450d 15221->15223 15225 7ff7b85b4479 15222->15225 15226 7ff7b85b445a 15222->15226 15547 7ff7b85b5690 15223->15547 15228 7ff7b85b4482 15225->15228 15229 7ff7b85b455c 15225->15229 15536 7ff7b85b6950 15226->15536 15232 7ff7b85b6950 50 API calls 15228->15232 15556 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15229->15556 15234 7ff7b85b448c 15232->15234 15557 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15233->15557 15234->15134 15236 7ff7b85b47ff 15235->15236 15237 7ff7b85ba968 std::_Facet_Register 3 API calls 15236->15237 15240 7ff7b85b480f 15236->15240 15237->15240 15238 7ff7b85b4883 ?tolower@?$ctype@D@std@@QEBADD 15241 7ff7b85b48aa 15238->15241 15239 7ff7b85b4897 15239->15241 15606 7ff7b85b5840 15239->15606 15240->15238 15240->15239 15243 7ff7b85b48d9 15241->15243 15244 7ff7b85b48be realloc 15241->15244 15243->15134 15244->15243 15245 7ff7b85b48d2 ?_Xbad_alloc@std@ 15244->15245 15245->15243 15248 7ff7b85b45aa 15246->15248 15252 7ff7b85b45a1 15246->15252 15247 7ff7b85b2430 strchr 15257 7ff7b85b460d 15247->15257 15248->15247 15249 7ff7b85b479e 15249->15134 15250 7ff7b85b4676 15614 7ff7b85b6b10 15250->15614 15251 7ff7b85b2430 strchr 15254 7ff7b85b46e4 15251->15254 15252->15248 15252->15249 15252->15251 15256 7ff7b85b5ed0 2 API calls 15254->15256 15255 7ff7b85b2430 strchr 15255->15250 15266 7ff7b85b46f1 15256->15266 15257->15250 15257->15255 15258 7ff7b85b47c8 15636 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15258->15636 15261 7ff7b85b2430 strchr 15263 7ff7b85b4757 15261->15263 15262 7ff7b85b47bd 15635 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15262->15635 15265 7ff7b85b4702 15263->15265 15267 7ff7b85b5ed0 2 API calls 15263->15267 15265->15248 15265->15262 15266->15258 15266->15261 15266->15265 15268 7ff7b85b476a 15267->15268 15268->15265 15269 7ff7b85b47b3 15268->15269 15634 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15269->15634 15283 7ff7b85b5ef0 15277->15283 15278 7ff7b85b4213 15278->15139 15278->15145 15279 7ff7b85b5fae 15332 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15279->15332 15282 7ff7b85b2430 strchr 15282->15283 15283->15278 15283->15279 15283->15282 15285 7ff7b85b6871 15284->15285 15288 7ff7b85b6393 15284->15288 15374 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15285->15374 15287 7ff7b85b687b 15375 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15287->15375 15290 7ff7b85b6491 15288->15290 15291 7ff7b85b65a5 15288->15291 15292 7ff7b85b63bd 15288->15292 15300 7ff7b85b649f 15290->15300 15317 7ff7b85b66c9 15290->15317 15294 7ff7b85b6646 15291->15294 15295 7ff7b85b65ae 15291->15295 15293 7ff7b85b2430 strchr 15292->15293 15296 7ff7b85b65a0 15293->15296 15316 7ff7b85b6655 15294->15316 15294->15317 15309 7ff7b85b65bc 15295->15309 15295->15317 15301 7ff7b85b431e 15296->15301 15376 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15296->15376 15298 7ff7b85b2430 strchr 15303 7ff7b85b6501 15298->15303 15299 7ff7b85b6891 15377 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15299->15377 15300->15298 15301->15159 15318 7ff7b85b5fc0 15301->15318 15302 7ff7b85b676e 15305 7ff7b85b676c 15302->15305 15315 7ff7b85b678f 15302->15315 15303->15287 15303->15292 15304 7ff7b85b2430 strchr 15307 7ff7b85b6626 15304->15307 15305->15301 15378 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15305->15378 15306 7ff7b85b2430 strchr 15306->15307 15333 7ff7b85b7a60 15307->15333 15309->15304 15310 7ff7b85b2430 strchr 15310->15301 15313 7ff7b85b2430 strchr 15313->15317 15315->15301 15315->15310 15316->15306 15317->15299 15317->15302 15317->15305 15317->15313 15317->15315 15319 7ff7b85b5fe2 15318->15319 15320 7ff7b85b60a7 15318->15320 15381 7ff7b85b8ab0 15319->15381 15320->15154 15323 7ff7b85b601a 15388 7ff7b85b8090 15323->15388 15327 7ff7b85b2430 strchr 15328 7ff7b85b6095 15327->15328 15328->15154 15334 7ff7b85b7b36 15333->15334 15341 7ff7b85b7a7e 15333->15341 15334->15296 15335 7ff7b85b7b41 15335->15334 15379 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15335->15379 15336 7ff7b85b7b4f 15380 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15336->15380 15339 7ff7b85b2430 strchr 15339->15341 15341->15334 15341->15335 15341->15336 15341->15339 15382 7ff7b85b8aef 15381->15382 15383 7ff7b85b5ffb 15381->15383 15382->15383 15384 7ff7b85b8b30 ?tolower@?$ctype@D@std@@QEBADD ?tolower@?$ctype@D@std@@QEBADD 15382->15384 15383->15320 15383->15323 15385 7ff7b85b6a70 15383->15385 15384->15382 15386 7ff7b85ba968 std::_Facet_Register 3 API calls 15385->15386 15387 7ff7b85b6a83 15386->15387 15387->15323 15389 7ff7b85b80c0 15388->15389 15390 7ff7b85b603f 15389->15390 15391 7ff7b85ba968 std::_Facet_Register 3 API calls 15389->15391 15390->15327 15391->15389 15393 7ff7b85b7d70 15392->15393 15397 7ff7b85b7b79 15392->15397 15398 7ff7b85b7d79 15393->15398 15409 7ff7b85b7ca6 15393->15409 15394 7ff7b85b2430 strchr 15395 7ff7b85b7bca 15394->15395 15399 7ff7b85b7bda 15395->15399 15395->15409 15396 7ff7b85b2430 strchr 15419 7ff7b85b7dcc 15396->15419 15397->15394 15398->15396 15400 7ff7b85b7c49 15399->15400 15417 7ff7b85b7be6 15399->15417 15403 7ff7b85b7c59 15400->15403 15406 7ff7b85b5fc0 6 API calls 15400->15406 15401 7ff7b85b7e5a 15401->15193 15402 7ff7b85b2430 strchr 15404 7ff7b85b7ed9 15402->15404 15407 7ff7b85b5ed0 2 API calls 15403->15407 15413 7ff7b85b7c5d 15403->15413 15404->15193 15405 7ff7b85b7d59 15405->15193 15406->15403 15410 7ff7b85b7c7e 15407->15410 15408 7ff7b85b2430 strchr 15412 7ff7b85b7c37 15408->15412 15409->15402 15409->15405 15414 7ff7b85b7c82 15410->15414 15415 7ff7b85b7c8e 15410->15415 15411 7ff7b85b2430 strchr 15416 7ff7b85b7e40 15411->15416 15412->15193 15413->15193 15414->15412 15471 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15414->15471 15418 7ff7b85b6380 26 API calls 15415->15418 15445 7ff7b85b93b0 15416->15445 15417->15408 15421 7ff7b85b7c96 15418->15421 15419->15401 15419->15411 15421->15193 15426 7ff7b85b7f1c ?tolower@?$ctype@D@std@@QEBADD ?tolower@?$ctype@D@std@@QEBADD 15425->15426 15429 7ff7b85b7f44 15425->15429 15426->15429 15427 7ff7b85b805e 15427->15193 15428 7ff7b85b7f9a 15428->15427 15431 7ff7b85b7fce 15428->15431 15432 7ff7b85b7fab 15428->15432 15429->15427 15429->15428 15430 7ff7b85ba968 std::_Facet_Register 3 API calls 15429->15430 15430->15429 15433 7ff7b85b7fe6 15431->15433 15435 7ff7b85ba968 std::_Facet_Register 3 API calls 15431->15435 15441 7ff7b85b7fc1 15432->15441 15528 7ff7b85b8170 15432->15528 15436 7ff7b85b8007 realloc 15433->15436 15437 7ff7b85b8024 15433->15437 15435->15433 15436->15437 15438 7ff7b85b801d ?_Xbad_alloc@std@ 15436->15438 15437->15427 15439 7ff7b85b8043 realloc 15437->15439 15438->15437 15439->15427 15440 7ff7b85b8057 ?_Xbad_alloc@std@ 15439->15440 15440->15427 15441->15193 15468 7ff7b85b93d6 15445->15468 15446 7ff7b85b946f 15447 7ff7b85b95c2 15446->15447 15449 7ff7b85b94b1 15446->15449 15450 7ff7b85b947c 15446->15450 15495 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15447->15495 15451 7ff7b85b94d0 15449->15451 15452 7ff7b85b94b6 15449->15452 15454 7ff7b85b8ab0 2 API calls 15450->15454 15458 7ff7b85b95dd 15451->15458 15466 7ff7b85b94af 15451->15466 15487 7ff7b85ba020 15451->15487 15456 7ff7b85b95d5 15452->15456 15472 7ff7b85b9e90 15452->15472 15453 7ff7b85b95ca 15496 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15453->15496 15455 7ff7b85b9497 15454->15455 15455->15453 15462 7ff7b85b8090 3 API calls 15455->15462 15497 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15456->15497 15498 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15458->15498 15462->15466 15463 7ff7b85b2430 strchr 15470 7ff7b85b954a 15463->15470 15464 7ff7b85b2430 strchr 15464->15468 15466->15463 15468->15446 15468->15464 15494 7ff7b85b2420 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15470->15494 15499 7ff7b85ba100 15472->15499 15474 7ff7b85ba100 17 API calls 15476 7ff7b85b9ec9 15474->15476 15475 7ff7b85b9f12 memcmp 15475->15476 15476->15474 15476->15475 15477 7ff7b85b9fed _invalid_parameter_noinfo_noreturn 15476->15477 15478 7ff7b85ba960 _Receive_impl free 15476->15478 15479 7ff7b85b9fb2 15476->15479 15480 7ff7b85ba968 std::_Facet_Register 3 API calls 15476->15480 15482 7ff7b85b9ff4 15477->15482 15478->15476 15481 7ff7b85b9ff9 15479->15481 15479->15482 15486 7ff7b85b9fe6 _invalid_parameter_noinfo_noreturn 15479->15486 15480->15476 15484 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15481->15484 15483 7ff7b85ba960 _Receive_impl free 15482->15483 15483->15481 15485 7ff7b85ba006 15484->15485 15485->15466 15486->15477 15488 7ff7b85ba04e 15487->15488 15489 7ff7b85ba968 std::_Facet_Register 3 API calls 15488->15489 15491 7ff7b85ba07c 15488->15491 15489->15491 15490 7ff7b85ba0dd 15490->15466 15491->15490 15492 7ff7b85ba0af realloc 15491->15492 15492->15491 15493 7ff7b85ba0f6 ?_Xbad_alloc@std@ 15492->15493 15500 7ff7b85ba2ed 15499->15500 15501 7ff7b85ba15c 15499->15501 15503 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15500->15503 15502 7ff7b85ba1dd 15501->15502 15504 7ff7b85ba310 15501->15504 15507 7ff7b85ba1b5 15501->15507 15508 7ff7b85ba189 15501->15508 15506 7ff7b85ba1e1 ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD 15502->15506 15505 7ff7b85ba2fc 15503->15505 15509 7ff7b85b23e0 ?_Xlength_error@std@@YAXPEBD 15504->15509 15505->15476 15520 7ff7b85ba207 15506->15520 15512 7ff7b85ba968 std::_Facet_Register __std_exception_copy malloc _CxxThrowException 15507->15512 15510 7ff7b85ba196 15508->15510 15511 7ff7b85ba30b 15508->15511 15513 7ff7b85ba316 15509->15513 15515 7ff7b85ba968 std::_Facet_Register __std_exception_copy malloc _CxxThrowException 15510->15515 15516 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 15511->15516 15517 7ff7b85ba1bd memcpy 15512->15517 15514 7ff7b85ba246 15519 7ff7b85ba2af 15514->15519 15522 7ff7b85ba2aa 15514->15522 15524 7ff7b85ba2a3 _invalid_parameter_noinfo_noreturn 15514->15524 15518 7ff7b85ba19b 15515->15518 15516->15504 15517->15506 15518->15517 15521 7ff7b85ba2e1 _invalid_parameter_noinfo_noreturn 15518->15521 15519->15500 15519->15521 15523 7ff7b85ba2e8 15519->15523 15520->15514 15520->15524 15525 7ff7b85ba960 _Receive_impl free 15520->15525 15521->15523 15526 7ff7b85ba960 _Receive_impl free 15522->15526 15527 7ff7b85ba960 _Receive_impl free 15523->15527 15524->15522 15525->15514 15526->15519 15527->15500 15529 7ff7b85b819f 15528->15529 15530 7ff7b85b818e ?tolower@?$ctype@D@std@@QEBADD 15528->15530 15531 7ff7b85b81b6 15529->15531 15532 7ff7b85ba968 std::_Facet_Register 3 API calls 15529->15532 15530->15529 15533 7ff7b85b81f2 15531->15533 15534 7ff7b85b81d7 realloc 15531->15534 15532->15531 15533->15432 15534->15533 15535 7ff7b85b81eb ?_Xbad_alloc@std@ 15534->15535 15535->15533 15537 7ff7b85ba968 std::_Facet_Register 3 API calls 15536->15537 15538 7ff7b85b6984 15537->15538 15539 7ff7b85ba968 std::_Facet_Register 3 API calls 15538->15539 15540 7ff7b85b69c5 15539->15540 15541 7ff7b85b2700 51 API calls 15540->15541 15542 7ff7b85b6a32 15541->15542 15543 7ff7b85b2970 3 API calls 15542->15543 15544 7ff7b85b6a3e 15543->15544 15545 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15544->15545 15546 7ff7b85b4464 15545->15546 15546->15134 15548 7ff7b85b56b2 15547->15548 15550 7ff7b85b5775 15547->15550 15558 7ff7b85b5ca0 15548->15558 15549 7ff7b85b5830 15549->15218 15550->15549 15572 7ff7b85b5a00 15550->15572 15559 7ff7b85b5ccd 15558->15559 15567 7ff7b85b5714 15558->15567 15560 7ff7b85b5ec3 15559->15560 15561 7ff7b85b5ce7 15559->15561 15599 7ff7b85b2400 ?_Xlength_error@std@@YAXPEBD 15560->15599 15564 7ff7b85b5d31 15561->15564 15565 7ff7b85b5d43 memset 15561->15565 15561->15567 15579 7ff7b85b8de0 15564->15579 15565->15567 15568 7ff7b85b7810 15567->15568 15569 7ff7b85b5767 15568->15569 15570 7ff7b85b7828 15568->15570 15569->15218 15570->15569 15571 7ff7b85b78e8 memset 15570->15571 15571->15569 15573 7ff7b85b5a2c 15572->15573 15576 7ff7b85b5bcd 15573->15576 15601 7ff7b85b9a20 15573->15601 15576->15549 15580 7ff7b85b8f5c 15579->15580 15585 7ff7b85b8e05 15579->15585 15600 7ff7b85b23e0 ?_Xlength_error@std@@YAXPEBD 15580->15600 15582 7ff7b85b8f61 15583 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 15582->15583 15584 7ff7b85b8f67 15583->15584 15585->15582 15586 7ff7b85b8e70 15585->15586 15587 7ff7b85b8e99 15585->15587 15593 7ff7b85b8e63 15585->15593 15586->15582 15592 7ff7b85ba968 std::_Facet_Register 3 API calls 15586->15592 15588 7ff7b85ba968 std::_Facet_Register 3 API calls 15587->15588 15588->15593 15589 7ff7b85b8ec5 15591 7ff7b85b8edf memcpy 15589->15591 15590 7ff7b85b8eb4 memset 15590->15591 15594 7ff7b85b8f2a 15591->15594 15595 7ff7b85b8ef9 15591->15595 15592->15593 15593->15589 15593->15590 15596 7ff7b85b8f55 _invalid_parameter_noinfo_noreturn 15593->15596 15594->15567 15595->15596 15597 7ff7b85b8f22 15595->15597 15596->15580 15598 7ff7b85ba960 _Receive_impl free 15597->15598 15598->15594 15602 7ff7b85b9a4d 15601->15602 15603 7ff7b85b5ba2 15602->15603 15604 7ff7b85b9cb2 memcpy 15602->15604 15603->15576 15605 7ff7b85b2400 ?_Xlength_error@std@@YAXPEBD 15603->15605 15604->15603 15608 7ff7b85b5871 15606->15608 15607 7ff7b85b58d0 15610 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15607->15610 15608->15607 15609 7ff7b85b58cb 15608->15609 15611 7ff7b85b58c4 _invalid_parameter_noinfo_noreturn 15608->15611 15612 7ff7b85ba960 _Receive_impl free 15609->15612 15613 7ff7b85b58e0 15610->15613 15611->15609 15612->15607 15613->15241 15615 7ff7b85b6b34 15614->15615 15617 7ff7b85b6b50 15614->15617 15616 7ff7b85b47e0 16 API calls 15615->15616 15615->15617 15616->15617 15618 7ff7b85b6d4b 15617->15618 15619 7ff7b85b6b82 15617->15619 15620 7ff7b85ba968 std::_Facet_Register 3 API calls 15618->15620 15621 7ff7b85ba968 std::_Facet_Register 3 API calls 15619->15621 15622 7ff7b85b6d55 15620->15622 15623 7ff7b85b6b91 15621->15623 15624 7ff7b85ba968 std::_Facet_Register 3 API calls 15622->15624 15625 7ff7b85ba968 std::_Facet_Register 3 API calls 15623->15625 15626 7ff7b85b6d91 15624->15626 15627 7ff7b85b6bc9 15625->15627 15628 7ff7b85ba968 std::_Facet_Register 3 API calls 15627->15628 15629 7ff7b85b6c0b 15628->15629 15630 7ff7b85ba968 std::_Facet_Register 3 API calls 15629->15630 15631 7ff7b85b6c46 15630->15631 15632 7ff7b85ba968 std::_Facet_Register 3 API calls 15631->15632 15633 7ff7b85b6c7c 15632->15633 15633->15249 15651 7ff7b85b3a80 15637->15651 15639 7ff7b85b2fb0 15684 7ff7b85b3000 15639->15684 15642 7ff7b85b2f65 15642->15639 15643 7ff7b85b1540 8 API calls 15642->15643 15643->15642 15644 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15646 7ff7b85b0831 15644->15646 15645 7ff7b85b1540 8 API calls 15649 7ff7b85b2e34 15645->15649 15646->14470 15646->14471 15646->14473 15649->15642 15649->15645 15650 7ff7b85b3a80 34 API calls 15649->15650 15672 7ff7b85b4f50 15649->15672 15677 7ff7b85b5150 15649->15677 15650->15649 15652 7ff7b85b3ac1 memset 15651->15652 15668 7ff7b85b3aba 15651->15668 15690 7ff7b85b3e30 15652->15690 15655 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15657 7ff7b85b3c7d 15655->15657 15657->15649 15659 7ff7b85b3c38 15712 7ff7b85b3d20 15659->15712 15660 7ff7b85b3bca 15660->15659 15662 7ff7b85b3c33 15660->15662 15664 7ff7b85b3c2c _invalid_parameter_noinfo_noreturn 15660->15664 15665 7ff7b85ba960 _Receive_impl free 15662->15665 15663 7ff7b85b3c5f 15666 7ff7b85b3d20 3 API calls 15663->15666 15664->15662 15665->15659 15666->15668 15667 7ff7b85b3bb5 15669 7ff7b85b4d40 29 API calls 15667->15669 15668->15655 15669->15660 15670 7ff7b85b4d40 29 API calls 15671 7ff7b85b3b2d 15670->15671 15671->15660 15671->15667 15671->15670 15673 7ff7b85b5138 15672->15673 15676 7ff7b85b4f7c 15672->15676 15673->15649 15674 7ff7b85b510f 15674->15649 15675 7ff7b85b1540 8 API calls 15675->15676 15676->15674 15676->15675 15678 7ff7b85b55c2 15677->15678 15683 7ff7b85b517b 15677->15683 15678->15649 15679 7ff7b85b557b 15680 7ff7b85b1540 8 API calls 15679->15680 15681 7ff7b85b544e 15679->15681 15680->15681 15681->15649 15682 7ff7b85b1540 8 API calls 15682->15683 15683->15679 15683->15681 15683->15682 15685 7ff7b85b3011 15684->15685 15686 7ff7b85b2fbc 15684->15686 15687 7ff7b85b3059 15685->15687 15688 7ff7b85b3074 _invalid_parameter_noinfo_noreturn 15685->15688 15686->15644 15689 7ff7b85ba960 _Receive_impl free 15687->15689 15689->15686 15691 7ff7b85b3ede 15690->15691 15692 7ff7b85b3f30 15691->15692 15693 7ff7b85b3f23 15691->15693 15696 7ff7b85b3b1f 15691->15696 15695 7ff7b85b3f35 memset 15692->15695 15692->15696 15725 7ff7b85b76a0 15693->15725 15695->15696 15697 7ff7b85b4d40 15696->15697 15698 7ff7b85b4d5d 15697->15698 15699 7ff7b85b4d6b 15697->15699 15745 7ff7b85b55e0 15698->15745 15700 7ff7b85b5690 12 API calls 15699->15700 15702 7ff7b85b4d8b 15700->15702 15703 7ff7b85b4da8 15702->15703 15704 7ff7b85b4dd5 15702->15704 15705 7ff7b85b4dc7 15702->15705 15765 7ff7b85b6e50 15703->15765 15704->15703 15708 7ff7b85b4dda memset 15704->15708 15707 7ff7b85b76a0 8 API calls 15705->15707 15707->15703 15708->15703 15710 7ff7b85b55e0 7 API calls 15711 7ff7b85b4e4e 15710->15711 15711->15671 15713 7ff7b85b3d69 15712->15713 15714 7ff7b85b3d38 15712->15714 15715 7ff7b85b3daf 15713->15715 15717 7ff7b85b3da7 15713->15717 15718 7ff7b85b3dc6 _invalid_parameter_noinfo_noreturn 15713->15718 15716 7ff7b85ba960 _Receive_impl free 15714->15716 15714->15718 15715->15663 15716->15713 15719 7ff7b85ba960 _Receive_impl free 15717->15719 15720 7ff7b85b3e13 15718->15720 15721 7ff7b85b3de2 15718->15721 15719->15715 15720->15663 15722 7ff7b85b3e0b 15721->15722 15723 7ff7b85b3e27 _invalid_parameter_noinfo_noreturn 15721->15723 15724 7ff7b85ba960 _Receive_impl free 15722->15724 15724->15720 15726 7ff7b85b77f8 15725->15726 15731 7ff7b85b76c1 15725->15731 15744 7ff7b85b23e0 ?_Xlength_error@std@@YAXPEBD 15726->15744 15728 7ff7b85b77fd 15729 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 15728->15729 15730 7ff7b85b7803 15729->15730 15731->15728 15732 7ff7b85b7751 15731->15732 15733 7ff7b85b7728 15731->15733 15740 7ff7b85b771b 15731->15740 15734 7ff7b85ba968 std::_Facet_Register 3 API calls 15732->15734 15733->15728 15737 7ff7b85ba968 std::_Facet_Register 3 API calls 15733->15737 15734->15740 15735 7ff7b85b7779 memcpy 15738 7ff7b85b7793 15735->15738 15739 7ff7b85b77c4 15735->15739 15736 7ff7b85b776e memset 15736->15735 15737->15740 15741 7ff7b85b77bc 15738->15741 15742 7ff7b85b77f1 _invalid_parameter_noinfo_noreturn 15738->15742 15739->15696 15740->15735 15740->15736 15740->15742 15743 7ff7b85ba960 _Receive_impl free 15741->15743 15742->15726 15743->15739 15746 7ff7b85b5621 15745->15746 15752 7ff7b85b5634 15745->15752 15746->15699 15747 7ff7b85b5667 15747->15699 15748 7ff7b85b8dc9 15778 7ff7b85b23e0 ?_Xlength_error@std@@YAXPEBD 15748->15778 15749 7ff7b85b8dce 15751 7ff7b8591850 Concurrency::cancel_current_task __std_exception_copy 15749->15751 15753 7ff7b85b8dd4 15751->15753 15752->15747 15752->15748 15752->15749 15754 7ff7b85b8cf1 15752->15754 15755 7ff7b85b8cc8 15752->15755 15758 7ff7b85b8cbb 15752->15758 15756 7ff7b85ba968 std::_Facet_Register 3 API calls 15754->15756 15755->15749 15761 7ff7b85ba968 std::_Facet_Register 3 API calls 15755->15761 15756->15758 15757 7ff7b85b8d25 memcpy 15759 7ff7b85b8d3f 15757->15759 15760 7ff7b85b8d8b 15757->15760 15758->15757 15758->15758 15763 7ff7b85b8dc2 _invalid_parameter_noinfo_noreturn 15758->15763 15762 7ff7b85b8d80 15759->15762 15759->15763 15760->15699 15761->15758 15764 7ff7b85ba960 _Receive_impl free 15762->15764 15763->15748 15764->15760 15766 7ff7b85b6e83 15765->15766 15767 7ff7b85b6e9b 15765->15767 15766->15767 15768 7ff7b85b6e8f ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15766->15768 15769 7ff7b85b6ebd 15767->15769 15770 7ff7b85b6eb1 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15767->15770 15768->15767 15771 7ff7b85b6ef5 15769->15771 15773 7ff7b85b74e7 ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@ 15769->15773 15770->15769 15772 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15771->15772 15775 7ff7b85b4e2f 15772->15775 15774 7ff7b85b74f3 15773->15774 15779 7ff7b85b23e0 ?_Xlength_error@std@@YAXPEBD 15774->15779 15775->15710 15775->15711 15782 7ff7b85ae99d 15781->15782 15783 7ff7b85ae9b3 memcpy 15782->15783 15784 7ff7b85ae9f8 15782->15784 15783->14486 15786 7ff7b85b1060 10 API calls 15784->15786 15787 7ff7b85aea0b 15786->15787 15787->14486 15789 7ff7b85ae904 15788->15789 15789->15789 15790 7ff7b85ae95f 15789->15790 15791 7ff7b85ae920 memcpy 15789->15791 15793 7ff7b85b1060 10 API calls 15790->15793 15791->14489 15794 7ff7b85ae972 15793->15794 15794->14489 15796 7ff7b85b12f5 15795->15796 15797 7ff7b85b135e 15795->15797 15796->15797 15798 7ff7b85b136e _invalid_parameter_noinfo_noreturn 15796->15798 15799 7ff7b85ba960 _Receive_impl free 15796->15799 15797->14613 15799->15796 15801 7ff7b85945e5 15800->15801 15802 7ff7b8594449 15800->15802 15803 7ff7b85b11f0 7 API calls 15801->15803 15804 7ff7b85b11f0 7 API calls 15802->15804 15811 7ff7b85945d2 15803->15811 15807 7ff7b8594480 15804->15807 15805 7ff7b85ba940 Concurrency::cancel_current_task 8 API calls 15806 7ff7b8594617 15805->15806 15806->14647 15808 7ff7b85944e1 memset 15807->15808 15810 7ff7b8594509 15807->15810 15808->15810 15809 7ff7b85b11f0 7 API calls 15812 7ff7b8594592 15809->15812 15810->15809 15811->15805 15812->15811 15813 7ff7b85945cd 15812->15813 15814 7ff7b85945c6 _invalid_parameter_noinfo_noreturn 15812->15814 15815 7ff7b85ba960 _Receive_impl free 15813->15815 15814->15813 15815->15811 15839 1622cb00000 15842 7ff7b8591610 __acrt_iob_func 15839->15842 15840 1622cb00021 15845 7ff7b8591600 15842->15845 15844 7ff7b8591642 __stdio_common_vfprintf 15844->15840 15845->15844
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: AllocVirtual$Concurrency::cancel_current_taskQuery_perf_counterQuery_perf_frequencyRandom_device@std@@_invalid_parameter_noinfo_noreturnmallocmemset
    • String ID: $.$50~jb$60~jb$:$:$L$L$L$L$L$L$N$N$P$P$R$T$V$X$\$d$d$d$d$d$d$d$d$d$d$d$d$d)65R$h$random
    • API String ID: 3798647520-2963567472
    • Opcode ID: 87ab6a15ddaa7428d1e95293d2efb970ea0ce3748a0253fc652b606824dc3296
    • Instruction ID: 49fd5770108a00a06b025a23e5b573e1555fa0fc021c6ab39a55c682e2941fd8
    • Opcode Fuzzy Hash: 87ab6a15ddaa7428d1e95293d2efb970ea0ce3748a0253fc652b606824dc3296
    • Instruction Fuzzy Hash: A4D3C92291DBC145E722AB38E4511E9E354FFF7784F40D322E78D66A5AEF38E1828714
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Random_device@std@@$Query_perf_counterQuery_perf_frequency$memchrmemset$Concurrency::cancel_current_taskCreateFactoryGlobalMemoryStatusmallocmemcmp
    • String ID: random
    • API String ID: 4003858199-373021397
    • Opcode ID: 92090a04ada771e9836e217aa0b1f2e93ae536986e940658b3567154b3932d68
    • Instruction ID: bfa88f1d9c3bc35e3567fe42b2b338b4db720c84d1d8a9195057f69f6f00a1e7
    • Opcode Fuzzy Hash: 92090a04ada771e9836e217aa0b1f2e93ae536986e940658b3567154b3932d68
    • Instruction Fuzzy Hash: 1F33D832A18A8685DB21EF38D8912FCE355FF66788F804231E74E5BA99DF38D546C314
    APIs
    • ?_Random_device@std@@YAIXZ.MSVCP140(00000000,0000006E00000006,?,00000000,-8000000000000000), ref: 00007FF7B85A3778
      • Part of subcall function 00007FF7B85B2150: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B85B2358
      • Part of subcall function 00007FF7B85B2150: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7B85B2365
    • _Query_perf_frequency.MSVCP140(?,00000000,-8000000000000000), ref: 00007FF7B85A3A7D
    • _Query_perf_counter.MSVCP140(?,00000000,-8000000000000000), ref: 00007FF7B85A3A86
    • log.API-MS-WIN-CRT-MATH-L1-1-0(?,00000000,-8000000000000000), ref: 00007FF7B85A3D4B
    • cos.API-MS-WIN-CRT-MATH-L1-1-0(?,00000000,-8000000000000000), ref: 00007FF7B85A3D57
    • sin.API-MS-WIN-CRT-MATH-L1-1-0(?,00000000,-8000000000000000), ref: 00007FF7B85A3D63
    • exp.API-MS-WIN-CRT-MATH-L1-1-0(?,00000000,-8000000000000000), ref: 00007FF7B85A3D74
    • pow.API-MS-WIN-CRT-MATH-L1-1-0(?,00000000,-8000000000000000), ref: 00007FF7B85A3DD3
    • tan.API-MS-WIN-CRT-MATH-L1-1-0(?,00000000,-8000000000000000), ref: 00007FF7B85A3E2E
      • Part of subcall function 00007FF7B85BA968: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF7B85B18F5), ref: 00007FF7B85BA982
    • memset.VCRUNTIME140(?,00000000,-8000000000000000), ref: 00007FF7B85A3EFA
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,00000000,-8000000000000000), ref: 00007FF7B85A447C
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,00000000,-8000000000000000), ref: 00007FF7B85A4483
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,00000000,-8000000000000000), ref: 00007FF7B85A44F3
    • SleepEx.KERNELBASE(?,00000000,-8000000000000000), ref: 00007FF7B85A4505
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_taskQuery_perf_counterQuery_perf_frequencyRandom_device@std@@Sleepmallocmemset
    • String ID: d$random
    • API String ID: 2134775511-2911377361
    • Opcode ID: 16452cfd0e712f89d915d6daee8606c00af68d80423a3433fefb7e7978eeaddb
    • Instruction ID: a8e1eee5f7e4c6cc4c5eb8003b63fa1e4cdb6ebc072befef5d0319e3c31646ac
    • Opcode Fuzzy Hash: 16452cfd0e712f89d915d6daee8606c00af68d80423a3433fefb7e7978eeaddb
    • Instruction Fuzzy Hash: 95821632A0CA4146EB11AF7894511BDE352FFA6794F908336E74E6BB99DF3CE4428314

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: __acrt_iob_func__stdio_common_vfprintf
    • String ID:
    • API String ID: 2168557111-0
    • Opcode ID: 57a41865e2a522d0e959f9447d4094606fd6f742e51a43451859619ab895bbc7
    • Instruction ID: e2e710d5e2b184ac55f8557ec64af908a7ca5ba354e24c5dcc7b5b196cd2ad0f
    • Opcode Fuzzy Hash: 57a41865e2a522d0e959f9447d4094606fd6f742e51a43451859619ab895bbc7
    • Instruction Fuzzy Hash: FEE01532A08B8182D7009F54F80445AE3A4FBA97C4F944135EB8947B28CF7CD1A6CB54

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 2548 1622cb00000-1622cb0001f call 7ff7b8591610 2549 1622cb00021-1622cb0002e 2548->2549
    Memory Dump Source
    • Source File: 00000000.00000002.1964028359.000001622CB00000.00000040.00001000.00020000.00000000.sdmp, Offset: 000001622CB00000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_1622cb00000_SecuriteInfo.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: d9a76d596100e906e42a18baf41ccc164cf4d2382328c9a176804d46515399a0
    • Instruction ID: 4ee9a1f44c7989a12476001a8ba19eb08aae74b9bfeae4ea2fa4c4b261d6df11
    • Opcode Fuzzy Hash: d9a76d596100e906e42a18baf41ccc164cf4d2382328c9a176804d46515399a0
    • Instruction Fuzzy Hash: 70E0E230218A0E9FDB84EF5CD484B65FBE0FBAC310F50066AA058D3264DB709990CB42
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task$BinaryCloseCryptHandleProcessStringmallocmemset$CodeCreateExitObjectQuery_perf_counterQuery_perf_frequencyRandom_device@std@@SingleWait_flushallfreegetenvmemcpy
    • String ID: random
    • API String ID: 2415399023-373021397
    • Opcode ID: 1d0c04de029e4bd8b1f367337c9b71c5695b1fd0bf1e3a21c8ef9e7edb2f254d
    • Instruction ID: 8a15c927376dabd98aa20d5ae79dbf77df42b4953af6059fed42c6ec3d029b96
    • Opcode Fuzzy Hash: 1d0c04de029e4bd8b1f367337c9b71c5695b1fd0bf1e3a21c8ef9e7edb2f254d
    • Instruction Fuzzy Hash: D0C20532E0CA4186E7119F7898511BDE365BFA6794F948336EB4E23B99DF38E4428314
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: AllocVirtual$Random_device@std@@$ByteCharMultiWide
    • String ID: d$d$random
    • API String ID: 1209970496-741463915
    • Opcode ID: 269b3f85e0548a18497a7961a42e876e4d0bc95ee96558bb2f9fe0aadf852576
    • Instruction ID: 6338101fb558b0c42e0c35c3d12ffbca0586cdc513263bfbd210f763e657b572
    • Opcode Fuzzy Hash: 269b3f85e0548a18497a7961a42e876e4d0bc95ee96558bb2f9fe0aadf852576
    • Instruction Fuzzy Hash: 5C53A922D1CBC586E7129F38D8511E9E760FFB6784F809322E74D66A5AEF34E186C314
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: Internet_invalid_parameter_noinfo_noreturn$CloseHandlememcpy$Openmemset$Concurrency::cancel_current_taskFileQuery_perf_counterQuery_perf_frequencyRandom_device@std@@Read
    • String ID: orn`$random
    • API String ID: 2635940824-2186681027
    • Opcode ID: e7303d7da917fb2e0ea9ee27e387a3a4fa5e2fce180ec751a63186f277889139
    • Instruction ID: 732e4e411aac7f5c0e97ada9730430ce8846e8eccaa72d89876f2cafc3e2d17e
    • Opcode Fuzzy Hash: e7303d7da917fb2e0ea9ee27e387a3a4fa5e2fce180ec751a63186f277889139
    • Instruction Fuzzy Hash: B2B2F522B1CA4146EB01AF38D4111BDE365BFB6784F949336EB4E67B99DF38E4428314
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_taskQuery_perf_counterQuery_perf_frequencyRandom_device@std@@_mkdir_stat64i32_time64memsetrandsrand
    • String ID: random
    • API String ID: 257508751-373021397
    • Opcode ID: 4b06b1fe7fba131225baf6bf73cdb2becfef04b9ca1b6505e141a25009f2691c
    • Instruction ID: 62c21d706a1f9670562225ef3de24b30cf7656bde1ab32b688d925b3f88beabb
    • Opcode Fuzzy Hash: 4b06b1fe7fba131225baf6bf73cdb2becfef04b9ca1b6505e141a25009f2691c
    • Instruction Fuzzy Hash: 7E530A36D19BC14AE7239B39A8111E4E754AFB73C4F50D323FA5C76E56EF25A1838208

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 4400 7ff7b85ba518-7ff7b85ba558 4401 7ff7b85ba55a-7ff7b85ba561 4400->4401 4402 7ff7b85ba56d-7ff7b85ba576 4400->4402 4401->4402 4403 7ff7b85ba563-7ff7b85ba568 4401->4403 4404 7ff7b85ba592-7ff7b85ba594 4402->4404 4405 7ff7b85ba578-7ff7b85ba57b 4402->4405 4408 7ff7b85ba7f6-7ff7b85ba81c call 7ff7b85ba940 4403->4408 4406 7ff7b85ba7f4 4404->4406 4407 7ff7b85ba59a-7ff7b85ba59e 4404->4407 4405->4404 4409 7ff7b85ba57d-7ff7b85ba585 4405->4409 4406->4408 4410 7ff7b85ba675-7ff7b85ba69c call 7ff7b85ba840 4407->4410 4411 7ff7b85ba5a4-7ff7b85ba5a7 4407->4411 4413 7ff7b85ba587-7ff7b85ba589 4409->4413 4414 7ff7b85ba58b-7ff7b85ba58e 4409->4414 4423 7ff7b85ba6be-7ff7b85ba6c7 4410->4423 4424 7ff7b85ba69e-7ff7b85ba6a7 4410->4424 4415 7ff7b85ba5a9-7ff7b85ba5b1 4411->4415 4416 7ff7b85ba5bb-7ff7b85ba5cd GetFileAttributesExW 4411->4416 4413->4404 4413->4414 4414->4404 4415->4416 4420 7ff7b85ba5b3-7ff7b85ba5b5 4415->4420 4421 7ff7b85ba620-7ff7b85ba62f 4416->4421 4422 7ff7b85ba5cf-7ff7b85ba5d8 GetLastError 4416->4422 4420->4410 4420->4416 4426 7ff7b85ba633-7ff7b85ba635 4421->4426 4422->4408 4425 7ff7b85ba5de-7ff7b85ba5f0 FindFirstFileW 4422->4425 4429 7ff7b85ba77f-7ff7b85ba788 4423->4429 4430 7ff7b85ba6cd-7ff7b85ba6e5 GetFileInformationByHandleEx 4423->4430 4427 7ff7b85ba6a9-7ff7b85ba6b1 CloseHandle 4424->4427 4428 7ff7b85ba6b7-7ff7b85ba6b9 4424->4428 4431 7ff7b85ba5f2-7ff7b85ba5f8 GetLastError 4425->4431 4432 7ff7b85ba5fd-7ff7b85ba61e FindClose 4425->4432 4433 7ff7b85ba641-7ff7b85ba66f 4426->4433 4434 7ff7b85ba637-7ff7b85ba63f 4426->4434 4427->4428 4435 7ff7b85ba830-7ff7b85ba836 abort 4427->4435 4428->4408 4436 7ff7b85ba78a-7ff7b85ba79e GetFileInformationByHandleEx 4429->4436 4437 7ff7b85ba7dd-7ff7b85ba7df 4429->4437 4438 7ff7b85ba710-7ff7b85ba729 4430->4438 4439 7ff7b85ba6e7-7ff7b85ba6f3 GetLastError 4430->4439 4431->4408 4432->4426 4433->4406 4433->4410 4434->4410 4434->4433 4440 7ff7b85ba837-7ff7b85ba83c 4435->4440 4441 7ff7b85ba7a0-7ff7b85ba7ac GetLastError 4436->4441 4442 7ff7b85ba7ca-7ff7b85ba7da 4436->4442 4445 7ff7b85ba7e1-7ff7b85ba7e5 4437->4445 4446 7ff7b85ba81d-7ff7b85ba821 4437->4446 4438->4429 4447 7ff7b85ba72b-7ff7b85ba72f 4438->4447 4443 7ff7b85ba6f5-7ff7b85ba700 CloseHandle 4439->4443 4444 7ff7b85ba709-7ff7b85ba70b 4439->4444 4440->4408 4441->4444 4449 7ff7b85ba7b2-7ff7b85ba7bd CloseHandle 4441->4449 4442->4437 4443->4444 4450 7ff7b85ba702-7ff7b85ba708 abort 4443->4450 4444->4408 4445->4406 4451 7ff7b85ba7e7-7ff7b85ba7f2 CloseHandle 4445->4451 4446->4440 4448 7ff7b85ba823-7ff7b85ba82e CloseHandle 4446->4448 4452 7ff7b85ba731-7ff7b85ba74b GetFileInformationByHandleEx 4447->4452 4453 7ff7b85ba778 4447->4453 4448->4435 4448->4440 4449->4444 4455 7ff7b85ba7c3-7ff7b85ba7c9 abort 4449->4455 4450->4444 4451->4406 4451->4435 4456 7ff7b85ba76f-7ff7b85ba776 4452->4456 4457 7ff7b85ba74d-7ff7b85ba759 GetLastError 4452->4457 4454 7ff7b85ba77c 4453->4454 4454->4429 4455->4442 4456->4454 4457->4444 4458 7ff7b85ba75b-7ff7b85ba766 CloseHandle 4457->4458 4458->4444 4459 7ff7b85ba768-7ff7b85ba76e abort 4458->4459 4459->4456
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: Close$ErrorFileFindHandleLast$AttributesFirst__std_fs_open_handleabort
    • String ID:
    • API String ID: 4293554670-0
    • Opcode ID: 44e7e6355c3c3b4b5313ce6daddb476d4210d714f126fdf26df65ff8189d85fc
    • Instruction ID: e28a5131d78daef7290056cd502bf1de29348d053dd3268a5011e2d6da352024
    • Opcode Fuzzy Hash: 44e7e6355c3c3b4b5313ce6daddb476d4210d714f126fdf26df65ff8189d85fc
    • Instruction Fuzzy Hash: 9D91A831A0DA4242E765AF1DA404679E2A0AF76774F980730FB6E477D8DE3CE4478724
    APIs
      • Part of subcall function 00007FF7B85AE060: ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z.MSVCP140 ref: 00007FF7B85AE080
      • Part of subcall function 00007FF7B85AE060: ??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z.MSVCP140 ref: 00007FF7B85AE0D6
      • Part of subcall function 00007FF7B85AE060: ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z.MSVCP140 ref: 00007FF7B85AE0F2
      • Part of subcall function 00007FF7B85AE060: ??Bid@locale@std@@QEAA_KXZ.MSVCP140 ref: 00007FF7B85AE102
      • Part of subcall function 00007FF7B85AE060: ?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z.MSVCP140 ref: 00007FF7B85AE111
      • Part of subcall function 00007FF7B85AE060: ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z.MSVCP140 ref: 00007FF7B85AE125
    • ?_Random_device@std@@YAIXZ.MSVCP140 ref: 00007FF7B85935A8
      • Part of subcall function 00007FF7B85B2150: _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B85B2358
      • Part of subcall function 00007FF7B85B2150: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7B85B2365
    • _Query_perf_frequency.MSVCP140 ref: 00007FF7B85938AB
    • _Query_perf_counter.MSVCP140 ref: 00007FF7B85938B4
    • log.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FF7B8593B7B
    • cos.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FF7B8593B87
    • sin.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FF7B8593B93
    • exp.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FF7B8593BA4
    • pow.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FF7B8593C03
    • tan.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FF7B8593C5E
      • Part of subcall function 00007FF7B85BA968: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF7B85B18F5), ref: 00007FF7B85BA982
    • memset.VCRUNTIME140 ref: 00007FF7B8593D28
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B859429A
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B85942A1
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B8594319
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$Locimp@locale@std@@$??0?$codecvt@_??4?$_Addfac@_Bid@locale@std@@Concurrency::cancel_current_taskD@std@@Init@locale@std@@Locimp@12@_Locimp@_Mbstatet@@@std@@New_Query_perf_counterQuery_perf_frequencyRandom_device@std@@V01@V123@V123@@Vfacet@23@_Yarn@mallocmemset
    • String ID: random
    • API String ID: 1122477867-373021397
    • Opcode ID: 0ec0e44b6cb64bfae8980dab31b6c5ea032862682337bbb87f8200897a804dee
    • Instruction ID: 79dc7000348390b0d9858113d79d37040f6310f58184f2b18a48be9b45e84163
    • Opcode Fuzzy Hash: 0ec0e44b6cb64bfae8980dab31b6c5ea032862682337bbb87f8200897a804dee
    • Instruction Fuzzy Hash: 91920432A0CA4186EB119F38D4111BDE361BFEA794F909336E74E67B99DF38E4428314
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID:
    • String ID: d$random
    • API String ID: 0-2911377361
    • Opcode ID: 49cc911175f5e0541264c47f7475ff60a416648821aaa9eb7b0ba933c28aea12
    • Instruction ID: 220e3c0499fa8345907a202d0735b7e593929b96d5eb4e30dbc0ec7b80005c9f
    • Opcode Fuzzy Hash: 49cc911175f5e0541264c47f7475ff60a416648821aaa9eb7b0ba933c28aea12
    • Instruction Fuzzy Hash: 4E22FC22E1C6C145E7219B7890517B9E351FFB7390F908336E78A67B8ADF38D4428B14
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID:
    • String ID: d$random
    • API String ID: 0-2911377361
    • Opcode ID: 6dbbad9deedadab13af357d3875e2cd51114ef503c27700929a8e952d94335ff
    • Instruction ID: 084964f2d98c1cf837676750b9dc3b5a4eebeae1d4f6a53a1c5bcd71055b1fad
    • Opcode Fuzzy Hash: 6dbbad9deedadab13af357d3875e2cd51114ef503c27700929a8e952d94335ff
    • Instruction Fuzzy Hash: 4722FB22A1CAC185D721AB38D0513B9E295FFB7390F509335E7DA67B8ADF38E4428714

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
    • String ID:
    • API String ID: 313767242-0
    • Opcode ID: 19b8450d50022a509fbeeb78ade14be2cd2f4d19ae30be10dbf0b2131a84a497
    • Instruction ID: b5c6af87762148c8d43bff0bf2e4c290c02dffa7fc3d5f9af756c483ac1f04ae
    • Opcode Fuzzy Hash: 19b8450d50022a509fbeeb78ade14be2cd2f4d19ae30be10dbf0b2131a84a497
    • Instruction Fuzzy Hash: 6F31A372608B8185EB609F65E8403EDB364FBA5344F84403AEB8E43B98EF7CC149C724

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 7187 7ff7b85943e0-7ff7b8594443 SHGetFolderPathA 7188 7ff7b85945e5-7ff7b8594600 call 7ff7b85b11f0 7187->7188 7189 7ff7b8594449-7ff7b859445f 7187->7189 7193 7ff7b8594605-7ff7b8594633 call 7ff7b85ba940 7188->7193 7190 7ff7b8594466-7ff7b859446d 7189->7190 7190->7190 7192 7ff7b859446f-7ff7b85944a9 call 7ff7b85b11f0 7190->7192 7198 7ff7b85944b0-7ff7b85944b7 7192->7198 7198->7198 7199 7ff7b85944b9-7ff7b85944d2 7198->7199 7200 7ff7b8594558 7199->7200 7201 7ff7b85944d8-7ff7b85944db 7199->7201 7202 7ff7b859455f-7ff7b859459b call 7ff7b85b11f0 7200->7202 7201->7200 7203 7ff7b85944e1-7ff7b8594507 memset 7201->7203 7211 7ff7b85945d2-7ff7b85945e3 7202->7211 7212 7ff7b859459d-7ff7b85945af 7202->7212 7205 7ff7b8594520-7ff7b859453e 7203->7205 7206 7ff7b8594509 7203->7206 7209 7ff7b8594540-7ff7b8594543 7205->7209 7210 7ff7b8594553-7ff7b8594556 7205->7210 7208 7ff7b8594510-7ff7b859451e 7206->7208 7208->7205 7208->7208 7209->7200 7213 7ff7b8594545-7ff7b8594551 7209->7213 7210->7202 7211->7193 7214 7ff7b85945b1-7ff7b85945c4 7212->7214 7215 7ff7b85945cd call 7ff7b85ba960 7212->7215 7213->7209 7213->7210 7214->7215 7216 7ff7b85945c6-7ff7b85945cc _invalid_parameter_noinfo_noreturn 7214->7216 7215->7211 7216->7215
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: FolderPath_invalid_parameter_noinfo_noreturnmemset
    • String ID: Failed to get AppData path.$L$\
    • API String ID: 1486729589-1473829883
    • Opcode ID: 48d7c37734061eddc4afed10d7cae08c14a93a7514c1b379dfaca0f549b88086
    • Instruction ID: 1355b99d7661323541aa10d5c6a789105ae31b53b185686ca249acf6d0c82d61
    • Opcode Fuzzy Hash: 48d7c37734061eddc4afed10d7cae08c14a93a7514c1b379dfaca0f549b88086
    • Instruction Fuzzy Hash: 2051E922A1CBC185E7509B29E4403AAE761FF663A4F905331FBAD02AD9DF3CE585C714
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
    • String ID:
    • API String ID: 2933794660-0
    • Opcode ID: 25896374efde6f4be44b9769546b532beb04d45f9bf927e805304f4314b9ef4c
    • Instruction ID: 9e770e77bc6f82ee776d50fb76ece05922c342abaab4f4e0b14cfeb093e2f99c
    • Opcode Fuzzy Hash: 25896374efde6f4be44b9769546b532beb04d45f9bf927e805304f4314b9ef4c
    • Instruction Fuzzy Hash: E1112132B18F018AEB40DF64E8542B8B3A4FB69758F440E31EB5D467A8DF7CD1958750
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: FormatInfoLocaleMessage
    • String ID: !x-sys-default-locale
    • API String ID: 4235545615-2729719199
    • Opcode ID: 80a4920f6669cba734518a6d54b8e5416cb3d2bb96b06634253721d9f0ddd4a7
    • Instruction ID: 5c5895639a5fec5cf3645aca3beaf60e8c7fac46ce701392adce5912f014f09b
    • Opcode Fuzzy Hash: 80a4920f6669cba734518a6d54b8e5416cb3d2bb96b06634253721d9f0ddd4a7
    • Instruction Fuzzy Hash: 3701A172A0C78182F7129F16B40476AE6A1FFB6784F988035EB4A06B9CCF3CD5468714
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 4de8fce81377e9415410f09b23be406b82806a22b0efd7ee3483ee5ff1d55997
    • Instruction ID: 65fb329b46af92cb7414a42c41cc408c664081e12c0a0b5ff1d1914954befc33
    • Opcode Fuzzy Hash: 4de8fce81377e9415410f09b23be406b82806a22b0efd7ee3483ee5ff1d55997
    • Instruction Fuzzy Hash: F9C1E173B2969587EB16CF16D944569F762FBE5BD0B85C130EB4A07B88DA3CD802C704
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 19177203c5f7e3e4428810e341f70abb33e4e6660a6a30719f5034a848a6654c
    • Instruction ID: 31e24990ca22fea1e371f589b79ddc0ecb2947c402209cd75dfb987220c7a2f7
    • Opcode Fuzzy Hash: 19177203c5f7e3e4428810e341f70abb33e4e6660a6a30719f5034a848a6654c
    • Instruction Fuzzy Hash: 9A61C422B18B8982DB149F1DE0452A9E361FB7A7D4F949231EB9D57B88EF7CD181C340
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: d406a45ebeab2dfcb8c903a12aa031135c655f79b932f30f18ed0330c4a30bac
    • Instruction ID: a2130766cf03e10fada51f078a0beaecbced90352182c0f258218e3772515adb
    • Opcode Fuzzy Hash: d406a45ebeab2dfcb8c903a12aa031135c655f79b932f30f18ed0330c4a30bac
    • Instruction Fuzzy Hash: 35419433B1554487E78CCE2EC8126AD73A6F7A9304F95C23DEB0AC7385DA359906C744
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 711dc0a1ce752c5b92a8b1a128afaf0d364a680493ec4af0cfb4a8513c4d417a
    • Instruction ID: 12f81120ca61e33c34863f88f9f720d5b688e0a1624fdea41526af3fc1f54d2f
    • Opcode Fuzzy Hash: 711dc0a1ce752c5b92a8b1a128afaf0d364a680493ec4af0cfb4a8513c4d417a
    • Instruction Fuzzy Hash: 35A0012190CC1AD4E744AF19A950170E220BF72300BD40431E64E422A8AE6CA95282A9

    Control-flow Graph

    APIs
    • ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ.MSVCP140 ref: 00007FF7B85AF1DD
    • ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z.MSVCP140 ref: 00007FF7B85AF1FC
    • ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ.MSVCP140 ref: 00007FF7B85AF22E
    • ?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ.MSVCP140 ref: 00007FF7B85AF249
    • ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z.MSVCP140 ref: 00007FF7B85AF273
    • ?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ.MSVCP140 ref: 00007FF7B85AF290
    • _get_stream_buffer_pointers.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FF7B85AF2B7
    • ?getloc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEBA?AVlocale@2@XZ.MSVCP140 ref: 00007FF7B85AF302
      • Part of subcall function 00007FF7B85B0940: ??0_Lockit@std@@QEAA@H@Z.MSVCP140 ref: 00007FF7B85B096D
      • Part of subcall function 00007FF7B85B0940: ??Bid@locale@std@@QEAA_KXZ.MSVCP140 ref: 00007FF7B85B0987
      • Part of subcall function 00007FF7B85B0940: ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ.MSVCP140 ref: 00007FF7B85B09B9
      • Part of subcall function 00007FF7B85B0940: ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z.MSVCP140 ref: 00007FF7B85B09E4
      • Part of subcall function 00007FF7B85B0940: std::_Facet_Register.LIBCPMT ref: 00007FF7B85B09FD
      • Part of subcall function 00007FF7B85B0940: ??1_Lockit@std@@QEAA@XZ.MSVCP140 ref: 00007FF7B85B0A1C
    • ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z.MSVCP140 ref: 00007FF7B85AF317
    • ?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ.MSVCP140 ref: 00007FF7B85AF32E
    • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FF7B85AF370
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: U?$char_traits@$D@std@@@std@@U?$char_traits@_W@std@@@std@@$Init@?$basic_streambuf@_$Lockit@std@@$??0?$basic_ios@??0?$basic_ostream@??0?$basic_streambuf@??0_??1_?getloc@?$basic_streambuf@_?setstate@?$basic_ios@?tolower@?$ctype@Bid@locale@std@@D@std@@D@std@@@1@_Facet_Fiopen@std@@Getcat@?$codecvt@Getgloballocale@locale@std@@Locimp@12@Mbstatet@@@std@@RegisterU_iobuf@@V42@@V?$basic_streambuf@Vfacet@locale@2@Vlocale@2@_get_stream_buffer_pointersstd::_
    • String ID:
    • API String ID: 83113347-0
    • Opcode ID: 23c5f14d9d2920ffdb8e200f91ecf5db91b09fde0a9e379cc2496c2f3c31cd4e
    • Instruction ID: c48bb4aa967e8ea3165ae0ae0ad2b4464d4c18215bf39f602ece877223ae35b0
    • Opcode Fuzzy Hash: 23c5f14d9d2920ffdb8e200f91ecf5db91b09fde0a9e379cc2496c2f3c31cd4e
    • Instruction Fuzzy Hash: E5512A36609B8186EB50DF29E850269B7A4FB9AF88F984035EB8E03718DF3CD056C754

    Control-flow Graph

    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: Locinfo@std@@$??0_??1_Lockit@std@@_invalid_parameter_noinfo_noreturn$??0facet@locale@std@@Bid@locale@std@@Collvec@@Facet_Getcoll@_Getgloballocale@locale@std@@Locimp@12@Registermallocstd::_
    • String ID:
    • API String ID: 1534690320-0
    • Opcode ID: 4225040be45d06bef3bda788dd2bc80e15e155bf0cb59504f001446e5fd6516f
    • Instruction ID: 95211c681dc402309c432150d62a5d7874590860d986d29f3198e10071835498
    • Opcode Fuzzy Hash: 4225040be45d06bef3bda788dd2bc80e15e155bf0cb59504f001446e5fd6516f
    • Instruction Fuzzy Hash: 2B413022A0DA8181EB55AF19E544369E361FFBABD0F844232EB5E03769DF3CD486C714

    Control-flow Graph

    APIs
    • ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ.MSVCP140 ref: 00007FF7B85AF5FE
    • ??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z.MSVCP140 ref: 00007FF7B85AF61D
    • ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ.MSVCP140 ref: 00007FF7B85AF64F
    • ?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ.MSVCP140 ref: 00007FF7B85AF66A
    • ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z.MSVCP140 ref: 00007FF7B85AF694
    • ?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ.MSVCP140 ref: 00007FF7B85AF6B1
    • ?getloc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEBA?AVlocale@2@XZ.MSVCP140 ref: 00007FF7B85AF6D5
      • Part of subcall function 00007FF7B85B0110: ??0_Lockit@std@@QEAA@H@Z.MSVCP140 ref: 00007FF7B85B013D
      • Part of subcall function 00007FF7B85B0110: ??Bid@locale@std@@QEAA_KXZ.MSVCP140 ref: 00007FF7B85B0157
      • Part of subcall function 00007FF7B85B0110: ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ.MSVCP140 ref: 00007FF7B85B0189
      • Part of subcall function 00007FF7B85B0110: ?_Getcat@?$codecvt@_WDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z.MSVCP140 ref: 00007FF7B85B01B4
      • Part of subcall function 00007FF7B85B0110: std::_Facet_Register.LIBCPMT ref: 00007FF7B85B01CD
      • Part of subcall function 00007FF7B85B0110: ??1_Lockit@std@@QEAA@XZ.MSVCP140 ref: 00007FF7B85B01EC
    • ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z.MSVCP140 ref: 00007FF7B85AF6EA
    • ?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ.MSVCP140 ref: 00007FF7B85AF701
    • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FF7B85AF743
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: U?$char_traits@_$W@std@@@std@@$Init@?$basic_streambuf@_$Lockit@std@@$??0?$basic_ios@_??0?$basic_ostream@_??0?$basic_streambuf@_??0_??1_?getloc@?$basic_streambuf@_?setstate@?$basic_ios@?tolower@?$ctype@Bid@locale@std@@D@std@@D@std@@@std@@Facet_Fiopen@std@@Getcat@?$codecvt@_Getgloballocale@locale@std@@Locimp@12@Mbstatet@@@std@@RegisterU?$char_traits@U_iobuf@@V42@@V?$basic_streambuf@_Vfacet@locale@2@Vlocale@2@W@std@@@1@_std::_
    • String ID:
    • API String ID: 2364978435-0
    • Opcode ID: 9c04b9d044b37bafc3c51e5e7a014765b17a55fa6c84eb2a6b0a163aa1681188
    • Instruction ID: 47aadda7fba8eeeb3dd509848e60712a17b066618141633829ad1448113825cb
    • Opcode Fuzzy Hash: 9c04b9d044b37bafc3c51e5e7a014765b17a55fa6c84eb2a6b0a163aa1681188
    • Instruction Fuzzy Hash: 8C415C36A09B4185EB04AF29E854369B7A4FF66F89F988034DB4E03728CF3CD05AC754

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 6878 7ff7b85b0400-7ff7b85b042f 6879 7ff7b85b0430-7ff7b85b0438 6878->6879 6879->6879 6880 7ff7b85b043a-7ff7b85b0449 6879->6880 6881 7ff7b85b0455 6880->6881 6882 7ff7b85b044b-7ff7b85b044e 6880->6882 6884 7ff7b85b0457-7ff7b85b0467 6881->6884 6882->6881 6883 7ff7b85b0450-7ff7b85b0453 6882->6883 6883->6884 6885 7ff7b85b0470-7ff7b85b0482 ?good@ios_base@std@@QEBA_NXZ 6884->6885 6886 7ff7b85b0469-7ff7b85b046f 6884->6886 6887 7ff7b85b04b4-7ff7b85b04ba 6885->6887 6888 7ff7b85b0484-7ff7b85b0493 6885->6888 6886->6885 6889 7ff7b85b04c6-7ff7b85b04df 6887->6889 6890 7ff7b85b04bc-7ff7b85b04c1 6887->6890 6892 7ff7b85b04b2 6888->6892 6893 7ff7b85b0495-7ff7b85b0498 6888->6893 6896 7ff7b85b04e1-7ff7b85b04e4 6889->6896 6897 7ff7b85b050f-7ff7b85b052a ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z 6889->6897 6895 7ff7b85b057e-7ff7b85b059c ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?uncaught_exceptions@std@@YAHXZ 6890->6895 6892->6887 6893->6892 6894 7ff7b85b049a-7ff7b85b04b0 ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?good@ios_base@std@@QEBA_NXZ 6893->6894 6894->6887 6898 7ff7b85b05a8-7ff7b85b05b8 6895->6898 6899 7ff7b85b059e-7ff7b85b05a7 ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ 6895->6899 6896->6897 6900 7ff7b85b04e6-7ff7b85b0501 ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z 6896->6900 6901 7ff7b85b0557 6897->6901 6902 7ff7b85b052c 6897->6902 6903 7ff7b85b05c1-7ff7b85b05db 6898->6903 6904 7ff7b85b05ba-7ff7b85b05c0 6898->6904 6899->6898 6905 7ff7b85b0503-7ff7b85b0508 6900->6905 6906 7ff7b85b050a-7ff7b85b050d 6900->6906 6908 7ff7b85b055a 6901->6908 6907 7ff7b85b0530-7ff7b85b0533 6902->6907 6904->6903 6905->6908 6906->6896 6909 7ff7b85b055e-7ff7b85b056e 6907->6909 6910 7ff7b85b0535-7ff7b85b0550 ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z 6907->6910 6908->6909 6909->6895 6910->6901 6912 7ff7b85b0552-7ff7b85b0555 6910->6912 6912->6907
    APIs
    • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF7B85B047A
    • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140 ref: 00007FF7B85B049A
    • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF7B85B04AA
    • ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z.MSVCP140 ref: 00007FF7B85B04F7
    • ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP140 ref: 00007FF7B85B0521
    • ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z.MSVCP140 ref: 00007FF7B85B0546
    • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FF7B85B058D
    • ?uncaught_exceptions@std@@YAHXZ.MSVCP140 ref: 00007FF7B85B0594
    • ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140 ref: 00007FF7B85B05A1
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: D@std@@@std@@U?$char_traits@$?good@ios_base@std@@?sputc@?$basic_streambuf@_U?$char_traits@_W@std@@@std@@$?flush@?$basic_ostream@?setstate@?$basic_ios@?sputn@?$basic_streambuf@?uncaught_exceptions@std@@Osfx@?$basic_ostream@V12@
    • String ID:
    • API String ID: 1082411713-0
    • Opcode ID: 45054d7cc04613a0964733ee300a69212865a64964a28420a2abc5d095f187e7
    • Instruction ID: a0cf43cd2f5fe1f0fd1dd79623423630f467af5cbe5c3fe5fd223c50c9ec86ef
    • Opcode Fuzzy Hash: 45054d7cc04613a0964733ee300a69212865a64964a28420a2abc5d095f187e7
    • Instruction Fuzzy Hash: 79510F26609A4181EB609F1DE5D0239E7A0FFA6F95B55C531EF4E43BA8CE3DD4838324

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 6913 7ff7b85b0890-7ff7b85b0899 6914 7ff7b85b089e-7ff7b85b1e34 6913->6914 6915 7ff7b85b089b 6913->6915 6917 7ff7b85b1e40 6914->6917 6918 7ff7b85b1e36-7ff7b85b1e39 6914->6918 6915->6914 6920 7ff7b85b1e42-7ff7b85b1e52 6917->6920 6918->6917 6919 7ff7b85b1e3b-7ff7b85b1e3e 6918->6919 6919->6920 6921 7ff7b85b1e54-7ff7b85b1e5a 6920->6921 6922 7ff7b85b1e5b-7ff7b85b1e6d ?good@ios_base@std@@QEBA_NXZ 6920->6922 6921->6922 6923 7ff7b85b1e9f-7ff7b85b1ea5 6922->6923 6924 7ff7b85b1e6f-7ff7b85b1e7e 6922->6924 6928 7ff7b85b1eb1-7ff7b85b1ec4 6923->6928 6929 7ff7b85b1ea7-7ff7b85b1eac 6923->6929 6926 7ff7b85b1e80-7ff7b85b1e83 6924->6926 6927 7ff7b85b1e9d 6924->6927 6926->6927 6930 7ff7b85b1e85-7ff7b85b1e9b ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?good@ios_base@std@@QEBA_NXZ 6926->6930 6927->6923 6932 7ff7b85b1ec6-7ff7b85b1ec9 6928->6932 6933 7ff7b85b1ef7-7ff7b85b1f12 ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z 6928->6933 6931 7ff7b85b1f61-7ff7b85b1f7f ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?uncaught_exceptions@std@@YAHXZ 6929->6931 6930->6923 6935 7ff7b85b1f81-7ff7b85b1f8a ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ 6931->6935 6936 7ff7b85b1f8b-7ff7b85b1f9a 6931->6936 6932->6933 6934 7ff7b85b1ecb-7ff7b85b1ee5 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z 6932->6934 6937 7ff7b85b1f14-7ff7b85b1f17 6933->6937 6938 7ff7b85b1f3a-7ff7b85b1f3d 6933->6938 6943 7ff7b85b1ef2-7ff7b85b1ef5 6934->6943 6944 7ff7b85b1ee7-7ff7b85b1ef0 6934->6944 6935->6936 6939 7ff7b85b1fa3-7ff7b85b1fb7 6936->6939 6940 7ff7b85b1f9c-7ff7b85b1fa2 6936->6940 6941 7ff7b85b1f41-7ff7b85b1f51 6937->6941 6942 7ff7b85b1f19-7ff7b85b1f33 ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z 6937->6942 6938->6941 6940->6939 6941->6931 6942->6938 6945 7ff7b85b1f35-7ff7b85b1f38 6942->6945 6943->6932 6944->6937 6945->6937
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: D@std@@@std@@U?$char_traits@$?good@ios_base@std@@$?flush@?$basic_ostream@?setstate@?$basic_ios@?uncaught_exceptions@std@@Osfx@?$basic_ostream@V12@
    • String ID:
    • API String ID: 929054647-0
    • Opcode ID: bb604f6eba23b001b1e28e65976775950ed75e85366b51f5158e4ac13b8c968f
    • Instruction ID: 39bb41e9768f9ca971f464ea60cebf04b9fa11334619c3a216bbbb669fb58f92
    • Opcode Fuzzy Hash: bb604f6eba23b001b1e28e65976775950ed75e85366b51f5158e4ac13b8c968f
    • Instruction Fuzzy Hash: 55510F32A0CA4181EB60AF1DD590638EBA0EFA6F95B558532EF4E47768CF39D4878314

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 6947 7ff7b85b1c30-7ff7b85b1c6a 6948 7ff7b85b1c76 6947->6948 6949 7ff7b85b1c6c-7ff7b85b1c6f 6947->6949 6951 7ff7b85b1c78-7ff7b85b1c88 6948->6951 6949->6948 6950 7ff7b85b1c71-7ff7b85b1c74 6949->6950 6950->6951 6952 7ff7b85b1c91-7ff7b85b1ca3 ?good@ios_base@std@@QEBA_NXZ 6951->6952 6953 7ff7b85b1c8a-7ff7b85b1c90 6951->6953 6954 7ff7b85b1cd5-7ff7b85b1cdb 6952->6954 6955 7ff7b85b1ca5-7ff7b85b1cb4 6952->6955 6953->6952 6956 7ff7b85b1ce7-7ff7b85b1d00 6954->6956 6957 7ff7b85b1cdd-7ff7b85b1ce2 6954->6957 6959 7ff7b85b1cb6-7ff7b85b1cb9 6955->6959 6960 7ff7b85b1cd3 6955->6960 6962 7ff7b85b1d02-7ff7b85b1d05 6956->6962 6963 7ff7b85b1d34-7ff7b85b1d4f ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z 6956->6963 6961 7ff7b85b1d9f-7ff7b85b1dbd ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ?uncaught_exceptions@std@@YAHXZ 6957->6961 6959->6960 6964 7ff7b85b1cbb-7ff7b85b1cd1 ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?good@ios_base@std@@QEBA_NXZ 6959->6964 6960->6954 6968 7ff7b85b1dbf-7ff7b85b1dc8 ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ 6961->6968 6969 7ff7b85b1dc9-7ff7b85b1dd8 6961->6969 6962->6963 6965 7ff7b85b1d07-7ff7b85b1d22 ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z 6962->6965 6966 7ff7b85b1d51-7ff7b85b1d54 6963->6966 6967 7ff7b85b1d78-7ff7b85b1d7b 6963->6967 6964->6954 6970 7ff7b85b1d2f-7ff7b85b1d32 6965->6970 6971 7ff7b85b1d24-7ff7b85b1d2d 6965->6971 6972 7ff7b85b1d7f-7ff7b85b1d8f 6966->6972 6973 7ff7b85b1d56-7ff7b85b1d71 ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z 6966->6973 6967->6972 6968->6969 6974 7ff7b85b1de1-7ff7b85b1dfb 6969->6974 6975 7ff7b85b1dda-7ff7b85b1de0 6969->6975 6970->6962 6971->6966 6972->6961 6973->6967 6976 7ff7b85b1d73-7ff7b85b1d76 6973->6976 6975->6974 6976->6966
    APIs
    • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF7B85B1C9B
    • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ.MSVCP140 ref: 00007FF7B85B1CBB
    • ?good@ios_base@std@@QEBA_NXZ.MSVCP140 ref: 00007FF7B85B1CCB
    • ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z.MSVCP140 ref: 00007FF7B85B1D18
    • ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z.MSVCP140 ref: 00007FF7B85B1D46
    • ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z.MSVCP140 ref: 00007FF7B85B1D67
    • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z.MSVCP140 ref: 00007FF7B85B1DAE
    • ?uncaught_exceptions@std@@YAHXZ.MSVCP140 ref: 00007FF7B85B1DB5
    • ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ.MSVCP140 ref: 00007FF7B85B1DC2
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: D@std@@@std@@U?$char_traits@$?good@ios_base@std@@?sputc@?$basic_streambuf@_U?$char_traits@_W@std@@@std@@$?flush@?$basic_ostream@?setstate@?$basic_ios@?sputn@?$basic_streambuf@?uncaught_exceptions@std@@Osfx@?$basic_ostream@V12@
    • String ID:
    • API String ID: 1082411713-0
    • Opcode ID: 0d5ec328a8f88ad9dde88304c696be7adf3c733013d7e46863af4980d22f23f1
    • Instruction ID: 75d89369cb79b1973639328f1a2b3fe6f1c9c3e48c67fb0397170da1f07c3e28
    • Opcode Fuzzy Hash: 0d5ec328a8f88ad9dde88304c696be7adf3c733013d7e46863af4980d22f23f1
    • Instruction Fuzzy Hash: 04510F3264CA8185EB609F1EE590239EBA0FFA6F85B558431EF4E47768CE3DD4478318

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 6989 7ff7b85af760-7ff7b85af7cc 6990 7ff7b85af7d2-7ff7b85af7ec 6989->6990 6991 7ff7b85af7ce 6989->6991 6992 7ff7b85af7f2-7ff7b85af7f6 6990->6992 6993 7ff7b85afadb-7ff7b85afaf1 6990->6993 6991->6990 6996 7ff7b85af800-7ff7b85af844 ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z 6992->6996 6994 7ff7b85afa1f-7ff7b85afa41 call 7ff7b85ba940 6993->6994 6995 7ff7b85afaf7-7ff7b85afb05 6993->6995 6998 7ff7b85afa1a call 7ff7b85ba960 6995->6998 6999 7ff7b85afb0b-7ff7b85afb1e 6995->6999 7000 7ff7b85af8b1-7ff7b85af8b8 6996->7000 7001 7ff7b85af846-7ff7b85af849 6996->7001 6998->6994 6999->6998 7003 7ff7b85afb24-7ff7b85afb2a _invalid_parameter_noinfo_noreturn 6999->7003 7004 7ff7b85af8ba-7ff7b85af8ca 7000->7004 7005 7ff7b85af917-7ff7b85af91f 7000->7005 7001->7000 7006 7ff7b85af84b-7ff7b85af84e 7001->7006 7008 7ff7b85afb2b-7ff7b85afb30 call 7ff7b8591980 7003->7008 7009 7ff7b85af8fd-7ff7b85af915 call 7ff7b85b1060 7004->7009 7010 7ff7b85af8cc-7ff7b85af8fb memcpy 7004->7010 7011 7ff7b85afa42-7ff7b85afa47 7005->7011 7012 7ff7b85af925-7ff7b85af933 7005->7012 7013 7ff7b85af993-7ff7b85af998 7006->7013 7014 7ff7b85af854-7ff7b85af85b 7006->7014 7015 7ff7b85afb31-7ff7b85afb56 call 7ff7b8591980 7008->7015 7019 7ff7b85af967 7009->7019 7010->7019 7011->7008 7017 7ff7b85afa4d-7ff7b85afa5e call 7ff7b85aeac0 7011->7017 7021 7ff7b85af935-7ff7b85af954 7012->7021 7022 7ff7b85af956-7ff7b85af962 call 7ff7b85b16b0 7012->7022 7013->7015 7016 7ff7b85af99e-7ff7b85af9af call 7ff7b85aeac0 7013->7016 7023 7ff7b85af861-7ff7b85af86c 7014->7023 7024 7ff7b85af96b-7ff7b85af984 7014->7024 7044 7ff7b85afb5f-7ff7b85afb63 7015->7044 7045 7ff7b85afb58-7ff7b85afb5e 7015->7045 7040 7ff7b85af9b1-7ff7b85af9c3 7016->7040 7041 7ff7b85af9e4-7ff7b85af9ec 7016->7041 7042 7ff7b85afa60-7ff7b85afa72 7017->7042 7043 7ff7b85afa96-7ff7b85afa9e 7017->7043 7019->7024 7021->7019 7022->7019 7032 7ff7b85af88e-7ff7b85af892 call 7ff7b85b1540 7023->7032 7033 7ff7b85af86e-7ff7b85af88c 7023->7033 7024->6993 7025 7ff7b85af98a-7ff7b85af98e 7024->7025 7025->6996 7038 7ff7b85af897-7ff7b85af8aa 7032->7038 7033->7038 7038->7023 7039 7ff7b85af8ac 7038->7039 7039->7024 7046 7ff7b85af9c5-7ff7b85af9d8 7040->7046 7047 7ff7b85af9de-7ff7b85af9e3 call 7ff7b85ba960 7040->7047 7041->6994 7050 7ff7b85af9ee-7ff7b85af9ff 7041->7050 7048 7ff7b85afa90-7ff7b85afa95 call 7ff7b85ba960 7042->7048 7049 7ff7b85afa74-7ff7b85afa87 7042->7049 7043->6994 7051 7ff7b85afaa4-7ff7b85afab5 7043->7051 7045->7044 7046->7047 7052 7ff7b85afa89-7ff7b85afa8f _invalid_parameter_noinfo_noreturn 7046->7052 7047->7041 7048->7043 7049->7048 7049->7052 7050->6998 7055 7ff7b85afa01-7ff7b85afa14 7050->7055 7051->6998 7057 7ff7b85afabb-7ff7b85aface 7051->7057 7052->7048 7055->6998 7060 7ff7b85afad4-7ff7b85afada _invalid_parameter_noinfo_noreturn 7055->7060 7057->6998 7057->7060 7060->6993
    APIs
    • ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z.MSVCP140 ref: 00007FF7B85AF83A
    • memcpy.VCRUNTIME140 ref: 00007FF7B85AF8EE
      • Part of subcall function 00007FF7B85B1060: memcpy.VCRUNTIME140(?,?,?,?,?,00007FF7B85AEA0B,?,?,?,?,?,00007FF7B8591B57), ref: 00007FF7B85B114E
      • Part of subcall function 00007FF7B85B1060: memcpy.VCRUNTIME140(?,?,?,?,?,00007FF7B85AEA0B,?,?,?,?,?,00007FF7B8591B57), ref: 00007FF7B85B115C
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B85AFA89
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B85AFAD4
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B85AFB24
    • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7B85AFB2B
    • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7B85AFB31
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturnmemcpy$Concurrency::cancel_current_task$?out@?$codecvt@Mbstatet@@Mbstatet@@@std@@
    • String ID:
    • API String ID: 862015687-0
    • Opcode ID: bd3986c8eac70713546aec029172baba793e63043bb13c5cd23aaf52f6ef5959
    • Instruction ID: 5001f1174580b9e645f0aa87b71d026e64e6fc7e807cad1db28650fb3805d210
    • Opcode Fuzzy Hash: bd3986c8eac70713546aec029172baba793e63043bb13c5cd23aaf52f6ef5959
    • Instruction Fuzzy Hash: 9FB1A462F0CB459AFB00EF69D4842ACA362EF66B98F844231DF5D17B99DE38D446C314

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 7061 7ff7b8592aa0-7ff7b8592b0f call 7ff7b85ba3dc 7064 7ff7b8592b11 7061->7064 7065 7ff7b8592b14-7ff7b8592b42 call 7ff7b85b0220 7061->7065 7064->7065 7068 7ff7b8592b44 7065->7068 7069 7ff7b8592b47-7ff7b8592b90 call 7ff7b85b0220 7065->7069 7068->7069 7072 7ff7b8592b92-7ff7b8592ba1 call 7ff7b85b0f10 7069->7072 7073 7ff7b8592ba5-7ff7b8592be0 call 7ff7b85b0370 * 2 call 7ff7b85ae980 7069->7073 7072->7073 7082 7ff7b8592c60-7ff7b8592c6b 7073->7082 7083 7ff7b8592be2-7ff7b8592c20 call 7ff7b85b0370 7073->7083 7085 7ff7b8592c89-7ff7b8592c94 call 7ff7b85b1540 7082->7085 7086 7ff7b8592c6d-7ff7b8592c7c 7082->7086 7092 7ff7b8592c50-7ff7b8592c5b call 7ff7b85b1060 7083->7092 7093 7ff7b8592c22-7ff7b8592c31 7083->7093 7094 7ff7b8592c95-7ff7b8592c9d 7085->7094 7089 7ff7b8592c81-7ff7b8592c87 7086->7089 7090 7ff7b8592c7e 7086->7090 7089->7094 7090->7089 7092->7082 7097 7ff7b8592c33 7093->7097 7098 7ff7b8592c36-7ff7b8592c4e memcpy 7093->7098 7095 7ff7b8592c9f-7ff7b8592cb0 7094->7095 7096 7ff7b8592cd3-7ff7b8592ceb 7094->7096 7100 7ff7b8592cb2-7ff7b8592cc5 7095->7100 7101 7ff7b8592cce call 7ff7b85ba960 7095->7101 7102 7ff7b8592d21-7ff7b8592d4b call 7ff7b85ba940 7096->7102 7103 7ff7b8592ced-7ff7b8592cfe 7096->7103 7097->7098 7098->7082 7100->7101 7104 7ff7b8592cc7-7ff7b8592ccd _invalid_parameter_noinfo_noreturn 7100->7104 7101->7096 7106 7ff7b8592d00-7ff7b8592d13 7103->7106 7107 7ff7b8592d1c call 7ff7b85ba960 7103->7107 7104->7101 7106->7107 7110 7ff7b8592d15-7ff7b8592d1b _invalid_parameter_noinfo_noreturn 7106->7110 7107->7102 7110->7107
    APIs
    • __std_fs_code_page.MSVCPRT ref: 00007FF7B8592AFF
      • Part of subcall function 00007FF7B85BA3DC: ___lc_codepage_func.API-MS-WIN-CRT-LOCALE-L1-1-0(?,?,?,?,00007FF7B8592B04), ref: 00007FF7B85BA3E0
      • Part of subcall function 00007FF7B85BA3DC: AreFileApisANSI.KERNEL32(?,?,?,?,00007FF7B8592B04), ref: 00007FF7B85BA3EF
    • memcpy.VCRUNTIME140 ref: 00007FF7B8592C40
      • Part of subcall function 00007FF7B85B1060: memcpy.VCRUNTIME140(?,?,?,?,?,00007FF7B85AEA0B,?,?,?,?,?,00007FF7B8591B57), ref: 00007FF7B85B114E
      • Part of subcall function 00007FF7B85B1060: memcpy.VCRUNTIME140(?,?,?,?,?,00007FF7B85AEA0B,?,?,?,?,?,00007FF7B8591B57), ref: 00007FF7B85B115C
      • Part of subcall function 00007FF7B85B1540: memcpy.VCRUNTIME140 ref: 00007FF7B85B1622
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B8592CC7
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B8592D15
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: memcpy$_invalid_parameter_noinfo_noreturn$ApisFile___lc_codepage_func__std_fs_code_page
    • String ID: ", "$: "
    • API String ID: 217746928-747220369
    • Opcode ID: 8af38dd4572e12346a7e861e0e5c0b37005e29a69315350ea585c524d2d42072
    • Instruction ID: f874b0f36fb3e4b7b8c7d555fddd2b2499c1200fb7aa784c677de0d6a48278c1
    • Opcode Fuzzy Hash: 8af38dd4572e12346a7e861e0e5c0b37005e29a69315350ea585c524d2d42072
    • Instruction Fuzzy Hash: 63817E62B08B4596EB00EF69E1803ACA376FB69B88F804531EF5D17B99DF38D056C354

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 7150 7ff7b85acb80-7ff7b85acbb5 7151 7ff7b85acbe4-7ff7b85acbec 7150->7151 7152 7ff7b85acbb7-7ff7b85acbc5 7150->7152 7154 7ff7b85acbf8-7ff7b85acc03 7151->7154 7155 7ff7b85acbee-7ff7b85acbf3 7151->7155 7152->7151 7153 7ff7b85acbc7-7ff7b85acbdf 7152->7153 7156 7ff7b85ace30-7ff7b85ace54 call 7ff7b85ba940 7153->7156 7157 7ff7b85acc05-7ff7b85acc27 7154->7157 7158 7ff7b85acc29-7ff7b85acc35 7154->7158 7155->7156 7157->7158 7160 7ff7b85acc53-7ff7b85acc7a fgetc 7158->7160 7161 7ff7b85acc37-7ff7b85acc45 fgetwc 7158->7161 7162 7ff7b85acc80-7ff7b85acc8b 7160->7162 7163 7ff7b85acd85 7160->7163 7165 7ff7b85ace2d 7161->7165 7166 7ff7b85acc4b-7ff7b85acc4e 7161->7166 7167 7ff7b85accad-7ff7b85accb5 call 7ff7b85b1540 7162->7167 7168 7ff7b85acc8d-7ff7b85accab 7162->7168 7169 7ff7b85acd8a-7ff7b85acd92 7163->7169 7165->7156 7166->7165 7170 7ff7b85accba-7ff7b85acd11 ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z 7167->7170 7168->7170 7169->7165 7172 7ff7b85acd98-7ff7b85acda9 7169->7172 7173 7ff7b85acd13-7ff7b85acd16 7170->7173 7174 7ff7b85acd1c-7ff7b85acd2c 7170->7174 7175 7ff7b85ace28 call 7ff7b85ba960 7172->7175 7176 7ff7b85acdab-7ff7b85acdbe 7172->7176 7173->7174 7178 7ff7b85acdc7-7ff7b85acdca 7173->7178 7179 7ff7b85acd32-7ff7b85acd7f memcpy fgetc 7174->7179 7180 7ff7b85acddf-7ff7b85acdf6 7174->7180 7175->7165 7176->7175 7181 7ff7b85acdc0-7ff7b85acdc6 _invalid_parameter_noinfo_noreturn 7176->7181 7178->7163 7184 7ff7b85acdcc-7ff7b85acddd 7178->7184 7179->7162 7179->7163 7182 7ff7b85ace1f-7ff7b85ace23 7180->7182 7183 7ff7b85acdf8 7180->7183 7181->7178 7182->7169 7185 7ff7b85ace00-7ff7b85ace17 ungetc 7183->7185 7184->7169 7185->7182 7186 7ff7b85ace19-7ff7b85ace1d 7185->7186 7186->7185
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: fgetwc
    • String ID:
    • API String ID: 2948136663-0
    • Opcode ID: bc5e876cd2a5ddaed97cc61b231dacbb275866b132a4b32473fa302d2f519a40
    • Instruction ID: 82585a7786a3c26e351a59b8ecbdb5e9cf7c8c2ced875c473e431a2e56bafd55
    • Opcode Fuzzy Hash: bc5e876cd2a5ddaed97cc61b231dacbb275866b132a4b32473fa302d2f519a40
    • Instruction Fuzzy Hash: 98819E22B18A8189EB109F69D0803BCB7B0FB69758F840532DF5E5BB98DF38D995C354

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 7112 7ff7b85abed0-7ff7b85abf05 7113 7ff7b85abf33-7ff7b85abf3b 7112->7113 7114 7ff7b85abf07-7ff7b85abf15 7112->7114 7116 7ff7b85abf47-7ff7b85abf52 7113->7116 7117 7ff7b85abf3d-7ff7b85abf42 7113->7117 7114->7113 7115 7ff7b85abf17-7ff7b85abf2e 7114->7115 7118 7ff7b85ac17f-7ff7b85ac1a3 call 7ff7b85ba940 7115->7118 7119 7ff7b85abf74-7ff7b85abf80 7116->7119 7120 7ff7b85abf54-7ff7b85abf72 7116->7120 7117->7118 7122 7ff7b85abf82-7ff7b85abf90 fgetc 7119->7122 7123 7ff7b85abf9e-7ff7b85abfc5 fgetc 7119->7123 7120->7119 7125 7ff7b85abf96-7ff7b85abf99 7122->7125 7126 7ff7b85ac17d 7122->7126 7127 7ff7b85ac0d5 7123->7127 7128 7ff7b85abfcb 7123->7128 7125->7126 7126->7118 7130 7ff7b85ac0da-7ff7b85ac0e2 7127->7130 7129 7ff7b85abfd0-7ff7b85abfdb 7128->7129 7131 7ff7b85abffd-7ff7b85ac005 call 7ff7b85b1540 7129->7131 7132 7ff7b85abfdd-7ff7b85abffb 7129->7132 7130->7126 7133 7ff7b85ac0e8-7ff7b85ac0f9 7130->7133 7134 7ff7b85ac00a-7ff7b85ac061 ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z 7131->7134 7132->7134 7136 7ff7b85ac178 call 7ff7b85ba960 7133->7136 7137 7ff7b85ac0fb-7ff7b85ac10e 7133->7137 7138 7ff7b85ac063-7ff7b85ac066 7134->7138 7139 7ff7b85ac06c-7ff7b85ac07c 7134->7139 7136->7126 7137->7136 7141 7ff7b85ac110-7ff7b85ac116 _invalid_parameter_noinfo_noreturn 7137->7141 7138->7139 7142 7ff7b85ac117-7ff7b85ac11a 7138->7142 7143 7ff7b85ac082-7ff7b85ac0cf memcpy fgetc 7139->7143 7144 7ff7b85ac12f-7ff7b85ac146 7139->7144 7141->7142 7142->7127 7147 7ff7b85ac11c-7ff7b85ac12d 7142->7147 7143->7127 7143->7129 7145 7ff7b85ac16f-7ff7b85ac173 7144->7145 7146 7ff7b85ac148 7144->7146 7145->7130 7148 7ff7b85ac150-7ff7b85ac167 ungetc 7146->7148 7147->7130 7148->7145 7149 7ff7b85ac169-7ff7b85ac16d 7148->7149 7149->7148
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: fgetc
    • String ID:
    • API String ID: 2807381905-0
    • Opcode ID: 16552ad37d9e7cabf55b3e3cc75e6a2ff078bb4e2370f03920dd24fe909c6b95
    • Instruction ID: c7e273c63541701e3531004e3232960a42c29d32f17f416cf7edfc1cb0411e1a
    • Opcode Fuzzy Hash: 16552ad37d9e7cabf55b3e3cc75e6a2ff078bb4e2370f03920dd24fe909c6b95
    • Instruction Fuzzy Hash: EE91A132B18A4189EB009F69D4803ACB7B0FB69768F940632DF5D57B98DF38D496C760
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: __scrt_acquire_startup_lock__scrt_get_show_window_mode__scrt_release_startup_lock_cexit_exit_get_narrow_winmain_command_line_register_thread_local_exe_atexit_callback
    • String ID:
    • API String ID: 3995423050-0
    • Opcode ID: 8cd200ff3fb6af25363896647357835655dc0060ded9db8e5413d661c60862be
    • Instruction ID: 87930cb00d7e8f201ed8215d2e02a3d2f6c90d883a4f2e8959bfae415f583357
    • Opcode Fuzzy Hash: 8cd200ff3fb6af25363896647357835655dc0060ded9db8e5413d661c60862be
    • Instruction Fuzzy Hash: 04313820A0E24256FB12BF6C95522B9E281AF73344FC40434F74D0B3DBDE6CA84A8279
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: Lockit@std@@$??0_??1_Bid@locale@std@@Concurrency::cancel_current_taskFacet_Getcat@?$codecvt@Getgloballocale@locale@std@@Locimp@12@Mbstatet@@@std@@RegisterV42@@Vfacet@locale@2@std::_
    • String ID:
    • API String ID: 762505753-0
    • Opcode ID: ec5f6a21aabe5f9c8435868cf51c71f3e6cb25a39774f1962e251aade7b4fb19
    • Instruction ID: 303ebd283ea819e2e6da30c63ad7107741bb27940f4b3255e70d0981a93134a1
    • Opcode Fuzzy Hash: ec5f6a21aabe5f9c8435868cf51c71f3e6cb25a39774f1962e251aade7b4fb19
    • Instruction Fuzzy Hash: 66312F2660CB4585EB14AF19E480169E360FFB9B94F884631EB9E07769DF3CE492C724
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: Lockit@std@@$??0_??1_Bid@locale@std@@Concurrency::cancel_current_taskD@std@@Facet_Getcat@?$ctype@Getgloballocale@locale@std@@Locimp@12@RegisterV42@@Vfacet@locale@2@std::_
    • String ID:
    • API String ID: 3790006010-0
    • Opcode ID: b69f92b5355667ebdc3ce19b389c52e9cfeac78d885bf03dc3f624fafab4667e
    • Instruction ID: f3b6c624be7437075cc867be5ccd9e2d4606fc0e0cc3e5a872103cce77e165e2
    • Opcode Fuzzy Hash: b69f92b5355667ebdc3ce19b389c52e9cfeac78d885bf03dc3f624fafab4667e
    • Instruction Fuzzy Hash: 4231822160CA4581EB14AF19E890169F760FFA9B94F880631EB8E0776CCF3CE482C724
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: Lockit@std@@$??0_??1_Bid@locale@std@@Concurrency::cancel_current_taskFacet_Getcat@?$codecvt@_Getgloballocale@locale@std@@Locimp@12@Mbstatet@@@std@@RegisterV42@@Vfacet@locale@2@std::_
    • String ID:
    • API String ID: 929128910-0
    • Opcode ID: e0bdb12422ee04a853e0566a4f3154f032d1ba6b9776c41d7419da004f2b5f89
    • Instruction ID: d017fb268ac87b49b4bcb7cf3f67e9fca3a1b082f10fecdf39154b40cbd7d91f
    • Opcode Fuzzy Hash: e0bdb12422ee04a853e0566a4f3154f032d1ba6b9776c41d7419da004f2b5f89
    • Instruction Fuzzy Hash: 44312125A0CB4181EB14AF19E880169F360FFB9B94F884531EB9E07769DF3CE592C724
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: memcpy$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 1775671525-0
    • Opcode ID: 0f7efee4358ba090960613f3f0ce7f840aec90c7a7dfc88def75aa78b168393a
    • Instruction ID: d0c418079d587997fa475edeff00b734c197de4a424215d6575b88d7e6efe0c3
    • Opcode Fuzzy Hash: 0f7efee4358ba090960613f3f0ce7f840aec90c7a7dfc88def75aa78b168393a
    • Instruction Fuzzy Hash: 0D41D262719B4195EB10AF19D4442ADE351EF66BE0F940231EB6D077D9DE3CE042C328
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: ?tolower@?$ctype@D@std@@Xbad_alloc@std@@realloc$malloc
    • String ID:
    • API String ID: 2093286772-0
    • Opcode ID: 9a06689949c14d7e461a2d91807c836f04e4942036bc0ee412a77415ea59dab1
    • Instruction ID: c6a4b1d4710be241c263295ff253b5f3f4decfceca56e4051cc1c9ecb103f80e
    • Opcode Fuzzy Hash: 9a06689949c14d7e461a2d91807c836f04e4942036bc0ee412a77415ea59dab1
    • Instruction Fuzzy Hash: 4241A432A08A85C7E7159F19E48016DF7A5EFA9B84B548135EB8E03758DF3CE892C324
    APIs
    • memcpy.VCRUNTIME140(?,?,?,?,?,00007FF7B85AEA0B,?,?,?,?,?,00007FF7B8591B57), ref: 00007FF7B85B114E
    • memcpy.VCRUNTIME140(?,?,?,?,?,00007FF7B85AEA0B,?,?,?,?,?,00007FF7B8591B57), ref: 00007FF7B85B115C
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,00007FF7B85AEA0B,?,?,?,?,?,00007FF7B8591B57), ref: 00007FF7B85B1195
    • memcpy.VCRUNTIME140(?,?,?,?,?,00007FF7B85AEA0B,?,?,?,?,?,00007FF7B8591B57), ref: 00007FF7B85B119F
    • memcpy.VCRUNTIME140(?,?,?,?,?,00007FF7B85AEA0B,?,?,?,?,?,00007FF7B8591B57), ref: 00007FF7B85B11AD
    • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7B85B11DF
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: memcpy$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 1775671525-0
    • Opcode ID: b3eafe77f23e340ab0fbbb27909d589890fe0f0ba594e75f2dca38e6e532e1e6
    • Instruction ID: a4350cac0cbfdfe5698047496d5e677ea4f5c5efb185f88ca36eb41667ab9392
    • Opcode Fuzzy Hash: b3eafe77f23e340ab0fbbb27909d589890fe0f0ba594e75f2dca38e6e532e1e6
    • Instruction Fuzzy Hash: 1441D262B0CA4581EF50AF1AA5043A9E351AF36BD4F944631EF6D0B78ADE7CD1439318
    APIs
    • ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z.MSVCP140 ref: 00007FF7B85AE080
      • Part of subcall function 00007FF7B85BA968: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF7B85B18F5), ref: 00007FF7B85BA982
    • ??0?$codecvt@_WDU_Mbstatet@@@std@@QEAA@_K@Z.MSVCP140 ref: 00007FF7B85AE0D6
    • ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z.MSVCP140 ref: 00007FF7B85AE0F2
    • ??Bid@locale@std@@QEAA_KXZ.MSVCP140 ref: 00007FF7B85AE102
    • ?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z.MSVCP140 ref: 00007FF7B85AE111
    • ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z.MSVCP140 ref: 00007FF7B85AE125
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: Locimp@locale@std@@$??0?$codecvt@_??4?$_Addfac@_Bid@locale@std@@D@std@@Init@locale@std@@Locimp@12@_Locimp@_Mbstatet@@@std@@New_V01@V123@V123@@Vfacet@23@_Yarn@malloc
    • String ID:
    • API String ID: 3292048638-0
    • Opcode ID: 0ab8c0a026c0748c62d6012465bef71c9a1080b2537e426b4505b28fce3cc969
    • Instruction ID: b107c59b159cd97f80f49f6fa0a1201b8db962de47f5562c80c36e5ed5da8ea5
    • Opcode Fuzzy Hash: 0ab8c0a026c0748c62d6012465bef71c9a1080b2537e426b4505b28fce3cc969
    • Instruction Fuzzy Hash: F6310F32609B4182DB249F6AE854269F765FBA9F80F548135DB8E03B64DF3CE095C354
    APIs
    • memcpy.VCRUNTIME140 ref: 00007FF7B85BA1D2
      • Part of subcall function 00007FF7B85BA968: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF7B85B18F5), ref: 00007FF7B85BA982
    • ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z.MSVCP140 ref: 00007FF7B85BA1EC
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B85BA2A3
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0 ref: 00007FF7B85BA2E1
    • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7B85BA30B
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$?tolower@?$ctype@Concurrency::cancel_current_taskD@std@@mallocmemcpy
    • String ID:
    • API String ID: 4246367773-0
    • Opcode ID: 0800a9535dcabee4fbfd6a71af2e2be3c79c328b64d21b603466176b62e4baa0
    • Instruction ID: dae6aaf1c0db735e93daed028fe90b45d28dd01ef7d721e7d65de3c4af49166c
    • Opcode Fuzzy Hash: 0800a9535dcabee4fbfd6a71af2e2be3c79c328b64d21b603466176b62e4baa0
    • Instruction Fuzzy Hash: 9B519262F09A4544FB01AFA9D4443BCE361AF66BE4F504635EF6D16B9DDF3890C28214
    APIs
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: __current_exception__current_exception_contextterminate
    • String ID: csm
    • API String ID: 2542180945-1018135373
    • Opcode ID: 4c1ebe9c889d1e24800d80439ee52151d95b01ed3f2a35e328354efeca4202be
    • Instruction ID: bc9ed6c5b92a0c1240d5394d2c2d6133515ea3d514d9760374481db26b601fd0
    • Opcode Fuzzy Hash: 4c1ebe9c889d1e24800d80439ee52151d95b01ed3f2a35e328354efeca4202be
    • Instruction Fuzzy Hash: 8AF04937909B40CAC710AF25E8800AC7364FB69B98F895130FB8D47719CF78D891C310
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: ?tolower@?$ctype@D@std@@
    • String ID:
    • API String ID: 1228470278-0
    • Opcode ID: a97732988279250aba83674aeb871580588b052a58e109c53ee7bb5f94d641bd
    • Instruction ID: 8fafe1dddee27d0bb5be1183d99613bca894bf2e71daa21a6b8f5821f6dcf223
    • Opcode Fuzzy Hash: a97732988279250aba83674aeb871580588b052a58e109c53ee7bb5f94d641bd
    • Instruction Fuzzy Hash: 25C1D622A0C79585EB559F29C450379E7E1EFB6B84F848136EB4D0339ADF2DE492C324
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: _invalid_parameter_noinfo_noreturn$__std_exception_copy__std_exception_destroy
    • String ID:
    • API String ID: 2138705365-0
    • Opcode ID: 6ec470a77b1fa5836db0abaf0a866b6d511d65f451efe17d2563e04f402c7661
    • Instruction ID: 02855f7222143874f736114ef499518b505e0ab79b1153aecf8fb67e8bd20057
    • Opcode Fuzzy Hash: 6ec470a77b1fa5836db0abaf0a866b6d511d65f451efe17d2563e04f402c7661
    • Instruction Fuzzy Hash: EB818F72A09A8691EB04EF2CD48436CA366EF65B88F948031E74D07B6DDF78D8D6C354
    APIs
    • memcpy.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B85912FB), ref: 00007FF7B85B1483
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B85912FB), ref: 00007FF7B85B14D6
    • memcpy.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B85912FB), ref: 00007FF7B85B14E0
    • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7B85B152C
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: memcpy$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 1775671525-0
    • Opcode ID: 437ba9ca0ac64ea12b731dda772070f396b9acd10d8a206341a260d8a852dfd7
    • Instruction ID: 70578bc99182bb275a2200ed4934355a4bf36534b8effcfd0dcd098c406db004
    • Opcode Fuzzy Hash: 437ba9ca0ac64ea12b731dda772070f396b9acd10d8a206341a260d8a852dfd7
    • Instruction Fuzzy Hash: 5641E066B08A4191EB40EF19A10426DE291BF66BF4FD40731EB6D07BD9EE7CE046C318
    APIs
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,00007FF7B85928E6), ref: 00007FF7B85AEB92
      • Part of subcall function 00007FF7B85BA968: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF7B85B18F5), ref: 00007FF7B85BA982
      • Part of subcall function 00007FF7B85918F0: ?_Xlength_error@std@@YAXPEBD@Z.MSVCP140(?,?,?,?,00007FF7B85B12E5,?,?,?,?,00007FF7B85912FB), ref: 00007FF7B85918FB
    • memcpy.VCRUNTIME140(?,?,?,00007FF7B85928E6), ref: 00007FF7B85AEBB3
    • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7B85AEBCF
      • Part of subcall function 00007FF7B8591850: __std_exception_copy.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B85B12EB), ref: 00007FF7B8591894
    • ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ.MSVCP140(?,?,?,?,?,?,?,00007FF7B85928E6), ref: 00007FF7B85AEC41
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: ??1?$basic_streambuf@Concurrency::cancel_current_taskD@std@@@std@@U?$char_traits@Xlength_error@std@@__std_exception_copy_invalid_parameter_noinfo_noreturnmallocmemcpy
    • String ID:
    • API String ID: 676814534-0
    • Opcode ID: c41ff4e6579c01bc50176846254f64b3af41fb1274ed5e0ef75fc1e8cbe97976
    • Instruction ID: 88839f09732908fc1fc1f2446809361fd2a186fcfd00d4366e3c1aef3230bbc9
    • Opcode Fuzzy Hash: c41ff4e6579c01bc50176846254f64b3af41fb1274ed5e0ef75fc1e8cbe97976
    • Instruction Fuzzy Hash: A641A122A0DB4681EB15AF2DE494368E390EF66F94F948131DB6D0B799DE3CD4D38314
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturnmemcpymemset
    • String ID:
    • API String ID: 268977704-0
    • Opcode ID: c37fed9d1c68c0c4a42d17a1c03663e9f90bc4b266fdd5148ccd75485bf01601
    • Instruction ID: 488d99e592529d33af7b666df9c85bb2de020dd2b1052ddd7393c90d6b0a1ccd
    • Opcode Fuzzy Hash: c37fed9d1c68c0c4a42d17a1c03663e9f90bc4b266fdd5148ccd75485bf01601
    • Instruction Fuzzy Hash: EC41E062B0D64181EB50AF1AA500369E395EF2ABD4F944231EF9D0B789DE7CE046C318
    APIs
    • memset.VCRUNTIME140(00000000,00007FF7B85B4527), ref: 00007FF7B85B8EBE
    • memcpy.VCRUNTIME140(00000000,00007FF7B85B4527), ref: 00007FF7B85B8EEC
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(00000000,00007FF7B85B4527), ref: 00007FF7B85B8F55
      • Part of subcall function 00007FF7B85BA968: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,7FFFFFFFFFFFFFFF,00007FF7B85B18F5), ref: 00007FF7B85BA982
    • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7B85B8F62
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturnmallocmemcpymemset
    • String ID:
    • API String ID: 2942768764-0
    • Opcode ID: 33f3f51ee331ee450bf700c08a71ec352e37e0c2b781dab10ece0f125a60a3a4
    • Instruction ID: e9d03eb1b07183e39d1a2bd0a4cf53c60973a722a827daf394aa71db79764031
    • Opcode Fuzzy Hash: 33f3f51ee331ee450bf700c08a71ec352e37e0c2b781dab10ece0f125a60a3a4
    • Instruction Fuzzy Hash: 5841A262709A4585EB14AF29D0442BDE351EF6ABE0F948635EB6D077C8DF3CE056C314
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: memcpy$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 1775671525-0
    • Opcode ID: b418927a2593d1719bd1dc61b1ee6dad147d38ec92ef0896e4b909110860578a
    • Instruction ID: 7f3ecb059630a52481f721f0d4ef23a31e42f9f5e5f35f5fc77133613dde4f89
    • Opcode Fuzzy Hash: b418927a2593d1719bd1dc61b1ee6dad147d38ec92ef0896e4b909110860578a
    • Instruction Fuzzy Hash: F231D421B4D78145EB51AF19A544368E255AF36BD4FD80235EF6D0BBC9DE7CE0428318
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturnmallocmemcpymemset
    • String ID:
    • API String ID: 2942768764-0
    • Opcode ID: bd08c812783b9a6ecf854335eb26d5a4ec54ec3837699574ebcca09e820636e9
    • Instruction ID: 46c0b9bd377077491e3ad044c6c9c4083c6c4cafdb477dcbff5940a8ec2d4eef
    • Opcode Fuzzy Hash: bd08c812783b9a6ecf854335eb26d5a4ec54ec3837699574ebcca09e820636e9
    • Instruction Fuzzy Hash: CA31D36270EA8686EB04EF2995042BCE215EF26BE0F944631EB6D177C9CE6CE047C314
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 80b2574775618b2a953b1da56e956ad3f1442988d985bf29964b0fb6b73cd5bc
    • Instruction ID: 6c5b4b3db9248bdb051d03c28df6f284dd445f602f983c38ee2c255308a5efa9
    • Opcode Fuzzy Hash: 80b2574775618b2a953b1da56e956ad3f1442988d985bf29964b0fb6b73cd5bc
    • Instruction Fuzzy Hash: C451703660CA8185DB109F28E49036DF3A5FB96B94F944136EB9D8B7A8DF3CC849C714
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: memcpy$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 1775671525-0
    • Opcode ID: a4b0fc4bd338293d66df060b2d692fb83dcad7e6df9281e22de21d85f6d2ebbf
    • Instruction ID: 23763e749fb2ab6d1ce982ee88691446e02d19ddd5cc03f3e7fa44fed105ff69
    • Opcode Fuzzy Hash: a4b0fc4bd338293d66df060b2d692fb83dcad7e6df9281e22de21d85f6d2ebbf
    • Instruction Fuzzy Hash: 2841E121B0C64581EA10AF19A58416DE361FF26BF4F944734EB6C07BD9DE7CE052C328
    APIs
    • memcpy.VCRUNTIME140(?,?,00000000,00000004,?,00007FF7B8592BA1), ref: 00007FF7B85B0FEC
    • _invalid_parameter_noinfo_noreturn.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,00000000,00000004,?,00007FF7B8592BA1), ref: 00007FF7B85B1020
    • memcpy.VCRUNTIME140(?,?,00000000,00000004,?,00007FF7B8592BA1), ref: 00007FF7B85B102A
    • Concurrency::cancel_current_task.LIBCPMT ref: 00007FF7B85B1053
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: memcpy$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
    • String ID:
    • API String ID: 1775671525-0
    • Opcode ID: c5d15f9dc8bb5760c0dcedafd9a0af3ba7b9201a5fe4c0a06c58c15f9e8c5fb9
    • Instruction ID: 9ccd083f7dc34901a5248f56c3fe16e0617dc453ee390fc20c8037cd895d5c6f
    • Opcode Fuzzy Hash: c5d15f9dc8bb5760c0dcedafd9a0af3ba7b9201a5fe4c0a06c58c15f9e8c5fb9
    • Instruction Fuzzy Hash: 1931A061B1D78585EF10AF19A5443A8E252BF36BE0F944631EB6D0B7DDDE7CE0428328
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: memcpy$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturnmalloc
    • String ID:
    • API String ID: 1155477157-0
    • Opcode ID: eeaddc8ae32b8eab1d560ada36b05638e19ae3ed09364c8144a7a82f262ba4ac
    • Instruction ID: ad312d2e5d11fe0a0145df2761e8327158720501e91a634dedb8da6ed80230e5
    • Opcode Fuzzy Hash: eeaddc8ae32b8eab1d560ada36b05638e19ae3ed09364c8144a7a82f262ba4ac
    • Instruction Fuzzy Hash: 8531B622A0DB4241EB14AB199550278E291EF26BB0FD44B34DB7D0B7D5DE7CE4D38358
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: memcpy$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturnmalloc
    • String ID:
    • API String ID: 1155477157-0
    • Opcode ID: 97c1cec92591c65101fb74efce355569a34a653934d8d81529aab32ce95c0102
    • Instruction ID: 8c6b837f10bc10eb56a0d091bc2497f1265fc0c0a1669166a3015132b6e63195
    • Opcode Fuzzy Hash: 97c1cec92591c65101fb74efce355569a34a653934d8d81529aab32ce95c0102
    • Instruction Fuzzy Hash: 11313A22B0CB4540EB24AF56A500369E255BF76BE4F840635EF6C077C9EE3CE082C314
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: memcpy$Concurrency::cancel_current_task
    • String ID:
    • API String ID: 326894585-0
    • Opcode ID: 2b3e32f679f3411a96c2b169fd33d6b045a9eec51f056b825c757273bb5d81ba
    • Instruction ID: ed50506c02d2a40e96bf5b831ce4477a65331ed61a12d19b239ec2fd6087b9b8
    • Opcode Fuzzy Hash: 2b3e32f679f3411a96c2b169fd33d6b045a9eec51f056b825c757273bb5d81ba
    • Instruction Fuzzy Hash: 64212922A4D74148EF547F9AA5403B8D150AF367E4F940730EF6D467CAEE7CA0839318
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: ByteCharErrorLastMultiWide
    • String ID:
    • API String ID: 203985260-0
    • Opcode ID: 8b623144414a10440eabf51239d1ed257e13474fb39b30ef0d4b909c3b566fa4
    • Instruction ID: 1c2099bd3654f0d9d2456bbf2b0af1a3463210ce95d04456e57382a22ddc54da
    • Opcode Fuzzy Hash: 8b623144414a10440eabf51239d1ed257e13474fb39b30ef0d4b909c3b566fa4
    • Instruction Fuzzy Hash: B0214C76A1CB4586E3109F15E44432EF6B4FBA9B90F540138EB8953B58CF3DD8468B14
    APIs
    • __std_fs_convert_narrow_to_wide.LIBCPMT ref: 00007FF7B859262D
      • Part of subcall function 00007FF7B85BA404: MultiByteToWideChar.KERNEL32 ref: 00007FF7B85BA420
      • Part of subcall function 00007FF7B85BA404: GetLastError.KERNEL32 ref: 00007FF7B85BA42E
    • __std_fs_convert_narrow_to_wide.LIBCPMT ref: 00007FF7B85926CA
      • Part of subcall function 00007FF7B85B1380: memcpy.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B85912FB), ref: 00007FF7B85B1483
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: __std_fs_convert_narrow_to_wide$ByteCharErrorLastMultiWidememcpy
    • String ID: Unknown exception
    • API String ID: 3269794198-410509341
    • Opcode ID: 875133cdc6b0287577d0eae591c5892374f0de79a45dd11bba635482a2eaf8d3
    • Instruction ID: c97615d83213b822ee133ad7e3e4219afa6492ab3351f355a53b69e9ec6a837a
    • Opcode Fuzzy Hash: 875133cdc6b0287577d0eae591c5892374f0de79a45dd11bba635482a2eaf8d3
    • Instruction Fuzzy Hash: 5331E0A2A1C78A41EB24AF5AD000668E295EF65FC8F905035EF6D07B88DF3CE492C344
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.1964122326.00007FF7B8591000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B8590000, based on PE: true
    • Associated: 00000000.00000002.1964104937.00007FF7B8590000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964157789.00007FF7B85BE000.00000002.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964182926.00007FF7B85C8000.00000004.00000001.01000000.00000003.sdmpDownload File
    • Associated: 00000000.00000002.1964233213.00007FF7B85CC000.00000002.00000001.01000000.00000003.sdmpDownload File
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff7b8590000_SecuriteInfo.jbxd
    Similarity
    • API ID: free
    • String ID:
    • API String ID: 1294909896-0
    • Opcode ID: 5306c08254be4f25b98c8f182cf3566cb9460f253310b9e3e7ebdeb50e1a0d8a
    • Instruction ID: c795b7797a107e888bef5e6757cd5b0126bcf646c0f9319ee9d6e03c20be74fa
    • Opcode Fuzzy Hash: 5306c08254be4f25b98c8f182cf3566cb9460f253310b9e3e7ebdeb50e1a0d8a
    • Instruction Fuzzy Hash: AE212F2560DB4182EB15AF1AE55026AE361EFB5FD0F985031EF8E07B9DDE3CE4428364